kevmap

TechniquesT1553 › AN1246

AN1246 Analytic 1246

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection correlates abnormal installation or modification of root or code-signing certificates, creation/modification of suspicious registry keys for trust providers, and unusual module loads from non-standard locations. Identifies unsigned or improperly signed executables bypassing trust prompts, combined with persistence artifacts.</p>
Detects
T1553 Subvert Trust Controls
Part of
DET0452 Detect Subversion of Trust Controls via Certificate, Registry, and Attribute Manipulation

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4657DC0063 Windows Registry Key Modification
WinEventLog:SysmonEventCode=11DC0039 File Creation
WinEventLog:SysmonEventCode=1DC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TrustedPublisherListBaseline list of approved certificate authorities that should not change frequently
FilePathAllowListExclusions for legitimate enterprise-signed binaries stored in unusual directories
TimeWindowCorrelation window for registry + file + process activity