CtrlK
BlogDocsLog inGet started
Tessl Logo

building-c2-redirector-infrastructure

Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxy_pass) and Apache (mod_rewrite), deriving filter rules from a Malleable C2 profile, layering Let's Encrypt TLS, and applying OPSEC controls like domain fronting and UA/geo filtering. Use when standing up red-team C2 that must survive blue-team triage or ensuring only profile-matching implant traffic reaches the hidden team server.

67

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-sequenced, largely executable workflow for building C2 redirectors with strong code examples and validation checkpoints. Its main weaknesses are some conceptual over-explanation, a vague OPSEC step, and a progressive-disclosure gap where bundle files are never linked and overlapping content is inlined instead.

Suggestions

Link the bundle files from the body: reference references/standards.md for the MITRE/NIST mapping table (and remove the inlined duplicate), references/api-reference.md for the directive reference, and scripts/agent.py for automated config generation and redirector validation.

Make the OPSEC step (7) actionable with concrete commands for geo filtering (e.g., an ipset/GeoIP iptables snippet) and a rotation mechanism, rather than comment-style 'consider...' guidance.

Trim the Overview's explanation of what a C2 redirector is — Claude already knows this — and keep only the skill-specific framing (dumb pipe vs filtering, profile lock-step).

DimensionReasoningScore

Conciseness

Mostly efficient and code-dense, but the Overview explains what a C2 redirector is ('an intermediary host that sits between victim implants and the real team server') and the inlined MITRE ATT&CK table duplicates references/standards.md, both of which could be trimmed.

3 / 5

Actionability

Steps 1–6 give copy-paste-ready commands (socat, iptables, nginx config, Apache mod_rewrite, cs2modrewrite, certbot), but step 7 (OPSEC) is hand-wavy — 'Consider CDN/domain fronting where supported' and 'rotate the redirector domain/IP on a schedule' appear as comments rather than executable commands.

4 / 5

Workflow Clarity

A clear 7-step sequence with per-step verification (`nginx -t`, `apache2ctl configtest`, curl checks) and a consolidated Validation Criteria checklist, though there is no explicit 'if validation fails, fix and retry' feedback loop embedded in the steps themselves.

4 / 5

Progressive Disclosure

Section structure is good (Overview, When to Use, Prerequisites, Workflow, Tools, Validation), but none of the three bundle files are referenced from the body — references/standards.md duplicates the inlined MITRE table, references/api-reference.md duplicates inlined directives, and scripts/agent.py (a generator/validator) is entirely orphaned.

3 / 5

Total

14

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A high-quality description that concisely states concrete capabilities and provides an explicit, scenario-based 'Use when' trigger in third-person voice. It is distinctive, comprehensive, and free of vague fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Build dumb-pipe and traffic-filtering C2 redirectors with nginx (proxy_pass) and Apache (mod_rewrite), deriving filter rules from a Malleable C2 profile, layering Let's Encrypt TLS, and applying OPSEC controls like domain fronting and UA/geo filtering' — giving comprehensive coverage of what the skill does.

5 / 5

Completeness

Explicitly answers both: what ('Build dumb-pipe and traffic-filtering C2 redirectors...') and when ('Use when standing up red-team C2 that must survive blue-team triage or ensuring only profile-matching implant traffic reaches the hidden team server'), with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural domain terms a red-team operator would actually say are present — 'red-team C2', 'blue-team triage', 'redirector', 'malleable C2 profile', 'domain fronting', 'OPSEC', 'nginx', 'mod_rewrite', 'Let's Encrypt' — with synonym coverage across the niche.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (C2 redirector infrastructure) with distinct triggers — 'malleable C2 profile', 'redirector', 'blue-team triage' — making conflict with unrelated skills minimal.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.