Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0523 — Detect Code Signing Policy Modification (Windows & macOS)
DET0523

Detect Code Signing Policy Modification (Windows & macOS)

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN1446 Analytic 1446
Windows

Monitors execution of administrative utilities (e.g., bcdedit.exe) or registry modifications that disable Driver Signature Enforcement (DSE) or enable Test Signing. Correlates command-line activity, registry changes, and subsequent process executions that bypass signing enforcement.

WinEventLog:Security EventCode=4688 WinEventLog:Security EventCode=4657
[MonitoredExecutables] Expand or restrict monitored utilities (e.g., bcdedit.exe, reg.exe) based on enterprise usage
[RegistryPaths] Customize registry paths tied to Driver Signing enforcement depending on OS version
[TimeWindow] Correlation window between registry modification and subsequent unsigned binary execution
AN1447 Analytic 1447
macOS

Detects modification of System Integrity Protection (SIP) or code signing enforcement policies through csrutil or kernel variable tampering. Correlates execution of csrutil disable commands with subsequent policy state changes and anomalous unsigned process executions.

macos:unifiedlog csrutil disable macos:unifiedlog g_CiOptions modification or SIP state change macos:unifiedlog Unsigned binary execution following SIP change
[PolicyPaths] Track configuration files and kernel extensions tied to SIP enforcement
[AllowedUsers] Restrict or expand which privileged accounts are monitored for SIP/CSRUTIL changes
[TimeWindow] Define correlation between csrutil execution and unsigned process activity

Detected Techniques

1

Details

MITRE ID
DET0523
STIX ID
x-mitre-detection-strategy--eec6a137-c506-4654-8780-8e3028f3fd28
Analytics
2
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.