C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
-
Updated
Mar 18, 2026 - Python
C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
Client-side C2 beaconing detector -- Random Forest + Isolation Forest ML, jitter analysis, ThreatFox IOC lookup, ATT&CK technique mapping, no data leaves browser
AI-augmented threat detection sidecar for Pi-hole — heuristic DGA, NXDOMAIN, volume, and beacon detection on the query log
Real-time C2 Beacon Detection Platform using Zeek, PostgreSQL, FFT, Autocorrelation, Entropy Analysis, and Python for advanced network threat detection
Structural detection framework for deterministic non-periodic C2 scheduling — ceiling theorem proof, taxonomy, and five validated detectors.
🛰️ أثر — Offline network forensics workbench. BPF builder, statistical beacon detection, DGA scoring, JA3 reference, and a command forge for tshark/Zeek/nfdump/Arkime. Single file, air-gapped, zero telemetry.
Real-time C2 Beacon Detection System using FFT, Autocorrelation, Entropy Analysis, PostgreSQL, and Python for advanced network traffic analysis.
Standalone Flask demo of the BeaconButty network beacon detector. No Zeek/RITA/ClickHouse/Suricata required — pre-baked fixtures, deployable on any Pi in <5 min.
Detect C2 beacons in network traffic using Floquet spectral analysis from quantum chaos theory. Fast, 274KB Zig binary. Reads pcap, live capture, or OpenTelemetry JSONL.
Raspberry Pi network beacon detector — Zeek + RITA + ClickHouse on a Pi 5 NAT router.
Add a description, image, and links to the beacon-detection topic page so that developers can more easily learn about it.
To associate your repository with the beacon-detection topic, visit your repo's landing page and select "manage topics."