Forum Discussion

LiliaF's avatar
LiliaF
Copper Contributor
Nov 04, 2022

OpenSSL version

Can I identify OpenSSL versions using Sentinel query? What kind of data type is needed?

7 Replies

  • Dutchboy's avatar
    Dutchboy
    Copper Contributor
    If you E5 , Try the TVM queries in the advanced hunting, the module can be found under Softwarename.
  • GBushey's avatar
    GBushey
    Iron Contributor
    Take a look at the "Insecure Protocols" workbook to see if that will give you the information you need.
  • GBushey's avatar
    GBushey
    Iron Contributor
    What data are you looking to query? Your question is a bit open ended without knowing where the data would be coming from.
    • LiliaF's avatar
      LiliaF
      Copper Contributor

      GBushey 

      I am looking for a way to identify OpenSSL versions for different systems. More precisely I am trying to understand if I can find logs  that shows there are vulnerable OpenSSL versions as our customer is having troubles identifying those in their reports. Is it possible to create a query in Sentinel to check on which server OpenSSL is installed and in which version?

      • GBushey's avatar
        GBushey
        Iron Contributor
        That would have to be done on a system-by-system basis. Without knowing what data each system is sending, it would not be possible to make this determination.

Resources