{"repo":"cognis-digital/c2detect","free":true,"listed":false,"github":"https://github.com/cognis-digital/c2detect","clone":"git clone https://github.com/cognis-digital/c2detect.git","description":"C2 server fingerprinter — Cobalt Strike, Sliver, Mythic, Havoc, Brute Ratel","language":"Python","stars":32,"topics":["cognis-digital","cognis-neural-suite","red-team","c2detect","automation","cli","infosec","mcp-server","offensive-security","pentest"],"license":null,"category":"mcp-servers","readme_excerpt":"c2detect Fingerprint the C2 server behind the beacon. Point it at network telemetry and it names the command-and-control framework — Cobalt Strike, Sliver, Mythic, Havoc, Brute Ratel, and 11+ more — with a confidence score and the exact indicators that matched. -success) Blue-team / defensive: detect known C2 infrastructure from telemetry. Passive by default; the active probe is opt-in and authorization-gated. See it work Real, reproducible output — point it at a captured observation and it fingerprints the framework: It fuses JA4/JARM/certificate/URI/port indicators against a bundled signature DB — and can emit ready-to-deploy Sigma and Suricata rules from those same signatures ( c2detect rules ), so a detection goes straight into your SIEM/IDS. Why c2detect threat-intel IP lists JARM alone c2detect --- :---: :---: :---: Names the C2 framework (not just \"bad IP\") ✗ partial ✅ JA4 + JARM + cert + URI + port fusion ✗ ✗ ✅ Confidence score + matched indicators ✗ ✗ ✅ Generates Sigma / Suricata rules ✗ ✗ ✅ Campaign correlation (shared infrastructure) ✗ ✗ ✅ Runs offline, zero runtime deps varies ✓ ✅ Blocks above are real c2detect output — reproduce them from a clone. Usage — step by step c2detect is defensive C2-infrastructure triage: it scans telemetry/observation records against a bundled signature DB and flags beaconing, suspicious TLS fingerprints, and staging URIs. It is passive by default — scan / match / correlate / db / rules read input you provide and make no network calls ","default_branch":null,"files":null,"tree":[],"storefront":"/r/cognis-digital","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cognis-digital/c2detect/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}