Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
neronidis
Explorer

Harmony Endpoint Behavioral Guard stops certutil.exe

Hello all,

after we have install the DHS Approved version (88.50) we are receiving very often the messages that certutil.exe was stopped by the behavioral guard. Thankfully the process is just stopped and not deleted or smth. As you already know this is a very important windows binary that can also be used for malicious purposes (LOTL attacks). So far we have identified that it is definately a false positive. The certutil is used by a local agent that uses the certutil.exe in order to check the Hash value of the packets that it receives from a server. 

Is anyone other in this forum facing the same issues? 

Adding an exlusion on the behavioral guard is possible but unfortunately the filtering options are limited. The distinguish between malicious and legit usage of the binary can be done only by filtering the command's arguments. Which is unfortunately not possible with the "add exclusion" option...

 

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

I've seen a couple of TAC cases where this was specifically mentioned, but did not see any specific instructions.
I assume it depends on what exactly is triggering certutil.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events