惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

M
MIT News - Artificial intelligence
AI
AI
月光博客
月光博客
爱范儿
爱范儿
博客园 - 司徒正美
Last Week in AI
Last Week in AI
博客园 - 三生石上(FineUI控件)
S
Security @ Cisco Blogs
腾讯CDC
W
WeLiveSecurity
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Help Net Security
Help Net Security
人人都是产品经理
人人都是产品经理
WordPress大学
WordPress大学
Cyberwarzone
Cyberwarzone
K
Kaspersky official blog
Security Latest
Security Latest
博客园 - 叶小钗
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
A
Arctic Wolf
C
Cisco Blogs
H
Heimdal Security Blog
雷峰网
雷峰网
阮一峰的网络日志
阮一峰的网络日志
Google DeepMind News
Google DeepMind News
小众软件
小众软件
T
Tenable Blog
Attack and Defense Labs
Attack and Defense Labs
N
News and Events Feed by Topic
The Last Watchdog
The Last Watchdog
V2EX - 技术
V2EX - 技术
Simon Willison's Weblog
Simon Willison's Weblog
Vercel News
Vercel News
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
V
Vulnerabilities – Threatpost
L
LangChain Blog
Y
Y Combinator Blog
V
V2EX
Hacker News - Newest:
Hacker News - Newest: "LLM"
Latest news
Latest news
D
Docker
AWS News Blog
AWS News Blog
Google Online Security Blog
Google Online Security Blog
H
Help Net Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Troy Hunt's Blog
TaoSecurity Blog
TaoSecurity Blog
Cloudbric
Cloudbric
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

SECURITY.COM

Spirals: New Stealthy Ransomware Deployed Against Asian IT Company Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor Humble Brag: Symantec® Data Center Security Achieves Common Criteria Certification GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses Tips to Harden Your Air Gapped Environments The Visibility Challenge Nobody Asked For AV-TEST Gives Symantec® Endpoint Security Complete a Perfect Score The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security 🎙️SECURITY.COM The Podcast: The Parasite in the Machine: Unmasking the Speagle Infostealer Your DLP Incident Backlog Owes You Closure Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker 5 Reasons Symantec® CBX Delivers Total Endpoint Visibility 8 XDR Questions From the Show Floor Another Year, Another Win: SE Labs® Recognizes Symantec® Endpoint Security Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden Locking Down the Server 🎙️SECURITY.COM The Podcast: The Death of SIEM Threats Rise on a Tide of Global Unrest When Nation-States Stop Caring About Size Espionage Campaign Targeted Stock Exchange Executive for Five Months Data Security Is Having A Moment 5 Ways XDR Helps SOCs Act Faster 🎙️SECURITY.COM The Podcast: The Evolution of Cybersecurity PR with W2 Communications The Maximalism Trap: When More Becomes Too Much Symantec DLP Cloud and DPSM are the Power Couple Security Strategists Need Symantec DLP Cloud and DSPM are the Power Couple Security Strategists Need The Future of the Partnership: AI, Automation, and Ecosystems Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations 🎙️SECURITY.COM The Podcast: Iran’s Cyber Warfare Playbook: What Defenders Need to Know Right Now 5 Ways To Keep AI in Check Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign Doing More with Less: How Government Agencies are Rethinking Cybersecurity Navigating Compliance and Insurance as a Competitive Edge Is SIEM Trying to Do Too Much? Every Defender Deserves Frontier AI The New Partner-Vendor Relationship DLP Made Easier on the Teams Running It The EU Digital Wallet: Why Waiting is Not an Option Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft Stopping Data Leaks at the Speed of AI Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor How AI Increases the Load on Security Teams Web Traffic Visibility is the New Non-Negotiable The Agentic AI Tsunami is Here: Is Your Legacy IAM Sinking or Swimming? Technical Enablement vs. Marketing Noise Enterprise-Grade Security for All in 2026 Architecting for Margin Beyond the Initial Sale 🎙️SECURITY.COM The Podcast: A Brief History of Data Loss Prevention Symantec CBX Through the Paparazzi Lens The U.S. Navy’s Playbook for Cost-Controlled, Reliable Cybersecurity The Modern Threat Landscape and The Partner’s New Burden Symantec CBX Rocked RSAC 2026 Conference For Financial Services, a Wake-Up Call for Reclaiming IAM Control The Next Identity Shift Cyber Legends: Behind the Scenes of CBX Built for This Moment (and All Those to Come)
The Detection Gap: MITRE ATT&CK T1140 and T1105
About the Author · 2026-07-13 · via SECURITY.COM
  • Certutil abuse often hides behind legitimate Windows behavior.
  • The difference between normal and malicious activity comes down to execution context.
  • Threat Tracer brings the chain into view so analysts can spend less time stitching and more time interpreting.

