Windows

Certutil.exeCertutil.exe

Platform
Windows
Abuse functions
7
Mapped techniques
4

Description

Certutil.exe is a Windows living-off-the-land binary catalogued by the LOLBAS Project. Documented abuse functions: Download, ADS, Encode, Decode. Mapped ATT&CK techniques (per LOLBAS / GTFOBins → MITRE crosswalk): T1027, T1105, T1140, T1564.004. Defenders should monitor execution of Certutil.exe under non-administrative or sudo contexts and alert when its arguments match the abuse-function signatures.

Abuse functions· 7

DownloadT1105

Download file from Internet

DownloadT1105

Download file from Internet

Download file from Internet and save it in an NTFS Alternate Data Stream

DownloadT1105

Download file from Internet

EncodeT1027.013

Encode files to evade defensive measures

DecodeT1140

Decode files to evade defensive measures

DecodeT1140

Decode files to evade defensive measures

MITRE ATT&CK techniques· 4

T1105T1564.004T1027.013T1140

Uses4

TypeTargetConfidenceTier
SubTechniqueNTFS File Attributest1564.004100%live
TechniqueIngress Tool Transfert1105100%live
Techniquet1027.013100%live
TechniqueDeobfuscate/Decode Files or Informationt1140100%live

Abuses4

TypeTargetConfidenceTier
TechniqueObfuscated Files or Informationt1027100%live
SubTechniqueNTFS File Attributest1564.00490%live
TechniqueIngress Tool Transfert110585%live
TechniqueDeobfuscate/Decode Files or Informationt114085%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

LOLbin
CertOC.exe
LOLbin
CertReq.exe
LOLbin
AppCert.exe
LOLbin
Installutil.exe
LOLbin
Fsutil.exe
LOLbin
dtutil.exe
Sourced from LOLBAS Project. Curated by Adam Lundqvist, SQUR.