Kali Dog Security CertStream
CertStream Pack.#
This Integration is part of theSupported versions
Supported Cortex XSOAR versions: 6.10.0 and later.
#
CertStream Integration Pack#
OverviewThe CertStream integration allows you to leverage the Certificate Transparency Log (CTL) network to get real-time alerts when new TLS/SSL certificates are issued. CertStream provides a stream of certificate transparency log data from dozens of CTL servers around the globe.
By integrating CertStream with Cortex XSOAR, you can build real-time detection and response workflows triggered by the issuance of TLS certificates that match specific criteria.
#
Configure CertStream Integration- Navigate to Integrations > CertStream
- Click Add instance to create a new integration
- Name your integration instance (e.g. my-certstream)
- Enter the API endpoint (default is the public CertStream endpoint)
- Set the Levenshtein distance threshold for matching domains (default is 0.9)
- Set the Homograph list name of domain permutations to pull from
- Click Test to validate the configuration
- Click Done to save the integration
#
Sample Use Cases- Get real-time alerts when certificates are issued for your brand, trademarks, exec names, etc.
- Detect type-squatting and potential phishing domains targeting your company.
- Monitor certificates issued by public CAs.
#
Notifications- New Certificate Detected - Incident triggered when a new certificate matching defined filters is issued.