// MITRE ATT&CK
T1553 · Subvert Trust Controls
Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would...
¿Cómo detectarlo y mitigarlo?
La detección de Subvert Trust Controls parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (6)
T1553.001
Gatekeeper Bypass T1553.002
Code Signing T1553.003
SIP and Trust Provider Hijacking T1553.004
Install Root Certificate T1553.005
Mark-of-the-Web Bypass T1553.006
Code Signing Policy Modification
Gatekeeper Bypass T1553.002
Code Signing T1553.003
SIP and Trust Provider Hijacking T1553.004
Install Root Certificate T1553.005
Mark-of-the-Web Bypass T1553.006
Code Signing Policy Modification
Técnicas relacionadas
T1687
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.