{"id":3895,"date":"2026-04-22T11:47:57","date_gmt":"2026-04-22T15:47:57","guid":{"rendered":"https:\/\/drkeithjones.com\/?p=3895"},"modified":"2026-04-23T14:09:08","modified_gmt":"2026-04-23T18:09:08","slug":"hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek","status":"publish","type":"post","link":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/","title":{"rendered":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with <a href=\"https:\/\/github.com\/qwqdanchun\/DcRat\/blob\/30ca53b068b4ab7a2542835f7456abd26e1a0ed4\/Server\/Helper\/CreateCertificate.cs#L32\" title=\"\">default, self-signed certificates<\/a>. If the operators don&#8217;t bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network traffic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Traditionally, hunting for these specific certificate strings across disparate log files requires clunky pipelines or heavy SIEM queries. But if you have Zeek logs and a terminal, <strong>DuckDB<\/strong> makes this process incredibly fast and elegant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here is how I recently used DuckDB\u2019s Zeek extension to hunt for this exact indicator in <a href=\"https:\/\/app.any.run\/tasks\/a72d5f1a-1703-4f86-af3a-6896282f5277\" title=\"\">a PCAP containing AsyncRAT traffic<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Hunt: Joining the Logs<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To find the malicious traffic, we need to map the base TCP connections directly to their negotiated certificate strings. This means we have to join three separate Zeek logs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-superbfont-xsmall-font-size\">conn.log (for the IPs and ports)<\/li>\n\n\n\n<li class=\"has-superbfont-xsmall-font-size\">ssl.log (for the SSL\/TLS session data)<\/li>\n\n\n\n<li class=\"has-superbfont-xsmall-font-size\">x509.log (for the actual certificate details)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Using <a href=\"https:\/\/github.com\/ynadji\/zeek-duckdb\" title=\"\">DuckDB&#8217;s <code>read_zeek()<\/code><\/a> function, we can query these raw log files directly as if they were SQL tables. Here is the query to connect the dots:<\/p>\n\n\n\n<pre style=\"white-space: pre; overflow-x: auto; font-family: monospace; font-size: 12px; background: #fdfdfd; padding: 20px; border: 1px solid #ddd; line-height: 1.5;\">\nSELECT \n    c.ts,\n    c.uid,\n    c.id_orig_h AS src_ip,\n    c.id_resp_h AS dst_ip,\n    c.id_resp_p AS dst_port,\n    s.server_name,\n    x.certificate_subject AS cert_subject,\n    x.certificate_issuer AS cert_issuer\nFROM read_zeek('conn.log') AS c\nJOIN read_zeek('ssl.log') AS s USING (uid)\nJOIN read_zeek('x509.log') AS x \n    ON list_contains(s.cert_chain_fps, x.fingerprint)\nWHERE x.certificate_subject ILIKE '%dcrat%' \n   OR x.certificate_issuer ILIKE '%dcrat%';\n<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Pro-Tip:<\/strong> Notice the <code>list_contains()<\/code> function. Zeek&#8217;s <code>cert_chain_fps<\/code> is a vector type (a list of strings). DuckDB parses this natively, allowing us to easily check if the fingerprint from <code>x509.log<\/code> exists anywhere in that SSL certificate chain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Execution &amp; Results<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Dropping into the DuckDB CLI, the query executes in milliseconds. No data ingestion, no indexing delays\u2014just straight SQL on raw files.<\/p>\n\n\n\n<pre style=\"white-space: pre; overflow-x: auto; font-family: monospace; font-size: 12px; background: #fdfdfd; padding: 20px; border: 1px solid #ddd; line-height: 1.5;\">\n% ls\na72d5f1a-1703-4f86-af3a-6896282f5277.pcap   ocsp.log\nconn.log                    packet_filter.log\ndns.log                     ssl.log\nfiles.log                   weird.log\nhttp.log                    x509.log\n\n% duckdb\nDuckDB v1.5.2 (Variegata)\nEnter \".help\" for usage hints.\n\nmemory D load zeek;\n\nmemory D SELECT\n             c.ts,\n             c.uid,\n             c.id_orig_h AS src_ip,\n             c.id_resp_h AS dst_ip,\n             c.id_resp_p AS dst_port,\n             s.server_name,\n             x.certificate_subject AS cert_subject,\n             x.certificate_issuer AS cert_issuer\n         FROM read_zeek('conn.log') AS c\n         JOIN read_zeek('ssl.log') AS s USING (uid)\n         JOIN read_zeek('x509.log') AS x\n             ON list_contains(s.cert_chain_fps, x.fingerprint)\n         WHERE x.certificate_subject ILIKE '%dcrat%'\n            OR x.certificate_issuer ILIKE '%dcrat%';\n\n\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n\u2502          ts           \u2502        uid         \u2502     src_ip     \u2502    dst_ip     \u2502 dst_port \u2502 server_name \u2502 cert_subject \u2502      cert_issuer      \u2502\n\u2502 timestamp with time z \u2502      varchar       \u2502      inet      \u2502     