Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
BerrySentinel — Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis, heuristic scoring, C2 framework signature detection, beacon interval analysis, and an interactive curses-based TUI with process kill engine. | Kitploit
Tools/GitHubGitHub/dereeqw/berrysentinel
Defensive ToolsNetwork SecurityMalware AnalysisPenetration TestingCommand and ControlThreat IntelligenceIntrusion DetectionRed TeamingIncident ResponseAnomaly DetectionLog Analysis
GitHubdereeqw/berrysentinel

BerrySentinel

View Repository
13207 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis, heuristic scoring, C2 framework signature detection, beacon interval analysis, and an interactive curses-based TUI with process kill engine.

Share

🫐 Berry Sentinel

Real-time behavioral C2 (Command & Control) connection detector

Zero-signature · Bulletproof Collection · Deep Scan · Kill Engine

Python 3.8+ Platform License: MIT


What is it?

Berry Sentinel monitors all active network connections on your system and analyzes the behavior of the processes that generate them to detect malicious activity — without using antivirus signature databases or blocked IP lists.

It detects reverse shells, webshells, RATs, C2 beacons and frameworks like Meterpreter, Cobalt Strike, Sliver or Empire by observing how a process behaves: if a Python interpreter has its stdin connected to a remote socket, that is suspicious even if the IP is unknown.

╔══════════════════════════════════════════════════════════════════════════════════╗
║  BERRY SENTINEL v5.0 — C2 Behavioral Detector · Interactive TUI                                 ║
║  Connections: 38 │ Threats: 2 │ Signatures: 1 │ via proc/open+ss │ 12ms │ #47                       ║
╠══════════════════════════════════════════════════════════════════════════════════╣
║ ID  SEV      PTS   PID    PROC    REMOTE               STATE   SIGNATURES/TAGS                     ║
╠══════════════════════════════════════════════════════════════════════════════════╣
║  3  █CRITICAL  85   1337   bash    1.2.3.4:4444   ESTAB  ⚑Meterpreter SHELL→NET.                ║
║  7  ▲HIGH     52   2048   python3 5.6.7.8:8443   ESTAB  TLS-NOBR BCN(60s)                      ║
╚══════════════════════════════════════════════════════════════════════════════════╝

Features

  • Interactive TUI with curses: ↑↓ navigation, connection detail, integrated kill engine
  • Pure behavioral analysis: no AV signatures, no IP blacklists
  • Beacon detection: identifies C2 connections by their regular intervals (Cobalt Strike ~60s, Empire ~5s, etc.)
  • 14+ recognized C2 frameworks: Meterpreter, Cobalt Strike, Sliver, Empire, Havoc, Brute Ratel, Pupy, Merlin, Covenant, Mythic...
  • Deep scan (with root): analyzes process memory, RWX regions, environment variables, deleted executables from disk
  • Bulletproof collection: uses 5 parallel collection methods (/proc/net, ss, netstat, psutil, lsof) with automatic deduplication
  • Cross-platform: Linux, macOS, Windows, Android/Termux
  • JSON and log export: alerts in JSONL format compatible with jq, ELK, Splunk
  • Whitelist: ignore trusted IPs or networks by CIDR
  • Zero dependencies in basic mode (only stdlib); psutil optional for extra coverage

Installation

# Clonar el repositorio
git clone https://github.com/dereeqw/BerrySentinel.git
cd BerrySentinel 

# (Opcional pero recomendado) instalar psutil
pip install psutil

# Ejecutar
python3 BerrySentinel.py

Android / Termux

pkg install python
pip install psutil
python3 BerrySentinel.py --no-tui  # curses puede no estar disponible en Termux

Sin instalación (one-liner)

curl -O https://raw.githubusercontent.com/dereeqw/BerrySentinel/main/BerrySentinel.py
python3 BerrySentinel.py

Usage

python3 BerrySentinel.py [opciones]

