kevmap

TechniquesT1553.004 › AN0155

AN0155 Analytic 0155

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection of malicious certificate installation via monitoring execution of the security add-trusted-cert command and modifications to system keychains.</p>
Detects
T1553.004 Install Root Certificate
Part of
DET0056 Detection Strategy for Subvert Trust Controls via Install Root Certificate.

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogExecution of /usr/bin/security add-trusted-cert or keychain modifications to System.keychainDC0064 Command Execution
macos:osqueryquery: Enumeration of root certificates showing unexpected additionsDC0061 File Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MonitoredCommandsCommands related to certificate management (e.g., security, profiles) that can be tuned per environment.
KeychainBaselineBaseline of expected certificates in System.keychain to reduce false positives from legitimate enterprise certificates.