Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).
Schema: 817/817 pass. Framework-ID gate: 0 defects.
Detects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header mismatches in proxy logs and inspecting TLS certificate discrepancies with pyOpenSSL. Use when hunting for command-and-control traffic hidden behind legitimate CDN domains, or when investigating proxy/TLS logs for signs of domain fronting evasion.
cybersecurity
threat-hunting
domain-fronting
c2-detection
tls-inspection
proxy-logs
pyopenssl
threat-hunting
network-security
1.0
mahipal
Apache-2.0
Application Protocol Command Analysis
Network Isolation
Network Traffic Analysis
Client-server Payload Profiling
Network Traffic Community Deviation
DE.CM-01
DE.AE-02
DE.AE-07
ID.RA-05
T1046
T1057
T1082
T1083
T1071
Hunting for Domain Fronting C2 Traffic
Overview
Domain fronting (MITRE ATT&CK T1090.004) is a technique where attackers use different domain names in the TLS SNI field and the HTTP Host header to disguise C2 traffic behind legitimate CDN-hosted domains. This skill detects domain fronting by parsing proxy/web gateway logs for SNI-Host header mismatches, analyzing TLS certificates for CDN provider identification, flagging connections where the SNI points to a high-reputation domain but the Host header targets an attacker-controlled domain, and correlating with known CDN provider IP ranges.
When to Use
When investigating security incidents that require hunting for domain fronting c2 traffic
When building detection rules or threat hunting queries for this domain
When SOC analysts need structured procedures for this analysis type
When validating security monitoring coverage for related attack techniques
Prerequisites
Web proxy or secure web gateway logs with SNI and Host header fields
Python 3.8+ with pyOpenSSL and cryptography libraries
TLS inspection enabled on proxy for Host header visibility
CDN provider IP range lists (CloudFront, Azure CDN, Cloudflare)
Steps
Parse proxy logs for connections with both SNI and Host header fields
Compare SNI domain against HTTP Host header for mismatches
Extract TLS certificate Subject and SAN fields using pyOpenSSL
Identify CDN-hosted connections via certificate issuer and IP ranges
Flag high-confidence domain fronting where SNI and Host differ on CDN IPs
Score alerts based on domain reputation differential
Generate detection report with network flow context