惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
C
Cyber Attacks, Cyber Crime and Cyber Security
博客园 - 司徒正美
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
罗磊的独立博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
博客园_首页
博客园 - 【当耐特】
Cisco Talos Blog
Cisco Talos Blog
J
Java Code Geeks
C
CXSECURITY Database RSS Feed - CXSecurity.com
S
SegmentFault 最新的问题
人人都是产品经理
人人都是产品经理
Jina AI
Jina AI
AWS News Blog
AWS News Blog
S
Schneier on Security
NISL@THU
NISL@THU
F
Fortinet All Blogs
L
LINUX DO - 热门话题
Google DeepMind News
Google DeepMind News
量子位
IT之家
IT之家
T
The Exploit Database - CXSecurity.com
爱范儿
爱范儿
GbyAI
GbyAI
T
The Blog of Author Tim Ferriss
T
Tor Project blog
V
Vulnerabilities – Threatpost
V
Visual Studio Blog
宝玉的分享
宝玉的分享
Spread Privacy
Spread Privacy
L
Lohrmann on Cybersecurity
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Y
Y Combinator Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
P
Privacy International News Feed
S
Securelist
P
Palo Alto Networks Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
A
Arctic Wolf
T
Tenable Blog
B
Blog
C
CERT Recently Published Vulnerability Notes
P
Proofpoint News Feed
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Threat Research - Cisco Blogs
T
Threatpost

SECURITY.COM

3 Ways to Defend Against LOTL Attacks Now Spirals: New Stealthy Ransomware Deployed Against Asian IT Company Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor Humble Brag: Symantec® Data Center Security Achieves Common Criteria Certification GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses Tips to Harden Your Air Gapped Environments The Visibility Challenge Nobody Asked For AV-TEST Gives Symantec® Endpoint Security Complete a Perfect Score The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security 🎙️SECURITY.COM The Podcast: The Parasite in the Machine: Unmasking the Speagle Infostealer Your DLP Incident Backlog Owes You Closure Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker 5 Reasons Symantec® CBX Delivers Total Endpoint Visibility 8 XDR Questions From the Show Floor Another Year, Another Win: SE Labs® Recognizes Symantec® Endpoint Security Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden Locking Down the Server 🎙️SECURITY.COM The Podcast: The Death of SIEM Threats Rise on a Tide of Global Unrest When Nation-States Stop Caring About Size Espionage Campaign Targeted Stock Exchange Executive for Five Months Data Security Is Having A Moment 5 Ways XDR Helps SOCs Act Faster 🎙️SECURITY.COM The Podcast: The Evolution of Cybersecurity PR with W2 Communications The Maximalism Trap: When More Becomes Too Much Symantec DLP Cloud and DPSM are the Power Couple Security Strategists Need Symantec DLP Cloud and DSPM are the Power Couple Security Strategists Need The Future of the Partnership: AI, Automation, and Ecosystems Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations 🎙️SECURITY.COM The Podcast: Iran’s Cyber Warfare Playbook: What Defenders Need to Know Right Now 5 Ways To Keep AI in Check Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign Doing More with Less: How Government Agencies are Rethinking Cybersecurity Navigating Compliance and Insurance as a Competitive Edge Is SIEM Trying to Do Too Much? Every Defender Deserves Frontier AI The New Partner-Vendor Relationship DLP Made Easier on the Teams Running It The EU Digital Wallet: Why Waiting is Not an Option Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft Stopping Data Leaks at the Speed of AI Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor How AI Increases the Load on Security Teams Web Traffic Visibility is the New Non-Negotiable The Agentic AI Tsunami is Here: Is Your Legacy IAM Sinking or Swimming? Technical Enablement vs. Marketing Noise Enterprise-Grade Security for All in 2026 Architecting for Margin Beyond the Initial Sale 🎙️SECURITY.COM The Podcast: A Brief History of Data Loss Prevention Symantec CBX Through the Paparazzi Lens The U.S. Navy’s Playbook for Cost-Controlled, Reliable Cybersecurity The Modern Threat Landscape and The Partner’s New Burden Symantec CBX Rocked RSAC 2026 Conference For Financial Services, a Wake-Up Call for Reclaiming IAM Control The Next Identity Shift Cyber Legends: Behind the Scenes of CBX Built for This Moment (and All Those to Come)
The Detection Gap: MITRE ATT&CK T1140 and T1105
About the Author · 2026-07-13 · via SECURITY.COM
  • Certutil abuse often hides behind legitimate Windows behavior.
  • The difference between normal and malicious activity comes down to execution context.
  • Threat Tracer brings the chain into view so analysts can spend less time stitching and more time interpreting.

The Detection Gap is a breakdown for security practitioners who have to make quick calls under tight time constraints. In each post of this series, we’ll take one MITRE ATT&CK technique and walk through what it looks like when it's legitimate activity and compare what changes when it's actually an attacker in your environment. No theory, and no query syntax to memorize. Just the exact distinction that separates a real incident from everyday noise, made explicit, one technique at a time.

Certutil isn't the problem. Context is.

An alert fires. Certutil.exe just ran on an endpoint in your environment, and it's carrying flags you don't usually see. Could it simply be your PKI team renewing a certificate, or is it the first indication of an attack chain? Before we can answer that question, let’s take a look at why attackers use certutil in the first place. 

If you've been around long enough in the industry, you’ve definitely seen certutil get abused. It ships with every Windows box, it's signed by Microsoft, and it has a quiet feature most admins forget about: it can decode base64 and make outbound requests to download files. Attackers exploit it for exactly that reason. Rather than deploying complex malware, they can use certutil for something it was never really designed for, in a way that looks totally legit to any tool that’s only checking signatures. 

So what actually separates legitimate activity from malicious behavior?

The legitimate case 

Your PKI or systems team uses certutil constantly for exactly what its name suggests: certificate management. A legitimate chain usually looks like this:

  • Parent process: a scheduled task, or an admin's interactive PowerShell or cmd session
  • Command line: something referencing a cert store operation, a .cer or .pfx file, or a domain-joined certificate authority
  • Network behavior: none, or a connection to an internal CA server
  • Timing: business hours, tied to certificate renewal cycles or new machine provisioning

The malicious case

Same binary, but notice its shape.

  • Parent process: often something already suspicious on its own, like an Office application spawning cmd, or a process chain that started with a phishing payload
  • Command line: -urlcache and -split flags are the two you should recognize immediately, often paired with -f to force a decode, pointed at a raw file path with no cert extension
  • Network behavior: outbound to an external IP or a domain that has no business reason to be contacted by that host
  • Timing: no relationship to any certificate lifecycle event, often off-hours

The chain spells out exactly what you need to know.

Where the signal comes together

This is the kind of investigation where context matters more than any single flag.

For many EDR workflows, that context starts with building the query. Pull the process tree, filter on certutil, filter again on the flags, and manually cross-reference the parent process. Those skills still matter, and that work is still part of good threat hunting. But Symantec® CBX changes where that manual effort gets spent.

Rather than manually stitching together the parent process, command line, and destination into a story, Threat Tracer (a visualization feature within CBX) surfaces that chain as a connected picture. Instead of rebuilding every step by hand, analysts can review the chain in context and spend more time interpreting what it means. Your job shifts from finding the connection to deciding whether that connection is expected or suspicious.

That’s the distinction this series is built around. A platform can assemble telemetry, but it still needs you, the analyst, to recognize when an execution chain deviates from normal behavior. 

What to look for in Threat Tracer 

First, focus on the process lineage, checking for anything that shouldn't be spawning certutil at all. Then, look at the destination. Does it align with your certificate infrastructure, or is it reaching out to an external host with no operational reason to be contacted? Once you've seen that sequence, you'll recognize it every time, regardless of what alert triggered the investigation.

A quick posture check

Before you close out, consider these questions about your own environment:

  1. If certutil executed with -urlcache -split -f against an external destination on one of your endpoints right now, would you catch it on the flags alone, or would you need the full attack chain?
  2. Do you have a clear baseline for how  your PKI teams legitimately use certutil, allowing you to distinguish expected activity from anomalous behavior quickly?
  3. If you opened up Threat Tracer with just this execution chain, with no other context, could you determine what happened without relying on additional context?

If any of these questions gave you pause or felt hard to answer, that’s not unusual. Every investigation starts with understanding what “normal” looks like in your own environment. The clearer your baselines, the easier it’ll be to recognize when something deviates from it. 

Next, we’ll look at another ATT&CK technique using the same approach: what’s normal, what’s not, and what tool can help you make that distinction faster. 

To see how Symantec CBX can help speed investigations, reach out to your in-region expert for a 1:1 demo.

You might also enjoy

The Detection Gap: MITRE ATT&CK T1140 and T1105

Kirk Hasty

Kirk Hasty

Technical Product Engineer & Manager of Technical Enablement, Enterprise Security Group, Broadcom