Another JA4+ Win 🏆
Been tracking the #RedTail Bot campaign (akamai.com/blog/security-res…) this week & using the Wireshark JA4 plugin.
The RedTail exploit source IPs all use the same JA4 fingerprint, which defenders could use for detection: "t13i170900_5b57614c22b0_78e6aca7449b"
Link to JA4+ Plugin for Wireshark: github.com/FoxIO-LLC/ja4/tre…
Nov 8, 2025 · 1:16 PM UTC