inet      \u2502  uint16  \u2502   varchar   \u2502   varchar    \u2502        varchar        \u2502\n\u2502          one          \u2502                    \u2502                \u2502               \u2502          \u2502             \u2502              \u2502                       \u2502\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524\n\u2502 2026-04-22 10:45:04.0 \u2502 CwW7GO2oFwvT98QrXf \u2502 192.168.100.17 \u2502 178.16.52.105 \u2502      207 \u2502 NULL        \u2502 CN=DcRat     \u2502 C=CN,L=SH,O=DcRat By  \u2502\n\u2502 28574-04              \u2502                    \u2502                \u2502               \u2502          \u2502             \u2502              \u2502 qwqdanchun,OU=qwqdanc \u2502\n\u2502                       \u2502                    \u2502                \u2502               \u2502          \u2502             \u2502              \u2502 hun,CN=DcRat Server   \u2502\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\n<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">The Breakdown<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Boom. The output immediately surfaces our malicious connection:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-superbfont-xsmall-font-size\"><strong>Victim IP:<\/strong> 192.168.100.17<\/li>\n\n\n\n<li class=\"has-superbfont-xsmall-font-size\"><strong>C2 Destination:<\/strong> 178.16.52.105<\/li>\n\n\n\n<li class=\"has-superbfont-xsmall-font-size\"><strong>Anomalous Port:<\/strong> 207 (A quick secondary indicator that this isn&#8217;t standard web traffic).<\/li>\n\n\n\n<li class=\"has-superbfont-xsmall-font-size\"><strong>The Smoking Gun:<\/strong> A certificate explicitly issued by C=CN,L=SH,O=DcRat By qwqdanchun,OU=qwqdanchun,CN=DcRat Server.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When performing incident response or threat hunting, speed and agility are everything. DuckDB\u2019s ability to cleanly parse Zeek&#8217;s complex list and vector types makes navigating complex log relationships incredibly clean. Next time you have a directory full of Zeek logs, skip the heavy ingestion pipelines and try querying them directly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>How is everyone else analyzing their Zeek logs these days? Let me know!<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with default, self-signed certificates. If the operators don&#8217;t bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[144,74,140,91,24,61,4],"tags":[],"class_list":["post-3895","post","type-post","status-publish","format-standard","hentry","category-detection","category-how-to","category-malware","category-open-source","category-pcaps","category-tools","category-zeek"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with default, self-signed certificates. If the operators don&#039;t bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network\" \/>\n\t<meta name=\"robots\" content=\"max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n\t<meta name=\"author\" content=\"drkeithjones\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"DrKeithJones.com - A cybersecurity researcher&#039;s journey.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek - DrKeithJones.com\" \/>\n\t\t<meta property=\"og:description\" content=\"Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with default, self-signed certificates. If the operators don&#039;t bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/drkeithjones.com\/wp-content\/uploads\/2023\/02\/ecb.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/drkeithjones.com\/wp-content\/uploads\/2023\/02\/ecb.jpg\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-04-22T15:47:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-04-23T18:09:08+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/keithjjones\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@keithjjones\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek - DrKeithJones.com\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with default, self-signed certificates. If the operators don&#039;t bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@keithjjones\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/drkeithjones.com\/wp-content\/uploads\/2023\/02\/ecb.