You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Running dockerized 4.8.0 version
Before enabling ja3 zkg two months ago, outputs of "rita show-useragents" and "useragents.html" from html-report matched.
Since ja3 zkg installation, "rita show-useragents" and "useragents.html" don't match at all.
useragents.html is filled with 1000 ja3 hashes all used 1 time while show-useragents only displays 819 occurences of 1 time use.
Hello, sorry for the confusion. The default sorting for the two displays is different. We prefer to display the agents in the order of least used to most used since anomalous useragents tend to be more interesting. However, the show-useragents command was developed before this preference was decided upon. In order to maintain compatibility with existing scripts, the default sorting for the show-useragents command was not updated to match the html-report.
The html-report outputs 1000 useragents in order of least used to most used. The show-useragents command will, by default, output 1000 useragents in order of most used to least used. I suspect the different sortings coupled with the limit of 1000 useragents is resulting in the differing numbers you are seeing.
In order to make the console output from show-useragents match the html report, please call it like so (assuming the dataset is named lastweek).
As a side note, you may pass --no-limit to obtain the full result set, however this will likely take additional computation time.
Each of these flags are documented and may be found by calling rita show-useragents --help.
Please let us know if the command above resolves the issue you are seeing. Thank you for writing in.
Thanks for the clarifications which make complete sense.
I wished there would be a way to get an automatic ja3 lookup since the output turns out useless and I'm getting this result only running rita on a small home network weekly. However, I don't think there is any publicly available ja3 DB.
I believe there might be ways to improve the usefulness of rita (html-report for) user agents. Maybe diff'ing datasets would highlight "more unique" ja3 or limiting the results to known malicious ja3 hashes only.
Given the verbosity introduced by ja3 hashes, I don't see a point in displaying them by count only. I know I'll get 1000 unique ja3 hashes which won't tell me anything relevant.
Using SIEM and doing statistical analysis on ja3 & ja3s can turn useful to highlight the bottom 100 combination along with associated domains.
So, unless you/anyone has better suggestions on how to use the ja3 hashes effectively in the scope of rita html-report, I'd rather stick to http user agents only.
Running dockerized 4.8.0 version
Before enabling ja3 zkg two months ago, outputs of "rita show-useragents" and "useragents.html" from html-report matched.
Since ja3 zkg installation, "rita show-useragents" and "useragents.html" don't match at all.
useragents.html is filled with 1000 ja3 hashes all used 1 time while show-useragents only displays 819 occurences of 1 time use.
Example:
rita show-user-agents lastweek output snip
HTML report output snip
Expectation is to have html-reports match exactly the show-X commands
The text was updated successfully, but these errors were encountered: