Certutil.exe Abused for Payload Download or Decode (T1105, T1140)
Detects the execution of the Windows binary 'certutil.exe' using flags commonly abused by adversaries to download files from remote URLs or decode base64-encoded files. It excludes instances where certutil is executed by Microsoft-signed processes from the System32 directory to reduce false positives.
SentinelOne

