Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- detections
Loading detections…
Loading detections
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
Loading detections…
Detects the execution of certutil with either the "decode" or "decodehex" flags to decode base64 or hex encoded files. This can be abused by attackers to decode an encoded payload before execution
Outside the enterprise matrix
Published to signed-in readers
The query as its source wrote it, its canonical form, and the content hash that pins this exact revision.