/** * JARM fingerprint signatures for server and C2 framework identification. * * JARM is an active TLS server fingerprinting method that sends 10 TLS Client Hello * packets with varying parameters and hashes the server responses into a 62-character * fingerprint. Different TLS implementations produce distinct JARM hashes, making it * effective for identifying C2 frameworks, web servers, and CDN infrastructure. * * References: * - https://github.com/salesforce/jarm * - https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a */ /** A known JARM fingerprint signature entry. */ export interface JarmSignature { /** The 62-character JARM hash value */ hash: string; /** Human-readable name of the identified software */ name: string; /** Classification category */ category: "c2" | "server" | "cdn" | "waf" | "other"; /** Confidence level for the identification (0.0 = low, 1.0 = certain) */ confidence: number; } export declare const JARM_SIGNATURES: JarmSignature[]; //# sourceMappingURL=jarm-signatures.d.ts.map