Skip to content

Add ja4l_delta and ja4ls_delta derived fields to JA4 wireshark plugin#245

Merged
igr001-galactica merged 3 commits intoFoxIO-LLC:mainfrom
vlvkobal:ja4l-delta
Aug 7, 2025
Merged

Add ja4l_delta and ja4ls_delta derived fields to JA4 wireshark plugin#245
igr001-galactica merged 3 commits intoFoxIO-LLC:mainfrom
vlvkobal:ja4l-delta

Conversation

@vlvkobal
Copy link
Member

@vlvkobal vlvkobal commented Aug 5, 2025

This PR adds two numeric fields to the JA4 Wireshark dissector:

  • ja4.ja4l_delta = ja4l_c / ja4l_a
  • ja4.ja4ls_delta = ja4ls_c / ja4ls_a

They are computed only when the _c value is numeric and exported for use in filters, columns, and JSON output.

Example (tshark):

ja4.ja4l = 2177_64_114732
ja4.ja4l_delta = 52.7
ja4.ja4ls = 781_238_9107
ja4.ja4ls_delta = 11.7

Also includes a minor documentation update mentioning JA4D.

@igr001-galactica igr001-galactica merged commit 5672966 into FoxIO-LLC:main Aug 7, 2025
5 checks passed
@vlvkobal vlvkobal deleted the ja4l-delta branch August 8, 2025 11:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants