2026-09-23 19:26 UTC
took some doing, but here is proof of concept for Suricata. I wrote two rules - one looking for example.com in TLS SNI data, and another looking for it in http.host field of the HTTP header. This confirms that suricata is getting both encrypted and unencrypted traffic. #suricata #nsm #TLSDecrypt
Replies (1)
-
@da_667@infosec.exchange 2026-09-23 19:29
if you're doing this at home, the most important thing I can tell you is: If you want to do this, look at both encrypted and unencrypted streams, you CANNOT capture both on the same interface. SSLProxy changes network traffic when it decrypts it, changes sequence and ACK numbers, etc. so Suricata will get confused with it gets the encrypted stream of data, along with the unencrypted stream of data on the same interface.