🔒 Certificate Intelligence (CERTINT)
TLS Certificates and Certificate Transparency
Cyber & Threat
Sources
0
0 no-auth
Mission domains
0
reach
Data points
0
covered
Related INT
0
disciplines
🔍 Lookup
📊 Pre-built Queries · Certificate Intelligence
📜 Playbook — Certificate Intelligence collection
- Direction — frame the requirement for Certificate Intelligence: what decision does this support, by when?
- Collection — collect from the 0 mapped sources (0 free) — filter the catalog by CERTINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎯 Mission
Certificate Intelligence monitors TLS/SSL certificate issuance through Certificate Transparency logs and live-host fingerprinting to detect infrastructure, phishing, and brand abuse in near real time. It answers which new certificates reference an organization's brand, what shared infrastructure links adversary hosts, and which internal or C2 servers are identifiable by their TLS fingerprints.
📡 Collection methods
- Real-time streaming of Certificate Transparency logs for brand and keyword matches in domains and SANs
- Enumerating Subject Alternative Names to expand an organization's or adversary's domain footprint
- Certificate fingerprint pivoting (SHA-256, serial, public-key hash) to cluster shared infrastructure
- JARM/JA3S active fingerprinting of live hosts to identify C2 frameworks and server stacks
- Issuer and validity analysis to flag self-signed, short-lived, or free-CA certs typical of malicious infra
- Historical CT search to reconstruct an entity's certificate timeline
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- CertStream
- crt.sh
- JARM
- tlsx
- ctfr
- Censys
- massdns
- Maltego
📜 Certificate Intelligence Tradecraft
- Subscribe to CT streams and historical CT search filtered on brand terms, owned domains, and target keywords
- Parse each certificate into issuer, SANs, validity window, and key/fingerprint fields and resolve SANs to live hosts
- Analyze issuance patterns to separate legitimate renewals from suspicious lookalike or bulk free-CA registrations
- Attribute clustered hosts to a common operator using shared fingerprints, JARM overlaps, and issuer/timing correlation
- Disseminate alerts on newly minted phishing certs and expiring owned certs to brand-protection and PKI teams
- Initiate takedown or blocklisting of malicious certs/domains and monitor CT for the actor re-issuing replacements
📊 Dashboard KPIs
New certs matching brandPhishing certs detectedExpiring owned certsSelf-signed on infraJARM cluster overlaps
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron