C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
-
Updated
Mar 18, 2026 - Python
C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
Structural detection framework for deterministic non-periodic C2 scheduling — ceiling theorem proof, taxonomy, and five validated detectors.
AI-augmented threat detection sidecar for Pi-hole — heuristic DGA, NXDOMAIN, volume, and beacon detection on the query log
Real-time C2 Beacon Detection Platform using Zeek, PostgreSQL, FFT, Autocorrelation, Entropy Analysis, and Python for advanced network threat detection
Raspberry Pi network beacon detector — Zeek + RITA + ClickHouse on a Pi 5 NAT router.
Real-time C2 Beacon Detection System using FFT, Autocorrelation, Entropy Analysis, PostgreSQL, and Python for advanced network traffic analysis.
Add a description, image, and links to the beacon-detection topic page so that developers can more easily learn about it.
To associate your repository with the beacon-detection topic, visit your repo's landing page and select "manage topics."