Suspicious certutil command line
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Command and Control (TA0011), Stealth (TA0005)
ATT&CK Technique
System Binary Proxy Execution (T1218), Ingress Tool Transfer (T1105)
Severity
Medium
Description
An attacker may use certutil to download malware.
Attacker's Goals
An attacker may use certutil to download malware.
Investigative actions
Check whether the URL is benign and if this was a desired behavior as part of its normal execution flow.
Check whether the downloaded file is malicious.
PreviousSuspicious Certutil AD CS contact
NextSuspicious cloud compute instance SSH keys modification attempt
Was this helpful?
