Elektrine lite

← Feed

@hrbrmstr@mastodon.social

Post #2872963

2026-05-07 13:29 UTC

@DaveMWilburn@infosec.exchange @adulau@infosec.exchange I've seen actors rotate through scads of JA4t and JA4h in a single campaign b/c so much is under their control. They are decent to use when dealing with C-lister attackers, but a giant problem that coming for us all is that real (i.e., not mirai-users) attackers are migrating to sitting behind residental proxies. And, even some mirai users are doing that too. Then the ciphers, 4t and 4h hashes are only good at telling you "yep! residential proxies!" 3/

Replies (1)

  • @hrbrmstr@mastodon.social 2026-05-07 13:33

    @DaveMWilburn@infosec.exchange @adulau@infosec.exchange I moved some JA4 tooling to private source (CLI & MCP with alot of baked-in knowledge), not b/c of fear of patent, but b/c I'm not keen on helping startups get rich and not getting even a public thank you or ACK in return (apologies for exposing some personal "pettiness" there). Glad to share w/y'all tho (DM me for signal handle). I'll stop ranting now 🙂 4/4

    Open ##2872964