CYFIRMA - Attack Surface - Weak Certificate Exposure - Medium Rule

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This alert indicates that a weak or insecure SSL/TLS certificate has been detected on a public-facing asset monitored by Cyfirma. Such certificates do not meet modern encryption standards and are considered insecure, especially for handling sensitive transactions. This exposure increases the risk of man-in-the-middle attacks and loss of data integrity or confidentiality. Immediate remediation is advised by replacing weak certificates with strong, industry-compliant ones.

Attribute Value
Type Analytic Rule
Solution Cyfirma Attack Surface
ID 5a617ff2-3e3d-44e7-b761-9f0d542ae191
Severity Medium
Status Available
Kind Scheduled
Tactics DefenseEvasion, ResourceDevelopment, Reconnaissance, InitialAccess, CredentialAccess
Techniques T1553, T1588, T1595, T1190, T1552
Required Connectors CyfirmaAttackSurfaceAlertsConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CyfirmaASCertificatesAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Cyfirma Attack Surface