Hfinger Logo

Hfinger

Tool for fingerprinting malware HTTP requests.

143
Visit website
Compare
Compare
0
MCPThe entire cybersecurity market, one prompt awayTry MCP Access

Hfinger Description

Tool for fingerprinting HTTP requests of malware. Based on Tshark and written in Python3. Working prototype stage :-) Its main objective is to provide unique representations (fingerprints) of malware requests, which help in their identification. Unique means here that each fingerprint should be seen only in one particular malware family, yet one family can have multiple fingerprints. Hfinger represents the request in a shorter form than printing the whole request, but still human interpretable. Hfinger can be used in manual malware analysis but also in sandbox systems or SIEMs. The generated fingerprints are useful for grouping requests, pinpointing requests to particular malware families, identifying different operations of one family, or discovering unknown malicious requests omitted by other security systems but which share fingerprint. An academic paper accompanies work on this tool, describing, for example, the motivation of design choices, and the evaluation of the tool compared to p0f, FATT, and Mercury.

Hfinger FAQ

Common questions about Hfinger including features, pricing, alternatives, and user reviews.

Hfinger is Tool for fingerprinting malware HTTP requests.. It is a Security Operations solution designed to help security teams with Fingerprinting.

Have more questions? Browse our categories or search for specific tools.

ALTERNATIVES

StrangeBee TheHive IaaS Images Logo

Collaborative case management platform for incident response and investigation

0
Seqrite Malware Analysis Platform Logo

Malware analysis platform for detecting and analyzing threats via sandbox

0
ORNA Digital Incident Response Plan Logo

Digital incident response plan built on SANS 504-B framework

0
AhnLab A-FIRST 디지털 포렌식 서비스 Logo

Digital forensics service for incident analysis and APT response

0
Cyber Triage Malware Forensics Tool Logo

Malware scanning tool for DFIR using 40+ engines from ReversingLabs

0

Stay Updated with Mandos Brief

Get strategic cybersecurity insights in your inbox