Sign inSign up

jonaslejon/polarproxy

By jonaslejon

•Updated over 6 years ago

PolarProxy is a transparent SSL/TLS proxy created for incident responders and malware researchers

Image
0

2.5K

jonaslejon/polarproxy repository overview

PolarProxy is a transparent SSL/TLS proxy created for incident responders and malware researchers. PolarProxy is primarily designed to intercept and decrypt TLS encrypted traffic from malware. PolarProxy decrypts and re-encrypts TLS traffic, while also saving the decrypted traffic in a PCAP file that can be loaded into Wireshark or an intrusion detection system (IDS).

⁠Usage

To download and run this container use the following command:

  • docker run -it --rm jonaslejon/polarproxy -v /pcap:/pcap -p 10080:10080 -p 10443:10443

The above command will do the following:

  • Listen and expose port 100800 for installing the root certificate on clients. You manually need to install the certificate
  • Listen on port 10443 for TLS inspection
  • Write pcap files to /pcap/polarproxy.pcap

Command running as following: /home/polarproxy/PolarProxy -v -p 10443,80,443 -w /pcap/polarproxy.pcap --certhttp 10080

Important: You need to redirect the traffic using iptables to the container on port 10443. For this usage please view [https://polarproxy.com⁠]

Tag summary

Content type

Image

Digest

Size

76.9 MB

Last updated

over 6 years ago

docker pull jonaslejon/polarproxy