// MITRE ATT&CK

T1553.003 · SIP and Trust Provider Hijacking

🎯 Defense Impairment Windows Sub-technique

Sub-technique of T1553 · Subvert Trust Controls.

Adversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks. In user mode, Windows Authenticode (Citation: Microsoft Authenticode) digital signatures are used to verify a file's origin and int...

How to detect & mitigate it

Detecting SIP and Trust Provider Hijacking starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.