JA4 TLS client fingerprint
t13i131000_f57a46bbacb6_ab7e3b40a677
Seen 2026-02-19 to 2026-09-02 across the retained window.
5.4K
Source IPs
79
Networks
31
Countries
30.1K
Ports hit
288.7K
Events
68
IPs / network
Top networks
Countries
US 2.8KJP 517DE 502GB 501SG 478MY 446NL 22FR 22HK 22CN 13
What it requests
User agents claimed
Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)414 IPs166.7K
Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity1.9K IPs86.3K
curl/7.64.12.6K IPs15.6K
Microsoft WinRM Client114 IPs6.9K
Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)21 IPs2.0K
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.