certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

ID: S0160
Associated Software: certutil.exe
Type: TOOL
Platforms: Windows
Version: 1.4
Created: 14 December 2017
Last Modified: 27 July 2023

Techniques Used

Domain ID Name Use
Enterprise T1140 反混淆/解码文件或信息

certutil has been used to decode binaries hidden inside certificate files as Base64 information.[2]

Enterprise T1560 .001 归档收集数据: Archive via Utility

certutil may be used to Base64 encode collected data.[1][3]

Enterprise T1105 输入工具传输

certutil can be used to download files from a given URL.[1][3]

Enterprise T1553 .004 颠覆信任控制: Install Root Certificate

certutil can be used to install browser root certificates as a precursor to performing Adversary-in-the-Middle between connections to banking websites. Example command: certutil -addstore -f -user ROOT ProgramData\cert512121.der.[4]

Groups That Use This Software

Campaigns

ID Name Description
C0040 APT41 DUST

APT41 DUST used certutil to load and execute DUSTPAN.[18]

References