For the complete documentation index, see llms.txt. This page is also available as Markdown.

Encoded information using Windows certificate management tool

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Obfuscated Files or Information: Encrypted/Encoded File (T1027.013), Deobfuscate/Decode Files or Information (T1140)

Severity

Medium

Description

Encoding/decoding to/from using certutil.exe could be used to evade detection.

Attacker's Goals

Evade detection by executing processes with obfuscated arguments.

Investigative actions

Check encoded/decoded command content and see whether it is benign or malicious.

Was this helpful?