fingerprint_search_tool
Search honeypot activity by TLS, HTTP, or SSH fingerprint. Find IPs sharing a specific fingerprint using JA4, JA4h, or HASSH types with time range filters.
Instructions
Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks: 'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?', 'how common is this HASSH?', 'find all scanners with this SSH client fingerprint'. fp_type: 'ja4' (TLS client, 3.7M events), 'ja4h' (HTTP client, 3.2M events), 'hassh' (SSH client, 26K events). since/until are ISO-8601 UTC strings.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| fingerprint | Yes | ||
| fp_type | Yes | ||
| since | Yes | ||
| until | Yes | ||
| limit | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||