Skip to content

JA3 Fingerprint

Definition

An MD5 hash computed from selected fields of the TLS Client Hello: the TLS version, cipher suites, extensions, elliptic curves, and elliptic-curve point formats. Because different TLS client implementations produce different combinations of these values, the JA3 hash can identify the TLS library or application that initiated a session. JA3S is the corresponding hash for the Server Hello.

Hash algorithm
MD5
Source fields
TLS version, cipher suites, extensions, curves, point formats
Captured from
TLS Client Hello
Server-side counterpart
JA3S

Common questions

Why can JA3 identify software without decrypting traffic?+

The Client Hello message that starts a TLS handshake is sent unencrypted, and different client libraries construct it with a distinctive, consistent ordering of cipher suites and extensions. Hashing those fields captures a signature of the client software itself, which stays visible even though everything after the handshake is encrypted.

What limits JA3's usefulness as an investigative signal?+

Many different applications share the same underlying TLS library, so a JA3 hash identifies the library or framework in use rather than the specific application, and widely used libraries can produce common hashes shared across large numbers of unrelated hosts, which limits how uniquely it can attribute a single piece of software.

Related terms

Flow Record
A summary record of a network conversation, typically recording source and destination IP addresses and ports, protocol, start time, duration, byte count...
Server Name Indication (SNI)
A TLS extension sent in plaintext in the Client Hello message that identifies the hostname the client intends to reach. SNI is...
SSL Inspection (TLS Interception)
A technique in which an intermediary device terminates an incoming TLS session, inspects the decrypted content, then re-encrypts and forwards it using...
SSLKEYLOGFILE
A file format, originally implemented in Mozilla Firefox and later adopted by Chrome and other browsers, that logs TLS session keys as...
Traffic Fingerprinting
The process of identifying an application, protocol, or user action from statistical properties of an encrypted flow, such as packet size distributions,...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.