Root Certificate Installed From Susp Locations

 Original Source: [Sigma source]
Title: Root Certificate Installed From Susp Locations
Status: test
Description:Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
References:
  -https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations/
  -https://learn.microsoft.com/en-us/powershell/module/pki/import-certificate?view=windowsserver2022-ps
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-09
modified:2023-01-16
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1553.004'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'Import-Certificate'
      -' -FilePath '
      -'Cert:\LocalMachine\Root'

    CommandLine|contains:
      -'\AppData\Local\Temp\'
      -':\Windows\TEMP\'
      -'\Desktop\'
      -'\Downloads\'
      -'\Perflogs\'
      -':\Users\Public\'

  condition:selection
Falsepositives:
  -Unlikely
Level: high