logo

Advanced Threat Hunting with New SSL Features: Unlocking HuntSQL™ Anomaly Flags for Deeper Detection

ID: 9960345f-5984-5523-aad1-68a82b0a07a4

STIX ID: report--9960345f-5984-5523-aad1-68a82b0a07a4

Feed Name: Hunt.io Blog

Threat Score
65/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

Hunt.io improved its SSL certificate parsing using Google’s Certificate Transparency library and added a set of HuntSQL flags to detect certificate anomalies and TLS misconfigurations; the report demonstrates how these flags help identify C2 infrastructure for malware such as PupyRAT (malformed X.509 versions), AsyncRAT (missing ephemeral RSA signatures), and the Coyote banking trojan (unknown authorities), and includes example query results and filtering strategies to reduce noise and isolate likely malicious servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.