Suspicious Download Via Certutil.EXE (19b08b1c-861d-4e75-a1ef-ea0c1baf202b)
Detects the execution of certutil with certain flags that allow the utility to download files.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Obfuscated Files or Information - T1027 (b3d682b6-98f2-4fb0-aa3b-b4df007ca70a) | Attack Pattern | Suspicious Download Via Certutil.EXE (19b08b1c-861d-4e75-a1ef-ea0c1baf202b) | Sigma-Rules | 1 |