<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Secure Firewall - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/secure-firewall/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 12:31:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/secure-firewall/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Detection of Malicious SSL Certificate Fingerprints in Cisco Secure Firewall</title><link>https://feed.craftedsignal.io/briefs/2026-10-cisco-ssl-fingerprint/</link><pubDate>Mon, 05 Oct 2026 12:31:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cisco-ssl-fingerprint/</guid><description>This detection utilizes Cisco Secure Firewall logs to identify TLS-encrypted sessions established using known malicious or blacklisted SSL certificate fingerprints associated with C2, malware, and phishing.</description><content:encoded><![CDATA[<p>Adversaries frequently employ self-signed or reused SSL/TLS certificates across their malicious infrastructure to maintain operational security or facilitate encrypted communication channels. Because these certificates are often deployed across multiple Command and Control (C2) servers or malware distribution sites, their unique SHA1 fingerprints serve as a high-fidelity indicator of malicious activity. This intelligence brief highlights a detection capability for Cisco Secure Firewall environments that cross-references observed TLS handshake events against the SSLBL (SSL Blacklist) database. By monitoring the SSL_CertFingerprint field in Cisco Firepower Threat Defense (FTD) connection logs, security teams can detect beaconing, data exfiltration, or secondary stage payload delivery even when the associated destination domains or IP addresses are dynamically rotated by the attacker. This technique provides visibility into encrypted traffic without requiring full SSL/TLS decryption.</p>
<h2 id="impact">Impact</h2>
<p>Successful identification of these fingerprints allows defenders to uncover hidden C2 traffic and malicious infrastructure that would otherwise remain opaque in network telemetry. If left unmonitored, attackers can sustain long-term persistence, exfiltrate sensitive data, and distribute malware through encrypted channels while bypassing traditional domain or IP-based reputation filters.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Integrate Cisco Secure Firewall Threat Defense connection logs into your SIEM using the Splunk Add-on for Cisco Security Cloud.</li>
<li>Implement the provided lookup-based detection logic to alert on any outbound connection matching a fingerprint in the SSLBL repository.</li>
<li>Enable SSL/TLS logging on your Cisco Secure Firewall access policies to ensure the <code>SSL_CertFingerprint</code> field is populated in connection events.</li>
<li>Cross-reference matches with destination IP reputation and internal asset criticality to prioritize incident response efforts.</li>
<li>Establish a process for regular updates to your local SSLBL lookup table to ensure the blacklist remains effective against evolving threat infrastructure.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>network-security</category><category>tls-inspection</category><category>c2-detection</category></item></channel></rss>