[Bug] Support all JA4_DB JAX fingerprint types and store them in DB. Closes #3541#3568
Open
chauhan-varun wants to merge 2 commits intointelowlproject:developfrom
Open
[Bug] Support all JA4_DB JAX fingerprint types and store them in DB. Closes #3541#3568chauhan-varun wants to merge 2 commits intointelowlproject:developfrom
chauhan-varun wants to merge 2 commits intointelowlproject:developfrom
Conversation
…d enhance the analyzer to support various JA4 fingerprint types.
Author
|
Hi @mlodic, this is ready for review Could you please take a look? |
Member
|
it's not there are no screenshots or JSON results |
Author
|
I’ve updated the PR description and added both the screenshot and the raw JSON from a finished JA4_DB analysis, PTAL |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR fixes #3541.
The existing
JA4_DBanalyzer was still tied to the old JSON-file cache and only handled the traditional JA4 lookup flow well. This change moves that storage into the database and expands the analyzer so it can work with all JAX fingerprint types currently returned by JA4DB, includingja4s,ja4h,ja4x,ja4t,ja4ts, andja4tscan.I added a new
Ja4DBEntrymodel plus the related migration, updated the analyzer to populate and query that table, and removed the dependency onja4_db.jsonfor runtime lookups. I also added test coverage for the updater path, several JAX lookup paths, duplicate match handling, and update failure handling.Type of change
Please delete options that are not relevant.
Checklist
developdumpplugincommand and added it in the project as a data migration. ("How to share a plugin with the community")test_files.zipand you added the default tests for that mimetype in test_classes.py.FREE_TO_USE_ANALYZERSplaybook by following this guide.urlthat contains this information. This is required for Health Checks (HEAD HTTP requests).get_mocker_response()method of the unittest class. This serves us to provide a valid sample for testing.DataModelfor the new analyzer following the documentation# This file is a part of IntelOwl https://github.com/intelowlproject/IntelOwl # See the file 'LICENSE' for copying permission.Ruff) gave 0 errors. If you have correctly installed pre-commit, it does these checks and adjustments on your behalf.testsfolder). All the tests (new and old ones) gave 0 errors.DeepSource,Django Doctorsor other third-party linters have triggered any alerts during the CI checks, I have solved those alerts.