TLS/SSL decryption profiles for deep packet inspection
Full SSL Inspection requires a CA certificate
Full Inspection (Inline Proxy) mode decrypts TLS traffic using your organization's CA certificate. Ensure your CA bundle is uploaded under CA Certificates and distributed to all managed endpoints. Financial and healthcare categories are exempt by default for compliance.
Detect malicious TLS clients & servers by their handshake fingerprint — no decryption required
| JA3 Hash | Threat | Category | Action | Hits (24h) |
|---|---|---|---|---|
| e7d705a3286e19ea… | Cobalt Strike Beacon | C2 Framework | Block | 3 |
| 72a589da586844d7… | Emotet Loader | Malware Dropper | Block | 7 |
| a0e9f5d64349fb13… | Metasploit Meterpreter | Exploitation Tool | Block | 1 |
| 51c64c77e60f3980… | TrickBot Banking Trojan | Banking Malware | Block | 0 |
| d44c5d7b9a370d84… | AsyncRAT | RAT | Block | 2 |
| 6734f37431670b3a… | Sliver C2 (Go) | C2 Framework | Block + Alert | 1 |
Non-standard cipher negotiation (TLS_NULL_WITH_NULL_NULL offered)
JA3S matches known Cobalt Strike TeamServer response
TLS 1.0 only — deprecated protocol, possible downgrade attack