Rule library
// Detection
Deprecated TLS negotiated
A session negotiated on TLS 1.0 or 1.1. A hygiene finding rather than an intrusion, but it is how downgrade paths stay open.
LowInvestigating0alerts raisedSignature
Armed
What this rule does
Rendered from the stored logic, so it cannot drift from what executes.
Any event where eventType is TLS_NEGOTIATION
{
"kind": "match",
"where": [
{
"op": "eq",
"field": "eventType",
"value": "TLS_NEGOTIATION"
}
]
}Revise
Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.
Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city
Alerts raised (0)
What this rule has actually caught.
Never fired
Armed, but nothing in the retained window has matched it.
Rule
- Category
- Hygiene
- ATT&CK tactic
- Defense Evasion
- Technique
- T1562
- Kind
- Signature
- State
- Armed
- Created
- 7d ago
- Last changed
- 7d ago
Firing history
- Total alerts
- 0
- First fired
- Never
- Last fired
- Never
- Escalated to cases
- 0
- Dismissed benign
- 0