defense-network-detection
Installation
SKILL.md
Network detection (NSM)
When it applies
You have network visibility (a tap/SPAN, Zeek/Suricata logs, or NetFlow) and want to catch activity that endpoint tooling misses — especially C2 and exfil that look like ordinary connections.
Why it works
Malware still has to talk. Even encrypted C2 leaks behavioural tells the payload can't hide: regular call-home intervals, tiny requests with large responses, odd JA3/JA4 TLS fingerprints, and destinations no user browses to. Metadata beats payload inspection in a TLS world.