Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. technique: T1553 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Manipulation of Crypto Subject Interface Package (SIP) Provider Malicious modification of crypto subject interface package (SIP) provider Registry keys can be leveraged to trick the OS into incorrectly validating invalid signing certificates. May have legitimate uses, but check for malicious activity. Informational Platform Analytics Registry Defense Evasion
BIOC New certificate added to the trusted root store Untrusted certificates could be used to install untrusted drivers and malicious code. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Rare signature signed executable executed in the network Attackers may use signed executables by less known vendors to bypass security features. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Root certificate installed Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system. Informational Platform Analytics Registry Defense Evasion
BIOC Root certificate installed Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system. Informational Platform Analytics Process execution Defense Evasion