CertUtil Used for File Download (Living off the Land)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects certutil.exe being used to download files from remote URLs via the -urlcache or -verifyctl flags. CertUtil is a signed Windows binary (LOLBin) that attackers abuse to download payloads while bypassing application whitelisting and network controls. Tune AllowlistedDomains to match your PKI/CA infrastructure.

Attribute Value
Type Analytic Rule
Solution Endpoint Threat Protection Essentials
ID 4a9d3c2e-7f1b-4e58-9a0c-2d5b8e3f1a7c
Severity High
Status Available
Kind Scheduled
Tactics CommandAndControl, DefenseEvasion
Techniques T1105, T1218, T1140
Required Connectors MicrosoftThreatProtection, SecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceProcessEvents ✓ ✗ ✓
SecurityEvent EventID == "4688" ✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Endpoint Threat Protection Essentials