Can your SOC see a payload wrapped up to look like nothing?
One real attacker move, a safe way to run it on a machine you own, and the detection that closes the gap — in that order, so you leave with better coverage than you arrived with.
technique T1027 · Obfuscated Files or Informationseen in Kimsukywhere any Windows box
What this is about
Can your SOC see a file encoded so nothing can read it?
A content scanner reads bytes. Encode those bytes to base64 and the scanner reads nothing — not a signature, not a keyword, not a file type. That is the whole trick, and Windows performs it for free: certutil -encode was built to handle certificates, and it will happily encode anything you hand it.
The detection does not try to decide whether the encoded thing is malicious — it cannot, and neither can your scanner, which is the point. It watches for the tool being used this way, because a certificate utility encoding a file is a question worth asking.
The detection watches one thing: certutil being used to encode a file to base64.
This is not hypothetical
The group tracked as Kimsuky is documented obfuscating files and information on the systems it touches. Encoding is what gets a payload past a content inspection on the way in, and what gets stolen data past one on the way out — the same trick in both directions.
No malware is needed to do it. The utility ships with Windows and needs no admin rights. The same command you are about to run.
The actor above is named in MITRE ATT&CK’s own Procedure Examples for this technique; the link is where you can read it. Nothing on this page discloses a move an attacker does not already have — it just makes sure the defender has it too.
Encoded bytes carry no signature and no recognisable file type. Anything looking at content has nothing left to look at.
A signed built-in does the work
certutil is a legitimate, signed Windows utility. There is no suspicious binary to flag, so the flag has to be on the usage.
It works in both directions
The same move hides a payload arriving and hides data leaving. One detection covers a step in two very different attacks.
The test
Run the real thing. Safely. On a box you own.
Encode a harmless file the way an intruder encodes a payload, then delete both — the script cleans up after itself.
01
Write a harmless marker file
The script creates one small text file in your own temp folder. Its contents are a plain sentence and nothing else.
02
Encode it with the built-in utility
Run certutil -encode on that file — the actual technique, a file turned into base64 so a content scanner reads nothing. This is the moment your SOC should notice.
03
Check your alerts, then let it clean up
Open your SOC or EDR and see whether encoding by certutil fired. The last line deletes exactly the two files the script created.
test-your-soc-obfuscation.ps1 · PowerShell · a machine you own
# test-your-soc-obfuscation.ps1 — run on a machine you own.
# Safe: makes one small text file in your own temp folder, encodes it, then deletes both. No admin.
# STEP 1 - write a harmless marker file.
Set-Content -Path "$env:TEMP\CyRaySOCTest.txt" -Value 'harmless marker for a SOC test'
# STEP 2 - the actual technique: encode it so a content scanner reads nothing.
certutil -encode "$env:TEMP\CyRaySOCTest.txt" "$env:TEMP\CyRaySOCTest.b64"
# STEP 3 - open your SOC / EDR. Did encoding by certutil alert?
# STEP 4 - clean up: delete exactly the two files this script created.
Remove-Item "$env:TEMP\CyRaySOCTest.txt","$env:TEMP\CyRaySOCTest.b64" -Force
The script creates two files in your own temp folder — a plain sentence and its base64 form — and the last line deletes exactly those two. Nothing is downloaded, nothing is executed, nothing existing is touched, and no admin rights are needed.
Reading the result — honestly
Something fired
Your tooling watches for a built-in utility being used to encode files
Good — you would see a payload being wrapped, or data being prepared to leave. On to the next one.
Silence
The encoding passed unseen — now you know
Not a verdict on your team; a specific, fixable gap you just found in a minute. The detection below closes it.
Straight with you: we never see your alerts — you’re the judge, which is also why we never touch your data. And a lab isn’t production; a test box often logs differently than the real fleet. "It fired" means your EDR flagged certutil encoding a file — note that legitimate certificate work uses the same flag, so the valuable version of this rule looks at what was encoded and where it came from, not just that encoding happened. Treat a pass as a reason to go check prod, not a finish line.
How to catch it
Missed it? Here’s the fix — take it straight to your SOC.
Copy this to your detection team
The logic is public and every major SIEM already supports it. Here it is in Sigma, the open, vendor-neutral format your team can translate into whatever you run.
proc_creation_win_certutil_encode.yml
title: File Encoded To Base64 Via Certutil.EXEid: e62a9f0c-ca1e-46b2-85d5-a6da77f86d1astatus: testdescription: Detects the execution of certutil with the "encode" flag to encode a file to base64. This can be abused by threat actors and attackers for data exfiltrationreferences: - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil - https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/ - https://lolbas-project.github.io/lolbas/Binaries/Certutil/author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems)date: 2019-02-24modified: 2024-03-05tags: - attack.stealth
- attack.t1027
logsource: category: process_creation product: windowsdetection: selection_img: - Image|endswith: '\certutil.exe' - OriginalFileName: 'CertUtil.exe' selection_cli: CommandLine|contains|windash: '-encode' condition: all of selection_*falsepositives: - As this is a general purpose rule, legitimate usage of the encode functionality will trigger some false positives. Apply additional filters accordingly
level: mediumregression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_certutil_encode/info.yml
File Encoded To Base64 Via Certutil.EXE · SigmaHQ rule e62a9f0c-ca1e-46b2-85d5-a6da77f86d1a
Author Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems) · quoted in full and unmodified under the Detection Rule License 1.1 (DRL 1.1)
If your test came back silent, that rule is the whole fix. Drop it into your SIEM, or send your provider this page — “we ran this, nothing fired, here’s the detection.” Either way your coverage is better tonight than it was this morning. That’s the point.
A new one every week
This is technique 11 of many.
Each one is a real attacker move, a safe way to try it, and the detection to close the gap. Run them over a few weeks and you’ll learn more about your real coverage than any dashboard has told you.
Curious how a system catches all of these at once, out of the box? That’s what we build — meet Mobula →
Credit & sources
The technique and the incident are documented by MITRE ATT&CK (T1027) and the sources linked above. The detection is expressed in Sigma, the open detection format maintained by the SigmaHQ community, so any team can use it freely; its author is credited above under DRL 1.1.
We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.
CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI