Hello all,
after we have install the DHS Approved version (88.50) we are receiving very often the messages that certutil.exe was stopped by the behavioral guard. Thankfully the process is just stopped and not deleted or smth. As you already know this is a very important windows binary that can also be used for malicious purposes (LOTL attacks). So far we have identified that it is definately a false positive. The certutil is used by a local agent that uses the certutil.exe in order to check the Hash value of the packets that it receives from a server.
Is anyone other in this forum facing the same issues?
Adding an exlusion on the behavioral guard is possible but unfortunately the filtering options are limited. The distinguish between malicious and legit usage of the binary can be done only by filtering the command's arguments. Which is unfortunately not possible with the "add exclusion" option...