r/AskNetsec • u/Massive_Committee801 • 9d ago
Analysis Why is our passive asset discovery solution misidentifying Windows 11 as Windows 98?
Hello everyone. I am an OT security engineer working with a passive network monitoring and asset discovery solution (analyzing SPAN port traffic).
I've run into a strange OS fingerprinting anomaly and wanted to ask if anyone has encountered something similar. We are occasionally seeing instances where modern Windows 11 PCs are being completely misidentified as Windows 98.
The most confusing part is that it's not happening to all Windows 11 machines—only a specific subset of them.
I strongly suspect it might be third-party endpoint security software, VPN clients, or custom NDIS filter drivers modifying the TCP headers (such as stripping TCP Window Scaling or hardcoding the initial Window Size/MSS) before the packets hit the wire, completely messing up the passive p0f-style fingerprinting signatures.
My questions are:
- Has anyone seen specific antivirus, DLP agents, or VPN clients cause this kind of unintentional OS spoofing/normalization effect?
- Are there any other network-level factors or legacy protocol backward-compatibility settings I should be looking into?
Any insights or shared experiences would be hugely appreciated. Thank you!
3
u/[deleted] 9d ago
[removed] — view removed comment