This document describes Hades, a Hadoop-based framework for detecting peer-to-peer botnets. Hades uses a distributed data collection architecture to gather data from multiple locations within a network. It then applies a host-aggregation approach, extracting statistical features per host from all network communications. These features are stored and analyzed using Hadoop ecosystem tools like HDFS, Hive, and Mahout. The features help distinguish botnets from benign P2P applications with high true positive rates and low false positive rates in testing.