Deprecated TLS Version or Weak Cipher Negotiated Externally

Last updated 2 months ago on 2026-06-25
Created 2 months ago on 2026-06-25

About

Identifies successful outbound TLS sessions that negotiate deprecated protocol versions (SSLv3, TLS 1.0, or TLS 1.1) or weak cipher suites such as RC4, 3DES, NULL, EXPORT, or anonymous Diffie-Hellman. Adversaries-in-the-middle and legacy malware often force these negotiations to decrypt or intercept traffic. Modern clients and services should negotiate TLS 1.2 or 1.3 with strong ciphers on internet-bound connections.
Tags
Domain: NetworkUse Case: Network Security MonitoringUse Case: Threat DetectionData Source: Network TrafficTactic: Credential AccessTactic: Command and ControlLanguage: kuery
Severity
medium
Risk Score
47
MITRE ATT&CK™

Credential Access (TA0006)(external, opens in a new tab or window)

Command and Control (TA0011)(external, opens in a new tab or window)

False Positive Examples
Legacy internal applications, industrial control systems, or embedded devices may still require deprecated TLS versions or weak ciphers. Exclude known legacy destination IPs or subnets after validation.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
New Terms Rule
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-network_traffic.tls-*
Related Integrations

network_traffic(external, opens in a new tab or window)

Query
text code block:
data_stream.dataset:network_traffic.tls and network.protocol: tls and network.transport: tcp and tls.established: true and source.ip:(10.0.0.0/8 or 172.16.0.0/12 or 192.168.0.0/16) and not destination.ip:( 10.0.0.0/8 or 100.64.0.0/10 or 127.0.0.0/8 or 169.254.0.0/16 or 172.16.0.0/12 or 192.0.0.0/24 or 192.0.0.0/29 or 192.0.0.10/32 or 192.0.0.170/32 or 192.0.0.171/32 or 192.0.0.8/32 or 192.0.0.9/32 or 192.0.2.0/24 or 192.168.0.0/16 or 192.175.48.0/24 or 192.31.196.0/24 or 192.52.193.0/24 or 192.88.99.0/24 or 198.18.0.0/15 or 198.51.100.0/24 or 203.0.113.0/24 or 224.0.0.0/4 or 240.0.0.0/4 or "::1" or "FE80::/10" or "FF00::/8" ) and ( tls.version:(1.0 or 1.1) or (tls.version_protocol:ssl and tls.version:3.0) or ( not tls.version:1.3 and ( tls.cipher:( *RC4* or *3DES* or *NULL* or *EXPORT* or *_anon_* or *ADH* or *AECDH* ) ) ) )

Install detection rules in Elastic Security

Detect Deprecated TLS Version or Weak Cipher Negotiated Externally in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).