Verify expected results for RISKIQ SSL certificate lookups
When a security incident generates observables for URLs, domains, IP addresses, certificate file hashes (SHA-1 fingerprint), and certificate serial numbers, security incident analysts use the SSL certificate lookup results to verify sites have certificates that have been issued by a trusted public Certificate Authority (CA).
Before you begin
Role required: sn_si.analyst
About this task
For supported observables, the ServiceNow AI Platform scans for the most recent occurrence of URLs, domains, IP addresses, certificate file hashes (SHA-1 fingerprint), and certificate serial numbers. These are possible outcomes from the scan:
- An exact match is found
- A valid issuer of an SSL certificate is listed on the Security Incident record.
- No certificate results are found
- No results are listed on the Security Incident record.
- An exact match is found for a self-signed, or internally generated certificate
- Results for an internally generated SSL certificate are displayed on the Security Incident record.
- An exact match is not found for a primary SSL certificate
- A lookup value returns multiple entries and a primary certificate cannot be identified. A summary message is displayed on the Security Incident record.