TheHive-Project / TheHive-Project/Cortex-Analyzers

[Bug] JA4_FoxIO analyzer doesn't work anymore

Open
#1,467 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
490
Forks
405
Avg merge
2d 43m
Merged PRs (30d)
8

Description

Describe the bug
The analyzer returns an error Expecting value: line 2 column 1 (char 1)

To Reproduce
Run JA4_FoxIO_1_0 Cortex analyzer with any supported data.

Expected behavior
The analyzer should work as advertised in https://strangebee.com/blog/ja4-fingerprinting-now-available-in-thehive/

Complementary information
Apparently, a public database at https://ja4db.com/api/read/ is no longer available.

Work environment

  • Client OS: N/A
  • Server OS: RedHat 8.10
  • Browse type and version: N/A
  • Cortex version: 4.0
  • Cortex Analyzer/Responder name: JA4_FoxIO
  • Cortex Analyzer/Responder version: 1.0

Possible solutions
The analyzer should either be removed or the code rewritten to support commercial access.

Additional context
N/A

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the JA4_FoxIO_1_0 analyzer entry point and reproduce the JSON parsing error with supported data. Check the ja4db.com/api/read/ dependency and its current response; done means an agreed path is documented and the analyzer either works with supported access or is removed.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.