百科.dev
全部条目AI 编程趋势榜开源项目技术资讯提交条目
登录
< 返回工具列表
J

ja4

> 安全
开源

JA4+ 是一套网络指纹识别标准

2.0K stars0 点赞0 次浏览
访问官网GitHub

工具介绍

JA4+ 是一套网络指纹识别标准

# JA4+™ Network Fingerprinting JA4+ is a suite of network fingerprinting methods by [FoxIO](https://foxio.io/) that are easy to use and easy to share. These methods are both human and machine readable to facilitate more effective threat-hunting and analysis. The use-cases for these fingerprints include scanning for threat actors, malware detection, session hijacking prevention, compliance automation, location tracking, DDoS detection, grouping of threat actors, reverse shell detection, and many more. For a quick explainer on JA4+ and to use as a reference during analysis see: [JA4+ Cheat Sheet](https://x.com/4A4133/status/1887269972545839559) For in-depth detail, please read our blogs on how JA4+ works, why it works, and examples of what can be detected/prevented with it: [JA4+ Network Fingerprinting](https://foxio.io/blog/ja4-network-fingerprinting) (JA4/S/H/L/X/SSH) [JA4T: TCP Fingerprinting](https://foxio.io/blog/ja4t-tcp-fingerprinting) (JA4T/TS/TScan) [Investigating Surfshark and NordVPN with JA4T](https://foxio.io/blog/investigating-surfshark-and-nordvpn-with-ja4t) (JA4T) [JA4D and JA4D6: DHCP Fingerprinting](https://foxio.io/blog/ja4d-and-ja4d6-dhcp-fingerprinting) (JA4D/6) If you love JA4+, consider getting a t-shirt or hoodie: [JA4+ Shirts, Hoodies, and Stickers](https://store.foxio.io/) ## Table of contents - [Current methods and implementation details](#current-methods-and-implementation-details) - [Implementations](#implementations) - [Tools that support JA4+](#tools-that-support-ja4) - [Examples](#examples) - [Plugins](#plugins) - [Binaries](#binaries) - [Release Assets](#release-assets) - [Installing tshark](#installing-tshark) - [Linux](#linux) - [macOS](#macos) - [Windows](#windows) - [Running JA4+](#running-ja4) - [Database](#database) - [Release Process](#release-process) - [How to Create a Release](#how-to-create-a-release) - [JA4+ Details](#ja4-details) - [Licensing](#licensing) - [Q\&A](#qa) - [JA4+ was created by](#ja4-was-created-by) ## Current methods and implementation details | Full Name | Short Name | Description | |---|---|---| | JA4 | JA4 | TLS Client Fingerprinting | | JA4Server | JA4S | TLS Server Response / Session Fingerprinting | | JA4HTTP | JA4H | HTTP Client Fingerprinting | | JA4Latency | JA4L | Client to Server Latency Measurment / Light Distance | | JA4LatencyServer | JA4LS | Server to Client Latency Measurement / Light Distance | | JA4X509 | JA4X | X509 TLS Certificate Fingerprinting | | JA4SSH | JA4SSH | SSH Traffic Fingerprinting | | JA4TCP | JA4T | TCP Client Fingerprinting | | JA4TCPServer | JA4TS | TCP Server Response Fingerprinting | | [JA4TCPScan](https://github.com/FoxIO-LLC/ja4tscan) | [JA4TScan](https://github.com/FoxIO-LLC/ja4tscan) | [Active TCP Fingerprint Scanner](https://github.com/FoxIO-LLC/ja4tscan) | | JA4DHCP | JA4D | DHCP Fingerprinting | | JA4DHCPv6 | JA4D6 | DHCPv6 Fingerprinting | | JA4NTP | JA4N | NTP Fingerprinting | | JA4Scan-TLS | JA4Scan-TLS | Active TLS Server Fingerprint