C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
-
Updated
Mar 18, 2026 - Python
C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
AI-augmented threat detection sidecar for Pi-hole — heuristic DGA, NXDOMAIN, volume, and beacon detection on the query log
Client-side C2 beaconing detector -- Random Forest + Isolation Forest ML, jitter analysis, ThreatFox IOC lookup, ATT&CK technique mapping, no data leaves browser
Structural detection framework for deterministic non-periodic C2 scheduling — ceiling theorem proof, taxonomy, and five validated detectors.
Add a description, image, and links to the beacon-detection topic page so that developers can more easily learn about it.
To associate your repository with the beacon-detection topic, visit your repo's landing page and select "manage topics."