{
  "node_id": "mitre-attack-t1553-003-sip-and-trust-provider-hijacking",
  "title": "MITRE ATT&CK T1553.003: SIP and Trust Provider Hijacking (Enterprise Tactic TA0005 - Defense Evasion)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1553.003 (SIP and Trust Provider Hijacking) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks. In user mode, Windows Authenticode digital signatures are used to verify a file's origin and integrity, variables that may be used to establish trust in signed code (ex: a driver with a valid Microsoft signature may be handled as safe). Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-07, CM-02, CM-03, CM-05, CM-06.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-t1553-subvert-trust-controls"
  ],
  "primary_citations_count": 7
}