Update ssa___windows_certutil_decode_file.yml

This commit is contained in:
mhaag-spl
2022-02-22 14:58:49 -07:00
parent fb9bdc0203
commit dfb089db4e
@@ -5,7 +5,7 @@ date: '2022-02-16'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
- Endpoint_Processes
description: CertUtil.exe may be used to `encode` and `decode` a file, including PE
and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----`
and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded