LOLBin Abuse - Certutil Download or Decode Flags
Detects the abuse of the Windows built-in utility 'certutil.exe' to download files or decode obfuscated payloads. Attackers frequently use certutil as a Living off the Land Binary (LOLBin) to bypass security controls by leveraging its native capabilities for file transfer (via URL cache) and base64 or hexadecimal decoding.
Sigma

