{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/c2-detection/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Secure Firewall"],"_cs_severities":["medium"],"_cs_tags":["network-security","tls-inspection","c2-detection"],"_cs_type":"advisory","_cs_vendors":["Cisco"],"content_html":"\u003cp\u003eAdversaries frequently employ self-signed or reused SSL/TLS certificates across their malicious infrastructure to maintain operational security or facilitate encrypted communication channels. Because these certificates are often deployed across multiple Command and Control (C2) servers or malware distribution sites, their unique SHA1 fingerprints serve as a high-fidelity indicator of malicious activity. This intelligence brief highlights a detection capability for Cisco Secure Firewall environments that cross-references observed TLS handshake events against the SSLBL (SSL Blacklist) database. By monitoring the SSL_CertFingerprint field in Cisco Firepower Threat Defense (FTD) connection logs, security teams can detect beaconing, data exfiltration, or secondary stage payload delivery even when the associated destination domains or IP addresses are dynamically rotated by the attacker. This technique provides visibility into encrypted traffic without requiring full SSL/TLS decryption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful identification of these fingerprints allows defenders to uncover hidden C2 traffic and malicious infrastructure that would otherwise remain opaque in network telemetry. If left unmonitored, attackers can sustain long-term persistence, exfiltrate sensitive data, and distribute malware through encrypted channels while bypassing traditional domain or IP-based reputation filters.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIntegrate Cisco Secure Firewall Threat Defense connection logs into your SIEM using the Splunk Add-on for Cisco Security Cloud.\u003c/li\u003e\n\u003cli\u003eImplement the provided lookup-based detection logic to alert on any outbound connection matching a fingerprint in the SSLBL repository.\u003c/li\u003e\n\u003cli\u003eEnable SSL/TLS logging on your Cisco Secure Firewall access policies to ensure the \u003ccode\u003eSSL_CertFingerprint\u003c/code\u003e field is populated in connection events.\u003c/li\u003e\n\u003cli\u003eCross-reference matches with destination IP reputation and internal asset criticality to prioritize incident response efforts.\u003c/li\u003e\n\u003cli\u003eEstablish a process for regular updates to your local SSLBL lookup table to ensure the blacklist remains effective against evolving threat infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T12:31:08Z","date_published":"2026-10-05T12:31:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cisco-ssl-fingerprint/","summary":"This detection utilizes Cisco Secure Firewall logs to identify TLS-encrypted sessions established using known malicious or blacklisted SSL certificate fingerprints associated with C2, malware, and phishing.","title":"Detection of Malicious SSL Certificate Fingerprints in Cisco Secure Firewall","url":"https://feed.craftedsignal.io/briefs/2026-10-cisco-ssl-fingerprint/"}],"language":"en","title":"CraftedSignal Threat Feed - C2-Detection","version":"https://jsonfeed.org/version/1.1"}