解析C2通信

原名:analyzing-command-and-control-communication

分析通过 HTTP、HTTPS、DNS 及自定义协议进行的恶意软件 C2 通信。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-25
TRACE 评分
4 / 5

内容概览

- Reverse engineering a malware sample has revealed network communication that needs protocol analysis - Building network-level detection signatures for a specific C2 framework (Cobalt Strike, Metasploit, Sliver) - Mapping C2 infrastructure including primary servers, fallback domains, and dead drops - Analyzing encrypted or encoded C2 traffic to understand the command set and data format - Attributing malware to a threat actor based on C2 infrastructure patterns and tooling Do not use for general network anomaly detection; this is specifically for understanding known or suspected C2 protocols from malware analysis. - PCAP capture of malware network traffic (from sandbox, network tap, or full packet capture) - Wireshark/tshark for packet-level analysis - Reverse engineering tools (Ghidra, dnSpy) for understanding C2 code in the malware binary - Python 3.8+ with scapy, dpkt, and requests f…

查看 SKILL 详情