[Bro] Detect tor (j. clark)

John Clark jwclark at ucar.edu
Wed Feb 22 12:08:51 PST 2017


I did some general research into this about a year ago and discovered
that the Cert used to encrypt tor changes about every half hour.  So if
you can detect repeated changes in the cert with a particular IP it
might be a good IoC.


More information about the Bro mailing list