mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 16:40:24 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
65 lines
2.5 KiB
Markdown
65 lines
2.5 KiB
Markdown
---
|
|
name: hunting-for-domain-fronting-c2-traffic
|
|
description: Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate
|
|
discrepancies using pyOpenSSL for certificate inspection
|
|
domain: cybersecurity
|
|
subdomain: threat-hunting
|
|
tags:
|
|
- domain-fronting
|
|
- c2-detection
|
|
- tls-inspection
|
|
- proxy-logs
|
|
- pyopenssl
|
|
- threat-hunting
|
|
- network-security
|
|
version: '1.0'
|
|
author: mahipal
|
|
license: Apache-2.0
|
|
d3fend_techniques:
|
|
- Application Protocol Command Analysis
|
|
- Network Isolation
|
|
- Network Traffic Analysis
|
|
- Client-server Payload Profiling
|
|
- Network Traffic Community Deviation
|
|
nist_csf:
|
|
- DE.CM-01
|
|
- DE.AE-02
|
|
- DE.AE-07
|
|
- ID.RA-05
|
|
---
|
|
|
|
# Hunting for Domain Fronting C2 Traffic
|
|
|
|
## Overview
|
|
|
|
Domain fronting (MITRE ATT&CK T1090.004) is a technique where attackers use different domain names in the TLS SNI field and the HTTP Host header to disguise C2 traffic behind legitimate CDN-hosted domains. This skill detects domain fronting by parsing proxy/web gateway logs for SNI-Host header mismatches, analyzing TLS certificates for CDN provider identification, flagging connections where the SNI points to a high-reputation domain but the Host header targets an attacker-controlled domain, and correlating with known CDN provider IP ranges.
|
|
|
|
|
|
## When to Use
|
|
|
|
- When investigating security incidents that require hunting for domain fronting c2 traffic
|
|
- When building detection rules or threat hunting queries for this domain
|
|
- When SOC analysts need structured procedures for this analysis type
|
|
- When validating security monitoring coverage for related attack techniques
|
|
|
|
## Prerequisites
|
|
|
|
- Web proxy or secure web gateway logs with SNI and Host header fields
|
|
- Python 3.8+ with pyOpenSSL and cryptography libraries
|
|
- TLS inspection enabled on proxy for Host header visibility
|
|
- CDN provider IP range lists (CloudFront, Azure CDN, Cloudflare)
|
|
|
|
## Steps
|
|
|
|
1. Parse proxy logs for connections with both SNI and Host header fields
|
|
2. Compare SNI domain against HTTP Host header for mismatches
|
|
3. Extract TLS certificate Subject and SAN fields using pyOpenSSL
|
|
4. Identify CDN-hosted connections via certificate issuer and IP ranges
|
|
5. Flag high-confidence domain fronting where SNI and Host differ on CDN IPs
|
|
6. Score alerts based on domain reputation differential
|
|
7. Generate detection report with network flow context
|
|
|
|
## Expected Output
|
|
|
|
JSON report containing detected domain fronting indicators with SNI-Host pairs, certificate details, CDN provider identification, confidence scores, and MITRE ATT&CK technique mapping.
|