Threat

Command and Control (C2)

Command and Control (C2) is the channel attackers use to remotely control compromised systems and exfiltrate data.

Command and Control (C2) is the infrastructure attackers use to remotely control compromised systems. Via the C2 channel, they send commands and receive data.

How it works

After an infection, malware establishes a connection to an attacker's server. This usually happens from the inside out, because outbound connections are less strictly controlled. The communication is frequently disguised as normal web traffic using HTTPS or DNS. Some groups use legitimate services like cloud storage or chat platforms as a channel. Well-known C2 tools include Cobalt Strike or Sliver, originally developed for testing purposes.

A practical example

A server makes a short connection to the same unknown domain every 60 seconds. The data volume is small and consistent. NDR detects this regular pattern, known as beaconing. The SOC finds a hidden process on the server and isolates the system.

What to look out for

  • Monitor outbound connections, not just inbound ones.
  • Look for regular connections to new or uncommon domains.
  • DNS logs are an important source as many C2 channels use DNS.
  • Restrict server internet access to only what is necessary.
  • Block known C2 addresses from CTI sources, but do not rely on this alone.

Why it matters

Without a C2 channel, an attacker has limited control over the asset. Detecting and disrupting this channel early can stop an attack before major damage occurs. C2 detection is therefore a central part of NDR and EDR.

Typical mistakes

Servers are often allowed unrestricted internet access. This makes it easy for attackers to establish a channel. A second mistake is relying solely on blocklists. Attackers change their addresses faster than lists can be updated.

How we implement it

We detect C2 connections using NDR, DNS logs, and EDR. We isolate affected systems and block the remote endpoint within the mandate.

How ANOMAL implements this