Certificates are used in the authentication process to establish secure connections between devices, such as web browsers and servers, or to digitally sign files or emails.
In the context of threat intelligence, certificate information is useful in a number of ways:
-
Identifying malicious websites and phishing attacks. Many attackers use fake or stolen certificates to make their websites appear legitimate, but analyzing certificate information helps to detect these fraudulent sites.
-
Tracking the activities of threat actors. By analyzing certificate information, security analysts can identify patterns and connections between different attacks, as well as the infrastructure and resources used by specific threat actors.
-
Verifying the authenticity of digital communications. By using certificate information to confirm the identity of a sender, or the authenticity of a file, security teams can reduce the risk of falling victim to phishing, malware, or other attacks.
Silent Push allows you to search through data from our daily scans of the Internet's IPv4 range to obtain information on a broad range of elements related to individual certificates.
-
Navigate to
Advanced Query Builder > IPv4 Queries > Scan Data - Certificates
-
Specify an
IP address
-
Specify a
netmask
to use in combination with an IP address to search across a range of IP addresses -
Specify a certificate fingerprint in
fingerprint_sha1
-
Specify a
domain
(wildcards are supported) -
Select
expired_certs_only
to only return only return data containing expired certificates -
Enter a value in
window
(days) to include scan results within the last amount of specified days -
Specify a value to
limit
the number of results returned -
Enter a value in
skip
to skip a specified number of results -
Click
Search
Saving queries
Organizational users are able to save individual queries ran from Advanced Query Builder
, and store them in the Private Queries
menu for future analysis, or to share with their organization.
-
Specify the query parameters
-
Click
Save Query
-
Give your query a
Name
-
Specify a
Description
to add more context -
Click
Save