Zeek x509: Default Cobalt Strike certificate serial observed in HTTPS traffic

Flags Zeek x509 certificates used in HTTPS when the certificate serial matches a known default Cobalt Strike value.

FreeReviewedSigma · High · v2
Product
zeek
Service
x509
Author
Bhabesh Raj (SigmaHQ), DRL 1.1
Published
2021-06-23
Updated
2026-07-31

What it detects

This rule flags HTTPS traffic where the observed x509 certificate serial number matches a known default value associated with Cobalt Strike. Attackers may reuse these default certificates for their C2 infrastructure, making this a useful indicator when certificate telemetry is available. It relies on Zeek x509-derived certificate fields present in the environment’s HTTPS and certificate logging.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.