Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0848 — Detection of Digital Certificates
DET0848

Detection of Digital Certificates

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1980 Analytic 1980
PRE

Consider use of services that may aid in the tracking of newly issued certificates and/or certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017) Some server-side components of adversary tools may have default values set for SSL/TLS certificates.(Citation: Recorded Future Beacon Certificates) Monitor for logged network traffic in response to a scan showing both protocol header and body values that may buy and/or steal SSL/TLS certificates that can be used during targeting. Detection efforts may be focused on related behaviors, such as Web Protocols, Asymmetric Cryptography, and/or Install Root Certificate.

Certificate None Internet Scan None

Detected Techniques

1

Resource Development (1)

Details

MITRE ID
DET0848
STIX ID
x-mitre-detection-strategy--4cadb231-5487-4135-834b-d0db75a93a45
Analytics
1
Techniques Detected
1
By Tactic
Resource Development
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.