Damus
pistolero · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqvanh2g3ep7e99ajvg28dmundltwqgm9va7lex5unycpm585uht0q6xzkjz It's actually just dumping SNI on the right and a histogram from the nginx log files o...
Plan-A̵̛͈̬̥̿͋̓͛̕ profile picture
@pistolero @Guy Real time monitoring of TLS connections to a specific server then extracting the requested domain names (SNI) and enriching the output with a country lookup and a connection counter.
And there is more refinement to not overload CPU , to geo localisate new IP's
A display filter that further processes only packets containing the Server Name Indication (SNI) extension. This occurs during the TLS "Client Hello" handshake and reveals the domain name the client is trying to reach (e.g., git.freespeechextremist.com), even though the rest of the traffic is encrypted.
And, outputs the data in a simple two-column format: the Source IP and the Requested Domain Name.

Good string as WS or T-Shark operator.