Title:New Root Certificate Installed Via Certutil.EXE Status:test Description:Detects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system.
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
References: -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1553.004/T1553.004.md Author: oscd.community, @redcanary, Zach Stanford @svch0st Date: 2023-03-05 modified:2024-03-05 Tags:
-'attack.defense-impairment'
-'attack.t1553.004'
Logsource:
category: process_creation
product: windows
Detection: selection_img: Image|endswith:'\certutil.exe'OriginalFileName:'CertUtil.exe'selection_cli_add: CommandLine|contains|windash:
'-addstore' selection_cli_store: CommandLine|contains:
'root' condition:all of selection_* Falsepositives:
-Help Desk or IT may need to manually add a corporate Root CA on occasion. Need to test if GPO push doesn't trigger FP Level:medium