Analytics BIOC
Medium
✕
Encoded information using Windows certificate management tool
Encoding/decoding to/from using certutil.exe could be used to evade detection.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Obfuscated Files or Information: Encrypted/Encoded File (T1027.013) Deobfuscate/Decode Files or Information (T1140)
Attacker's goals:
Evade detection by executing processes with obfuscated arguments.
Investigative actions:
Check encoded/decoded command content and see whether it is benign or malicious.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day