Skip to content

Add JA4D fingerprint to Wireshark plugin#238

Merged
igr001-galactica merged 5 commits intoFoxIO-LLC:mainfrom
vlvkobal:ja4d
Jul 28, 2025
Merged

Add JA4D fingerprint to Wireshark plugin#238
igr001-galactica merged 5 commits intoFoxIO-LLC:mainfrom
vlvkobal:ja4d

Conversation

@vlvkobal
Copy link
Member

JA4D is a method for fingerprinting DHCP and DHCPv6 client/server behavior, similar to other JA4+ methods. This PR adds JA4D fingerprinting support to the Wireshark plugin.

Example JA4D fingerprints:

4-1-00_61-50-55_1-3-6-42
4-2-00_1-58-59-51-54_00
4-3-00_61-50-54-55_1-3-6-42
4-5-00_58-59-51-54-1_00
6-1-14_1-6-8-25_23-24
6-2-14_25-26-1-2_00
6-3-14_1-2-6-8-25-26_23-24
6-7-14_25-26-1-2_00
6-8-14_1-2-6-8-25-26_23-24
6-7-14_1-2-13_00

@igr001-galactica igr001-galactica merged commit 904b075 into FoxIO-LLC:main Jul 28, 2025
5 checks passed
@vlvkobal vlvkobal deleted the ja4d branch August 2, 2025 11:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants