HASSH Logo

HASSH

0
Free
Visit Website

HASSH is a network fingerprinting standard used to identify specific Client and Server SSH implementations, allowing for easy storage, search, and sharing of MD5 fingerprints. Invented at Salesforce in 2018, now actively maintained by Ben Reardon at Corelight. HASSH can help in detecting and investigating brute force or Cred Stuffing password attempts with higher granularity than IP Source, even in NATed or botnet-like scenarios, and in detecting covert exfiltration of data within SSH Client algorithm sets.

FEATURES

ALTERNATIVES

netsniff-ng is a free Linux networking toolkit with zero-copy mechanisms for network development, analysis, and auditing.

MIDAS (Mac Intrusion Detection Analysis System) - archived and no longer supported.

Fail2ban is a daemon that scans log files and bans IPs showing malicious signs to protect servers from brute-force attacks.

A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

Detects and prevents SSRF attacks

A textmode sniffer for tracking tcp streams and capturing data in various modes.

A tool for performing subdomain enumeration using Censys API

DirSearch is a simple tool for finding files and directories on a web server.

PINNED