Post #3563261
2026-07-03 18:45 UTC
@netresec@infosec.exchange @james_inthe_box@infosec.exchange yeah I ended up sigging on the tls.cert_issuer via Suricata, so that should provide some reliable detection regardless of what random port they use.
Replies (1)
-
@netresec@infosec.exchange 2026-07-03 18:47
@da_667@infosec.exchange @james_inthe_box@infosec.exchange Great work, thanks!