Botnet appears to be one of the significant threats to public cloud. They exploit new vulnerabilities(0-days) to take down a large part of the internet. As a cloud service provider, we built an automated 0-day monitoring solution to block the attack before botnet coming. In the early of 2019, we captured the world's first WebLogic RCE(CVE-2019-2725) 0-day payload and saved thousands of cloud server from the Muhstik botnet.This talk shows the technical details of how we capture 0-day attack payloads automatically without knowing any vulnerability details beforehand. We will walk through real cases to show model performance and give results of 0-day monitoring.