hunting-for-cobalt-strike-beacons
mukul975/Anthropic-Cybersecurity-Skills
This skill provides comprehensive methods to detect Cobalt Strike beacon command-and-control (C2) traffic. It uses advanced network forensics techniques, including analyzing default TLS certificates (e.g., serial 8BB00EE), JA3/JA3S fingerprints, HTTP malleable profiles, and beacon interval jitter, leveraging Zeek logs, Suricata rules, and Python PCAP analysis. It is essential for threat hunters and SOC analysts investigating sophisticated C2 communications.