Post-Quantum Authentication Readiness Monitoring
Organizations participating in post-quantum authentication testing will exhibit specific Windows build versions, the presence of ML-DSA-87 pilot root certificates, and network activity to designated pilot CA coordination domains.
Based on research by Microsoft 2026-10-09 10 steps · 3 queries T1195
Brief
Why PQC Testing Visibility Matters
Microsoft recently highlighted the need to test certificate ecosystems in their post Post-quantum authentication: Why organizations should start testing certificate ecosystems now (https://www.microsoft.com/en-us/security/blog/2026/10/08/post-quantum-authentication-why-organizations-should-start-testing-certificate-ecosystems-now/). As organizations adopt the PQC TLS Pilot Program, they introduce non-production roots and specific Windows builds into the environment. Monitoring this activity ensures the transition remains controlled and identifies where non-standard cryptographic primitives are in use.
How the Hunt Flows
The first phase scopes the environment for PQC-capable Windows hosts. A query identifies Windows 11 systems running the July 2026 updates or later, specifically targeting builds like 28000.2608, 26200.8973, and 26100.8973. These versions provide the necessary cryptographic primitives for ML-DSA-87 pilot testing. Systems missing these updates cannot participate in the pilot, so this step defines the maximum possible testing surface. The hunt then moves into a parallel corroboration phase to find active indicators of participation. One path searches the local trust stores for pilot certificates issued by CAs such as SSL.com, DigiCert, Sectigo, or ComSign. It specifically looks for certificates using the ML-DSA signature algorithm or those containing pqc in the common name. Finding these certificates indicates that a host is prepared to trust or present post-quantum credentials during TLS handshakes. Simultaneously, the hunt checks DNS activity for resolutions of pilot coordination domains. This includes traffic to aka.ms, asp.net, or CA-specific endpoints mentioned in the pilot documentation. The query correlates this traffic back to the scoped hosts from the first phase. By combining network activity with certificate presence, the hunt distinguishes between a system that is merely update-ready and one actively engaging with pilot infrastructure. An analyst or agent then triages the results to categorize hosts as active testers, ready hosts, or unrelated systems. This step confirms whether the cryptographic infrastructure matches the PQC TLS Pilot profile. The triage process helps security teams understand the scope of testing and ensures that shadow testing does not occur on critical production systems. The hunt concludes by tagging these hosts in the asset inventory to prevent their unique performance profiles from skewing standard baselines.
What the Hunt Cannot See
The hunt faces two primary limitations. First, endpoint-based certificate inventory cannot see keys stored exclusively on Hardware Security Modules (HSMs) or specialized appliances. These devices often handle high-value cryptography but do not expose their internal trust stores to standard endpoint telemetry. Second, current telemetry often lacks a direct link between a specific certificate and the hostname in a single table, requiring the analyst to correlate findings by owner or timing.
How to Run the Hunt
This hunt is available as an open hunt.md playbook. You can import it into Huntbase or any hunt.md-aware runtime to begin auditing your PQC posture. The playbook is designed for periodic execution as pilot adoption grows and more systems receive the necessary Windows updates. Microsoft Security Blog
Steps
-
Scope PQC-Capable Windows Hosts
Query · scopingIdentify hosts running the specific Windows 11 builds required for ML-DSA-87 pilot testing.
reads hb_devicessqlSELECT hostname, os_version, last_seen FROM hb_devices WHERE platform = 'Windows' AND (instr(',' || '{{pqc_build_strings}}' || ',', ',' || os_version || ',') > 0 OR os_version LIKE '%28000.2608%' OR os_version LIKE '%26200.8973%' OR os_version LIKE '%26100.8973%') AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Hosts running Windows 11 with the July 2026 updates or later. Silence suggests no hosts are currently ready for PQC pilot testing.
-
Detect PQC Pilot Certificates
Query · baselineSearch for certificates using ML-DSA or issued by the designated pilot CAs in the trust store.
reads hb_certificatessqlSELECT common_name, issuer, signature_algorithm, status, owner FROM hb_certificates WHERE (LOWER(signature_algorithm) LIKE '%ml-dsa%' OR LOWER(common_name) LIKE '%pqc%' OR LOWER(issuer) LIKE '%ssl.com%' OR LOWER(issuer) LIKE '%comsign%' OR LOWER(issuer) LIKE '%digicert%' OR LOWER(issuer) LIKE '%sectigo%' OR LOWER(issuer) LIKE '%harica%')What a hit looks like. Presence of non-production pilot root certificates or ML-DSA signed certificates. Silence means no pilot certificates are installed.
