Techniques
Sample rules
Deprecated TLS Version or Weak Cipher Negotiated Externally
- source: elastic
- technicques:
- T1557
- T1573
Description
Identifies successful outbound TLS sessions that negotiate deprecated protocol versions (SSLv3, TLS 1.0, or TLS 1.1) or weak cipher suites such as RC4, 3DES, NULL, EXPORT, or anonymous Diffie-Hellman. Adversaries-in-the-middle and legacy malware often force these negotiations to decrypt or intercept traffic. Modern clients and services should negotiate TLS 1.2 or 1.3 with strong ciphers on internet-bound connections.
Detection logic
data_stream.dataset:network_traffic.tls
and network.protocol: tls
and network.transport: tcp
and tls.established: true
and source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16)
and not destination.ip:(
10.0.0.0/8 or
100.64.0.0/10 or
127.0.0.0/8 or
169.254.0.0/16 or
172.16.0.0/12 or
192.0.0.0/24 or
192.0.0.0/29 or
192.0.0.10/32 or
192.0.0.170/32 or
192.0.0.171/32 or
192.0.0.8/32 or
192.0.0.9/32 or
192.0.2.0/24 or
192.168.0.0/16 or
192.175.48.0/24 or
192.31.196.0/24 or
192.52.193.0/24 or
192.88.99.0/24 or
198.18.0.0/15 or
198.51.100.0/24 or
203.0.113.0/24 or
224.0.0.0/4 or
240.0.0.0/4 or
"::1" or
"FE80::/10" or
"FF00::/8"
)
and (
tls.version:(1.0 or 1.1) or
(tls.version_protocol:ssl and tls.version:3.0) or
(
not tls.version:1.3 and (
tls.cipher:(
*RC4* or
*3DES* or
*NULL* or
*EXPORT* or
*_anon_* or
*ADH* or
*AECDH*
)
)
)
)