DEF CON 34 – Aleksandr Krasnov – Weakened/downgraded TLS handshake consistent with harvest-now-decrypt-later staging
This rule identifies network connections using deprecated, insecure TLS versions (TLS 1.0, 1.1) or weak cipher suites (RC4, 3DES, NULL). The use of these legacy cryptographic protocols is a security risk, as they are vulnerable to various attacks like man-in-the-middle, and may indicate misconfigured servers, legacy infrastructure, or attempts by an adversary to downgrade encryption to facilitate traffic interception or inspection.
Microsoft Sentinel (KQL)

