Windows certutil.exe Used to Download Files via Suspicious Command-Line Flags
Alerts on certutil.exe runs with URL/HTTP-related flags indicative of remote file download.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-02-15
- Updated
- 2026-07-31
ATT&CK techniques
Defense Evasion → C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags process creation events where certutil.exe is executed with command-line content consistent with downloading files (e.g., urlcache/verifyctl/URL) and with HTTP present in the command line. Attackers often use certutil.exe (a built-in Windows utility) to retrieve payloads or stage additional content while blending in with legitimate administrative tools. Detection relies on Windows process creation telemetry, including Image/OriginalFileName and CommandLine fields.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil
- forensicitguy.github.iohttps://forensicitguy.github.io/agenttesla-vba-certutil-download/
- news.sophos.comhttps://news.sophos.com/en-us/2021/04/13/compromised-exchange-server-hosting-cryptojacker-targeting-other-exchange-servers/
- twitter.comhttps://twitter.com/egre55/status/1087685529016193025
- lolbas-project.github.iohttps://lolbas-project.github.io/lolbas/Binaries/Certutil/
- hexacorn.comhttps://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_certutil_download.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows certutil.exe Used to Download Files via Suspicious Command-Line Flags
id: 406f276a-42ca-4709-bbdc-f0b4cd17ff04
related:
- id: 13e6fe51-d478-4c7e-b0f2-6da9b400a829
type: similar
- id: 19b08b1c-861d-4e75-a1ef-ea0c1baf202b
type: derived
status: test
description: This rule flags process creation events where certutil.exe is executed with command-line content consistent with downloading files (e.g., urlcache/verifyctl/URL) and with HTTP present in the command line. Attackers often use certutil.exe (a built-in Windows utility) to retrieve payloads or stage additional content while blending in with legitimate administrative tools. Detection relies on Windows process creation telemetry, including Image/OriginalFileName and CommandLine fields.
references:
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil
- https://forensicitguy.github.io/agenttesla-vba-certutil-download/
- https://news.sophos.com/en-us/2021/04/13/compromised-exchange-server-hosting-cryptojacker-targeting-other-exchange-servers/
- https://twitter.com/egre55/status/1087685529016193025
- https://lolbas-project.github.io/lolbas/Binaries/Certutil/
- https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_certutil_download.yml
author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-02-15
modified: 2025-12-01
tags:
- attack.stealth
- attack.t1027
- attack.command-and-control
- attack.t1105
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \certutil.exe
- OriginalFileName: CertUtil.exe
selection_flags:
CommandLine|contains:
- "urlcache "
- "verifyctl "
- "URL "
selection_http:
CommandLine|contains: http
condition: all of selection_*
falsepositives:
- Unknown
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_certutil_download/info.yml
license: DRL-1.1