match:
event_type: tls
tls.version: "TLS 1.3 draft-<16"
+ - filter:
+ requires:
+ features:
+ - HAVE_JA3
+ count: 1
+ match:
+ event_type: tls
+ tls.version: "TLS 1.3 draft-<16"
tls.ja3.hash: "65825469c473e48f3ee2571129256ab0"
tls.ja3.string: "772,49195-49199-52393-52392-49196-49200-49162-49161-49171-49172-51-57-47-53-10,0-23-65281-10-11-35-13172-16-5-65282-40-13,23-24-25-256-257-258-259-260,0"
match:
event_type: tls
tls.version: "TLS 1.3 draft-18"
+
+ - filter:
+ requires:
+ features:
+ - HAVE_JA3
+ count: 1
+ match:
+ event_type: tls
+ tls.version: "TLS 1.3 draft-18"
tls.ja3.hash: "23d254f72096d25c350e4a4a792f4948"
tls.ja3.string: "771,4865-4866-4867-49195-49199-158-49196-49200-159-52393-52392-52244-52243-49161-49187-49171-49191-51-103-49162-49188-49172-49192-57-107-156-157-47-60-53-61-10,65281-23-35-13-11-40-45-43-10,29-23-24,0"
checks:
- filter:
+ count: 3
+ match:
+ event_type: tls
+ tls.sni: "localhost"
+ tls.version: "TLS 1.3 draft-19"
+
+ - filter:
+ requires:
+ features:
+ - HAVE_JA3
count: 1
match:
event_type: tls
tls.ja3.string: "771,4866-255,0-11-10-35-13-22-23-43-45-40,29-23-25-24,0-1-2"
- filter:
+ requires:
+ features:
+ - HAVE_JA3
count: 1
match:
event_type: tls
tls.ja3.string: "771,4866-255,0-11-10-35-13-22-23-43-45-40-42-41,29-23-25-24,0-1-2"
- filter:
+ requires:
+ features:
+ - HAVE_JA3
count: 1
match:
event_type: tls
event_type: tls
tls.sni: "localhost"
tls.version: "TLS 1.3 draft-22"
+
+ - filter:
+ requires:
+ features:
+ - HAVE_JA3
+ count: 1
+ match:
+ event_type: tls
+ tls.sni: "localhost"
+ tls.version: "TLS 1.3 draft-22"
tls.ja3.hash: "786468211b4d23f9b725987b0de9d090"
tls.ja3.string: "771,4865-4867,0-43-13-10-40,23,"
match:
event_type: tls
tls.version: "TLS 1.3 draft-23"
+
+ - filter:
+ requires:
+ features:
+ - HAVE_JA3
+ count: 1
+ match:
+ event_type: tls
+ tls.version: "TLS 1.3 draft-23"
tls.ja3.hash: "0558cf38ebac58d332d7f39308fcd006"
tls.ja3.string: "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49161-49187-49171-49191-49162-49188-49172-49192-156-157-47-60-53-61-10,65281-23-35-13-11-51-45-43-10,29-23-24,0"
checks:
- filter:
+ requires:
+ features:
+ - HAVE_JA3
count: 1
match:
event_type: tls
tls.ja3.string: "771,4866-4867-4865-4868-49196-52393-49325-49162-49195-49324-49161-49200-52392-49172-49199-49171-157-49309-53-156-49308-47-159-52394-49311-57-158-49310-51,5-10-11-13-22-23-35-51-43-65281-0-45-41,23,0"
- filter:
+ requires:
+ features:
+ - HAVE_JA3
count: 1
match:
event_type: tls
checks:
- filter:
+ count: 2
+ match:
+ event_type: tls
+ tls.sni: "localhost"
+ tls.version: "TLS 1.3 draft-28"
+
+ - filter:
+ requires:
+ features:
+ - HAVE_JA3
count: 1
match:
event_type: tls
tls.ja3.string: "771,4866-4867-4865-4868-49196-52393-49325-49162-49195-49324-49161-49200-52392-49172-49199-49171-157-49309-53-156-49308-47-159-52394-49311-57-158-49310-51,5-10-11-13-22-23-35-51-43-65281-0-45-41,23,0"
- filter:
+ requires:
+ features:
+ - HAVE_JA3
count: 1
match:
event_type: tls