Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0230 — Detect Suspicious or Malicious Code Signing Abuse
DET0230

Detect Suspicious or Malicious Code Signing Abuse

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0643 Analytic 0643
Windows

Detects execution of binaries signed with unusual or recently issued certificates, correlation of process execution with abnormal publisher metadata, and mismatched certificate chains. Monitors for revoked or unknown code signing certificates used in high-privilege contexts.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=7
[AllowedCertificateAuthorities] Define trusted issuers to suppress noise from legitimate enterprise signing chains
[TimeWindow] Correlation window for detecting execution of binaries with newly observed or anomalous certificates
[CertificateAgeThreshold] Baseline normal age of certificates; flag very recent or expired certificates
AN0644 Analytic 0644
macOS

Monitors Gatekeeper, spctl, and unified log entries for binaries executed with unexpected or untrusted signatures. Correlates file metadata changes with process launches where signature validation is skipped, altered, or fails but the process still executes.

macos:unifiedlog Code signing verification failures or bypassed trust decisions macos:unifiedlog Execution of binaries with unsigned or anomalously signed certificates
[DeveloperIDAllowList] Maintain list of expected Developer IDs to minimize false positives from enterprise apps
[TimeWindow] Correlates file signature changes with subsequent executions

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0230
STIX ID
x-mitre-detection-strategy--01cc085c-7d7d-49fc-9d15-bc5b2226026a
Analytics
2
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.