The Detection Gap: MITRE ATT&CK T1140 and T1105
ID: b65bbe45-97d8-5e27-baac-a9f21c4c5399
STIX ID: report--b65bbe45-97d8-5e27-baac-a9f21c4c5399
Feed Name: security.com
Threat Score
This article explains how attackers can abuse the built-in Windows tool certutil for stealthy file downloads and decoding, contrasts legitimate PKI-related certutil usage with malicious patterns (suspicious parent processes, -urlcache -split -f flags, external network calls, off-hours execution), and recommends focusing on process lineage and destination to detect misuse, highlighting Threat Tracer as a tool to visualize the execution chain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
