Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1140 | Deobfuscate/Decode Files or Information |
certutil has been used to decode binaries hidden inside certificate files as Base64 information.[2] |
|
Enterprise | T1105 | Ingress Tool Transfer |
certutil can be used to download files from a given URL.[1][3] |
|
Enterprise | T1553 | .004 | Subvert Trust Controls: Install Root Certificate |
certutil can be used to install browser root certificates as a precursor to performing Adversary-in-the-Middle between connections to banking websites. Example command: |
ID | Name | References |
---|---|---|
G0010 | Turla | |
G0126 | Higaisa | |
G0027 | Threat Group-3390 | |
G0045 | menuPass | |
G0096 | APT41 | |
G0075 | Rancor | |
G0007 | APT28 | |
G0049 | OilRig |