What does 'Untrusted Certificate Authority (CA) Detected' mean in SOC or domain analysis?
It means that the SSL/TLS certificate presented by the domain was issued or signed by a Certificate Authority that is not included in the trusted CA store of major browsers or operating systems. This can indicate the use of rogue or self-created CAs, commonly used in malicious infrastructures.