wireshark_extract_fingerprints
Extract JA3 and JA3S TLS fingerprints from pcap files for forensic analysis, optionally matching against custom fingerprint databases.
Instructions
[Forensics] Extract JA3 (client) and JA3S (server) TLS fingerprints.
Matches against ~/.wireshark-mcp/fingerprints/*.json if you maintain any; no fingerprint list ships with this package. A JA3 identifies a TLS configuration, not an application, so treat any match as a lead to corroborate.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| pcap_file | Yes |