consider using [JA3](https://github.com/salesforce/ja3) to further distinguish client TLS libraries and their configurations. this would help detect weaknesses when a client is reaching out to the same base domain but with differently configured libraries.