Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
38 rules
Suspicious File Download via certutil urlcache
This rule detects certutil used with the urlcache and split flags to download a remote file, an ingress tool transfer technique observed in the REF7707 espionage campaign. Adversaries abuse the signed certutil utility to retrieve payloads while blending in with trusted Windows binaries. This flag combination has no routine administrative use and reliably indicates tooling download.
HuntRule TeamWindowsprocess_creationHigh337Premium2026-06-23Masquerading Blank Grabber Payload Decoding via Certutil Decode Flag (via process_creation)
This rule detects certutil being run with its decode flag to convert a base64-encoded file back into an executable payload, the deobfuscation step Blank Grabber uses to reconstruct its loader while masquerading the data as a certificate. Adversaries leverage certutil as a trusted LOLBin to decode staged payloads and evade content controls, making early detection critical for catching the loader before execution.
HuntRule TeamWindowsprocess_creationHigh146Premium2026-06-22Suspicious File Download via certutil
This rule detects certutil.exe being used with URL-cache download arguments to retrieve remote files, a living-off-the-land technique used by RansomHub affiliates to stage tooling. certutil is not a general purpose downloader, so its use to fetch remote content commonly indicates ingress tool transfer by an adversary.
HuntRule TeamWindowsprocess_creationMedium367Premium2026-06-19Suspicious Certutil URL Download to Public Directory (Soco404 Cryptomining)
This rule detects certutil used with its urlcache flag to fetch a remote payload, the download technique of the Soco404 campaign that staged binaries under the Public user directory. It matters because certutil acting as a downloader is a living off the land pattern used to pull cryptomining payloads onto Windows hosts.
HuntRule TeamWindowsprocess_creationMedium132Premium2026-06-08Suspicious Certutil URLCache Download
This rule detects certutil.exe used with the urlcache option to download a remote file. The DragonRank SEO-poisoning operators abused certutil urlcache to pull additional tooling onto compromised IIS servers. Certutil functioning as a downloader is a living-off-the-land ingress technique that evades controls expecting a browser or dedicated transfer tool.
HuntRule TeamWindowsprocess_creationHigh83Premium2026-06-03Malicious Payload Decoding via Certutil
This rule detects certutil using its decode function against PDF-named files to reconstruct an executable payload from base64, a defense-evasion and deobfuscation step. This was observed in a Vietnamese threat actor chain delivering PureRAT. Abusing certutil to decode disguised files bypasses download controls and unpacks the next-stage loader.
HuntRule TeamWindowsprocess_creationHigh2710Premium2026-05-16Suspicious File Download via Certutil URLCache [Huntress] #2
This rule detects certutil.exe downloading a remote file using the urlcache option, a LOLBIN download technique Huntress observed after Wing FTP CVE-2025-47812 exploitation. Attackers use certutil to retrieve payloads over HTTP while blending in with a trusted signed binary. Certutil retrieving content from a URL is a common ingress tool transfer indicator that warrants review of the fetched resource.
HuntRule TeamWindowsprocess_creationMedium141Premium2026-05-14Malicious LOLBin Download Saved as Windows Utility ping.exe via certutil or curl
This rule detects use of certutil or curl to download a remote file and save it under the name of a legitimate Windows utility such as ping.exe. The Mysterious Elephant APT used this masquerading technique to stage payloads disguised as trusted system binaries. Writing downloaded content to a well-known utility name in a non-System32 location is a strong indicator of ingress tool transfer combined with defense evasion.
HuntRule TeamWindowsprocess_creationHigh294Premium2026-05-01Suspicious Child Process Spawned by Diskshadow.exe (Windows Process Creation)
Alerts on process creation where Diskshadow.exe spawns certutil, cscript, mshta, PowerShell, regsvr32, rundll32, or wscript.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium110Free2023-09-15Windows Process Creation: certutil.exe Encodes Files to Base64 in Suspicious Paths
Alert on certutil.exe running with -encode when the command line references files under suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh110Free2023-05-15Windows: certutil.exe Encodes Files to Base64 Using -encode With Suspicious Extensions
Alert on certutil.exe -encode activity that targets files with suspicious extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh140Free2023-05-15Windows: Root Certificate Added Using certutil.exe -addstore
Flags certutil.exe executions that use -addstore with root-related parameters to install a certificate.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationMedium389Free2023-03-05Windows: certutil.exe ExportPFX certificate export via -exportPFX flag
Flags certutil.exe executions on Windows that include the -exportPFX argument to export certificate material.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium364Free2023-02-15Windows: certutil.EXE Downloading Files from File-Sharing Domains via Suspicious Flags
Alert when certutil.exe is run with URL/download flags targeting common file-sharing domains.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh140Free2023-02-15Windows certutil.exe Download from Direct IP Using URL/IP-Related Flags
Alerts when certutil.exe is launched with direct-IP download indicators and download-capable certutil flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-02-15