logo

Encryption Does Not Equal Invisibility – Detecting Anomalous TLS Certificates with the Half-Space-Trees Algorithm

ID: 3670841f-7910-51e3-b48c-14b95826a62f

STIX ID: report--3670841f-7910-51e3-b48c-14b95826a62f

Feed Name: Fox-IT blog

Threat Score
45/100

Date Published: 2021-12-07

Date Updated: 2026-04-27

Author: Joost Jansen

...
...

This report presents an approach for detecting suspicious TLS certificates in encrypted traffic by applying incremental, unsupervised anomaly detection (Half-Space-Trees). It explains how attackers obtain and misuse TLS certificates (self-signed, free CAs, stolen/fraudulently issued), contrasts malicious and legitimate certificate attributes with examples (including a Ryuk ransomware certificate), and describes model development, validation, and deployment in SOC environments where anomaly scores are combined with other signals (JA3, beaconing, domain analysis) to enable real-time detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.