detecting-command-and-control-over-dns
mukul975/Anthropic-Cybersecurity-Skills
Detects command-and-control communications tunneled over DNS by spotting tunneling tools, DGAs, encoded payloads, and beaconing patterns with entropy, statistical anomaly, ML classification, and Zeek/Suricata rules for SOC/SIEM workflows.