mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update ssa___windows_certutil_decode_file.yml
This commit is contained in:
@@ -5,7 +5,7 @@ date: '2022-02-16'
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
- Endpoint_Processes
|
||||
description: CertUtil.exe may be used to `encode` and `decode` a file, including PE
|
||||
and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----`
|
||||
and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded
|
||||
|
||||
Reference in New Issue
Block a user