Skip to main content

P0f module

The P0f module performs passive OS fingerprinting by querying a local p0f daemon. This allows Rspamd to identify the operating system of the connecting client based on TCP/IP stack characteristics.

Prerequisites​

You need to have p0f v3 installed and running. The p0f daemon should be configured to listen on a Unix socket that Rspamd can connect to.

Example p0f startup:

p0f -i eth0 -s /var/run/p0f.sock

Configuration​

To enable the module, create /etc/rspamd/local.d/p0f.conf:

# Enable the module
enabled = true;

# Path to the unix socket that p0f listens on
socket = "/var/run/p0f.sock";

# Connection timeout
timeout = 5s;

# If defined, insert symbol with lookup results
symbol = "P0F";

# Patterns to match against results returned by p0f
# Symbol will be yielded on OS string, link type or distance matches
patterns = {
WINDOWS = "^Windows.*";
LINUX = "^Linux.*";
# DSL = "^link=DSL$";
# DISTANCE10 = "^distance=10$";
}

# Cache lifetime in seconds (default - 2 hours)
expire = 7200;

# Cache key prefix for Redis
prefix = "p0f";

Configuration options​

OptionDefaultDescription
enabledfalseEnable the p0f module
socketrequiredPath to the p0f Unix socket
timeout5sConnection timeout
symbolP0FSymbol to insert with OS fingerprint results
symbol_failP0F_FAILSymbol inserted when the p0f scan fails
patterns{}Map of symbol names to regex patterns for matching p0f results
message${SCANNER}: fingerprint matched: "${VIRUS}"Log/result message template on a match
expire7200Cache lifetime in seconds
prefixp0fRedis cache key prefix

Pattern matching​

The patterns option allows you to define custom symbols that fire when the p0f result matches a specific pattern. Patterns can match against:

  • Operating system name (e.g., Windows, Linux)
  • Link type, prefixed with link= (e.g., ^link=DSL$, ^link=Ethernet$)
  • Network distance, prefixed with distance= (e.g., ^distance=10$)

Symbols​

The module registers the following symbols:

  • P0F_CHECK - callback symbol (internal)
  • P0F - virtual symbol containing OS fingerprint (if symbol is set)
  • P0F_FAIL - virtual symbol set when the p0f scan fails (configurable via symbol_fail)
  • Custom pattern symbols as defined in patterns configuration

Redis caching​

If Redis is configured globally or for this module, p0f results are cached to avoid repeated lookups for the same IP address.