salesforce/ja3
JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way. observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 19
- Release rhythm 35
- Longevity 100
Flags: no_releases archived
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3368
- days_rel: n/a
- days_push: 489
- n_releases_24m: 0
Adoption not part of the score
3103 stars · 313 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
JA3 is a standard and set of scripts (Python and Zeek) for generating SSL/TLS client fingerprints that are easy to produce and share for threat intelligence. The project is no longer actively maintained by Salesforce, with successor work continuing as JA4 at FoxIO.
Use cases
- fingerprint tls clients from network traffic
- detect malware by ssl handshake fingerprint
- share tls fingerprints for threat intelligence
- profile ssl clients in zeek
- generate ja3 hashes from pcaps
When to choose
- you need the original JA3 fingerprinting standard for compatibility with existing tools
- you want Zeek or Python scripts for TLS client fingerprinting
When to avoid
- you need actively maintained TLS fingerprinting - use JA4 instead
- you need JA3S or newer fingerprint methods with ongoing support
Facets
library · maturity maintenance
security networking monitoring security networking developer-tools python cross-platform tls-fingerprinting ja3 threat-intelligence zeek network-security linux
1 source
- readme: https://github.com/salesforce/ja3 · fetched 2026-08-28 · 0f6a2d5b9b00
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| salesforce/ja3 | main | 10 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem