JA4+ Fingerprint
The JA4+ fingerprint object provides detailed fingerprint information about various aspects of network traffic which is both machine and human readable.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
Raw Data | raw_data |
JSON | The event data as received from the event source. |
Record ID | record_id |
String | Unique identifier for the object |
JA4 Section A | section_a |
String | The 'a' section of the JA4 fingerprint. |
JA4 Section B | section_b |
String | The 'b' section of the JA4 fingerprint. |
JA4 Section C | section_c |
String | The 'c' section of the JA4 fingerprint. |
JA4 Section D | section_d |
String | The 'd' section of the JA4 fingerprint. |
Type | type |
String | The JA4+ fingerprint type as defined by FoxIO, normalized to the caption of 'type_id'. In the case of 'Other', it is defined by the event source. |
Type ID | type_id |
Integer |
The identifier of the JA4+ fingerprint type.
|
Unmapped Data | unmapped |
Unmapped[] | The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source. |
Value | value |
String | The JA4+ fingerprint value. |
Relationships
Inbound Relationships
These objects and events reference JA4+ Fingerprint in their attributes:
- SSH Activity
- Network Activity
- Network File Activity
- RDP Activity
- Network
- SMB Activity
- Tunnel Activity
- HTTP Activity
- FTP Activity
- NTP Activity
- DHCP Activity
- DNS Activity
Outbound Relationships
JA4+ Fingerprint references the following objects and events in its attributes:
This page describes qdm-1.3.2+ocsf-1.3.0
Updated about 1 month ago