When analyzing C2 traffic, which characteristic of a TLS/SSL certificate is most indicative of a potentially malicious beaconing endpoint?
Self-signed certificates are common in rapid-deployment C2 infrastructure because they are easy to generate and cost nothing. While they trigger warnings in a browser, malware can be configured to ignore these warnings, making them a telltale sign of non-standard, likely malicious, backend communication infrastructure.
Why this answer
Malicious C2 infrastructure often uses self-signed certificates or certificates issued by untrusted/free Certificate Authorities to encrypt traffic. In a professional environment, legitimate services typically use well-known, trusted CAs. When a penetration tester sees an endpoint using a certificate with a random common name, short expiration period, or invalid chain, it serves as a strong indicator that the connection is intended for unauthorized command and control purposes.
Exam trap
Candidates often overthink technical details like cipher suites or TLS versions. They miss the most obvious red flag: the lack of a trusted, verifiable certificate chain for a production-facing endpoint.