// MITRE ATT&CK
T1588.004 · Digital Certificates
Sub-técnica de T1588 · Obtain Capabilities.
Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They include information about the key, information about its owner's identity, and the digital signature of an entity that has verified the certificate's cont...
¿Cómo detectarlo y mitigarlo?
La detección de Digital Certificates parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Técnicas relacionadas
T1583
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1583.002
DNS Server T1587.003
Digital Certificates T1587.001
Malware
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1583.002
DNS Server T1587.003
Digital Certificates T1587.001
Malware
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.