Skip to content

TLS fingerprinting (JA3/JA3S) for encrypted channel detection (M8) #6

@nevinshine

Description

@nevinshine

Milestone M8: TLS client/server fingerprinting for encrypted C2 and evasion techniques.

  • Implement JA3/JA3S fingerprinting in XDP Go user space.
  • Detect known malicious client fingerprints for MITRE ATT&CK T1071.001 (HTTPS), T1573 (encrypted channel).
  • Document limitations (e.g., no decryption, only handshake metadata).

References:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions