Advanced Threat Hunting with New SSL Features: Unlocking HuntSQL⢠Anomaly Flags for Deeper Detection
ID: 9960345f-5984-5523-aad1-68a82b0a07a4
STIX ID: report--9960345f-5984-5523-aad1-68a82b0a07a4
Feed Name: Hunt.io Blog
Hunt.io improved its SSL certificate parsing using Google’s Certificate Transparency library and added a set of HuntSQL flags to detect certificate anomalies and TLS misconfigurations; the report demonstrates how these flags help identify C2 infrastructure for malware such as PupyRAT (malformed X.509 versions), AsyncRAT (missing ephemeral RSA signatures), and the Coyote banking trojan (unknown authorities), and includes example query results and filtering strategies to reduce noise and isolate likely malicious servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