-
DNS Traffic to Pilot Domains
Query · enrichmentIdentify hosts resolving domains mentioned in the PQC pilot program, narrowed by scoped hosts.
reads hb_dns_activitysqlSELECT device_hostname, query_hostname, COUNT(*) as lookup_count FROM hb_dns_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{pilot_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostnameWhat a hit looks like. DNS lookups for pilot domains like aka.ms or ssl.com during the test window. Silence means no network-based pilot activity observed.
-
Triage PQC Testing Context
Agent triageWeigh OS version capability, certificate presence, and network activity to determine if a host is actively participating in PQC testing.
-
Route Based on Testing Activity
DecisionDirect confirmed PQC testers to tagging and documentation steps.
-
Tag PQC Testing Hosts
Response actionMark identified hosts in the inventory as active PQC pilot participants for future monitoring.
-
Analyst Review of PQC Findings
Analyst taskValidate the findings with the PKI team and document any shadow testing.
-
Update Readiness Report
Analyst taskFinalize the hunt by updating the organizational PQC readiness documentation.
-
Close Out
Analyst taskFinalize the hunt when no active PQC testing is identified.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| PQC Supply Chain and Infrastructure Inventory T1195 |
Yes | scope-pqc-capable-hosts, detect-pqc-certificates |
| PQC Pilot Interoperability and Connectivity T1195 |
Yes | dns-pqc-traffic, triage-pqc-readiness |
Blind spots
- Needs hb_certificates with device_hostname linkage. The current hb_certificates schema does not provide a direct hostname column, requiring an analyst to correlate cert findings with other telemetry by timing or certificate owner. It would answer Which specific hosts have installed the ML-DSA pilot certificates?.
- Needs Direct logging from Hardware Security Modules (HSMs). Certificates stored exclusively on HSMs or in specialized appliance stores are invisible to endpoint-based certificate inventory. It would answer Is the cryptographic hardware generating PQC keys that never reach the endpoint trust store?.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine for network activity. |
pilot_domains | list[domain] | ssl.com, aka.ms, asp.net | Domains associated with the PQC Pilot Program and coordination. |
pqc_build_strings | list[string] | 28000.2608, 26200.8973, 26100.8973 | Windows OS builds known to support ML-DSA-87 in the pilot. |
scope_hosts | list[host] | — | Optional list of hosts to narrow the hunt. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
Source
---
analysis: While a detection rule can alert on a specific OS build, this hunt correlates
build capability with actual certificate presence and network activity to pilot
CAs, providing a holistic view of the testing environment that isolated rules cannot
capture.
blind_spots:
- id: incomplete-certificate-visibility
question: Which specific hosts have installed the ML-DSA pilot certificates?
requires: hb_certificates with device_hostname linkage
risk: The current hb_certificates schema does not provide a direct hostname column,
requiring an analyst to correlate cert findings with other telemetry by timing
or certificate owner.
stage: pqc-supply-chain-inventory
- id: hsm-blind-spot
question: Is the cryptographic hardware generating PQC keys that never reach the
endpoint trust store?
requires: Direct logging from Hardware Security Modules (HSMs)
risk: Certificates stored exclusively on HSMs or in specialized appliance stores
are invisible to endpoint-based certificate inventory.
stage: pqc-supply-chain-inventory
coverage:
- stage: pqc-supply-chain-inventory
status: covered
steps:
- scope-pqc-capable-hosts
- detect-pqc-certificates
- stage: pqc-pilot-interoperability-testing
status: covered
steps:
- dns-pqc-traffic
- triage-pqc-readiness
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: The transition to Post-Quantum Cryptography is a multi-year requirement
to mitigate 'harvest now, decrypt later' risks. Monitoring the organization's
testing activity ensures the PKI infrastructure is modernized in a controlled
fashion and identifies shadow testing that could disrupt production services.
methodology: model-assisted
trigger: intel-report
hypothesis: Organizations participating in post-quantum authentication testing will
exhibit specific Windows build versions, the presence of ML-DSA-87 pilot root certificates,
and network activity to designated pilot CA coordination domains.
labels:
- hunt
- attack.t1195
- initial access
name: Post-Quantum Authentication Readiness Monitoring
parameters:
lookback_days:
default: '14'
description: Days of history to examine for network activity.
type: number
pilot_domains:
default:
- ssl.com
- aka.ms
- asp.net
description: Domains associated with the PQC Pilot Program and coordination.
from:
kind: article
observed: '2026-10-08'
ref: msrc-blog-pqc-tls-pilot
type: list[domain]
pqc_build_strings:
default:
- '28000.2608'
- '26200.8973'
- '26100.8973'
description: Windows OS builds known to support ML-DSA-87 in the pilot.
from:
kind: article
observed: '2026-10-08'
ref: msrc-blog-pqc-tls-pilot
type: list[string]
scope_hosts:
default: []
description: Optional list of hosts to narrow the hunt.
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.microsoft.com/en-us/security/blog/2026/10/08/post-quantum-authentication-why-organizations-should-start-testing-certificate-ecosystems-now/
gates:
- dry-run
- lint
- critic
model: hb_google/gemini-3-flash-preview
rationale: Prioritize developer workstations, security lab hosts, and Windows 11 systems
recently updated after July 2026. Focus scoping on hosts that handle internal PKI
or external TLS authentication.
references:
- name: "Microsoft Security Blog \u2014 Post-quantum authentication: Why organizations\
\ should start testing certificate ecosystems now"
url: https://www.microsoft.com/en-us/security/blog/2026/10/08/post-quantum-authentication-why-organizations-should-start-testing-certificate-ecosystems-now/
related:
- hunt: pqc-handshake-performance-degradation
reason: This hunt focuses on inventory and readiness, not the performance impact
of larger PQC certificate chains on network traffic.
relation: out-of-scope-alternative
scenario:
stages:
- name: PQC Supply Chain and Infrastructure Inventory
observables:
- ML-DSA-87 algorithm support
- embedded devices
- operational technology systems
- KB5101681
- KB5101684
- OS Build 28000.2608
- OS Build 26200.8973
- OS Build 26100.8973
slug: pqc-supply-chain-inventory
tactic: initial-access
techniques:
- T1195
- name: PQC Pilot Interoperability and Connectivity
observables:
- ML-DSA-87 certificate chains
- aka.ms/rootcert
- ssl.com
- asp.net
- ComSign pilot roots
- DigiCert pilot roots
- HARICA pilot roots
- IdenTrust Services pilot roots
- Sectigo pilot roots
- Shanghai Electronic Certification Authority pilot roots
slug: pqc-pilot-interoperability-testing
tactic: initial-access
techniques:
- T1195
summary: Organizations are initiating post-quantum authentication (PQC) readiness
assessments to identify and mitigate 'harvest now, decrypt later' threats and
supply chain dependencies. The process involves auditing infrastructure for ML-DSA-87
support and testing certificate interoperability through the Microsoft PQC TLS
Pilot Program using non-production pilot roots.
severity: medium
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
tlp: clear
type: investigation
---
# Post-Quantum Authentication Readiness Monitoring
This hunt identifies hosts and infrastructure already engaging with Post-Quantum Cryptography (PQC) testing. It focuses on identifying the prerequisites for the Microsoft PQC TLS Pilot Program, such as specific Windows 11 builds (KB5101681, KB5101684) and the presence of non-production pilot root certificates from CAs like SSL.com and DigiCert. By inventorying these capabilities and correlating them with network traffic to pilot endpoints, we map the organization's PQC supply chain and readiness posture.
## scope-pqc-capable-hosts
<!-- Scope PQC-Capable Windows Hosts -->
Identify hosts running the specific Windows 11 builds required for ML-DSA-87 pilot testing.
```sqlite target=endpoint role=scoping params=(pqc_build_strings=pqc_build_strings, lookback_days=lookback_days)
~~~yaml
expected: Hosts running Windows 11 with the July 2026 updates or later. Silence suggests
no hosts are currently ready for PQC pilot testing.
reads:
- hostname
- os_version
- last_seen
- platform
- time
silence: not_evidence_of_absence
source: hb_devices
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT hostname, os_version, last_seen FROM hb_devices WHERE platform = 'Windows' AND (instr(',' || '{{pqc_build_strings}}' || ',', ',' || os_version || ',') > 0 OR os_version LIKE '%28000.2608%' OR os_version LIKE '%26200.8973%' OR os_version LIKE '%26100.8973%') AND time >= datetime('now', '-{{lookback_days}} days')
```
## parallel-corroboration
<!-- Corroborate Pilot Evidence -->
parallel:
- → detect-pqc-certificates
- → dns-pqc-traffic
join: → triage-pqc-readiness
## detect-pqc-certificates
<!-- Detect PQC Pilot Certificates -->
Search for certificates using ML-DSA or issued by the designated pilot CAs in the trust store.
```sqlite target=endpoint role=baseline
~~~yaml
baseline:
compare: first_seen
window: 30d
expected: Presence of non-production pilot root certificates or ML-DSA signed certificates.
Silence means no pilot certificates are installed.
prevalence:
by: owner
key:
- issuer
- signature_algorithm
rare_below: 5
reads:
- common_name
- issuer
- signature_algorithm
- status
- owner
silence: not_evidence_of_absence
source: hb_certificates
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT common_name, issuer, signature_algorithm, status, owner FROM hb_certificates WHERE (LOWER(signature_algorithm) LIKE '%ml-dsa%' OR LOWER(common_name) LIKE '%pqc%' OR LOWER(issuer) LIKE '%ssl.com%' OR LOWER(issuer) LIKE '%comsign%' OR LOWER(issuer) LIKE '%digicert%' OR LOWER(issuer) LIKE '%sectigo%' OR LOWER(issuer) LIKE '%harica%')
```
## dns-pqc-traffic
<!-- DNS Traffic to Pilot Domains -->
Identify hosts resolving domains mentioned in the PQC pilot program, narrowed by scoped hosts.
```sqlite target=endpoint role=enrichment params=(scope_hosts=scope_hosts, pilot_domains=pilot_domains, lookback_days=lookback_days)
~~~yaml
expected: DNS lookups for pilot domains like aka.ms or ssl.com during the test window.
Silence means no network-based pilot activity observed.
reads:
- device_hostname
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, query_hostname, COUNT(*) as lookup_count FROM hb_dns_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND instr(',' || '{{pilot_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, query_hostname
```
## triage-pqc-readiness
<!-- Triage PQC Testing Context -->
```agent target=hunter
cite: required
context:
- scope-pqc-capable-hosts
- detect-pqc-certificates
- dns-pqc-traffic
max_iterations: 3
objective: Determine which hosts are actively testing post-quantum certificates and
whether their infrastructure dependencies match the PQC TLS Pilot Program profile.
success_criteria: A list of hosts with confirmed PQC capabilities or active testing
status, citing the specific build numbers and certificate issuers found.
tools:
- endpoint
```
## route-pqc-findings
<!-- Route Based on Testing Activity -->
if~: "The triage verdict identifies at least one host as an active PQC tester with ML-DSA certificates or CA traffic." (confidence: high, judge=hunter)
then: → tag-pqc-hosts
indeterminate: → pki-analyst-review
unavailable: → pki-analyst-review (blind_spot: incomplete-certificate-visibility)
else: → close-out-task
## tag-pqc-hosts
<!-- Tag PQC Testing Hosts -->
```action target=endpoint
~~~yaml
approval: required
~~~
Tag identified hosts in the asset inventory with PQC_Pilot_Tester to ensure they are excluded from production performance baselines.
```
→ pki-analyst-review
## pki-analyst-review
<!-- Analyst Review of PQC Findings -->
```manual target=analyst
Review the identified hosts and certificates with the PKI administrator to confirm authorization. Update the PQC transition roadmap with any newly discovered dependencies.
```
→ update-readiness-report
## update-readiness-report
<!-- Update Readiness Report -->
```manual target=analyst
Document the PQC-capable host count and the presence of pilot certificates in the quarterly security readiness report.
```
→ end
## close-out-task
<!-- Close Out -->
```manual target=analyst
Record that no PQC pilot activity was detected. Schedule a re-run for next month as pilot adoption is expected to increase.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.