/** * Multi-layer C2 (Command & Control) framework detection profiles. * * Combines JARM TLS fingerprints, certificate anomalies, HTTP behavioral * patterns, and known IOC paths to identify C2 team-servers in the wild. * These profiles are used for proactive threat hunting — not exploitation. * * JARM hashes are sourced from public research; certificate and HTTP patterns * are derived from default/untuned framework configurations. * * References: * - https://github.com/salesforce/jarm * - https://michaelkoczwara.medium.com/cobalt-strike-c2-hunting-with-shodan-c448d501a6e2 * - https://blog.fox-it.com/2022/08/31/sliver-c2-hunting/ */ /** A multi-signal C2 framework detection profile. */ export interface C2Signature { /** Framework name */ name: string; /** JARM TLS fingerprint hash (62 chars) — may vary with malleable profiles */ jarm?: string; /** TLS certificate anomaly patterns for the default/out-of-box configuration */ certPatterns: { /** Common Name regex patterns (e.g., "localhost", random hex strings) */ cn?: string[]; /** Organization field regex patterns */ o?: string[]; /** Certificate validity window anomalies */ validity?: { minDays?: number; maxDays?: number; }; /** Whether the default cert is self-signed */ selfSigned?: boolean; /** Serial number format regex (some frameworks use predictable serials) */ serialPattern?: string; }; /** HTTP-layer behavioral indicators */ httpPatterns?: { /** Default URI paths served by the team-server or stager */ defaultPaths?: string[]; /** Specific response body size for a given status (e.g., 404 page with fixed length) */ responseSize?: { status: number; size: number; }; /** Characteristic HTTP headers on responses */ headers?: Record; }; /** Brief description of the framework and its primary use case */ description: string; } export declare const C2_SIGNATURES: C2Signature[]; //# sourceMappingURL=c2-signatures.d.ts.map