Detecttechnique

D3-CACertificate Analysis

Certificate Analysis

Definition

Analyzing Public Key Infrastructure certificates to detect if they have been misconfigured or spoofed using both network traffic, certificate fields and third-party logs.

Defends against6

TypeTargetConfidenceTier
TechniqueApplication Layer Protocolt1071100%live
TechniqueExfiltration Over C2 Channelt1041100%live
SubTechniqueAsymmetric Cryptographyt1573.002100%live
SubTechniqueExfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002100%live
TechniqueSteal or Forge Authentication Certificatest1649100%live
SubTechniqueWeb Protocolst1071.001100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Active Certificate Analysis
Defence
Passive Certificate Analysis
Defence
Connection Attempt Analysis
Defence
DNS Traffic Analysis
Defence
Application Protocol Command Analysis
Defence
IP Reputation Analysis
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.