Discovering SSL/TLS Certificates with Legendary OSINT
Legendary OSINT aggregates Abuse.ch SSLBL and Censys to enable analysts to discover, validate, and hunt SSL/TLS certificates across the internet for threat intelligence and infrastructure mapping.
Legendary OSINT is a curated repository of open-source intelligence resources maintained by K2SOsint. For discovering SSL/TLS certificates with Legendary OSINT, the documentation points to two primary external services documented across specific markdown files. These integrations allow investigators to query certificate transparency logs, detect malicious certificates, and automate infrastructure discovery without requiring native tooling within the repository itself.
Abuse.ch SSLBL for Malicious Certificate Detection
According to docs/intel-feeds.md at line 16, Legendary OSINT references the Abuse.ch SSL Blacklist (SSLBL), a public repository of malicious SSL certificates associated with phishing campaigns and malware distribution. Analysts can query this blocklist to identify certificates that have been flagged for nefarious activity by cross-referencing SHA-256 fingerprints against the continuously updated dataset.
Censys for Internet-Wide Certificate Discovery
The repository documents Censys in two distinct contexts within the documentation structure.
Search Engine Capabilities
As noted in docs/search-engines.md at line 62, Censys is listed as a comprehensive search engine capable of indexing hosts and their associated SSL/TLS certificates across the entire IPv4 space. This allows analysts to locate certificates by subject, issuer, or fingerprint and enumerate all services presenting a specific certificate.
Intel Feed Integration
Additionally, docs/intel-feeds.md at line 23 references Censys as an enriched data feed, providing structured access to host and certificate datasets. The docs/malware-cti.md file further reinforces Censys as a source for certificate-related cyber threat intelligence, enabling integration into automated detection pipelines.
Practical Implementation Examples
While Legendary OSINT does not package built-in scripts, the following implementations demonstrate how to leverage the documented services programmatically.
Querying Abuse.ch SSLBL via Python
The following Python function checks a certificate fingerprint against the Abuse.ch SSLBL blocklist:
import requests
def is_cert_malicious(fingerprint: str) -> bool:
"""
Query the Abuse.ch SSLBL blocklist for a SHA‑256 fingerprint.
Returns True if the certificate is listed as malicious.
"""
url = "https://sslbl.abuse.ch/sslblocklist/"
resp = requests.get(url, params={"fingerprint": fingerprint})
resp.raise_for_status()
# The blocklist returns a plain‑text line per fingerprint; presence means malicious.
return fingerprint.lower() in resp.text.lower()
# Usage
sha256_fp = "AB:C1:23:...:EF"
if is_cert_malicious(sha256_fp):
print("⚠️ Certificate is known malicious")
else:
print("✅ Certificate not found in SSLBL")
Automated Censys Certificate Search
To programmatically discover certificates using the Censys API as referenced in the intel feeds:
import os
import requests
from requests.auth import HTTPBasicAuth
CENSYS_API_ID = os.getenv("CENSYS_API_ID") # <-- set in your environment
CENSYS_API_SECRET = os.getenv("CENSYS_API_SECRET") # <-- set in your environment
def search_certificates(query: str, page: int = 1):
"""
Perform a Censys certificate search.
`query` follows the Censys query language, e.g.:
'parsed.fingerprint_sha256:YOUR_SHA256'
"""
endpoint = f"https://search.censys.io/api/v2/certificates/search"
payload = {"q": query, "per_page": 100, "page": page}
r = requests.post(
endpoint,
json=payload,
auth=HTTPBasicAuth(CENSYS_API_ID, CENSYS_API_SECRET),
)
r.raise_for_status()
return r.json()["result"]["hits"]
# Example: Find all certificates issued by "Let's Encrypt"
for cert in search_certificates('parsed.issuer.common_name:"Let\'s Encrypt Authority X3"'):
print(cert["parsed"]["subject"]["common_name"], cert["parsed"]["fingerprint_sha256"])
Bulk Blocklist Monitoring with Shell
For lightweight integration, download the complete SSLBL dataset via command line:
curl -s https://sslbl.abuse.ch/sslblocklist/ > sslbl.txt
# Grep for a specific fingerprint
grep -i "AB:C1:23:...:EF" sslbl.txt && echo "Malicious!" || echo "Clean"
Summary
- Abuse.ch SSLBL, documented at line 16 of
docs/intel-feeds.md, provides a blocklist of malicious certificates for threat detection. - Censys appears in both
docs/search-engines.md(line 62) as a search engine anddocs/intel-feeds.md(line 23) as a structured data feed for certificate discovery. - No native scripts are packaged in the repository; instead, Legendary OSINT provides curated entry points to external APIs and blocklists.
- Analysts can integrate these services using Python requests or shell commands to automate certificate validation and infrastructure enumeration.
Frequently Asked Questions
How do I check if a certificate is malicious using Legendary OSINT?
Legendary OSINT references the Abuse.ch SSLBL service in docs/intel-feeds.md. You can query this blocklist by downloading the dataset from https://sslbl.abuse.ch/sslblocklist/ and searching for your certificate's SHA-256 fingerprint. If the fingerprint appears in the list, the certificate has been flagged as malicious by the security community.
What is the difference between Censys as a search engine and as an intel feed in Legendary OSINT?
In docs/search-engines.md at line 62, Censys is presented as an interactive search engine for manual certificate discovery. Conversely, docs/intel-feeds.md at line 23 lists Censys as a programmatic data feed suitable for API integration and automated threat intelligence pipelines. Both entries point to the same underlying service but emphasize different operational use cases.
Does Legendary OSINT provide built-in automation scripts for certificate discovery?
No, the repository does not contain native Python or shell scripts for certificate analysis. Instead, Legendary OSINT serves as a curated index that directs analysts to external services like Abuse.ch SSLBL and Censys, allowing users to implement their own API clients or download utilities based on the documented endpoints.
Which documentation files contain the SSL/TLS certificate resources?
Three primary files in the repository contain relevant references: docs/intel-feeds.md (lines 16 and 23) covers both SSLBL and Censys data feeds, docs/search-engines.md (line 62) details Censys search capabilities, and docs/malware-cti.md provides additional context on Censys for cyber threat intelligence applications.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →