{"repo":"FoxIO-LLC/ja4","free":true,"listed":false,"github":"https://github.com/FoxIO-LLC/ja4","clone":"git clone https://github.com/FoxIO-LLC/ja4.git","description":"JA4+ is a suite of network fingerprinting standards","language":"Rust","stars":2049,"topics":["cybersecurity","ja3","ja3-fingerprint","jarm","network-analysis","network-forensics","ja4","ja4-fingerprint","ja4h","ja4x"],"license":null,"category":"security-tools","readme_excerpt":"JA4+™ Network Fingerprinting JA4+ is a suite of network fingerprinting methods by FoxIO that are easy to use and easy to share. These methods are both human and machine readable to facilitate more effective threat-hunting and analysis. The use-cases for these fingerprints include scanning for threat actors, malware detection, session hijacking prevention, compliance automation, location tracking, DDoS detection, grouping of threat actors, reverse shell detection, and many more. For a quick explainer on JA4+ and to use as a reference during analysis see: JA4+ Cheat Sheet For in-depth detail, please read our blogs on how JA4+ works, why it works, and examples of what can be detected/prevented with it: JA4+ Network Fingerprinting (JA4/S/H/L/X/SSH) JA4T: TCP Fingerprinting (JA4T/TS/TScan) Investigating Surfshark and NordVPN with JA4T (JA4T) If you love JA4+, consider getting a t-shirt or hoodie: JA4+ Shirts, Hoodies, and Stickers Table of contents - Current methods and implementation details - Implementations - Tools that support JA4+ - Examples - Plugins - Binaries - Release Assets - Installing tshark - Linux - macOS - Windows - Running JA4+ - Database - Release Process - How to Create a Release - JA4+ Details - Licensing - Q\\&A - JA4+ was created by Current methods and implementation details Full Name Short Name Description --- --- --- JA4 JA4 TLS Client Fingerprinting JA4Server JA4S TLS Server Response / Session Fingerprinting JA4HTTP JA4H HTTP Client Fingerprinting JA4Latency","default_branch":null,"files":null,"tree":[],"storefront":"/r/FoxIO-LLC","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/FoxIO-LLC/ja4/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}