What MITRE ATT&CK T1553.006: Code Signing Policy Modification (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1553.006 (Code Signing Policy Modification) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may modify code signing policies to enable execution of unsigned or self-signed code. Code signing provides a level of authenticity on a program from a developer and a guarantee that the program has not been tampered with. Security controls can include enforcement mechanisms to ensure that only valid, signed code can be run on an operating system. Affected platforms: Windows, macOS. MITRE-documented mitigations include M1026 Privileged Account Management, M1046 Boot Integrity, M1024 Restrict Registry Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CM-02, CM-03, CM-05, CM-06, CM-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1553/006/
SHA-256 integrity: c89b55405af2834f0f62e0675abe7517a27b7fd28f54541790810b373017ca69
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1553.006: Code Signing Policy Modification (https://attack.mitre.org/techniques/T1553/006/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access