- Add validated mitre_attack frontmatter to all 754 skills (286 distinct
techniques), verified against MITRE ATT&CK v19.1 via the official
mitreattack-python library: 0 revoked, deprecated, or invalid IDs
- Curate precise per-skill technique IDs for forensics, malware-analysis,
threat-intel, and red-team skills (e.g. DCSync -> T1003.006,
Kerberoasting -> T1558.003, Pass-the-Ticket -> T1550.003)
- Reconcile v19.1 tactic restructuring: Defense Evasion split into
Stealth (TA0005) and Defense Impairment (TA0112); revoked T1562.*
family and T1070.001/.002 remapped to active equivalents (T1685.*)
- Normalize word-split tags across 35 skills (remove filename-derived
stopword tags, add semantic cybersecurity tags)
- Add api-reference.md for 3 skills that were missing it
- Update README ATT&CK section with accurate v19.1 tactic distribution
Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection
cybersecurity
threat-hunting
domain-fronting
c2-detection
tls-inspection
proxy-logs
pyopenssl
threat-hunting
network-security
1.0
mahipal
Apache-2.0
Application Protocol Command Analysis
Network Isolation
Network Traffic Analysis
Client-server Payload Profiling
Network Traffic Community Deviation
DE.CM-01
DE.AE-02
DE.AE-07
ID.RA-05
T1046
T1057
T1082
T1083
T1071
Hunting for Domain Fronting C2 Traffic
Overview
Domain fronting (MITRE ATT&CK T1090.004) is a technique where attackers use different domain names in the TLS SNI field and the HTTP Host header to disguise C2 traffic behind legitimate CDN-hosted domains. This skill detects domain fronting by parsing proxy/web gateway logs for SNI-Host header mismatches, analyzing TLS certificates for CDN provider identification, flagging connections where the SNI points to a high-reputation domain but the Host header targets an attacker-controlled domain, and correlating with known CDN provider IP ranges.
When to Use
When investigating security incidents that require hunting for domain fronting c2 traffic
When building detection rules or threat hunting queries for this domain
When SOC analysts need structured procedures for this analysis type
When validating security monitoring coverage for related attack techniques
Prerequisites
Web proxy or secure web gateway logs with SNI and Host header fields
Python 3.8+ with pyOpenSSL and cryptography libraries
TLS inspection enabled on proxy for Host header visibility
CDN provider IP range lists (CloudFront, Azure CDN, Cloudflare)
Steps
Parse proxy logs for connections with both SNI and Host header fields
Compare SNI domain against HTTP Host header for mismatches
Extract TLS certificate Subject and SAN fields using pyOpenSSL
Identify CDN-hosted connections via certificate issuer and IP ranges
Flag high-confidence domain fronting where SNI and Host differ on CDN IPs
Score alerts based on domain reputation differential
Generate detection report with network flow context