Actions
Feature #2754
closedJA3 and JA3S - sets / reputation
Effort:
Difficulty:
Label:
Description
Support matching on large amounts of ja3/ja3s hashes.
Updated by Victor Julien about 6 years ago
- Related to Task #2685: SuriCon 2018 brainstorm added
Updated by Victor Julien about 6 years ago
- Blocked by Feature #2318: matching on large amounts of data with dynamic updates added
Updated by Victor Julien about 6 years ago
- Related to Feature #2684: Add JA3S added
Updated by Victor Julien over 5 years ago
- Target version changed from TBD to 5.0rc1
TLS JA3/JA3S:
Blacklist:
alert tls any any -> any any (ja3.hash; dataset:isset,bad_ja3_hash, load bad_ja3_hash.rep, type string; sid:3;)
Reputation:
alert tls any any -> any any (ja3s.hash; datarep:ja3s_rep, >, 200, load ja3s_rep.rep, type string; sid:4;) alert tls any any -> any any (ja3s.string; datarep:ja3s_str_rep, >, 200, load ja3s_str_rep.rep, type md5; sid:5;)
https://github.com/OISF/suricata/pull/4166
https://suricata.readthedocs.io/en/latest/rules/datasets.html
Updated by Victor Julien over 5 years ago
- Status changed from Assigned to Closed
Actions