CYFIRMA - Attack Surface - Weak Certificate Exposure - High Rule

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This alert indicates that a weak or insecure SSL/TLS certificate has been detected on a public-facing asset monitored by Cyfirma. Such certificates do not meet modern encryption standards and are considered insecure, especially for handling sensitive transactions. This exposure increases the risk of man-in-the-middle attacks and loss of data integrity or confidentiality. Immediate remediation is advised by replacing weak certificates with strong, industry-compliant ones.

Attribute Value
Type Analytic Rule
Solution Cyfirma Attack Surface
ID 3b5a1c0e-7f3a-4d47-8416-6c0b8b91e9ce
Severity High
Status Available
Kind Scheduled
Tactics DefenseEvasion, ResourceDevelopment, Reconnaissance, InitialAccess, CredentialAccess
Techniques T1553, T1588, T1595, T1190, T1552
Required Connectors CyfirmaAttackSurfaceAlertsConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CyfirmaASCertificatesAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Cyfirma Attack Surface