Trust Provider Registry Write by Non-System Process – T1553.006/T1112

This rule detects modifications to sensitive Windows Registry keys under HKLM\SOFTWARE\Microsoft\Cryptography, such as Providers, OID, Trust, and Protectedroots. These keys control cryptographic services and trust stores on Windows systems. Modifications by non-system processes or accounts may indicate attempts to subvert trust controls, install rogue root certificates, or tamper with system-level security providers.