Suspicious File Download via Certutil URLCache

PremiumReviewedSigma · Medium · v1
Category
process_creation
Author
HuntRule
Published
2026-07-02
Updated
2026-08-28

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects certutil being used with its url cache download flags which the ALPHV intrusion leveraged as a living off the land downloader to stage tooling and this matters because certutil is a signed system binary frequently abused to retrieve remote payloads and its download flags rarely appear in legitimate certificate operations.

Related detections9 linkedT1105 — drag to rearrange
BITS Payload Downloaded via Commandline (via process_creation)
BITS Payload Downloaded via PowerShell (via powershell)
Suspicious sLoad Payload Download via BITSAdmin LOLBin Transfer (via process_creation)
Windows Process Creation: bitsadmin Downloads Files to Suspicious Directories
Windows Process Creation: BITSAdmin Downloading File with Suspicious Extension
Windows BITSAdmin Downloads from File-Sharing Domains
Windows BITSAdmin File Download via bitsadmin.exe with Transfer/Addfile Arguments
Suspicious Remote HTA Payload Execution via MSHTA
Possible PurpleFox MSHTA to Msiexec Remote MSI Chain
Suspicious File Download via Certutil URLCache
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.