Windows certutil.exe, a legitimate certificate-management utility, has been documented as a living-off-the-land binary that attackers can abuse to download payloads and support follow-on compromise. Public LOLBAS and Hexacorn references describe certutil as both a command-line and GUI-capable LOLBin, highlighting how trusted native tooling can be repurposed to fetch remote content while blending into normal administrative activity.
Splunk Threat Research published a detection for certutil.exe abuse involving the -VerifyCtl and -f arguments, a pattern associated with ingress tool transfer under MITRE ATT&CK T1105, before later deprecating it in favor of a broader analytic for Windows file downloads via CertUtil. The detection relied on EDR and Windows process telemetry with full command-line logging, underscoring that monitoring certutil execution remains important because misuse can lead to malicious file retrieval, arbitrary code execution, data exfiltration, and wider system compromise.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detection "CertUtil Download With VerifyCtl and Split Arguments" from its content library and marked it deprecated in favor of "Windows File Download Via CertUtil." The removal is noted as part of content library version 5.8.0.
The LOLBAS project published an entry for Certutil, cataloging it as a legitimate Windows binary that can be abused for attacker activity.
A Hexacorn blog post documented certutil as "one more GUI lolbin," adding to public research on the utility's living-off-the-land abuse potential.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourcelolbas-project.github.io
Open sourcehexacorn.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.