Skip to content

0.1 of sensor-d4-tls-fingerprinting released

Compare
Choose a tag to compare
@gallypette gallypette released this 25 Apr 08:15
· 4 commits to master since this release
864fc59

This is the inital release of sensor-d4-tls-fingerprinting.

Current Features

  • Extract x509 certificates from pcap files or network interfaces
  • Export TLS sessions description in JSON form - to stdout or to disk
  • Export Certificates to disk
  • Fingerprints TLS client/server interactions with ja3/ja3s
  • Fingerprints TLS interactions with TLSH fuzzy hashing on the tuple {ja3, ja3s, [certficate.issuer, certificate.subject]}

SHA 256

2c52f40ce7b606b4edeef7d9c6b2b5f622464effcfd3408852019b567e0620df  d4-tlsf-amd64l