Security researchers highlighted continued abuse of the Windows utility certutil.exe as a living-off-the-land tool for downloading malicious files from remote locations. The activity centers on use of the -urlcache and -f arguments, which allow attackers to retrieve payloads while blending into legitimate system activity, even though certutil.exe is intended for certificate management rather than file transfer.
Splunk published detection guidance for identifying this behavior in Windows process and EDR telemetry, specifically looking for command-line patterns associated with remote downloads and payload staging. The analytic was later deprecated and replaced by "Windows File Download Via CertUtil", but the underlying risk remains the same: successful abuse of certutil.exe can enable malware delivery, follow-on execution, system compromise, and unauthorized access, with defenders advised to tune detections using parent-child process relationships and related network activity.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk marked the detection "CertUtil Download With URLCache and Split Arguments" as removed and deprecated in favor of the replacement analytic "Windows File Download Via CertUtil." The entry states the detection was removed in content version 5.8.0 and is no longer maintained or supported.
A FireEye threat research post documented malicious use of certutil, including abuse of URL cache functionality to download payloads as a living-off-the-land technique.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.