discovered 03 Aug 2026
c2detect
→ View on GitHubc2detect is a tool designed to fingerprint command-and-control (C2) servers behind network beacons by analyzing telemetry data, specifically naming frameworks like Cobalt Strike and Sliver with a confidence score and matched indicators. Notable features include offline operation, the ability to generate Sigma and Suricata detection rules directly from detected signatures, and the fusion of indicators such as JA4, JARM, certificate, URI, and port for enhanced C2 identification. This tool serves as a passive defense mechanism for blue teams to detect known C2 infrastructure efficiently.