Network detection (NSM)

SkillMonitoring & ops

Detect attacker activity in network telemetry, C2 beaconing, DNS tunnelling, data exfil, and lateral movement. Load for "detect C2", "find beaconing", "network monitoring / NSM", "suspicious traffic", or building Zeek/Suricata coverage. The defensive counterpart to the offensive network/pivoting skills.

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Network detection (NSM) skill

What this skill tells your AI

The instructions your AI receives, as published by noorqureshi/sploitagent in skills/defense/defense-network-detection/SKILL.md and read by ahel’s review.

When it applies

You have network visibility (a tap/SPAN, Zeek/Suricata logs, or NetFlow) and want to catch activity that endpoint tooling misses — especially C2 and exfil that look like ordinary connections.

Why it works

Malware still has to talk. Even encrypted C2 leaks behavioural tells the payload can't hide: regular call-home intervals, tiny requests with large responses, odd JA3/JA4 TLS fingerprints, and destinations no user browses to. Metadata beats payload inspection in a TLS world.

Method

  1. Beaconing: hunt for connections at regular intervals with low jitter to the same destination (RITA's beacon analysis over Zeek conn.log); score by consistency, not volume.
  2. DNS tunnelling: high volume of TXT/NULL queries, long/high-entropy subdomains, one domain answering for everything — flag on query length + entropy + count per parent domain.
  3. Exfil: outbound bytes >> inbound to a rare destination, off-hours transfers, upload to unsanctioned cloud — baseline egress and alert on the outliers.
  4. Lateral movement: internal SMB/WinRM/RDP between hosts that never normally talk; new admin-share access — east-west, not just north-south.
  5. TLS fingerprinting: JA3/JA4(S) on the client hello — known-bad or rare fingerprints betray tooling even without decryption.

Gotchas

  • Legit software beacons too (update checks, telemetry) — baseline and allowlist, or you drown.
  • Encrypted payloads mean you detect patterns, not content; don't wait for a plaintext IOC.
  • CDNs and cloud fronting make destination reputation noisy — combine signals, don't rely on one.

Verify success

A controlled C2/exfil reproduction (e.g. a lab beacon) is flagged by the beacon/entropy/egress logic, while normal baseline traffic stays quiet.

References

Zeek; Suricata; Active Countermeasures RITA; JA3/JA4; MITRE ATT&CK (Command and Control, Exfiltration).

Signals

GitHub stars
20
Forks
7
Last commit
Sep 2026
Advanced
Item type
skill
Key
defense-network-detection
Source
github.com/noorqureshi/sploitagent