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#blogposting\",\"name\":\"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek - DrKeithJones.com\",\"headline\":\"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek\",\"author\":{\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/author\\\/drkeithjones_iitpux\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#articleImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/dee83de34730f3a340cb0cdf15ab1de7f04e96f129f78c426da03098df1912fb?s=96&d=retro&r=g\",\"width\":96,\"height\":96,\"caption\":\"drkeithjones\"},\"datePublished\":\"2026-04-22T11:47:57-04:00\",\"dateModified\":\"2026-04-23T14:09:08-04:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#webpage\"},\"articleSection\":\"Detection, How-To, Malware, Open Source, PCAPs, Tools, Zeek\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/drkeithjones.com#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/drkeithjones.com\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/category\\\/zeek\\\/#listItem\",\"name\":\"Zeek\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/category\\\/zeek\\\/#listItem\",\"position\":2,\"name\":\"Zeek\",\"item\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/category\\\/zeek\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#listItem\",\"name\":\"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/drkeithjones.com#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#listItem\",\"position\":3,\"name\":\"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/category\\\/zeek\\\/#listItem\",\"name\":\"Zeek\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/#person\",\"name\":\"drkeithjones\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/dee83de34730f3a340cb0cdf15ab1de7f04e96f129f78c426da03098df1912fb?s=96&d=retro&r=g\",\"width\":96,\"height\":96,\"caption\":\"drkeithjones\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/author\\\/drkeithjones_iitpux\\\/#author\",\"url\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/author\\\/drkeithjones_iitpux\\\/\",\"name\":\"drkeithjones\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/dee83de34730f3a340cb0cdf15ab1de7f04e96f129f78c426da03098df1912fb?s=96&d=retro&r=g\",\"width\":96,\"height\":96,\"caption\":\"drkeithjones\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#webpage\",\"url\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/\",\"name\":\"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek - DrKeithJones.com\",\"description\":\"Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with default, self-signed certificates. If the operators don't bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/2026\\\/04\\\/22\\\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/author\\\/drkeithjones_iitpux\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/index.php\\\/author\\\/drkeithjones_iitpux\\\/#author\"},\"datePublished\":\"2026-04-22T11:47:57-04:00\",\"dateModified\":\"2026-04-23T14:09:08-04:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/#website\",\"url\":\"https:\\\/\\\/drkeithjones.com\\\/\",\"name\":\"DrKeithJones.com\",\"description\":\"A cybersecurity researcher's journey.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/drkeithjones.com\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek - DrKeithJones.com","description":"Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with default, self-signed certificates. If the operators don't bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network","canonical_url":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/","robots":"max-snippet:-1, max-image-preview:large, max-video-preview:-1","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#blogposting","name":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek - DrKeithJones.com","headline":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek","author":{"@id":"https:\/\/drkeithjones.com\/index.php\/author\/drkeithjones_iitpux\/#author"},"publisher":{"@id":"https:\/\/drkeithjones.com\/#person"},"image":{"@type":"ImageObject","@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#articleImage","url":"https:\/\/secure.gravatar.com\/avatar\/dee83de34730f3a340cb0cdf15ab1de7f04e96f129f78c426da03098df1912fb?s=96&d=retro&r=g","width":96,"height":96,"caption":"drkeithjones"},"datePublished":"2026-04-22T11:47:57-04:00","dateModified":"2026-04-23T14:09:08-04:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#webpage"},"isPartOf":{"@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#webpage"},"articleSection":"Detection, How-To, Malware, Open Source, PCAPs, Tools, Zeek"},{"@type":"BreadcrumbList","@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/drkeithjones.com#listItem","position":1,"name":"Home","item":"https:\/\/drkeithjones.com","nextItem":{"@type":"ListItem","@id":"https:\/\/drkeithjones.com\/index.php\/category\/zeek\/#listItem","name":"Zeek"}},{"@type":"ListItem","@id":"https:\/\/drkeithjones.com\/index.php\/category\/zeek\/#listItem","position":2,"name":"Zeek","item":"https:\/\/drkeithjones.com\/index.php\/category\/zeek\/","nextItem":{"@type":"ListItem","@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#listItem","name":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek"},"previousItem":{"@type":"ListItem","@id":"https:\/\/drkeithjones.com#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#listItem","position":3,"name":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek","previousItem":{"@type":"ListItem","@id":"https:\/\/drkeithjones.com\/index.php\/category\/zeek\/#listItem","name":"Zeek"}}]},{"@type":"Person","@id":"https:\/\/drkeithjones.com