Compliance Node Overview
MITRE ATT&CK T1553.004 (Install Root Certificate) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers. Root certificates are used in public key cryptography to identify a root certificate authority (CA). When a root certificate is installed, the system or application will trust certificates in the root's chain of trust that have been signed by the root certificate. Certificates are commonly used for establishing secure TLS/SSL communications within a web browser. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1054 Software Configuration, M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CM-02, CM-03, CM-05, CM-06, CM-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1553/004/
SHA-256 integrity: 5b84460ea91ccc4c59664b45345261fee787e45bbba88ebc336672ae0fcef34e
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1553.004: Install Root Certificate (https://attack.mitre.org/techniques/T1553/004/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access