precursor 0.2.3

Pre-protocol payload tagging, similarity clustering, and packet/firmware triage CLI.
1
2
3
4
{"tlsh":"lzjd:128:7444f380d9e8e27d137724032cc5bc12","similarity_hash":"lzjd:128:7444f380d9e8e27d137724032cc5bc12","tags":["squashfs_magic"],"protocol_label":"unknown","protocol_abstained":true,"protocol_confidence":0.11090354888959125,"protocol_candidates":[{"protocol":"unknown","score":0.11090354888959125,"evidence":["no protocol heuristics matched","similarity cluster boost from 3 neighbors"]}],"xxh3_64_sum":"b0ce40a09e1ccb47","tlsh_similarities":{"lzjd:128:c3d965665ff17f725c8aeec96473f9fa":56,"lzjd:128:a80e56e24b7cecb0e8ef66a66fbf63eb":85,"lzjd:92:080b140fc538c915e49113fab6b29809":82}}
{"tlsh":"lzjd:128:c3d965665ff17f725c8aeec96473f9fa","similarity_hash":"lzjd:128:c3d965665ff17f725c8aeec96473f9fa","tags":["cramfs_magic"],"protocol_label":"unknown","protocol_abstained":true,"protocol_confidence":0.08788898309344878,"protocol_candidates":[{"protocol":"unknown","score":0.08788898309344878,"evidence":["no protocol heuristics matched","similarity cluster boost from 2 neighbors"]}],"xxh3_64_sum":"42807c8d890da0ac","tlsh_similarities":{"lzjd:128:a80e56e24b7cecb0e8ef66a66fbf63eb":80,"lzjd:92:080b140fc538c915e49113fab6b29809":82}}
{"tlsh":"lzjd:128:a80e56e24b7cecb0e8ef66a66fbf63eb","similarity_hash":"lzjd:128:a80e56e24b7cecb0e8ef66a66fbf63eb","tags":["romfs_magic"],"protocol_label":"unknown","protocol_abstained":true,"protocol_confidence":0.055451774444795626,"protocol_candidates":[{"protocol":"unknown","score":0.055451774444795626,"evidence":["no protocol heuristics matched","similarity cluster boost from 1 neighbors"]}],"xxh3_64_sum":"ceb02867d7ec999c","tlsh_similarities":{"lzjd:92:080b140fc538c915e49113fab6b29809":91}}
{"tlsh":"lzjd:92:080b140fc538c915e49113fab6b29809","similarity_hash":"lzjd:92:080b140fc538c915e49113fab6b29809","tags":["gzip_magic"],"protocol_label":"compressed_binary","protocol_abstained":false,"protocol_confidence":0.88,"protocol_candidates":[{"protocol":"compressed_binary","score":0.88,"evidence":["gzip magic header"]}],"xxh3_64_sum":"28c8a22844c12a80","tlsh_similarities":{}}