Description
A process modified the non-Microsoft trusted root certificates through the registry. The Authroot registry key stores certificates from non-Microsoft root CAs. Malware may modify this setting to add a trusted root certificate and bypass certificate checks, making the target accept self-signed malicious content without errors.
Trigger
This indicator is triggered when the registry key similar to '\SOFTWARE\Microsoft\SystemCertificates\Authroot\Certificates' is modified.