LoFP LoFP / t1553.004

t1553.004

TitleTags
false positives will be limited to a legitimate business applicating consistently adding new root certificates to the endpoint. filter by user, process, or thumbprint.
help desk or it may need to manually add a corporate root ca on occasion. need to test if gpo push doesn't trigger fp
legitimate administration activities
legitimate administrative script
not commonly run by administrators. also whitelist your known good certificates
there may be legitimate reasons for administrators to add a certificate to the untrusted certificate store. in such cases, this will typically be done on a large number of systems.
unlikely