Scanner | | JA4Scan-QUIC | JA4Scan-QUIC | Active QUIC Server Fingerprint Scanner | The full name or short name can be used interchangeably. Additional JA4+ methods are in the works... To understand how to read JA4+ fingerprints, see [Technical Details](./technical_details/README.md) ## Implementations This repo includes JA4+ in - [Python](./python/README.md) - [Rust](./rust/README.md) - [C, as a Wireshark plugin](./wireshark/README.md). - [Zeek](./zeek/README.md) ## Tools that support JA4+ | Tool/Vendor | JA4+ Support | |-------------|--------------| | [Wireshark](https://github.com/FoxIO-LLC/ja4/tree/main/wireshark) | JA4+ | | [Zeek](https://github.com/FoxIO-LLC/ja4/tree/main/zeek) | JA4+ | | [Arkime](https://arkime.com/) | JA4+ (our recommended open source JA4+ tool) | | [Suricata](https://docs.suricata.io/en/latest/rules/ja-keywords.html#ja4-hash) | JA4+ (under development) | | [GreyNoise](https://www.greynoise.io/) | JA4+ | | [Hunt](https://hunt.io/) | JA4+ | | [Driftnet](https://driftnet.io/) | JA4+ | | [GoLang (1)](https://github.com/driftnet-io/go-ja4x) | JA4X | | [GoLang (2)](https://github.com/exaring/ja4plus) | JA4 | | [nzyme](https://www.nzyme.org/) | JA4+ (under development) | | [Netresec's CapLoader](https://www.netresec.com/?page=Blog&month=2023-11&post=CapLoader-1-9-6-Released) | JA4+ (under development) | | [Netresec's NetworkMiner](https://www.netresec.com/?page=NetworkMiner) | JA4+ (under development) | | [NGINX](https://github.com/FoxIO-LLC/ja4-nginx-module) | JA4+ | | [F5 BIG-IP](https://github.com/f5devcentral/f5-ja4) | JA4+ | | [nfdump](https://github.com/phaag/nfdump) | JA4+ | | [ntop's ntopng](https://github.com/ntop/ntopng) | JA4+ | | [ntop's nDPI](https://github.com/ntop/nDPI) | JA4 | | [Team Cymru](https://www.team-cymru.com/) | JA4+ | | [NetQuest](https://netquestcorp.com/) | JA4+ | | [Censys](https://censys.com/) | JA4+ | | [Exploit.org's Netryx](https://github.com/OWASP/www-project-netryx) | JA4 and JA4H | | [Cloudflare](https://developers.cloudflare.com/bots/concepts/ja3-ja4-fingerprint/) | JA4 | | [Fastly](https://www.fastly.com/documentation/reference/vcl/variables/client-connection/tls-client-ja4/) | JA4+ (ask for it) | | [MISP](https://www.misp-project.org/) | JA4+ | | [OCSF](https://schema.ocsf.io/1.3.0-dev/objects/ja4_fingerprint?extensions=) | JA4+ | | [Vercel](https://vercel.com/docs/security/tls-fingerprints) | JA4 | | [Seika](https://seika.io/) | JA4+ | | [VirusTotal](https://www.virustotal.com/) | JA4 | | [AWS Cloudfront](https://aws.amazon.com/about-aws/whats-new/2024/10/amazon-cloudfront-ja4-fingerprinting/) | JA4 | | [ELLIO](https://ellio.tech/) | JA4+ | | [Webscout](https://webscout.io/) | JA4+ | | [Rama](https://github.com/plabayo/rama) | JA4 and JA4H | | [Vectra](https://www.vectra.ai/) | JA4+ | | [AWS WAF](https://aws.amazon.com/about-aws/whats-new/2025/03/aws-waf-ja4-fingerprinting-aggregation-ja3-ja4-fingerprints-rate-based-rules/) | JA4 | | [Tacticly](https://tactic.ly/) | JA4+ | | [Palo Alto Networks](https://www.paloaltonetworks.com/) | JA4+ | | [ngrok](https://ngrok.com/docs/traffic-policy/variables/connection/#conntlsja4_fingerprint) | JA4 | | [Vertex Synapse](https://vertex.link/) | JA4 and JA4S | | [Google Cloud Armor](https://cloud.google.com/armor/docs/rules-language-reference#allow_or_deny_traffic_based_on_a_known_ja4_fingerprint) | JA4 | | [Fortinet](https://docs.fortinet.com/document/fortindr-cloud/25.2.c/user-guide/393114/event-fields#SSL) | JA4 | | [AppOmni](https://appomni.com/) | JA4+ | | [IntelliGenesis](https://intelligenesisllc.com/) | JA4+ | | [HAProxy](https://www.haproxy.org/) | [JA4](https://github.com/O-X-L/haproxy-ja4-fingerprint) and [JA4H](https://github.com/O-X-L/haproxy-ja4h-fingerprint) plugins by [OXL](https://www.o-x-l.com/) | | [SentinelOne](https://www.sentinelone.com/) | JA4 | | [Akamai](https://techdocs.akamai.com/application-security/reference/get-ja4-fingerprint-settings) | JA4 | | [Alibaba Cloud](https://www.alibabacloud.com/help/en/anti-ddos/anti-ddos-pro-and-premium/user-guide/fields-included-in-full-logs) | JA4 | | [Huawei Cloud](https://support.huaweicloud.com/intl/en-us/usermanual-waf/waf_01_3157.html) | JA4 | | [Google Cloud LBs](https://cloud.google.com/release-notes#July_28_2025) | JA4 | | [eSentire](https://www.esentire.com/) | JA4+ | | [Microsoft Azure Front Door CDN](https://learn.microsoft.com/en-us/azure/frontdoor/front-door-http-headers-protocol) | JA4 | | [Synapse](https://github.com/gen0sec/synapse) by [Gen0Sec](https://gen0sec.com) | JA4X | | [Zscaler](https://www.zscaler.com/blogs/product-insights/zscaler-endpoint-context-endpoint-cloud-visibility-and-enforcement-secops) | JA4 | | [ExtraHop](https://www.extrahop.com/) | JA4+ | | [Validin](https://www.validin.com/) | JA4+ | | [Auth0](https://auth0.com/changelog#40upcFBPuFxKG7nacgSlQc) | JA4 | | [Security Onion](https://blog.securityonion.net/2026/03/security-onion-300-now-available-with.html) | JA4+ | | [bunny.net](https://docs.bunny.net/cdn/security/ja4-fingerprinting) | JA4 | | [ENEA](https://www.enea.com/) | JA4+ | | [F5 Distributed Cloud Services](https://www.f5.com/products/distributed-cloud-services) | JA4+ | with more to be announced... ## Examples | Application |JA4+ Fingerprints | |----|----| | Chrome | ```JA4=t13d1517h2_8daaf6152771_cb7bf5808d99``` (TCP)
```JA4=q13d0312h3_55b375c5d22e_178839b6cec1``` (QUIC) | | IcedID Malware Dropper | ```JA4H=ge11cn020000_9ed1ff1f7b03_cd8dafe26982``` | | IcedID Malware | ```JA4=t13d201100_2b729b4bf6f3_9e7b989ebec8```
```JA4S=t120300_c030_5e2616a54c73``` | | Sliver Malware | ```JA4=t13d190900_9dc949149365_97f8aa674fd9```
```JA4S=t130200_1301_a56c5b993250```
```JA4X=000000000000_4f24da86fad6_bf0f0589fc03```
```JA4X=000000000000_7c32fa18c13e_bf0f0589fc03``` | | Cobalt Strike | ```JA4H=ge11cn060000_4e59edc1297a_4da5efaf0cbd```
```JA4X=2166164053c1_2166164053c1_30d204a01551``` | | SoftEther VPN | ```JA4=t13d880900_fcb5b95cb75a_b0d3b4ac2a14``` (client)
```JA4S=t130200_1302_a56c5b993250```
