ID: T1553.003
Description: Detects modifications to SIP and Trust Provider-related registry keys/values by a non-Administrator user.
Links:
https://attack.mitre.org/techniques/T1553/003/
Red Teaming Experiments
SpecterOps Subverting Trust in Windows