mandiant / capa-rules

Standard collection of rules for capa: the tool for enumerating the capabilities of programs
https://github.com/mandiant/capa/
Apache License 2.0
531 stars 159 forks source link

Install Root Certificate #373

Open mr-tz opened 3 years ago

mr-tz commented 3 years ago

https://attack.mitre.org/techniques/T1553/004/

williballenthin: https://www.fireeye.com/blog/threat-research/2012/08/hikit-rootkit-advanced-persistent-attack-techniques-part-2.html

certmgr.exe localMachine localMachineTrustedPublisher

recvfrom commented 3 years ago

It might make sense to cover the Windows API equivalents as part of this as well...

and:

references: