-
Notifications
You must be signed in to change notification settings - Fork 19
Open
Description
I'd like to save JA3 signatures when NFR encounters TLS sessions on TCP port 443.
Here's a simple way that we can load tcpdump output into ja3.py and get the signatures. The code is over at https://github.com/salesforce/ja3/ and a large list of signatures at https://github.com/salesforce/ja3/tree/master/lists. We can then use the signatures on the backend to flag infections within riswiz.
Metadata
Metadata
Assignees
Labels
No labels