Elastic medium stable eql
Suspicious CertUtil Commands
Identifies suspicious commands being used with certutil.exe. CertUtil is a native Windows component which is part of Certificate Services. CertUtil is often abused by attackers to live off the land for stealthier command and control or data exfiltration.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
(process.name : "certutil.exe" or ?process.pe.original_file_name == "CertUtil.exe") and
process.args : ("?decode", "?encode", "?urlcache", "?verifyctl", "?encodehex", "?decodehex", "?exportPFX") Field Validations
Loading…
Comments (0)
Loading comments...