Uncommon Network Connection Initiated By Certutil.EXE — Detection Rule

Detects a network connection initiated by the certutil.exe utility. Attackers can abuse the utility in order to download malware or additional payloads.

Read the full analysis on IntelFusions