Skip to content

Posts tagged: #threat-hunting

How to read DNS in a packet capture: queries and responses, result codes, rare and random-looking domains, and high-level signs of DNS tunnelling, with limits.
What a JA3 fingerprint is, how JA4 differs, why Chrome's extension-order randomization broke JA3 stability, and how defenders use TLS fingerprints in triage.