Yes. Fidelis Network® profiles encrypted east-west traffic using metadata attributes extracted during session reconstruction: JA3 and JA3S fingerprints, certificate chain details, cipher suite selections, handshake timing metrics, and packet-size distributions. Machine learning models profile normal encrypted behavior per internal host and flag deviations consistent with C2 tunneling, rogue certificates, or beaconing, without decrypting payload content.
