Back to updates
New releaseAug 15, 2026

ja4 v1.0.0

JA4+ is a suite of network fingerprinting standards

Share

logo

JA4+™ Network Fingerprinting

JA4+ is a suite of network fingerprinting methods by FoxIO that are easy to use and easy to share. These methods are both human and machine readable to facilitate more effective threat-hunting and analysis. The use-cases for these fingerprints include scanning for threat actors, malware detection, session hijacking prevention, compliance automation, location tracking, DDoS detection, grouping of threat actors, reverse shell detection, and many more.

For a quick explainer on JA4+ and to use as a reference during analysis see:
JA4+ Cheat Sheet

For in-depth detail, please read our blogs on how JA4+ works, why it works, and examples of what can be detected/prevented with it:
JA4+ Network Fingerprinting (JA4/S/H/L/X/SSH)
JA4T: TCP Fingerprinting (JA4T/TS/TScan)
Investigating Surfshark and NordVPN with JA4T (JA4T)
JA4D and JA4D6: DHCP Fingerprinting (JA4D/6)

If you love JA4+, consider getting a t-shirt or hoodie:
JA4+ Shirts, Hoodies, and Stickers

Table of contents

Current methods and implementation details

Full NameShort NameDescription
JA4JA4TLS Client Fingerprinting
JA4ServerJA4STLS Server Response / Session Fingerprinting
JA4HTTPJA4HHTTP Client Fingerprinting
JA4LatencyJA4LClient to Server Latency Measurment / Light Distance
JA4LatencyServerJA4LSServer to Client Latency Measurement / Light Distance
JA4X509JA4XX509 TLS Certificate Fingerprinting
JA4SSHJA4SSHSSH Traffic Fingerprinting
JA4TCPJA4TTCP Client Fingerprinting
JA4TCPServerJA4TSTCP Server Response Fingerprinting
JA4TCPScanJA4TScanActive TCP Fingerprint Scanner
JA4DHCPJA4DDHCP Fingerprinting
JA4DHCPv6JA4D6DHCPv6 Fingerprinting
JA4NTPJA4NNTP Fingerprinting
JA4Scan-TLSJA4Scan-TLSActive TLS Server Fingerprint Scanner
JA4Scan-QUICJA4Scan-QUICActive QUIC Server Fingerprint Scanner

The full name or short name can be used interchangeably. Additional JA4+ methods are in the works...

To understand how to read JA4+ fingerprints, see Technical Details

Implementations

This repo includes JA4+ in

Tools that support JA4+

Categories