# c2detect

> c2detect — cognis-digital-c2detect. Use this tool when you need to identify and fingerprint C2 servers, such as Cobalt Strike, Sliver, Mythic, Havoc, and Brute Ratel, to detect potential threats and vulnerabilities. It solves problems related to security assessment and penetration testing by providing insights into command and control server infrastructure. The tool takes network traffic or server information as input and outputs a fingerprint of the C2 server, aiding in threat detection and incident response.

Canonical page: https://skillsregistry.net/skills/cognis-digital-c2detect  
JSON: https://api.skillsregistry.net/v1/skills/cognis-digital-c2detect

## Description

C2 server fingerprinter — Cobalt Strike, Sliver, Mythic, Havoc, Brute Ratel

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Updated:** 2026-09-24

## Source

- **Source listing:** [GitHub](https://github.com/cognis-digital/c2detect)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "cognis-digital-c2detect"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-c2detect` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-c2detect/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