Opciones:
  --all, -a           Incluir conexiones locales/loopback (además de remotas)
  --interval N, -i N  Refresco cada N segundos (default: 2, mín: 0.5)
  --log FILE, -l FILE Guardar alertas en archivo (formato JSONL)
  --json, -j          Exportar JSON completo al salir
  --whitelist LISTA   IPs o CIDRs a ignorar, separadas por coma
  --no-color          Sin colores ANSI (útil para pipes o logs)
  --verbose, -v       Mostrar todas las conexiones, no solo las sospechosas
  --top N, -t N       Máximo de filas en la tabla (default: 50)
  --diag, -d          Diagnóstico: muestra qué métodos de colección funcionan
  --no-tui            Modo legacy sin curses (scroll clásico, más portable)
  --version, -V       Mostrar versión y salir

Examples

# TUI interactivo — modo recomendado
python3 BerrySentinel.py

# Deep scan con root (accede a memoria de procesos)
sudo python3 BerrySentinel.py --all

# Guardar alertas y exportar JSON al terminar
python3 BerrySentinel.py --log /var/log/sentinel.log --json

# Ignorar red interna y refrescar cada 5 segundos
python3 BerrySentinel.py --whitelist 192.168.0.0/16,10.0.0.0/8 --interval 5

# Modo texto para usar en scripts o por SSH sin terminal interactiva
python3 BerrySentinel.py --no-tui --no-color | tee monitoring.txt

# Ver qué métodos de colección funcionan en el sistema actual
python3 BerrySentinel.py --diag --no-tui

# Solo alertas graves, actualización cada 10 segundos, guardar log
sudo python3 BerrySentinel.py --all --interval 10 --log sentinel.log --json

Interactive TUI Keys

KeyAction
↑ / ↓Navigate between connections
d / DView details panel of the selected connection
k / KKill process (asks for PID confirmation)
f / FCycle severity filter: ALL → MEDIUM → HIGH → CRITICAL
rForce immediate refresh
ESCClose detail panel or cancel operation
qQuit

Scoring System

Each connection receives a score from 0 to 100 based on detected indicators:

IndicatorPointsTag
stdin/stdout → socket+55FD→SOCK
Binary shell with remote connection+40SHELL→NET
Webshell (shell as child of Apache/Nginx)+35WEBSHELL
Bind shell on high port+35BIND-SHELL
Use of netcat/socat+35NETCAT
Redirection /dev/tcp or mkfifo+40PIPE-REDIR
Executable deleted from disk+25EXE-DEL!
Executable in /tmp or /dev/shm+15EXE-TMP
Beacon detected (cyclical connection)+25×confBCN(60s)
Meterpreter signature+55SIG:Meterpreter
Cobalt Strike signature+60SIG:CobaltStrike
Sliver signature+58SIG:Sliver
RWX memory regions+20RWX(N)
LD_PRELOAD or HISTFILE=/dev/null+10ENV:LD_PRELOAD
Script interpreter connected+25INTERP→NET
eval/exec in command line+18EVAL
Remote PowerShell (IEX, DownloadString)+30PS-REM

Severity by score:

ScoreSeverityColor
≥ 65CRITICAL🔴 Bright red
≥ 45HIGH🟠 Orange
≥ 25MEDIUM🟡 Yellow
≥ 8LOW🔵 Cyan
< 8INFO⚪ Gray

Detected C2 Frameworks

Berry Sentinel includes signatures for the following frameworks (evaluation by ports, process name, command line and beacon patterns):

FrameworkScore bonusKey indicators
Meterpreter+55Port 4444, ruby/msfconsole process
Cobalt Strike+60Port 50050, beacon ~60s, java process
Sliver+58Port 31337/8888, beacon ~60s
Empire+55Port 1234/7777, PowerShell -enc
Brute Ratel+62Port 2083, badger process
Havoc+58Port 40056, demon.x64/x86
Pupy RAT+52Port 9999, pupy.py
Merlin+54Port 8443, merlin-agent
Covenant+54Port 7443, GruntHTTP
PoshC2+52FComServer, ImplantCore
Mythic+56Port 7443, poseidon/apfell
QuasarRAT+50Port 4782-4785
NetcatShell+45socat exec bash, pty
DNS-C2+40Port 53, dnscat/iodine

Log Format (JSONL)

Each alert is recorded as an independent JSON line:

Download Tool