Skip to content

Conversation

@railisac
Copy link
Contributor

Added dedicated fields to document JA4, JA4HTTP & JA4TCP signatures when a TA / phishing kit attempts to authenticate toward a service, typically Entra.

As an example, Entra records since December 2025 JA4 signatures in field GatewayJA4.

We use misp-attribute text to store these signatures, as JA4 is currently only modelled as a MISP object.

Added dedicated fields to document JA4, JA4HTTP & JA4TCP signatures when a TA / phishing kit attempts to authenticate toward a service, typically Entra.

As an example, Entra records since December 2025 JA4 signatures in field GatewayJA4.
@adulau adulau merged commit 90e3eee into MISP:main Jan 12, 2026
2 of 7 checks passed
@adulau
Copy link
Member

adulau commented Jan 12, 2026

It makes sense. Thank you very much!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants