app:auto_fingerprint
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| app:auto_fingerprint [2017/11/29 18:02] – vivek | app:auto_fingerprint [2017/11/29 22:58] (current) – [Web Server Access Log] veera | ||
|---|---|---|---|
| Line 19: | Line 19: | ||
| - | Internally we use a Ruby TRP script that can automate this process if given access to web server logs. The script is available at [[https:// | + | Internally we use a Ruby TRP script that can automate this process if given access to web server logs. The script is available |
| Line 34: | Line 34: | ||
| - | <code json> | ||
| - | {" | + | Running the script. |
| - | {" | + | |
| - | {" | + | |
| - | </code> | + | //Usage : mk_ja3fingerprint.rb |
| - | Running | + | A sample run of the script |
| - | < | + | < |
| + | |||
| + | $ ruby mk_ja3fingerprint.rb | ||
| - | vivek@viveku14: | ||
| "Found 29 Unresolved JA3 TLS Prints" | "Found 29 Unresolved JA3 TLS Prints" | ||
| " | " | ||
| Line 61: | Line 59: | ||
| " | " | ||
| .. | .. | ||
| + | " | ||
| + | |||
| </ | </ | ||
| + | |||
| + | |||
| + | Once the script is finished, the JSON output is written to ''/ | ||
| + | |||
| + | <code json> | ||
| + | |||
| + | {" | ||
| + | {" | ||
| + | {" | ||
| + | |||
| + | </ | ||
| + | |||
| + | |||
| + | Iteratively running this script for a few days can resolve most of the unknown prints. That makes outlier detection much easier. | ||
| + | |||
| + | ===== Other methods to resolve ===== | ||
| + | |||
| + | Once you get the unknown prints down to 10-20% you can use Trisul' | ||
| + | |||
app/auto_fingerprint.1511958748.txt.gz · Last modified: 2017/11/29 18:02 by vivek