โ† All cheat sheets

CERTUTIL

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: LOLBin / GTFOBins Browser

Windows Certificate Utility: Built-in tool for certificate management.
Also useful for encoding, hashing, and file operations.

HASH OPERATIONS#


    

FILE HASHING#

certutil -hashfile file.txt                  # SHA1 hash (default)
certutil -hashfile file.txt MD5              # MD5 hash
certutil -hashfile file.txt SHA1             # SHA1 hash
certutil -hashfile file.txt SHA256           # SHA256 hash
certutil -hashfile file.txt SHA384           # SHA384 hash
certutil -hashfile file.txt SHA512           # SHA512 hash

# Verify file integrity
certutil -hashfile download.exe SHA256 | findstr /v "hash"

ENCODING & DECODING#


    

BASE64#

certutil -encode file.txt encoded.b64        # Encode to Base64
certutil -decode encoded.b64 decoded.txt     # Decode from Base64

# Encode file inline (for transfer)
certutil -encode file.exe file.txt
type file.txt | clip                         # Copy to clipboard

HEX#

certutil -encodehex file.txt hex.txt         # Encode to hex
certutil -decodehex hex.txt decoded.txt      # Decode from hex

# Hex encoding types
certutil -encodehex file hex.txt 0           # Hex with address
certutil -encodehex file hex.txt 1           # Hex with ASCII
certutil -encodehex file hex.txt 4           # Raw hex
certutil -encodehex file hex.txt 12          # Hex no spaces

FILE DOWNLOAD#

certutil -urlcache -split -f http://url/file.exe output.exe
certutil -urlcache -f http://url/file.exe C:\path\file.exe

# Clean URL cache
certutil -urlcache * delete                  # Clear all cache
certutil -urlcache http://url delete         # Clear specific

# List cached files
certutil -urlcache                           # Show cache

CERTIFICATE MANAGEMENT#


    

VIEW CERTIFICATES#

certutil -store my                           # Personal certs
certutil -store root                         # Trusted root CAs
certutil -store CA                           # Intermediate CAs
certutil -store -user my                     # User personal certs
certutil -dump cert.cer                      # Dump cert details
certutil -dump cert.pfx                      # Dump PFX details
certutil -verify cert.cer                    # Verify certificate

# Store locations
# my        - Personal
# root      - Trusted Root CAs
# CA        - Intermediate CAs
# trust     - Enterprise Trust
# disallowed - Untrusted Certs

IMPORT & EXPORT#

certutil -addstore root cert.cer             # Import to root
certutil -addstore my cert.cer               # Import to personal
certutil -addstore -f root cert.cer          # Force import
certutil -delstore my "cert name"            # Delete from store

# Export certificate
certutil -exportPFX my "cert name" export.pfx

CERTIFICATE REQUESTS#

certutil -submit request.req                 # Submit CSR
certutil -retrieve requestID                 # Retrieve cert
certutil -pulse                              # Trigger autoenroll

CERTIFICATE REVOCATION#

certutil -verify -urlfetch cert.cer          # Verify with CRL
certutil -CRL                                # Get CRL
certutil -URL cert.cer                       # Open URL retrieval tool

CA OPERATIONS#

certutil -ca                                 # CA info
certutil -CAInfo                             # Detailed CA info
certutil -config "CA\Name"                   # Specify CA
certutil -getconfig                          # Interactive CA select
certutil -ping                               # Ping CA service
certutil -pingadmin                          # Ping CA admin

# CA database
certutil -view -out requestid,commonname     # View issued certs
certutil -view -restrict "disposition=20"   # Pending requests
certutil -view -restrict "requestid>=100"   # Filter by ID

KEY OPERATIONS#

certutil -key                                # List key containers
certutil -key -user                          # User key containers
certutil -key -csp "Microsoft Base Cryptographic Provider v1.0"
certutil -delkey containername               # Delete key container
certutil -verifykeys                         # Verify key integrity

CSP & PROVIDER INFO#

certutil -csplist                            # List CSPs
certutil -csptest "CSP Name"                 # Test CSP

CRL MANAGEMENT#

certutil -addstore root crl.crl              # Add CRL
certutil -setreg ca\CRLDeltaPeriodUnits 1    # Configure CRL
certutil -getreg ca\CRLDeltaPeriodUnits      # Get CRL config

TROUBLESHOOTING#

certutil -v -verify cert.cer                 # Verbose verify
certutil -verifyctl AuthRoot                 # Verify CTL
certutil -syncWithWU                         # Sync with Windows Update
certutil -generateSSTFromWU roots.sst        # Download root certs

# Event logging
certutil -setreg chain\ChainCacheResyncFiletime @now
certutil -setreg -user policy\EnableCertPaddingCheck 1

SECURITY USES#

# Download and verify hash
certutil -urlcache -split -f http://url/file.exe file.exe
certutil -hashfile file.exe SHA256

# Encode payload for transfer
certutil -encode payload.exe payload.b64

# Decode on target
certutil -decode payload.b64 payload.exe

# ADS (Alternate Data Streams) - read hidden data
certutil -dump file.txt:hidden

FORMAT CONVERSION#

# DER to PEM
certutil -encode cert.der cert.pem

# PEM to DER
certutil -decode cert.pem cert.der

# Extract cert from PFX (shows in console)
certutil -dump cert.pfx

TEMPLATE MANAGEMENT#

certutil -template                           # List templates
certutil -CATemplates                        # CA templates
certutil -dstemplate "templatename"          # Template details

REGISTRY OPERATIONS#

certutil -getreg                             # Get all registry
certutil -getreg ca\*                        # CA registry settings
certutil -setreg ca\setting value            # Set registry value

QUICK REFERENCE#

# File operations
certutil -hashfile file.txt SHA256           # Hash file
certutil -encode file.txt file.b64           # Base64 encode
certutil -decode file.b64 file.txt           # Base64 decode
certutil -urlcache -split -f url output      # Download file

# Certificate viewing
certutil -store my                           # Personal store
certutil -store root                         # Root CAs
certutil -dump cert.cer                      # View certificate

# Verification
certutil -verify cert.cer                    # Verify cert
certutil -verify -urlfetch cert.cer          # Verify with CRL

DEFENSIVE NOTES#

# Certutil is often used by attackers for:
# - Downloading malicious files
# - Encoding/decoding payloads
# - Bypassing application whitelisting

# Monitor for suspicious certutil usage:
# - certutil -urlcache (file downloads)
# - certutil -encode/-decode (payload handling)
# - Execution from temp directories

# Detection: Look for Event ID 4688 (process creation)
# with certutil.exe and suspicious arguments