Because a lot of EDR detections are purely string based and will be closely watching for certutil doing things that attackers like to use it for.
Making a copy with a new random name defeats this detection logic.
Making a copy with a new random name defeats this detection logic.
No comments yet.