InfraGuard v0.4.3 is a sophisticated command-and-control redirection proxy designed to protect red team infrastructure by validating inbound traffic against malleable C2 profiles and blocking unauthorized security probes.
Key Points
- Supports eight C2 frameworks, including Cobalt Strike, Mythic, Brute Ratel C4, Sliver, Havoc, Nighthawk, and PoshC2.
- Utilizes a scoring-based filter pipeline to detect and block scanners, bots, and sandboxes using JA3 fingerprinting and header analysis.
- Features automated infrastructure rotation, circuit breakers, and protocol failover to maintain operational resilience during engagements.
- Includes a web-based dashboard and Command Post for multi-instance aggregation, real-time request monitoring, and AI-assisted profile generation via Ollama.
- Integrates with SIEM platforms and provides automated threat intelligence updates from sources like abuse.ch and Spamhaus.