\/#person","name":"drkeithjones","image":{"@type":"ImageObject","@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/dee83de34730f3a340cb0cdf15ab1de7f04e96f129f78c426da03098df1912fb?s=96&d=retro&r=g","width":96,"height":96,"caption":"drkeithjones"}},{"@type":"Person","@id":"https:\/\/drkeithjones.com\/index.php\/author\/drkeithjones_iitpux\/#author","url":"https:\/\/drkeithjones.com\/index.php\/author\/drkeithjones_iitpux\/","name":"drkeithjones","image":{"@type":"ImageObject","@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/dee83de34730f3a340cb0cdf15ab1de7f04e96f129f78c426da03098df1912fb?s=96&d=retro&r=g","width":96,"height":96,"caption":"drkeithjones"}},{"@type":"WebPage","@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#webpage","url":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/","name":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek - DrKeithJones.com","description":"Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with default, self-signed certificates. If the operators don't bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/drkeithjones.com\/#website"},"breadcrumb":{"@id":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/#breadcrumblist"},"author":{"@id":"https:\/\/drkeithjones.com\/index.php\/author\/drkeithjones_iitpux\/#author"},"creator":{"@id":"https:\/\/drkeithjones.com\/index.php\/author\/drkeithjones_iitpux\/#author"},"datePublished":"2026-04-22T11:47:57-04:00","dateModified":"2026-04-23T14:09:08-04:00"},{"@type":"WebSite","@id":"https:\/\/drkeithjones.com\/#website","url":"https:\/\/drkeithjones.com\/","name":"DrKeithJones.com","description":"A cybersecurity researcher's journey.","inLanguage":"en-US","publisher":{"@id":"https:\/\/drkeithjones.com\/#person"}}]},"og:locale":"en_US","og:site_name":"DrKeithJones.com - A cybersecurity researcher's journey.","og:type":"article","og:title":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek - DrKeithJones.com","og:description":"Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with default, self-signed certificates. If the operators don't bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network","og:url":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/","og:image":"https:\/\/drkeithjones.com\/wp-content\/uploads\/2023\/02\/ecb.jpg","og:image:secure_url":"https:\/\/drkeithjones.com\/wp-content\/uploads\/2023\/02\/ecb.jpg","article:published_time":"2026-04-22T15:47:57+00:00","article:modified_time":"2026-04-23T18:09:08+00:00","article:publisher":"https:\/\/www.facebook.com\/keithjjones","twitter:card":"summary_large_image","twitter:site":"@keithjjones","twitter:title":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek - DrKeithJones.com","twitter:description":"Threat actors love to reuse tools, and sometimes, they get lazy. Case in point: AsyncRAT and its notorious fork, DcRAT. These remote access trojans often ship with default, self-signed certificates. If the operators don't bother to swap them out before deploying their infrastructure, they leave a massive, highly visible behavioral red flag in the network","twitter:creator":"@keithjjones","twitter:image":"https:\/\/drkeithjones.com\/wp-content\/uploads\/2023\/02\/ecb.jpg"},"aioseo_meta_data":{"post_id":"3895","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-04-22 15:48:01","updated":"2026-04-23 19:10:37","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/drkeithjones.com\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/drkeithjones.com\/index.php\/category\/zeek\/\" title=\"Zeek\">Zeek<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tHunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/drkeithjones.com"},{"label":"Zeek","link":"https:\/\/drkeithjones.com\/index.php\/category\/zeek\/"},{"label":"Hunting Lazy OPSEC: Spotting Default C2 Certificates with DuckDB and Zeek","link":"https:\/\/drkeithjones.com\/index.php\/2026\/04\/22\/hunting-lazy-opsec-spotting-default-c2-certificates-with-duckdb-and-zeek\/"}],"jetpack_featured_media_url":"","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/drkeithjones.com\/index.php\/wp-json\/wp\/v2\/posts\/3895","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/drkeithjones.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/drkeithjones.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/drkeithjones.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/drkeithjones.com\/index.php\/wp-json\/wp\/v2\/comments?post=3895"}],"version-history":[{"count":0,"href":"https:\/\/drkeithjones.com\/index.php\/wp-json\/wp\/v2\/posts\/3895\/revisions"}],"wp:attachment":[{"href":"https:\/\/drkeithjones.com\/index.php\/wp-json\/wp\/v2\/media?parent=3895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/drkeithjones.com\/index.php\/wp-json\/wp\/v2\/categories?post=3895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/drkeithjones.com\/index.php\/wp-json\/wp\/v2\/tags?post=3895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}