The ntop project released nDPI 6.0, an open-source deep-packet-inspection library derived from OpenDPI that classifies network protocols independently of port assignments. The update identifies more than 450 protocols and applications and 56 flow-risk categories, including encrypted and tunneled traffic.
Version 6.0 adds detection for slow HTTP denial-of-service techniques—Slowloris, Slow POST, and Slow GET—and expands JA4 TLS fingerprinting to improve encrypted-connection identification. It also introduces USDT tracing, recognizes mesh-network protocols and additional GitHub and Proton services, and improves parsing and handling of SSL/TLS, JSON, MsgPack, and other application-layer protocols.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
The ntop project released nDPI 6.0, an open-source deep-packet-inspection library derived from OpenDPI. The release adds detection for Slowloris, Slow POST, and Slow GET patterns, expanded JA4 TLS fingerprinting, USDT probes, and recognition for mesh protocols and GitHub and Proton services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
opennet.ru
Open sourceopennet.me
Open sourcentop.org
Open sourcentop.org
Open sourcedatatracker.ietf.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.