LetsDefend: Suspicious Certutil.exe Usage-LOLBAS TTPs
LetsDefend — SOC163 WriteUp
3 min readMay 25, 2022
--
Walkthrough
We can kick off our investigation with the CMD history of the compromised endpoint “EricProd” which caused an…
--
We can kick off our investigation with the CMD history of the compromised endpoint “EricProd” which caused an…