# salesforce/jarm

Repository: https://github.com/salesforce/jarm
Canonical: https://ross.abutalabs.com/products/jarm
Language: Python
License: BSD-3-Clause
License Family: permissive
Last push: 2026-08-13T17:58:03+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 35, longevity 100
- inputs: {"age_days": 2246, "days_push": 20, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1317, forks 151 (observed 2026-08-28T04:04:21.075590+00:00)

## What it is
JARM is an active TLS server fingerprinting tool that generates unique fingerprints of TLS server configurations. It is used to group and identify servers on the internet, including malware command-and-control infrastructure.

## Use cases
- fingerprint tls servers on the internet
- identify malware command and control servers
- verify all servers in a group share the same tls configuration
- detect default applications or infrastructure from tls config
- batch scan a large list of domains for jarm fingerprints

## When to choose
- you need to fingerprint TLS server configurations at scale
- you are doing threat intelligence or hunting for malicious C2 infrastructure
- you want to verify consistent TLS setups across a fleet of servers

## When to avoid
- you need passive TLS fingerprinting without actively connecting to servers
- you need a general-purpose vulnerability scanner rather than a TLS fingerprinter

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, networking, cli
- domain: security, networking, osint, developer-tools
- platform: python, cli, cross-platform
- tags: tls-fingerprinting, jarm, threat-intelligence, malware-detection

## Member repositories
- salesforce/jarm (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:21.075590+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:48:14.443875+00:00, confidence not recorded.
  - readme: https://github.com/salesforce/jarm (fetched 2026-08-28T04:04:21.075590+00:00, sha f33166a52765)
- Data as of 2026-08-30T08:39:29.467469+00:00.
