From dfb089db4e451a244f4fcf990f44b860be7cc67c Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Tue, 22 Feb 2022 14:58:49 -0700 Subject: [PATCH] Update ssa___windows_certutil_decode_file.yml --- detections/endpoint/ssa___windows_certutil_decode_file.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/ssa___windows_certutil_decode_file.yml b/detections/endpoint/ssa___windows_certutil_decode_file.yml index ce33b4835a..a6e43eac7f 100644 --- a/detections/endpoint/ssa___windows_certutil_decode_file.yml +++ b/detections/endpoint/ssa___windows_certutil_decode_file.yml @@ -5,7 +5,7 @@ date: '2022-02-16' author: Michael Haag, Splunk type: TTP datamodel: -- Endpoint +- Endpoint_Processes description: CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded