{"id":"T1587.003","name":"Digital Certificates","url":"https://attack.mitre.org/techniques/T1587/003","tactics":["resource-development"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0844","stix_id":"x-mitre-detection-strategy--2e8be762-9987-4f19-997d-2f7c7540b8e1","name":"Detection of Digital Certificates","url":"https://attack.mitre.org/detectionstrategies/DET0844","analytics":[{"id":"AN1976","stix_id":"x-mitre-analytic--06c3cd77-148a-424e-a55e-1e11ff3d9504","name":"Analytic 1976","description":"Consider use of services that may aid in the tracking of certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017)\nDetection efforts may be focused on related behaviors, such as [Web Protocols](https://attack.mitre.org/techniques/T1071/001) , [Asymmetric Cryptography](https://attack.mitre.org/techniques/T1573/002) , and/or [Install Root Certificate](https://attack.mitre.org/techniques/T1553/004) .","url":"https://attack.mitre.org/detectionstrategies/DET0844#AN1976","platforms":["PRE"],"log_source_references":[{"name":"Internet Scan","channel":"None","data_component":"DC0104","data_component_name":"Response Content","log_source_slug":"internet-scan"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0844"],"techniques":["T1587.003"]}],"live":true,"version":"1.0","techniques":["T1587.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}