{"id":"T1553","name":"Subvert Trust Controls","url":"https://attack.mitre.org/techniques/T1553","tactics":["defense-impairment"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0452","stix_id":"x-mitre-detection-strategy--73cde34a-247f-4ebc-87a5-ab6a9c400f40","name":"Detect Subversion of Trust Controls via Certificate, Registry, and Attribute Manipulation","url":"https://attack.mitre.org/detectionstrategies/DET0452","analytics":[{"id":"AN1246","stix_id":"x-mitre-analytic--35b0b263-f85d-4e6a-8bcb-5e2c1a9da080","name":"Analytic 1246","description":"Detection correlates abnormal installation or modification of root or code-signing certificates, creation/modification of suspicious registry keys for trust providers, and unusual module loads from non-standard locations. Identifies unsigned or improperly signed executables bypassing trust prompts, combined with persistence artifacts.","url":"https://attack.mitre.org/detectionstrategies/DET0452#AN1246","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TrustedPublisherList","description":"Baseline list of approved certificate authorities that should not change frequently"},{"field":"FilePathAllowList","description":"Exclusions for legitimate enterprise-signed binaries stored in unusual directories"},{"field":"TimeWindow","description":"Correlation window for registry + file + process activity"}],"live":true,"detection_strategies":["DET0452"],"techniques":["T1553"]},{"id":"AN1247","stix_id":"x-mitre-analytic--06ec22c9-b32f-49bc-81cc-ed5cee622493","name":"Analytic 1247","description":"Detection monitors extended attribute manipulation (xattr) to strip quarantine or trust metadata, anomalous installation of root certificates in /etc/ssl or /usr/local/share/ca-certificates, and unauthorized modification of system trust stores. Correlates with unexpected process execution involving package managers or custom certificate utilities.","url":"https://attack.mitre.org/detectionstrategies/DET0452#AN1247","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"chmod, chown, setxattr, or file writes to /etc/ssl/* or /usr/local/share/ca-certificates/*","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"Process execution of update-ca-certificates or openssl with suspicious arguments","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"CertificatePathList","description":"Paths to monitor for changes depending on distro-specific trust locations"},{"field":"RegexPatterns","description":"Regex patterns for suspicious use of xattr or openssl parameters"}],"live":true,"detection_strategies":["DET0452"],"techniques":["T1553"]},{"id":"AN1248","stix_id":"x-mitre-analytic--94340be7-068e-446a-bca2-d414b66912fc","name":"Analytic 1248","description":"Detection monitors modification of code signing attributes, Gatekeeper/quarantine flags, and insertion of new trust certificates via security add-trusted-cert. Identifies adversary use of xattr to strip quarantine flags from downloaded binaries. Correlates with abnormal module loads bypassing SIP protections.","url":"https://attack.mitre.org/detectionstrategies/DET0452#AN1248","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"New certificate trust settings added by unexpected process","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"xattr -d com.apple.quarantine or similar removal commands","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"Unsigned or ad-hoc signed process executions in user contexts","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"QuarantineBypassAllowList","description":"List of enterprise apps where quarantine flag removal is expected"},{"field":"CertificateAuthorityList","description":"Baseline trusted root and intermediate CAs for comparison"}],"live":true,"detection_strategies":["DET0452"],"techniques":["T1553"]}],"live":true,"version":"1.0","techniques":["T1553"]}],"sigma_rules":[{"id":"0090b851-3543-42db-828c-02fee986ff0b","title":"Potential BOINC Software Execution (UC-Berkeley Signature)","author":"Matt Anderson (Huntress)","status":"test","level":"informational","date":"2024-07-23","modified":null,"description":"Detects the use of software that is related to the University of California, Berkeley via metadata information.\nThis indicates it may be related to BOINC software and can be used maliciously if unauthorized.\n","references":["https://boinc.berkeley.edu/","https://www.huntress.com/blog/fake-browser-updates-lead-to-boinc-volunteer-computing-software"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1553","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_boinc_execution.yml","techniques":["T1553"],"cves":[]},{"id":"30d07da2-83ab-45d8-ae75-ec7c0edcaffc","title":"Renamed BOINC Client Execution","author":"Matt Anderson (Huntress)","status":"test","level":"medium","date":"2024-07-23","modified":null,"description":"Detects the execution of a renamed BOINC binary.","references":["https://boinc.berkeley.edu/","https://www.virustotal.com/gui/file/91e405e8a527023fb8696624e70498ae83660fe6757cef4871ce9bcc659264d3/details","https://www.huntress.com/blog/fake-browser-updates-lead-to-boinc-volunteer-computing-software"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1553"],"path":"rules/windows/process_creation/proc_creation_win_renamed_boinc.yml","techniques":["T1553"],"cves":[]},{"id":"6e4dcdd1-e48b-42f7-b2d8-3b413fc58cb4","title":"Suspicious Execution via macOS Script Editor","author":"Tim Rauch (rule), Elastic (idea)","status":"test","level":"medium","date":"2022-10-21","modified":"2022-12-28","description":"Detects when the macOS Script Editor utility spawns an unusual child process.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-7f541fbc4a4a28a92970e8bf53effea5bd934604429112c920affb457f5b2685","https://wojciechregula.blog/post/macos-red-teaming-initial-access-via-applescript-url/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1566","attack.t1566.002","attack.initial-access","attack.t1059","attack.t1059.002","attack.t1204","attack.t1204.001","attack.execution","attack.persistence","attack.t1553"],"path":"rules/macos/process_creation/proc_creation_macos_susp_execution_macos_script_editor.yml","techniques":["T1566","T1566.002","T1059","T1059.002","T1204","T1204.001","T1553"],"cves":[]},{"id":"a4eaf250-7dc1-4842-862a-5e71cd59a167","title":"Suspicious RazerInstaller Explorer Subprocess","author":"Florian Roth (Nextron Systems), Maxime Thiebaut","status":"test","level":"high","date":"2021-08-23","modified":"2024-12-01","description":"Detects a explorer.exe sub process of the RazerInstaller software which can be invoked from the installer to select a different installation folder but can also be exploited to escalate privileges to LOCAL SYSTEM","references":["https://twitter.com/j0nh4t/status/1429049506021138437","https://streamable.com/q2dsji"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.defense-impairment","attack.t1553","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/RazerInstaller-LPE-Exploit/proc_creation_win_exploit_other_razorinstaller_lpe.yml","techniques":["T1553"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}