// MITRE ATT&CK
T1588.004 · Digital Certificates
Sub-technique of T1588 · Obtain Capabilities.
Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They include information about the key, information about its owner's identity, and the digital signature of an entity that has verified the certificate's cont...
How to detect & mitigate it
Detecting Digital Certificates starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1583
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1583.002
DNS Server T1587.003
Digital Certificates T1587.001
Malware
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1583.002
DNS Server T1587.003
Digital Certificates T1587.001
Malware
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.