Command and Control
C2 channels allow adversaries to maintain communication with compromised systems, receive instructions, and exfiltrate data. Modern C2 traffic blends with legitimate HTTPS, DNS, and SaaS API traffic — making network-layer detection difficult without behavioural context.
Coverage
- Techniques covered
- 16
- Detection rules
- 29
- DNS-based rules
- 11
Threat context
How adversaries establish and maintain C2 channels
C2 infrastructure has evolved far beyond simple reverse shells. Modern C2 frameworks (Cobalt Strike, Sliver, Havoc) support HTTPS beacons with domain fronting, malleable C2 profiles that mimic legitimate CDN traffic, and peer-to-peer mesh architectures that are resilient to takedowns. DNS tunnelling remains effective because many environments permit outbound DNS on port 53 without inspection.
ManySignal detects C2 through three complementary approaches: network flow beaconing analysis (detecting periodic connection patterns), DNS query analytics (DGA detection and high-entropy subdomain identification), and threat intelligence enrichment (Recorded Future, VirusTotal) for known C2 infrastructure IOCs.
C2 techniques ManySignal detects
Application Layer Protocol
C2 traffic disguised as HTTP/S, DNS, or SMTP to blend with legitimate traffic.
Web Service
Using legitimate web services (Dropbox, GitHub, Slack) as C2 channels.
Dynamic Resolution
Domain generation algorithms (DGA) and fast-flux DNS for C2 resilience.
Encrypted Channel
TLS and custom encryption to hide C2 traffic from inspection.
Remote Access Software
Legitimate RMM tools (AnyDesk, TeamViewer, Cobalt Strike) repurposed for C2.
Command and Control: frequently asked questions
What is ATT&CK Command and Control (TA0011)?
C2 covers the techniques adversaries use to communicate with and control compromised systems from the internet. Modern C2 frameworks disguise traffic as legitimate web traffic, making detection reliant on behavioural analysis rather than signature matching.
How does ManySignal detect C2 beaconing?
C2 beaconing is characterised by regular, periodic outbound connections to a fixed or rotating set of external endpoints. ManySignal's network flow analysis detects periodic connection patterns with unusually consistent inter-arrival times — a signature of automated C2 check-ins rather than human browsing.
Can attackers hide C2 traffic in legitimate SaaS services?
Yes. C2 over legitimate services (T1102) uses platforms like Slack, Dropbox, and GitHub as intermediaries. ManySignal correlates unusual API patterns from these services with other threat indicators — a compromised host that suddenly starts making Slack API calls it has never made before is a detection signal.
Detect C2 channels before adversaries issue their first command
ManySignal correlates network flows, DNS telemetry, and threat intelligence to surface C2 beaconing within minutes of deployment.