// MITRE ATT&CK
T1553 · Subvert Trust Controls
Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would...
How to detect & mitigate it
Detecting Subvert Trust Controls starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (6)
T1553.001
Gatekeeper Bypass T1553.002
Code Signing T1553.003
SIP and Trust Provider Hijacking T1553.004
Install Root Certificate T1553.005
Mark-of-the-Web Bypass T1553.006
Code Signing Policy Modification
Gatekeeper Bypass T1553.002
Code Signing T1553.003
SIP and Trust Provider Hijacking T1553.004
Install Root Certificate T1553.005
Mark-of-the-Web Bypass T1553.006
Code Signing Policy Modification
Related techniques
T1687
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.