<<< Hide Navigation Hide TOC >>>
Root Certificate Installed From Susp Locations (5f6a601c-2ecb-498b-9c33-660362323afa)
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
Root Certificate Installed From Susp Locations (5f6a601c-2ecb-498b-9c33-660362323afa) | Sigma-Rules | Install Root Certificate - T1553.004 (c615231b-f253-4f58-9d47-d5b4cbdb6839) | Attack Pattern | 1 |
Install Root Certificate - T1553.004 (c615231b-f253-4f58-9d47-d5b4cbdb6839) | Attack Pattern | Subvert Trust Controls - T1553 (b83e166d-13d7-4b52-8677-dff90c548fd7) | Attack Pattern | 2 |