With the upcoming ratification of TLS 1.3, network based detection of malware within encrypted tunnels will become increasingly difficult pushing more and more focus on the endpoint. Stopping malicious payloads before they reach the endpoint on the wire can still be achieved without decryption by correlating multiple metadata-points around the flow together including a measurement of the sequence of packet lengths and times. With a rich set of information around the TLS header, traffic telemetry details and public destination reputation, a score can be formed and relied upon to detect certain malicious payloads on the wire without decryption.