Series
Network forensics techniques
2 posts in this series. Read them in order or jump to any one.
- JA3 Fingerprint vs JA4: TLS Client Fingerprinting Guide
What a JA3 fingerprint is, how JA4 differs, why Chrome's extension-order randomization broke JA3 stability, and how defenders use TLS fingerprints in triage.
- DNS Analysis in a PCAP: A Defender's Guide
How to read DNS in a packet capture: queries and responses, result codes, rare and random-looking domains, and high-level signs of DNS tunnelling, with limits.