defense-network-detection

Installation
SKILL.md

Network detection (NSM)

When it applies

You have network visibility (a tap/SPAN, Zeek/Suricata logs, or NetFlow) and want to catch activity that endpoint tooling misses — especially C2 and exfil that look like ordinary connections.

Why it works

Malware still has to talk. Even encrypted C2 leaks behavioural tells the payload can't hide: regular call-home intervals, tiny requests with large responses, odd JA3/JA4 TLS fingerprints, and destinations no user browses to. Metadata beats payload inspection in a TLS world.

Installs
2
GitHub Stars
19
First Seen
7 days ago
defense-network-detection — noorqureshi/sploitagent