Currently viewing ATT&CK v8.2 which was live between October 27, 2020 and April 28, 2021. Learn more about the versioning system or see the live site.

certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

ID: S0160
Associated Software: certutil.exe
Type: TOOL
Platforms: Windows
Version: 1.1
Created: 14 December 2017
Last Modified: 31 July 2019

Techniques Used

Domain ID Name Use
Enterprise T1140 Deobfuscate/Decode Files or Information

certutil has been used to decode binaries hidden inside certificate files as Base64 information.[2]

Enterprise T1105 Ingress Tool Transfer

certutil can be used to download files from a given URL.[1][3]

Enterprise T1553 .004 Subvert Trust Controls: Install Root Certificate

certutil can be used to install browser root certificates as a precursor to performing man-in-the-middle between connections to banking websites. Example command: certutil -addstore -f -user ROOT ProgramData\cert512121.der.[4]

Groups That Use This Software

ID Name References
G0075 Rancor

[5]

G0045 menuPass

[6][7]

G0007 APT28

[8]

G0049 OilRig

[9]

G0010 Turla

[10]

G0096 APT41

[11]

References