
Rule Info
Tags
attack.defense_evasion DEMO attack.t1553.004
Modified
None
Author
oscd.community, @redcanary, Zach Stanford @svch0st
Name
New Root Certificate Installed Via Certutil.EXE
Description
Detects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system.
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Date
2023-03-05 00:00:00
Id
d2125259-ddea-4c1c-9c22-977eb5b29cf0
Type
Community Rule
Link to Public Repo
Rule History
Commit
Date
Author
Title