Test your SOC · about a minute

Can your SOC see a payload wrapped up to look like nothing?

One real attacker move, a safe way to run it on a machine you own, and the detection that closes the gap — in that order, so you leave with better coverage than you arrived with.

technique T1027 · Obfuscated Files or Informationseen in Kimsukywhere any Windows box

What this is about

Can your SOC see a file encoded so nothing can read it?

A content scanner reads bytes. Encode those bytes to base64 and the scanner reads nothing — not a signature, not a keyword, not a file type. That is the whole trick, and Windows performs it for free: certutil -encode was built to handle certificates, and it will happily encode anything you hand it.

The detection does not try to decide whether the encoded thing is malicious — it cannot, and neither can your scanner, which is the point. It watches for the tool being used this way, because a certificate utility encoding a file is a question worth asking.

The detection watches one thing: certutil being used to encode a file to base64.

This is not hypothetical

The group tracked as Kimsuky is documented obfuscating files and information on the systems it touches. Encoding is what gets a payload past a content inspection on the way in, and what gets stolen data past one on the way out — the same trick in both directions.

No malware is needed to do it. The utility ships with Windows and needs no admin rights. The same command you are about to run.

The actor above is named in MITRE ATT&CK’s own Procedure Examples for this technique; the link is where you can read it. Nothing on this page discloses a move an attacker does not already have — it just makes sure the defender has it too.

It defeats content inspection

Encoded bytes carry no signature and no recognisable file type. Anything looking at content has nothing left to look at.

A signed built-in does the work

certutil is a legitimate, signed Windows utility. There is no suspicious binary to flag, so the flag has to be on the usage.

It works in both directions

The same move hides a payload arriving and hides data leaving. One detection covers a step in two very different attacks.

The test

Run the real thing. Safely. On a box you own.

Encode a harmless file the way an intruder encodes a payload, then delete both — the script cleans up after itself.

01

Write a harmless marker file

The script creates one small text file in your own temp folder. Its contents are a plain sentence and nothing else.

02

Encode it with the built-in utility

Run certutil -encode on that file — the actual technique, a file turned into base64 so a content scanner reads nothing. This is the moment your SOC should notice.

03

Check your alerts, then let it clean up

Open your SOC or EDR and see whether encoding by certutil fired. The last line deletes exactly the two files the script created.

test-your-soc-obfuscation.ps1 · PowerShell · a machine you own
# test-your-soc-obfuscation.ps1 — run on a machine you own.
# Safe: makes one small text file in your own temp folder, encodes it, then deletes both. No admin.
# STEP 1 - write a harmless marker file.
Set-Content -Path "$env:TEMP\CyRaySOCTest.txt" -Value 'harmless marker for a SOC test'
# STEP 2 - the actual technique: encode it so a content scanner reads nothing.
certutil -encode "$env:TEMP\CyRaySOCTest.txt" "$env:TEMP\CyRaySOCTest.b64"
# STEP 3 - open your SOC / EDR. Did encoding by certutil alert?
# STEP 4 - clean up: delete exactly the two files this script created.
Remove-Item "$env:TEMP\CyRaySOCTest.txt","$env:TEMP\CyRaySOCTest.b64" -Force

The script creates two files in your own temp folder — a plain sentence and its base64 form — and the last line deletes exactly those two. Nothing is downloaded, nothing is executed, nothing existing is touched, and no admin rights are needed.

Reading the result — honestly

Something fired

Your tooling watches for a built-in utility being used to encode files

Good — you would see a payload being wrapped, or data being prepared to leave. On to the next one.

Silence

The encoding passed unseen — now you know

Not a verdict on your team; a specific, fixable gap you just found in a minute. The detection below closes it.

Straight with you: we never see your alerts — you’re the judge, which is also why we never touch your data. And a lab isn’t production; a test box often logs differently than the real fleet. "It fired" means your EDR flagged certutil encoding a file — note that legitimate certificate work uses the same flag, so the valuable version of this rule looks at what was encoded and where it came from, not just that encoding happened. Treat a pass as a reason to go check prod, not a finish line.

How to catch it

Missed it? Here’s the fix — take it straight to your SOC.

The logic is public and every major SIEM already supports it. Here it is in Sigma, the open, vendor-neutral format your team can translate into whatever you run.

proc_creation_win_certutil_encode.yml
title: File Encoded To Base64 Via Certutil.EXE
id: e62a9f0c-ca1e-46b2-85d5-a6da77f86d1a
status: test
description: Detects the execution of certutil with the "encode" flag to encode a file to base64. This can be abused by threat actors and attackers for data exfiltration
references:
    - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil
    - https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/
    - https://lolbas-project.github.io/lolbas/Binaries/Certutil/
author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems)
date: 2019-02-24
modified: 2024-03-05
tags:
    - attack.stealth
    - attack.t1027
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith: '\certutil.exe'
        - OriginalFileName: 'CertUtil.exe'
    selection_cli:
        CommandLine|contains|windash: '-encode'
    condition: all of selection_*
falsepositives:
    - As this is a general purpose rule, legitimate usage of the encode functionality will trigger some false positives. Apply additional filters accordingly
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_certutil_encode/info.yml

File Encoded To Base64 Via Certutil.EXE · SigmaHQ rule e62a9f0c-ca1e-46b2-85d5-a6da77f86d1a

Author Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems) · quoted in full and unmodified under the Detection Rule License 1.1 (DRL 1.1)

https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_certutil_encode.yml

Retrieved 2026-09-11 · file sha256 7772ab83ef885b07904dbcc7824ce86d2a907fa9eec9c95861251cae02ab9e76

If your test came back silent, that rule is the whole fix. Drop it into your SIEM, or send your provider this page — “we ran this, nothing fired, here’s the detection.” Either way your coverage is better tonight than it was this morning. That’s the point.

A new one every week

This is technique 11 of many.

Each one is a real attacker move, a safe way to try it, and the detection to close the gap. Run them over a few weeks and you’ll learn more about your real coverage than any dashboard has told you.

Curious how a system catches all of these at once, out of the box? That’s what we build — meet Mobula →

Credit & sources

The technique and the incident are documented by MITRE ATT&CK (T1027) and the sources linked above. The detection is expressed in Sigma, the open detection format maintained by the SigmaHQ community, so any team can use it freely; its author is credited above under DRL 1.1.

We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.

CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI