Techniques › T1553.003 › AN1222
AN1222 Analytic 1222
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detection of anomalous registry modifications to Subject Interface Packages (SIPs) or trust provider DLL mappings, unexpected loading of non-Microsoft cryptographic modules, or attempts to redirect WinVerifyTrust validation logic. Defender view focuses on registry tampering, suspicious DLL loads into trusted processes, and abnormal trust validation failures correlated across event streams.</p>
- Detects
- T1553.003 SIP and Trust Provider Hijacking
- Part of
- DET0442 Detection Strategy for Subvert Trust Controls using SIP and Trust Provider Hijacking.
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Security | EventCode=4657 | DC0063 Windows Registry Key Modification |
| WinEventLog:Sysmon | EventCode=7 | DC0016 Module Load |
| WinEventLog:CodeIntegrity | EventCode=3033 | DC0061 File Modification |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
RegistryPathBaselines | Monitor for changes in Registry paths. |
TimeWindow | Correlate between changes in Registry values, system files, and modules loaded. |