| name | analyzing-command-and-control-communication |
| description | Use when analyzing malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping. |
| domain | cybersecurity |
| tags | ["malware","C2","command-and-control","beacon","protocol-analysis"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Analyzing Command And Control Communication
Overview
Cybersecurity skill for analyzing command and control communication. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"analyzing command and control communication"
-
"Analyzes malware command-and-control (C2) communication protocols to understand "
-
Reverse engineering a malware sample has revealed network communication that needs protocol analysis
-
Building network-level detection signatures for a specific C2 framework (Cobalt Strike, Metasploit, Sliver)
-
Mapping C2 infrastructure including primary servers, fallback domains, and dead drops
-
Analyzing encrypted or encoded C2 traffic to understand the command set and data format
-
Attributing malware to a threat actor based on C2 infrastructure patterns and tooling
Do not use for general network anomaly detection; this is specifically for understanding known or suspected C2 protocols from malware analysis.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- PCAP capture of malware network traffic (from sandbox, network tap, or full packet capture)
- Wireshark/tshark for packet-level analysis
- Reverse engineering tools (Ghidra, dnSpy) for understanding C2 code in the malware binary
- Python 3.8+ with
scapy, dpkt, and requests for protocol analysis and replay
- Threat intelligence databases for C2 infrastructure correlation (VirusTotal, Shodan, Censys)
- JA3/JA3S fingerprint databases for TLS-based C2 identification
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}