Skip to content

<<< Hide Navigation Hide TOC >>>

Root Certificate Installed From Susp Locations (5f6a601c-2ecb-498b-9c33-660362323afa)

Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.

Galaxy ColorsSigma-Rule...Attack Pat...
Rows: 2
Loading extensions...
Collapse filters
Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
<, <=, >, >=, =, *, !, {, }, ||,&&, [empty], [nonempty], rgx:
Learn more

TableFilter v0.7.2

https://www.tablefilter.com/
©2015-2025 Max Guglielmi
?
Cluster A Galaxy A Cluster B Galaxy B Level
Root Certificate Installed From Susp Locations (5f6a601c-2ecb-498b-9c33-660362323afa) Sigma-Rules Install Root Certificate - T1553.004 (c615231b-f253-4f58-9d47-d5b4cbdb6839) Attack Pattern 1
Install Root Certificate - T1553.004 (c615231b-f253-4f58-9d47-d5b4cbdb6839) Attack Pattern Subvert Trust Controls - T1553 (b83e166d-13d7-4b52-8677-dff90c548fd7) Attack Pattern 2