
Rule Info
Tags
attack.defense_evasion DEMO attack.t1553.004
Modified
None
Author
oscd.community, @redcanary, Zach Stanford @svch0st
Name
New Root Certificate Installed Via CertMgr.EXE
Description
Detects execution of "certmgr" with the "add" flag in order to install a new certificate on the system.
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Date
2023-03-05 00:00:00
Id
ff992eac-6449-4c60-8c1d-91c9722a1d48
Type
Community Rule
Link to Public Repo
Rule History
Commit
Date
Author
Title