tls-fingerprint-impersonation

Installation
SKILL.md

TLS Fingerprint Impersonation

Spoof TLS ClientHello parameters — cipher suites, key exchange groups, signature algorithms, and extension order — to match real browsers at the JA3/JA4 fingerprint level. Uses patched rustls to rebuild the TLS layer with browser-identical configurations. Bypasses TLS fingerprinting detection (Cloudflare, Akamai, F5) that flags non-browser TLS stacks. Supports 20 browser profiles including Chrome 100-142, Firefox 128-144, Safari iOS 18, and OkHttp 3-5 (Android).

When to Use

  • Target returns 403/blocked on curl/httpx even with correct User-Agent headers.
  • Cloudflare or Akamai is fingerprinting TLS ClientHello (JA3/JA4 mismatch with browser).
  • API probing requires mobile-app impersonation (OkHttp fingerprint for Android).
  • Need high-throughput HTTP requests that pass TLS fingerprint checks without running a full browser.
  • Target shows different behavior based on TLS fingerprint (mobile vs desktop endpoints).

Prerequisites

  • terminal with python3.
  • Python: pip install impit (wraps the Rust library via PyO3).
  • Or Node.js: npm install impit (native binding).
  • Or Rust: impit crate with patched dependencies in Cargo.toml.
Installs
11
GitHub Stars
1.2K
First Seen
Jul 9, 2026
tls-fingerprint-impersonation — uphiago/recon-skills