Using blacklist of malicious SSL Certificates in Netwitness?

Question asked by RSA Admin Employee on Jul 21, 2014
Similar to Blacklisted IP, Domain feeds, we have a feed for malicious ssl certificates from

The feed contains SHA1 fingerprint for a malicious certificate involved in C2 Communication.


However, i don't see any meta field capturing this info in netwitness.

i can see, ssl.subject, crypto related to TLS Communication.


Is there way to write a parser or so to capture sha1 fingerprint of the SSL Certifciates ?