Network detection (NSM)
SkillMonitoring & opsDetect attacker activity in network telemetry, C2 beaconing, DNS tunnelling, data exfil, and lateral movement. Load for "detect C2", "find beaconing", "network monitoring / NSM", "suspicious traffic", or building Zeek/Suricata coverage. The defensive counterpart to the offensive network/pivoting skills.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Network detection (NSM) skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/defense/defense-network-detection/SKILL.md and read by ahel’s review.
When it applies
You have network visibility (a tap/SPAN, Zeek/Suricata logs, or NetFlow) and want to catch activity that endpoint tooling misses — especially C2 and exfil that look like ordinary connections.
Why it works
Malware still has to talk. Even encrypted C2 leaks behavioural tells the payload can't hide: regular call-home intervals, tiny requests with large responses, odd JA3/JA4 TLS fingerprints, and destinations no user browses to. Metadata beats payload inspection in a TLS world.
Method
- Beaconing: hunt for connections at regular intervals with low jitter to the same destination
(RITA's beacon analysis over Zeek
conn.log); score by consistency, not volume. - DNS tunnelling: high volume of TXT/NULL queries, long/high-entropy subdomains, one domain answering for everything — flag on query length + entropy + count per parent domain.
- Exfil: outbound bytes >> inbound to a rare destination, off-hours transfers, upload to unsanctioned cloud — baseline egress and alert on the outliers.
- Lateral movement: internal SMB/WinRM/RDP between hosts that never normally talk; new admin-share access — east-west, not just north-south.
- TLS fingerprinting: JA3/JA4(S) on the client hello — known-bad or rare fingerprints betray tooling even without decryption.
Gotchas
- Legit software beacons too (update checks, telemetry) — baseline and allowlist, or you drown.
- Encrypted payloads mean you detect patterns, not content; don't wait for a plaintext IOC.
- CDNs and cloud fronting make destination reputation noisy — combine signals, don't rely on one.
Verify success
A controlled C2/exfil reproduction (e.g. a lab beacon) is flagged by the beacon/entropy/egress logic, while normal baseline traffic stays quiet.
References
Zeek; Suricata; Active Countermeasures RITA; JA3/JA4; MITRE ATT&CK (Command and Control, Exfiltration).
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
defense-network-detection- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
More in Monitoring & ops
Skill · anthropics
More in Monitoring & opsagent-eval
Skill · affaan-m
More in Monitoring & opsarchitecture-decision-records
Skill · affaan-m
More in Monitoring & opsbabysit
Skill · thedotmack
More in Monitoring & opseng-runbook
Skill · nexu-io
More in Monitoring & opsweekly-update
Skill · nexu-io
More in Monitoring & ops