-
Notifications
You must be signed in to change notification settings - Fork 1
ja3 fingerprinting
Summary: JA3 is a stable MD5 hash of a TLS ClientHello's negotiation parameters — version, cipher suites, extensions, supported groups, EC point formats. Same client library + version → same JA3 across hosts. Sloth computes JA3 for every observed ClientHello on TCP/443.
Sources: docs/views/tls.md, src/tls_log.c, src/md5.c.
Last updated: 2026-05-25.
The JA3 string is a comma-joined concatenation of:
- TLS legacy version (note: TLS 1.3 hides as
0x0303in this field; sloth also readssupported_versionsfor the real version display). - Cipher suites.
- Extensions.
- Supported elliptic-curve groups.
- EC point formats.
GREASE values per RFC 8701 are filtered out so the hash stays stable across browser restarts.
The resulting string is MD5-hashed. The MD5 implementation in
src/md5.c is embedded (no OpenSSL dep) and verified against RFC 1321
test vectors.
src, dst, host (SNI), TLS version (1.3 / 1.2 / 1.1 / 1.0 /
unknown), 32-char hex JA3. The view shows a 12-char prefix; full hash
is available for export.
- Implant detection: malware often uses a custom TLS library whose JA3 doesn't match Chrome/Firefox even when the User-Agent claims it is one of those browsers. A JA3-vs-UA mismatch is a classic implant signature.
- Cross-host correlation: same JA3 from different source IPs suggests the same client software — useful for tracing a tool through a network.
- Threat-intel pivoting: known-bad JA3s are published in feeds (see salesforce/ja3).
- ECH / encrypted ClientHello — when it lands, the SNI and most negotiation fields move inside an encrypted envelope.
- Clients that randomise their negotiation (rare today; some research builds do it).
-
alerts —
THREAT_DOMAINfires when SNI hits the IOC list. - threat-intel — IOC list format used for SNI matching.
- attack-map — TLS downgrade / weak crypto / implant fingerprint entries.
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance