docs

Fingerprint evasion

Make Hugin look like a real browser across TLS (JA3/JA4), HTTP/2 and the JavaScript environment, so a target that fingerprints non-browser clients still serves your tooling. (Pro)

Anti-bot services do not just read your User-Agent. They fingerprint the TLS handshake (JA3 and JA4 — the hash of how your client opens TLS), the HTTP/2 settings, and the JavaScript environment, then block or quietly serve fake content to anything that does not look like a real browser. Point a stock Rust or Python HTTP client at one of these targets and you get a 403, or a clean-looking page that is a decoy.

Hugin shows the target a convincing browser fingerprint across every layer at once, so a target that blocks non-browser TLS clients still serves your tooling.

What the target sees, and what Hugin shows it

Three layers, lined up so they agree with each other:

TLS handshake — JA3 / JA4

Hugin connects upstream with a real Chrome ClientHello, built on Chrome's own TLS stack: the same cipher order, GREASE values, randomised extension order (so your JA3 shifts per connection, exactly like current Chrome), key shares including the X25519MLKEM768 post-quantum group Chrome now ships, ALPN of h2 then http/1.1, OCSP stapling, certificate timestamps, and a TLS 1.2 floor. The JA3/JA4 the target computes is Chrome's, not a scripting library's. This is what gets you past Akamai, Cloudflare, Imperva, and DataDome TLS checks.

HTTP/2 fingerprint

The HTTP/2 SETTINGS, the connection window update, and the pseudo-header order match Chrome — the Akamai-format fingerprint 1:65536;2:0;3:1000;4:6291456;6:262144;8:1;9:1|15663105|0|m,a,s,p. A target that fingerprints your h2 frames reads Chrome.

Browser traits and JS environment

The Chrome 134 User-Agent and the full Sec-CH-UA client-hint set, plus the navigator, screen, font, and WebGL values a detection script reads inside the page — navigator.webdriver false, the right plugin and language list, a GPU renderer string that matches the operating system. For the Hugin Browser, these answer the JavaScript probes a bare automation tool fails.

The profile is cross-platform: macOS (Apple M1 through M4, or Intel), Windows (Nvidia, AMD, Intel GPUs), or Linux. A built-in consistency check refuses a fingerprint that contradicts itself — a macOS User-Agent with a Windows GPU, or a desktop profile reporting touch points — because that exact mismatch is what anti-bot scoring hunts for.

Pick a browser to imitate

The default profile is Chrome. You can also imitate Firefox, Safari, Safari on iOS, or Edge — each carries a genuine per-browser JA3/JA4, not a Chrome handshake wearing a Firefox User-Agent.

Where you turn it on

Evasion is not one global switch. You enable it on the surface you are driving.

Repeater

Toggle Browser TLS on a send, or set it as the default in proxy settings, then pick a profile. The request re-originates so the upstream handshake, HTTP/2, and User-Agent are the browser's, not Hugin's stock stack. Off by default — turn it on for engagements where TLS fingerprinting is in play.

Proxy upstream

The Proxy already sits in the middle of the connection (a man-in-the-middle, MITM), so it re-originates each upstream connection to the target with the Chrome ClientHello. Flows you drive through the Proxy — and the Scanner and Intruder runs that ride on them — inherit the browser handshake.

Browser automation

The Hugin Browser carries the full Chrome 134 JavaScript-environment fingerprint. Switch its TLS profile at runtime with the browser set_tls_profile action (chrome, firefox, safari, or default). See Browser automation.

FFuzzer and Crawler

Run them in Mullvad-browser mode to defeat TLS fingerprinting on targets that block raw clients. See FFuzzer and Crawler.

The in-browser set_tls_profile pivot is a guarded action. Hugin refuses it unless you set HUGIN_BROWSER_TLS_OVERRIDE=1, so you cannot change a live engagement's fingerprint by accident.

What it does not fake

HTTP/3. A browser-TLS send drops to HTTP/1.1 or HTTP/2 over the Chrome connector instead of HTTP/3, because Hugin does not yet reproduce Chrome's byte-exact QUIC fingerprint (the GREASE, transport parameters, and extension order a QUIC fingerprinter reads). If a target gates on a genuine Chrome QUIC handshake, that path stays honest rather than sending a tell-tale fake.

Tier

Browser integration — the Hugin Browser, the Mullvad/Firefox backend, the Chrome JavaScript-environment fingerprint, and the runtime TLS-profile pivot — is Pro. Repeater's Browser-TLS toggle ships with Repeater. Check your tier in Settings.

Evasion is for getting authorised testing past a defence, not for reaching systems you have no permission to touch. Keep it in scope and inside your engagement.

The opposite of recon Fingerprint

This page is about defeating a target that fingerprints you. Reading the target's own fingerprint — its servers, frameworks, languages, CDNs, and WAFs — runs the other direction: see Fingerprint.

Last updated 2026-06-17.