C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
-
Updated
Mar 18, 2026 - Python
C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
Raspberry Pi network beacon detector — Zeek + RITA + ClickHouse on a Pi 5 NAT router.
Client-side C2 beaconing detector -- Random Forest + Isolation Forest ML, jitter analysis, ThreatFox IOC lookup, ATT&CK technique mapping, no data leaves browser
Structural detection framework for deterministic non-periodic C2 scheduling — ceiling theorem proof, taxonomy, and five validated detectors.
Real-time C2 Beacon Detection Platform using Zeek, PostgreSQL, FFT, Autocorrelation, Entropy Analysis, and Python for advanced network threat detection
Detect C2 beacons in network traffic using Floquet spectral analysis from quantum chaos theory. Fast, 274KB Zig binary. Reads pcap, live capture, or OpenTelemetry JSONL.
Real-time C2 Beacon Detection System using FFT, Autocorrelation, Entropy Analysis, PostgreSQL, and Python for advanced network traffic analysis.
🛰️ أثر — Offline network forensics workbench. BPF builder, statistical beacon detection, DGA scoring, JA3 reference, and a command forge for tshark/Zeek/nfdump/Arkime. Single file, air-gapped, zero telemetry.
AI-augmented threat detection sidecar for Pi-hole — heuristic DGA, NXDOMAIN, volume, and beacon detection on the query log
Zeek 8.2.1 and RITA v5.1.2 beacon hunt on a live SSLoad plus Cobalt Strike PCAP. 17 structured logs, beacon score 0.504 at 477s intervals, 6 MITRE ATT&CK techniques, 2 Sigma rules.
Standalone Flask demo of the BeaconButty network beacon detector. No Zeek/RITA/ClickHouse/Suricata required — pre-baked fixtures, deployable on any Pi in <5 min.
To associate your repository with the beacon-detection topic, visit your repo's landing page and select "manage topics."