C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
-
Updated
Mar 18, 2026 - Python
C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
Client-side C2 beaconing detector -- Random Forest + Isolation Forest ML, jitter analysis, ThreatFox IOC lookup, ATT&CK technique mapping, no data leaves browser
AI-augmented threat detection sidecar for Pi-hole — heuristic DGA, NXDOMAIN, volume, and beacon detection on the query log
Real-time C2 Beacon Detection Platform using Zeek, PostgreSQL, FFT, Autocorrelation, Entropy Analysis, and Python for advanced network threat detection
Structural detection framework for deterministic non-periodic C2 scheduling — ceiling theorem proof, taxonomy, and five validated detectors.
Detect C2 beacons in network traffic using Floquet spectral analysis from quantum chaos theory. Fast, 274KB Zig binary. Reads pcap, live capture, or OpenTelemetry JSONL.
Real-time C2 Beacon Detection System using FFT, Autocorrelation, Entropy Analysis, PostgreSQL, and Python for advanced network traffic analysis.
🛰️ أثر — Offline network forensics workbench. BPF builder, statistical beacon detection, DGA scoring, JA3 reference, and a command forge for tshark/Zeek/nfdump/Arkime. Single file, air-gapped, zero telemetry.
Raspberry Pi network beacon detector — Zeek + RITA + ClickHouse on a Pi 5 NAT router.
Standalone Flask demo of the BeaconButty network beacon detector. No Zeek/RITA/ClickHouse/Suricata required — pre-baked fixtures, deployable on any Pi in <5 min.
Add a description, image, and links to the beacon-detection topic page so that developers can more easily learn about it.
To associate your repository with the beacon-detection topic, visit your repo's landing page and select "manage topics."