title: Suspicious Download Via Certutil.EXE id: 19b08b1c-861d-4e75-a1ef-ea0c1baf202b related: - id: 13e6fe51-d478-4c7e-b0f2-6da9b400a829 type: similar status: test description: Detects the execution of certutil with certain flags that allow the utility to download files. references: - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil - https://forensicitguy.github.io/agenttesla-vba-certutil-download/ - https://news.sophos.com/en-us/2021/04/13/compromised-exchange-server-hosting-cryptojacker-targeting-other-exchange-servers/ - https://twitter.com/egre55/status/1087685529016193025 - https://lolbas-project.github.io/lolbas/Binaries/Certutil/ - https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems) date: 2023-02-15 modified: 2025-12-01 tags: - attack.stealth - attack.t1027 - attack.command-and-control - attack.t1105 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\certutil.exe' - OriginalFileName: 'CertUtil.exe' selection_flags: CommandLine|contains: - 'urlcache ' - 'verifyctl ' - 'URL ' selection_http: CommandLine|contains: 'http' condition: all of selection_* falsepositives: - Unknown level: medium regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_certutil_download/info.yml