Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
fatt — FATT /fingerprintAllTheThings - 一个基于pyshark的脚本,用于从pcap文件和实时网络流量中提取网络元数据和指纹。 | Kitploit
工具/GitHubGitHub/0x4d31/fatt
数据包嗅探与分析网络取证威胁情报
GitHub0x4d31/fatt

fatt

FATT /fingerprintAllTheThings - 一个基于pyshark的脚本,用于从pcap文件和实时网络流量中提取网络元数据和指纹。

查看仓库
68497744年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
66 61 74 74 2e

给所有事物打指纹!

License: GPL v3

有关指纹识别方法、示例用例和研究结果的更多信息将很快添加到仓库中。敬请期待!

一个用于从数据包捕获文件(pcap)或实时网络流量中提取网络元数据和指纹(如 JA3 和 HASSH)的脚本。主要用途是监控蜜罐,但你也可以将其用于其他场景,例如网络取证分析。fatt 可在 Linux、macOS 和 Windows 上运行。

请注意,fatt 使用 pyshark(tshark 的 Python 封装),因此性能不佳!但这并不是大问题,显然这不是一个用于生产环境的工具。对于更严肃的用例,你可以使用其他网络分析工具,如 Bro/Zeek、Suricata 或 Netcap。Joy 是另一个可用于捕获和分析网络流数据的优秀工具。

除此之外,我正在开发一个基于 Go 的 fatt 版本,速度更快,并且你可以将其库用于基于 gopacket 的工具(如 packetbeat)。我已经发布了其 gQUIC 库的初始版本(QUICk)。

功能特性

  • 协议支持:SSL/TLS、SSH、RDP、HTTP、gQUIC。
    • 即将添加:IETF QUIC、MySQL、MSSQL 等。
  • 指纹识别
    • JA3:TLS 客户端/服务器指纹
    • HASSH:SSH 客户端/服务器指纹
    • RDFP:我针对标准 RDP 安全协议的实验性 RDP 指纹(注意:其他 RDP 安全模式使用 TLS,可以通过 JA3 进行指纹识别)
    • HTTP 头部指纹
    • gQUIC/iQUIC 指纹将很快添加
  • JSON 输出

开始使用

  1. 安装 tshark

你首先需要安装 tshark。确保你拥有 v2.9.0 或更高版本。从 v2.9.0 开始,Tshark/Wireshak 将 'ssl' 重命名为 'tls',并且 fatt 是基于新版本 tshark 编写的。

如果你使用的是旧版本 tshark(< v2.9.0),可以使用来自 "old-tshark" 分支 的 fatt 脚本。

  1. 安装依赖
cd fatt/
pip3 install pipenv
pipenv install

或者,如果你不想使用虚拟环境,直接安装 pyshark:

pip3 install pyshark==0.4.2.2

要激活虚拟环境,运行 pipenv shell:

$ pipenv shell
Launching subshell in virtual environment…
bash-3.2$  . /Users/adel/.local/share/virtualenvs/fatt-ucJHMzzt/bin/activate
(fatt-ucJHMzzt) bash-3.2$ python3 fatt.py -h

或者,使用 pipenv run 在虚拟环境中运行命令:

$ pipenv run python3 fatt.py -h

输出:

usage: fatt.py [-h] [-r READ_FILE] [-d READ_DIRECTORY] [-i INTERFACE]
               [-fp [{tls,ssh,rdp,http,gquic} [{tls,ssh,rdp,http,gquic} ...]]]
               [-da DECODE_AS] [-f BPF_FILTER] [-j] [-o OUTPUT_FILE]
               [-w WRITE_PCAP] [-p]

A python script for extracting network fingerprints

optional arguments:
  -h, --help            show this help message and exit
  -r READ_FILE, --read_file READ_FILE
                        pcap file to process
  -d READ_DIRECTORY, --read_directory READ_DIRECTORY
                        directory of pcap files to process
  -i INTERFACE, --interface INTERFACE
                        listen on interface
  -fp [{tls,ssh,rdp,http,gquic} [{tls,ssh,rdp,http,gquic} ...]], --fingerprint [{tls,ssh,rdp,http,gquic} [{tls,ssh,rdp,http,gquic} ...]]
                        protocols to fingerprint. Default: all
  -da DECODE_AS, --decode_as DECODE_AS
                        a dictionary of {decode_criterion_string:
                        decode_as_protocol} that is used to tell tshark to
                        decode protocols in situations it wouldn't usually.
  -f BPF_FILTER, --bpf_filter BPF_FILTER
                        BPF capture filter to use (for live capture only).'
  -j, --json_logging    log the output in json format
  -o OUTPUT_FILE, --output_file OUTPUT_FILE
                        specify the output log file. Default: fatt.log
  -w WRITE_PCAP, --write_pcap WRITE_PCAP
                        save the live captured packets to this file
  -p, --print_output    print the output

用法

实时网络流量捕获:

$ python3 fatt.py -i en0 --print_output --json_logging
192.168.1.10:59565 -> 192.168.1.3:80 [HTTP] hash=598c34a2838e82f9ec3175305f233b89 userAgent="Spotify/109600181 OSX/0 (MacBookPro14,3)"
192.168.1.10:59566 -> 13.237.44.5:22 [SSH] hassh=ec7378c1a92f5a8dde7e8b7a1ddf33d1 client=SSH-2.0-OpenSSH_7.9
13.237.44.5:22 -> 192.168.1.10:59566 [SSH] hasshS=3f0099d323fed5119bbfcca064478207 server=SSH-2.0-babeld-80573d3e
192.168.1.10:59584 -> 93.184.216.34:443 [TLS] ja3=e6573e91e6eb777c0933c5b8f97f10cd serverName=example.com
93.184.216.34:443 -> 192.168.1.10:59584 [TLS] ja3s=ae53107a2e47ea20c72ac44821a728bf
192.168.1.10:59588 -> 192.168.1.3:80 [HTTP] hash=598c34a2838e82f9ec3175305f233b89 userAgent="Spotify/109600181 OSX/0 (MacBookPro14,3)"
192.168.1.10:59601 -> 216.58.196.142:80 [HTTP] hash=d6662c018cd4169689ddf7c6c0f8ca1b userAgent="curl/7.54.0"
216.58.196.142:80 -> 192.168.1.10:59601 [HTTP] hash=c5241aca9a7c86f06f476592f5dda9a1 server=gws
192.168.1.10:54387 -> 216.58.203.99:443 [QUIC] UAID="Chrome/74.0.3729.169 Intel Mac OS X 10_14_5" SNI=clientservices.googleapis.com AEAD=AESG KEXS=C255

JSON 输出:

下载工具