hunting-for-cobalt-strike-beacons
mukul975/Anthropic-Cybersecurity-Skills
Detects Cobalt Strike beacon activity through TLS certificate serial checks, JA3/JA3S/JARM fingerprinting, HTTP profile matching, beacon jitter timing, and named pipe clues using Zeek, Suricata, and Python PCAP workflows.