Installing Root Certificate
Defense Evasion
Execution
Adding a certificate with a native windows binary:
certutil.exe -addstore -f -user Root C:\Users\spot\Downloads\certnew.cer
Checking to see the certificate got installed:

Adding the certificate with powershell:

Observations
Advanced poweshell logging to the rescue:

Commandline logging:

The CAs get installed to:
..so it is worth monitoring registry changes there:

References
Last updated