Detectsubtechnique

D3-PCAPassive Certificate Analysis

Definition

Collecting host certificates from network traffic or other passive sources like a certificate transparency log and analyzing them for unauthorized activity.

Defends against6

TypeTargetConfidenceTier
SubTechniqueWeb Protocolst1071.001100%live
TechniqueExfiltration Over C2 Channelt1041100%live
SubTechniqueAsymmetric Cryptographyt1573.002100%live
SubTechniqueExfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002100%live
TechniqueSteal or Forge Authentication Certificatest1649100%live
TechniqueApplication Layer Protocolt1071100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Active Certificate Analysis
Defence
Certificate Analysis
Defence
Connection Attempt Analysis
Defence
Application Protocol Command Analysis
Defence
Network Traffic Signature Analysis
Defence
DNS Traffic Analysis
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.