Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection
Installs into .claude/skills of the current project.
Are you the author of Cyber Hunting For Domain Fronting C2 Traffic?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/nexuslinkproductions-cyber-hunting-for-domain-fronting-c2-traffic)
---
name: cyber-hunting-for-domain-fronting-c2-traffic
description: "Detect domain fronting C2 traffic by analyzing SNI vs HTTP Host header mismatches in proxy logs and TLS certificate discrepancies using pyOpenSSL for certificate inspection"
hide: true
---
<!-- GENERATED:YURI-CODEX-SKILL-ADAPTER:v1 -->
# YURI skill adapter
Authoritative source: `.claude/skills/cyber-hunting-for-domain-fronting-c2-traffic/SKILL.md`
Authoritative source SHA-256: `e5c786d8eedfed6b97b34565ca921d21988ed8d13a926142768971daa1255787`
Source class: `cyber-armed`
Before acting, read the authoritative source file above completely from beginning to end. If the governed source is absent, run `node _SYSTEM/Scripts/skill-recall.mjs --show cyber-hunting-for-domain-fronting-c2-traffic` and read its complete verified output. Follow that source as the skill body; this adapter is a non-authoritative metadata-and-pointer projection.