Malware analysis CSIRT-led

Hfinger

Fingerprints malware HTTP requests from packet captures so analysts can compare traffic patterns and group activity associated with malware families.

By CERT Polska · Poland

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
CERT Polska
Recorded country
Poland
Product model
Open source
Deployment
Desktop/CLI
Software license
GPL-3.0
Upstream status
Experimental
Evidence class
CSIRT-led

What the sources establish

Origin note

CERT Polska publishes the Python/Tshark prototype as a standalone CLI and library.

Reported capabilities

  • HTTP request fingerprints
  • PCAP file or folder input
  • JSON output

Scope and limits

README calls this a working prototype/PoC and recommends isolated execution; repository API shows latest code push in May 2023, so ongoing maintenance is unverified.

Inspect the research evidence 4 source observations
  1. identity / origin / capabilities / deployment / maintenance

    README identifies malware HTTP request fingerprinting, PCAP CLI/PyPI usage, JSON output, CERT Polska repository and working-prototype status.

    Read source
  2. license

    Actual LICENSE text is GNU General Public License version 3.

    Read source
  3. maintenance

    GitHub API reports nonarchived repository but latest code push 16 May 2023; no current support inference is made.

    Read source
  4. country

    Verified organization identifies the Polish CERT team in Warsaw.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Documented EU funding

Connecting Europe Facility (CEF) · Advanced Threat Monitoring and Cooperation on the European and National Levels (AMCE)

Reference: 2018-PL-IA-0168

CERT Polska identifies Hfinger development in 2020 as AMCE work and expressly credits CEF co-financing. This is historical development funding.

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files