From 9d5f78d24c71944fd7045a5599414e5544a64a9e Mon Sep 17 00:00:00 2001 From: Sandeep Singh Date: Fri, 20 May 2022 16:18:49 +0530 Subject: [PATCH] Added self-signed-ssl detection (#4457) --- ssl/self-signed-ssl.yaml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 ssl/self-signed-ssl.yaml diff --git a/ssl/self-signed-ssl.yaml b/ssl/self-signed-ssl.yaml new file mode 100644 index 0000000000..ff4d602cb5 --- /dev/null +++ b/ssl/self-signed-ssl.yaml @@ -0,0 +1,28 @@ +id: self-signed-ssl + +info: + name: Self Signed SSL Certificate + author: righettod,pdteam + severity: low + tags: ssl + +ssl: + - address: "{{Host}}:{{Port}}" + + extractors: + - type: json + name: common_name + json: + - ".common_name[]" + internal: true + + - type: json + name: issuer_common_name + json: + - ".issuer_common_name[]" + internal: true + + matchers: + - type: dsl + dsl: + - "common_name == issuer_common_name" \ No newline at end of file