cognis-digital/c2detect

Scan TLS/network telemetry for known C2-framework fingerprints (Cobalt Strike, Sliver, Mythic, Havoc, Brute Ratel, …). Defensive triage only.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 4, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: cognis-digital/c2detect@cc494a3b889ebf58d5f2613a7a365d3755574f1e # whitepaper-v1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathFile or directory of observation/telemetry to scan.no.
formatOutput format: table | json | sarif | html | badge.nosarif
fail-onFail the step if a match at/above this severity is found (critical|high|medium|low|info). Empty = never fail on severity.nohigh
thresholdMinimum confidence (0-100) to report a match.no35
outputWrite the report to this file (in addition to stdout).noc2detect-report.sarif
comment-prIf 'true' and run on a pull_request, post a findings comment via gh api.notrue
namedescription
findingsNumber of C2 indicators found.
badgeshields.io endpoint JSON for a status badge.