From 5be1bc1ae70d621a25645ddfc779467cc841329e Mon Sep 17 00:00:00 2001 From: Sandeep Singh Date: Wed, 15 Dec 2021 20:43:36 +0530 Subject: [PATCH] Added Initial SSL Templates (#3339) --- ssl/expired-ssl.yaml | 14 ++++++++++++++ ssl/ssl-dns-names.yaml | 15 +++++++++++++++ ssl/tls-version.yaml | 15 +++++++++++++++ 3 files changed, 44 insertions(+) create mode 100644 ssl/expired-ssl.yaml create mode 100644 ssl/ssl-dns-names.yaml create mode 100644 ssl/tls-version.yaml diff --git a/ssl/expired-ssl.yaml b/ssl/expired-ssl.yaml new file mode 100644 index 0000000000..d72fb1e379 --- /dev/null +++ b/ssl/expired-ssl.yaml @@ -0,0 +1,14 @@ +id: expired-ssl + +info: + name: Expired SSL Certificate + author: pdteam + severity: low + tags: ssl + +ssl: + - address: "{{Host}}:{{Port}}" + matchers: + - type: dsl + dsl: + - "unixtime() > not_after" diff --git a/ssl/ssl-dns-names.yaml b/ssl/ssl-dns-names.yaml new file mode 100644 index 0000000000..34fda5a6e2 --- /dev/null +++ b/ssl/ssl-dns-names.yaml @@ -0,0 +1,15 @@ +id: ssl-dns-names + +info: + name: SSL DNS Names + author: pdteam + severity: info + tags: ssl + +ssl: + - address: "{{Host}}:{{Port}}" + + extractors: + - type: json + json: + - " .dns_names[]" diff --git a/ssl/tls-version.yaml b/ssl/tls-version.yaml new file mode 100644 index 0000000000..c5d3afc1db --- /dev/null +++ b/ssl/tls-version.yaml @@ -0,0 +1,15 @@ +id: tls-version + +info: + name: TLS Version + author: pdteam + severity: info + tags: ssl + +ssl: + - address: "{{Host}}:{{Port}}" + + extractors: + - type: json + json: + - " .tls_version"