Umbra Wiki defense defense/D3-CA
Back to wiki

D3-CA — Certificate Analysis

provenance: imported · ATT&CK: T1041 T1048 T1048.002 T1071 T1071.001 T1071.002 T1071.003 T1071.004 T1071.005 T1573 T1573.002 T1649

D3-CA: Certificate Analysis

MITRE D3FEND countermeasure

What it does

Analyzing Public Key Infrastructure certificates to detect if they have been misconfigured or spoofed using both network traffic, certificate fields and third-party logs.

Attacks this counters

The chain in this corpus runs CVE → CWE → CAPEC → ATT&CK technique, which ends at what an adversary does. This is the hop after: what stops it.

Source