Skip to content

Series

Network forensics techniques

2 posts in this series. Read them in order or jump to any one.

  1. JA3 Fingerprint vs JA4: TLS Client Fingerprinting Guide

    What a JA3 fingerprint is, how JA4 differs, why Chrome's extension-order randomization broke JA3 stability, and how defenders use TLS fingerprints in triage.

  2. DNS Analysis in a PCAP: A Defender's Guide

    How to read DNS in a packet capture: queries and responses, result codes, rare and random-looking domains, and high-level signs of DNS tunnelling, with limits.

All posts in this series

What a JA3 fingerprint is, how JA4 differs, why Chrome's extension-order randomization broke JA3 stability, and how defenders use TLS fingerprints in triage.
How to read DNS in a packet capture: queries and responses, result codes, rare and random-looking domains, and high-level signs of DNS tunnelling, with limits.