Windows: certutil.exe Encodes Files to Base64 Using -encode With Suspicious Extensions
Alert on certutil.exe -encode activity that targets files with suspicious extensions.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-05-15
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process executions of certutil.exe where the command line includes the -encode flag and the targeted filename or extension appears in a suspicious list. Base64 encoding can be used to obfuscate file content or stage data for later decoding, reducing visibility for casual inspection. It relies on process creation telemetry, specifically the executable path or original filename plus command-line arguments and embedded file extensions.
Reporting behind it
- virustotal.comhttps://www.virustotal.com/gui/file/35c22725a92d5cb1016b09421c0a6cdbfd860fd4778b3313669b057d4a131cb7/behavior
- virustotal.comhttps://www.virustotal.com/gui/file/427616528b7dbc4a6057ac89eb174a3a90f7abcf3f34e5a359b7a910d82f7a72/behavior
- virustotal.comhttps://www.virustotal.com/gui/file/34de4c8beded481a4084a1fd77855c3e977e8ac643e5c5842d0f15f7f9b9086f/behavior
- virustotal.comhttps://www.virustotal.com/gui/file/4abe1395a09fda06d897a9c4eb247278c1b6cddda5d126ce5b3f4f499e3b8fa2/behavior
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_certutil_encode_susp_extensions.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: certutil.exe Encodes Files to Base64 Using -encode With Suspicious Extensions"
id: 1d195dd8-1ead-4b5f-a963-3787ce57a4ad
related:
- id: e62a9f0c-ca1e-46b2-85d5-a6da77f86d1a
type: derived
- id: ea0cdc3e-2239-4f26-a947-4e8f8224e464
type: derived
status: test
description: This rule flags Windows process executions of certutil.exe where the command line includes the -encode flag and the targeted filename or extension appears in a suspicious list. Base64 encoding can be used to obfuscate file content or stage data for later decoding, reducing visibility for casual inspection. It relies on process creation telemetry, specifically the executable path or original filename plus command-line arguments and embedded file extensions.
references:
- https://www.virustotal.com/gui/file/35c22725a92d5cb1016b09421c0a6cdbfd860fd4778b3313669b057d4a131cb7/behavior
- https://www.virustotal.com/gui/file/427616528b7dbc4a6057ac89eb174a3a90f7abcf3f34e5a359b7a910d82f7a72/behavior
- https://www.virustotal.com/gui/file/34de4c8beded481a4084a1fd77855c3e977e8ac643e5c5842d0f15f7f9b9086f/behavior
- https://www.virustotal.com/gui/file/4abe1395a09fda06d897a9c4eb247278c1b6cddda5d126ce5b3f4f499e3b8fa2/behavior
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_certutil_encode_susp_extensions.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-05-15
modified: 2024-03-05
tags:
- attack.stealth
- attack.t1027
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \certutil.exe
- OriginalFileName: CertUtil.exe
selection_cli:
CommandLine|contains|windash: -encode
selection_extension:
CommandLine|contains:
- .acl
- .bat
- .doc
- .gif
- .jpeg
- .jpg
- .mp3
- .pdf
- .png
- .ppt
- .tmp
- .xls
- .xml
condition: all of selection_*
falsepositives:
- Unknown
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_certutil_encode_susp_extensions/info.yml
license: DRL-1.1