Skip to content

Free-Issued SSL Certificate

It indicates that the domain uses an SSL certificate issued by a free or automated Certificate Authority, such as Let's Encrypt. While free SSLs are legitimate, they are frequently abused by threat actors due to their anonymity, ease of issuance, and short lifecycle.

Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Free-Issued SSL Certificate' mean in SOC or threat analysis?

It indicates that the domain uses an SSL certificate issued by a free or automated Certificate Authority, such as Let's Encrypt. While free SSLs are legitimate, they are frequently abused by threat actors due to their anonymity, ease of issuance, and short lifecycle.

Why it matters02

Why are free SSL certificates often seen in malicious infrastructures?

Because attackers can obtain them quickly and without identity verification, making it easier to establish HTTPS trust indicators on phishing or malware delivery sites. Their short renewal cycle also aligns with the short lifespan of malicious domains.

How analysts use it03

Does using a free SSL certificate always mean a domain is malicious?

No. Many legitimate websites also use free SSLs for cost efficiency and automation. However, analysts should evaluate other contextual indicators — such as domain reputation, age, and category — before drawing conclusions.

Often paired with:alert_only
Evidence shape

What Free-Issued SSL Certificate looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "free_ssl_usage",
  "name": "Free-Issued SSL Certificate",
  "group": "http_crawling_history",
  "subgroup": "ssl_behavior",
  "direction": "malicious",
  "evidence": {
    "cert_issued_days_ago": 9,
    "issuer": "letsencrypt",
    "valid_for_days": 90,
    "rotation_count_90d": 3,
    "cert_type": "DV"
  }
}
See in API reference
Siblings

Peers in SSL Behavior

15 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Critical SSL Certificate Authentication Failure

It means that the SSL/TLS certificate presented by the domain failed critical validation checks. This can occur due to m

MaliciousCore
Invalid Hostname Validation (CN/SAN Mismatch)

It means the SSL/TLS certificate’s Common Name (CN) or Subject Alternative Name (SAN) does not match the accessed domain

MaliciousCore
Organization-Validated (OV) SSL Certificate Detected

It means the SSL/TLS certificate of the domain includes verified organizational details that have been authenticated by

SafeCore
Self-Signed SSL Certificate Detected

It means the domain is using an SSL/TLS certificate that was generated and signed by the same entity, without verificati

MaliciousCore
Show 11 more in SSL Behavior
In the wild

See Free-Issued SSL Certificate fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Free-Issued SSL Certificate. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.