Compliance Node Overview
MITRE ATT&CK T1553.003 (SIP and Trust Provider Hijacking) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks. In user mode, Windows Authenticode digital signatures are used to verify a file's origin and integrity, variables that may be used to establish trust in signed code (ex: a driver with a valid Microsoft signature may be handled as safe). Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-07, CM-02, CM-03, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1553/003/
SHA-256 integrity: 27518bcdd4d093b84e8e9738f7c7d005b16b914084116f8241bbb543782d0622
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1553.003: SIP and Trust Provider Hijacking (https://attack.mitre.org/techniques/T1553/003/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access