The Detection Gap is a breakdown for security practitioners who have to make quick calls under tight time constraints. In each post of this series, we’ll take one MITRE ATT&CK technique and walk through what it looks like when it's legitimate activity and compare what changes when it's actually an attacker in your environment. No theory, and no query syntax to memorize. Just the exact distinction that separates a real incident from everyday noise, made explicit, one technique at a time.

Certutil isn't the problem. Context is.

An alert fires. Certutil.exe just ran on an endpoint in your environment, and it's carrying flags you don't usually see. Could it simply be your PKI team renewing a certificate, or is it the first indication of an attack chain? Before we can answer that question, let’s take a look at why attackers use certutil in the first place. 

If you've been around long enough in the industry, you’ve definitely seen certutil get abused. It ships with every Windows box, it's signed by Microsoft, and it has a quiet feature most admins forget about: it can decode base64 and make outbound requests to download files. Attackers exploit it for exactly that reason. Rather than deploying complex malware, they can use certutil for something it was never really designed for, in a way that looks totally legit to any tool that’s only checking signatures. 

So what actually separates legitimate activity from malicious behavior?

The legitimate case 

Your PKI or systems team uses certutil constantly for exactly what its name suggests: certificate management. A legitimate chain usually looks like this:

  • Parent process: a scheduled task, or an admin's interactive PowerShell or cmd session
  • Command line: something referencing a cert store operation, a .cer or .pfx file, or a domain-joined certificate authority
  • Network behavior: none, or a connection to an internal CA server
  • Timing: business hours, tied to certificate renewal cycles or new machine provisioning

The malicious case

Same binary, but notice its shape.

  • Parent process: often something already suspicious on its own, like an Office application spawning cmd, or a process chain that started with a phishing payload
  • Command line: -urlcache and -split flags are the two you should recognize immediately, often paired with -f to force a decode, pointed at a raw file path with no cert extension
  • Network behavior: outbound to an external IP or a domain that has no business reason to be contacted by that host
  • Timing: no relationship to any certificate lifecycle event, often off-hours

The chain spells out exactly what you need to know.

Where the signal comes together

This is the kind of investigation where context matters more than any single flag.

For many EDR workflows, that context starts with building the query. Pull the process tree, filter on certutil, filter again on the flags, and manually cross-reference the parent process. Those skills still matter, and that work is still part of good threat hunting. But Symantec® CBX changes where that manual effort gets spent.

Rather than manually stitching together the parent process, command line, and destination into a story, Threat Tracer (a visualization feature within CBX) surfaces that chain as a connected picture. Instead of rebuilding every step by hand, analysts can review the chain in context and spend more time interpreting what it means. Your job shifts from finding the connection to deciding whether that connection is expected or suspicious.

That’s the distinction this series is built around. A platform can assemble telemetry, but it still needs you, the analyst, to recognize when an execution chain deviates from normal behavior. 

What to look for in Threat Tracer 

First, focus on the process lineage, checking for anything that shouldn't be spawning certutil at all. Then, look at the destination. Does it align with your certificate infrastructure, or is it reaching out to an external host with no operational reason to be contacted? Once you've seen that sequence, you'll recognize it every time, regardless of what alert triggered the investigation.

A quick posture check

Before you close out, consider these questions about your own environment:

  1. If certutil executed with -urlcache -split -f against an external destination on one of your endpoints right now, would you catch it on the flags alone, or would you need the full attack chain?
  2. Do you have a clear baseline for how  your PKI teams legitimately use certutil, allowing you to distinguish expected activity from anomalous behavior quickly?
  3. If you opened up Threat Tracer with just this execution chain, with no other context, could you determine what happened without relying on additional context?

If any of these questions gave you pause or felt hard to answer, that’s not unusual. Every investigation starts with understanding what “normal” looks like in your own environment. The clearer your baselines, the easier it’ll be to recognize when something deviates from it. 

Next, we’ll look at another ATT&CK technique using the same approach: what’s normal, what’s not, and what tool can help you make that distinction faster. 

To see how Symantec CBX can help speed investigations, reach out to your in-region expert for a 1:1 demo.

You might also enjoy

The Detection Gap: MITRE ATT&CK T1140 and T1105

Kirk Hasty

Kirk Hasty

Technical Product Engineer & Manager of Technical Enablement, Enterprise Security Group, Broadcom