Question Is it possible and easy to setup a whitelist of browser utilizing JA4+

Please provide comments and solutions that are helpful to the author of this topic.

Victor M

Level 22
Thread author
Verified
Top Poster
Well-known
Oct 3, 2022
1,120
3,658
2,069
Hi everyone,

Just read about JA3, JA4+. Is it possible to setup a whitelist of browser client traffic using JA4+ that works in near realtime? The goal is to drop RAT and hackerware traffic since the browser is all I use. I don't know if it is possible. Suricata supposedly understands JA4 already. So it should be only a matter of having the correct rules? Has anybody tried this? ChatGPT says it is do-able, but you know chat, it top downs to solve a problem and can hallucinate about things it doesn't know for sure.
 
Last edited:
  • Like
Reactions: simmerskool
Yes, it's possible to set up a whitelist of browser traffic using JA4+ in near real-time. Suricata does indeed support JA3/JA4, but you'll need to create and implement the appropriate rules. It's not a simple task and requires a good understanding of network protocols and security. I'd recommend seeking professional assistance if you're not familiar with it. As for ChatGPT, while it's a powerful tool, it's always good to double-check its suggestions with real-world applications and expert advice.
 
  • HaHa
Reactions: simmerskool