```JA4X=d55f458d5a6c_d55f458d5a6c_0fc8c171b6ae``` | | Qakbot | ```JA4X=2bab15409345_af684594efb4_000000000000``` | | Pikabot | ```JA4X=1a59268f55e5_1a59268f55e5_795797892f9c``` | | Darkgate | ```JA4H=po10nn060000_cdb958d032b0``` | | LummaC2 | ```JA4H=po11nn050000_d253db9d024b``` | | Evilginx | ```JA4=t13d191000_9dc949149365_e7c285222651``` | | Reverse SSH Shell | ```JA4SSH=c76s76_c71s59_c0s70``` | | Windows 11 | ```JA4T=64240_2-1-3-1-1-4_1460_8``` | | Epson Printer | ```JA4TScan=28960_2-4-8-1-3_1460_3_1-4-8-16``` | | Windows 11 | ```JA4D=disco0000in_61-12-60-55_1-3-6-15-31-33-43-44-46-47-119-121-249-252``` | | Sony Receiver | ```JA4D6=solct0010nn_8-1-3-6_24-23``` | For more examples, see [ja4plus-mapping.csv](./ja4plus-mapping.csv) For a complete database, see [ja4db.com](https://ja4db.com/) ## Plugins [Wireshark](https://github.com/FoxIO-LLC/ja4/tree/main/wireshark) [Zeek](https://github.com/FoxIO-LLC/ja4/tree/main/zeek) [Arkime](https://arkime.com/settings#ja4plus) ## Binaries JA4 binaries are built from the [Rust implementation](rust/README.md) of the suite. To ensure full functionality, `tshark` (version 4.0.6 or later) is required. Download the latest JA4 binaries from the [Releases](https://github.com/FoxIO-LLC/ja4/releases) page. The release versions for the Rust implementation follow [Semantic Versioning](https://semver.org/) and are marked as `vX.Y.Z`, unlike Wireshark plugin releases. ### Release Assets Release assets are named according to the component and platform: - **Rust:** - `ja4-vX.Y.Z--.tar.gz` (e.g., `ja4-v0.18.5-x86_64-unknown-linux-musl.tar.gz`) - **Python:** - `ja4-python-vX.Y.Z.tar.gz` (contains the full `python/` directory) - **Wireshark:** - `ja4.so.linux`, `ja4.so.macos`, `ja4.dll` (attached to a release named like `wireshark-vX.Y.Z`) Choose the appropriate file for your system and component. ### Installing tshark #### Linux Install it using your package manager (the name of the package `tshark` or `wireshark-cli` depends on the distribution). For example, on Ubuntu: ```sh sudo apt install tshark ``` #### macOS 1. [Download](https://www.wireshark.org/download.html) and install Wireshark (includes `tshark`). 2. Add `tshark` to your `PATH`: ```sh sudo ln -s /Applications/Wireshark.app/Contents/MacOS/tshark /usr/local/bin/tshark ``` #### Windows 1. [Download](https://www.wireshark.org/download.html) and install Wireshark (includes `tshark.exe`). 2. Locate `tshark.exe` (usually in `C:\Program Files\Wireshark\tshark.exe`). 3. Add the folder containing `tshark.exe` to your system `PATH`: - Open **System Properties** > **Environment Variables** > **Edit Path**. ### Running JA4+ Once `tshark` and the JA4+ binaries are available, run JA4+ using the following command: - On Linux and macOS: ```sh ./ja4 [options] [pcap] ``` - On Windows, open *

GitHub Issues· 0 开放

在 GitHub 查看全部

暂无开放 Issues,或尚未同步最近议题。

核心特点

  • •Current methods and implementation details
  • •Implementations
  • •Tools that support JA4+
  • •Examples
  • •Binaries
  • •Release Assets
  • •Installing tshark
  • •Running JA4+
  • •Database
  • •Release Process

> 标签

Rustcybersecurityja3ja3-fingerprintja4

暂无评论,来聊聊你的看法吧

> 工具信息

发布日期2026年8月1日
最后更新2026年9月17日
分类安全
定价开源

> 相关工具

O
OWASP ZAP
开源 Web 应用安全扫描器
O
owasp-wstg-tracker
Simple web app to track OWASP WSTG security testing progress
H
homebridge-mi-gateway-security
XiaoMi Gateway Security plugin for HomeBridge.