Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.
| Protocol | t (TLS over TCP) |
| TLS version | 13 |
| SNI | d (domain) |
| Cipher count | 41 |
| Extension count | 13 |
| ALPN | h2 |
| Ciphers | 002f, 0032, 0033, 0035, 0038, 0039, 003c, 003d, 0040, 0067, 006a, 006b, 009c, 009d, 009e, 009f, 00a2, 00a3, 1301, 1302, 1303, 1304, c009, c00a, c013, c014, c023, c027, c02b, c02c, c02f, c030, c09c, c09d, c09e, c09f, c0ac, c0ad, cca8, cca9, ccaa |
| Extensions | 000a, 000b, 000d, 0016, 0017, 001b, 002b, 002d, 0031, 0033, ff01 |
| Signature algorithms | 0904, 0905, 0906, 0403, 0503, 0603, 0807, 0808, 0809, 080a, 080b, 0804, 0805, 0806, 0401, 0501, 0601, 0303, 0301, 0402, 0502, 0602, 0302 |
| JA4_r | t13d4113h2_002f,0032,0033,0035,0038,0039,003c,003d,0040,0067,006a,006b,009c,009d,009e,009f,00a2,00a3,1301,1302,1303,1304,c009,c00a,c013,c014,c023,c027,c02b,c02c,c02f,c030,c09c,c09d,c09e,c09f,c0ac,c0ad,cca8,cca9,ccaa_000a,000b,000d,0016,0017,001b,002b,002d,0031,0033,ff01_0904,0905,0906,0403,0503,0603,0807,0808,0809,080a,080b,0804,0805,0806,0401,0501,0601,0303,0301,0402,0502,0602,0302 |
| JA4_o (sample) | t13d4113h2_105127c7c643_6e0ef15f811f |
| JA4_ro (sample) | t13d4113h2_1302,1303,1301,1304,c02c,c030,cca9,cca8,c0ad,c02b,c02f,c0ac,c023,c027,c00a,c014,c009,c013,009d,c09d,009c,c09c,003d,003c,0035,002f,00a3,009f,ccaa,c09f,00a2,009e,c09e,006b,006a,0067,0040,0039,0038,0033,0032_ff01,0000,000b,000a,0010,0016,0017,0031,000d,002b,002d,0033,001b_0904,0905,0906,0403,0503,0603,0807,0808,0809,080a,080b,0804,0805,0806,0401,0501,0601,0303,0301,0402,0502,0602,0302 |
Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.
TLS ClientHello fingerprints observed from the same client via the beacon's correlation id on the other transport (e.g. this stack over TCP ↔ that stack over QUIC).