Hi Suricata Team,
Any plans to add JARM to be supported by suricata like Ja3 and Ja3s fingerprints.
Regards,
Tito
Hi Suricata Team,
Any plans to add JARM to be supported by suricata like Ja3 and Ja3s fingerprints.
Regards,
Tito
My understanding of JARM is that it requires active scanning (sending of TLS client hello packages) to generate the hash. That means it cannot be generated from an IDS/IPS that is just listening in on the connection.