finch

Fingerprint-aware TLS reverse proxy. Use Finch to outsmart bad traffic, collect client fingerprints (JA3, JA4 +QUIC, JA4H, HTTP/2) and act on them: block, reroute, tarpit, or deceive in real time.

Not yet testedsource: GitHubGoApache-2.0commit db48717b4888

Go, Apache-2.0 licensed. The project labels itself: deception, fingerprint, fingerprinting, go, honeypot, ja3, ja4 and reverse proxy.

finch has not been verified yet.

Measured by Argusic on a fresh machine every time. Every number links to its evidence.

At a glance

verdict
Not yet tested
Argusic Score
not scored yet
recorded runs
0
last tested
-
stars
307
forks
21
open issues
2
watchers
3
size
3 MB
created
last push

Subject data from GitHub, linked at the top of this page, refreshed . Test data by Argusic (CC BY 4.0); every number links to a run page with the full log, the recording, and their sha256 hashes.

Also tested, in the same area

Every one of these was installed and run by Argusic on a clean machine. Nothing appears here that was not tested.

Run history

No recorded runs.

Topics (from GitHub)

deceptionfingerprintfingerprintinggohoneypotja3ja4reverse-proxysecuritysecurity-tools

Embed the badge

Markdown for the project README. It links back here; terms on the terms page.

[![Tested by Argusic](https://argusic.com/badge/finch.svg)](https://argusic.com/subject/finch)

Questions

Does finch run?
finch has not been fully verified yet. No recorded run has produced a verdict yet.
How did Argusic test finch?
On a fresh, disposable machine, with every command recorded. 0 attempts are recorded, and the full method is on the methodology page.
Where is the evidence for finch?
All 0 recorded runs are on this page, each linking to its full log and terminal recording, stored with a sha256 fingerprint so it cannot be quietly altered.

Discussion