Subvert Trust Controls

T1553

Technique with 6 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would include a program being allowed to run because it is signed by a valid code signing certificate, a program prompting the user with a warning because it has an attribute set from being downloaded from the Internet, or getting an indication that you are about to connect to an untrusted site.

Adversaries may attempt to subvert these trust mechanisms. The method adversaries use will depend on the specific mechanism they seek to subvert. Adversaries may conduct File and Directory Permissions Modification or Modify Registry in support of subverting these controls. Adversaries may also create or steal code signing certificates to acquire trust on target systems.

Detection rules32

Rules on DetectionCode tagged with T1553 or one of its sub-techniques.

Sigma21

RuleLevelLog sourceTechnique
Cisco Crypto Commandshighcisco / NULLT1553.004
Root Certificate Installed From Susp Locationshighwindows / process_creationT1553.004
New Root Certificate Installed Via CertMgr.EXEmediumwindows / process_creationT1553.004
New Root Certificate Installed Via Certutil.EXEmediumwindows / process_creationT1553.004
Persistence Via New SIP Providermediumwindows / registry_setT1553.003
Potential Secure Deletion with SDeletemediumwindows / NULLT1553.002
Renamed BOINC Client Executionmediumwindows / process_creationT1553
Root Certificate Installed - PowerShellmediumwindows / ps_scriptT1553.004
Suspicious Execution via macOS Script Editormediummacos / process_creationT1553
Suspicious Invoke-Item From Mount-DiskImagemediumwindows / ps_scriptT1553.005
Suspicious Package Installed - Linuxmediumlinux / process_creationT1553.004
Suspicious Unblock-Filemediumwindows / ps_scriptT1553.005
Suspicious X509Enrollment - Process Creationmediumwindows / process_creationT1553.004
Suspicious X509Enrollment - Ps Scriptmediumwindows / ps_scriptT1553.004
Windows AppX Deployment Full Trust Package Installationmediumwindows / NULLT1553.005

Splunk11

RuleTypeRiskData sourceTechnique
Attempt To Add Certificate To Untrusted StoreAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1553.004
MacOS Gatekeeper BypassAnomalyNULLOsquery ResultsT1553.001
Windows Advanced Installer MSIX with AI_STUBS ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1553.005
Windows AppX Deployment Full Trust Package InstallationHuntingNULLWindows Event Log AppXDeployment-Server 400T1553.005
Windows AppX Deployment Unsigned Package InstallationTTPNULLWindows Event Log AppXDeployment-Server 855T1553.005
Windows Developer-Signed MSIX Package InstallationAnomalyNULLWindows Event Log AppXDeployment-Server 855T1553.005
Windows Mark Of The Web BypassTTPNULLSysmon EventID 23, Sysmon EventID 26T1553.005
Windows Registry Certificate AddedAnomalyNULLSysmon EventID 13T1553.004
Windows Registry SIP Provider ModificationTTPNULLSysmon EventID 13T1553.003
Windows SIP Provider InventoryHuntingNULLT1553.003
Windows SIP WinVerifyTrust Failed Trust ValidationAnomalyNULLWindows Event Log CAPI2 81T1553.003

Sub-techniques6

IDNameExamples
T1553.001Gatekeeper Bypass6
T1553.002Code Signing89
T1553.003SIP and Trust Provider Hijacking0
T1553.004Install Root Certificate5
T1553.005Mark-of-the-Web Bypass5
T1553.006Code Signing Policy Modification5

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

Groups1

Used byProcedure example
GroupAxiom

Axiom has used digital certificates to deliver malware.

Software1

Used byProcedure example
MalwareShai-Hulud

Shai-Hulud has suppressed victim NPM warnings using `process[“exit’](0x0);` which results in having all errors exit with code 0.

References3

  1. Securelist Digital Certificates Open source
    Ladikov, A. (2015, January 29). Why You Shouldn’t Completely Trust Files Signed with Digital Certificates. Retrieved March 31, 2016.
  2. SpectorOps Subverting Trust Sept 2017 Open source
    Graeber, M. (2017, September). Subverting Trust in Windows. Retrieved January 31, 2018.
  3. Symantec Digital Certificates Open source
    Shinotsuka, H. (2013, February 22). How Attackers Steal Private Keys from Digital Certificates. Retrieved March 31, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.