# First orig\_h packet after 3 way handshake

**URL:** <https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241>\
**Category:** Zeek\
**Created:** [July 13, 2016, 10:36pm UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241 "2016-07-13T22:36:16Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ben\_Mixon-Baca](https://avatars.discourse-cdn.com/v4/letter/b/f9ae1b/32.png) [@Ben\_Mixon-Baca](https://community.zeek.org/u/Ben_Mixon-Baca)\
**Post date:** [July 13, 2016, 10:36pm UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241/1 "2016-07-13T22:36:16Z")

</div>

Does Bro have an event that will get fired for the first packet after  
the tcp 3-way handshake, or is there a way to get at that easily or does  
it require a lot of state to be maintained in the script?

I am trying to get at this first packet following the 3 way handshake  
because that is where the client hello in the ssl handshake should be.

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin\_S](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Azoff\_Justin\_S](https://community.zeek.org/u/Azoff_Justin_S)\
**Post date:** [July 13, 2016, 10:58pm UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241/2 "2016-07-13T22:58:32Z")

</div>

Can you use the ssl\_client\_hello event?

event ssl\_client\_hello(c: connection, version: count, possible\_ts: time, client\_random: string, session\_id: string, ciphers: index\_vec)

---

<div class="post-metadata">

**Author:** ![Ben\_Mixon-Baca](https://avatars.discourse-cdn.com/v4/letter/b/f9ae1b/32.png) [@Ben\_Mixon-Baca](https://community.zeek.org/u/Ben_Mixon-Baca)\
**Post date:** [July 13, 2016, 11:04pm UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241/3 "2016-07-13T23:04:05Z")

</div>

Unfortunately for what I am doing, I cannot.

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [July 14, 2016, 12:17am UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241/4 "2016-07-14T00:17:08Z")

</div>

Out of curiosity - what are you trying to do?

(I am always curious what people try to get from the SSL handshake that we do not parse out yet...)

Johanna

---

<div class="post-metadata">

**Author:** ![Ben\_Mixon-Baca](https://avatars.discourse-cdn.com/v4/letter/b/f9ae1b/32.png) [@Ben\_Mixon-Baca](https://community.zeek.org/u/Ben_Mixon-Baca)\
**Post date:** [July 14, 2016, 5:26pm UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241/5 "2016-07-14T17:26:33Z")

</div>

I'm looking at Tor+obfs4. Normally, everything parsed out using the  
events in the SSL module would be perfect but since the handshake is  
obfuscated, none of those events fire. I was trying to look at the  
packet that \_should\_ be the client hello in order to see if there is  
anything regular about that particular payload.

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [July 14, 2016, 5:30pm UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241/6 "2016-07-14T17:30:37Z")

</div>

Oh, interesting.

You should be able to use the new\_packet/packet\_contents events and add some counter to the connection record to let you count at which place in the handshake you are.

But - these are very expensive events, so you might get into problems when trying to run this on a link that has any real volume on it.

Johanna

---

<div class="post-metadata">

**Author:** ![johanna](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@johanna](https://community.zeek.org/u/johanna)\
**Post date:** [July 14, 2016, 5:31pm UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241/7 "2016-07-14T17:31:39Z")

</div>

Actually, thinking a bit more about it - tcp\_packet might be the best event for this.

---

<div class="post-metadata">

**Author:** ![Ben\_Mixon-Baca](https://avatars.discourse-cdn.com/v4/letter/b/f9ae1b/32.png) [@Ben\_Mixon-Baca](https://community.zeek.org/u/Ben_Mixon-Baca)\
**Post date:** [July 14, 2016, 5:39pm UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241/8 "2016-07-14T17:39:34Z")

</div>

Cool, thanks Johanna! I had started to use the tcp\_packet event but was  
concerned about the amount of state I would need to keep, I hadn't even  
thought to add to the connection record, thanks!

Fortunately, all of the analysis I am doing is on pcaps so I don't need  
to worry about running my script on live traffic.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/first-orig-h-packet-after-3-way-handshake/4241/9 "2022-05-06T15:43:50Z")

</div>


