From 48aacaf909a40fd5af16fa4fa4e6b0d3fe9ba4b0 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Fri, 1 Apr 2022 07:31:52 -0600 Subject: [PATCH] Update windows_registry_certificate_added.yml --- detections/endpoint/windows_registry_certificate_added.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/detections/endpoint/windows_registry_certificate_added.yml b/detections/endpoint/windows_registry_certificate_added.yml index 64738185fc..f05718ed6e 100644 --- a/detections/endpoint/windows_registry_certificate_added.yml +++ b/detections/endpoint/windows_registry_certificate_added.yml @@ -24,7 +24,7 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: False positives will be limited to a legitimate business applicating consistently adding new root certificates to the endpoint. Filter by user, process, or thumbprint. references: - https://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec -- https://github.com/redcanaryco/atomic-red-team/tree/master/atomics/T1587.002 +- https://github.com/redcanaryco/atomic-red-team/tree/master/atomics/T1553.004 tags: analytic_story: - Windows Rootkits @@ -44,8 +44,8 @@ tags: - Exploitation message: A root certificate was added on $dest$. mitre_attack_id: - - T1587.002 - - T1587 + - T1553.004 + - T1553 nist: - DE.CM observable: