‘This detection uses Normalized Process Events to hunt Certutil activities’
imProcessCreate
| where Process has "certutil.exe"
// Uncomment the next line and add your commandLine Whitelisted/ignore terms.For example "urlcache"
// | where CommandLine !contains ("urlcache")
| extend HostCustomEntity = Dvc, AccountCustomEntity = User
id: 28233666-c235-4d55-b456-5cfdda29d62d
name: Certutil (LOLBins and LOLScripts, Normalized Process Events)
description: |
'This detection uses Normalized Process Events to hunt Certutil activities'
requiredDataConnectors: []
tactics:
- CommandAndControl
relevantTechniques:
- T1105
query: |
imProcessCreate
| where Process has "certutil.exe"
// Uncomment the next line and add your commandLine Whitelisted/ignore terms.For example "urlcache"
// | where CommandLine !contains ("urlcache")
| extend HostCustomEntity = Dvc, AccountCustomEntity = User
entityMappings:
- entityType: Account
fieldMappings:
- identifier: FullName
columnName: AccountCustomEntity
- entityType: Host
fieldMappings:
- identifier: FullName
columnName: HostCustomEntity
| Sentinel Table | Notes |
|---|---|
imProcessCreate | Ensure this data connector is enabled |
certutil -addstore -user TrustedRootCert."-addstore" or `“Trusted