Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 1.14 KB

MATCH-S00510.md

File metadata and controls

34 lines (27 loc) · 1.14 KB

Rules: Attempt to Add Certificate to Store

Description

Observes for attempts to add a certificate to the untrusted store

Additional Details

Detail Value
Type Templated Match
Category Defense Evasion
Apply Risk to Entities device_hostname, user_username
Signal Name Attempt to Add Certificate to Store
Summary Expression Attempt to add certificate to store on host: {{device_hostname}} by user: {{user_username}}
Score/Severity Static: 0
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0005, _mitreAttackTechnique:T1553, _mitreAttackTechnique:T1553.002, _mitreAttackTechnique:T1553.004

Vendors and Products

Fields Used

Origin Field
Normalized Schema baseImage
Normalized Schema commandLine
Normalized Schema device_hostname
Normalized Schema user_username