New Root Certificate Installed Via Certutil.EXE

Rule Info

Name
New Root Certificate Installed Via Certutil.EXE
Author
oscd.community, @redcanary, Zach Stanford @svch0st
Description
Detects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Date
2023-03-05 00:00:00
Modified
2024-03-05 00:00:00
Id
d2125259-ddea-4c1c-9c22-977eb5b29cf0
Tags
attack.defense_evasion attack.t1553.004 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
frack113
Merge PR #4752 from @frack113 - Update rules to use the `windash` modifier
2024-03-11
Nasreddine Bencherchali
feat: more updates
2023-03-06