logo

The Detection Gap: MITRE ATT&CK T1140 and T1105

ID: b65bbe45-97d8-5e27-baac-a9f21c4c5399

STIX ID: report--b65bbe45-97d8-5e27-baac-a9f21c4c5399

Feed Name: security.com

Threat Score
45/100

Date Published: 2026-07-13

Date Updated: 2026-07-20

Author: Kirk Hasty

...
...

This article explains how attackers can abuse the built-in Windows tool certutil for stealthy file downloads and decoding, contrasts legitimate PKI-related certutil usage with malicious patterns (suspicious parent processes, -urlcache -split -f flags, external network calls, off-hours execution), and recommends focusing on process lineage and destination to detect misuse, highlighting Threat Tracer as a tool to visualize the execution chain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.