Threat Hunting with JARM, (Fri, Nov 27th)

SANS Internet Storm Center, InfoCON: green 2020-11-28

Summary:

Recently I have been testing a new tool created by the people at Salesforce. The tool is called JARM and what it does is query TLS instances (HTTPS servers and services) to create a fingerprint of their TLS configuration. Much like analyzing the nuances of network traffic can be used to fingerprint the operating system and version of a server, JARM fingerprints TLS instances to create a fingerprint which can be used to compare one TLS service to another.

Link:

https://isc.sans.edu/diary/rss/26832

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

11/28/2020, 02:15

Date published:

11/27/2020, 17:33