| name | hunting-for-beaconing-with-frequency-analysis |
| description | Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks from compromised endpoints. Use when working with hunting for beaconing with frequency analysis. |
| domain | cybersecurity |
| tags | ["threat-hunting","beaconing","c2-detection","frequency-analysis","network-traffic","RITA","jitter-detection","mitre-t1071"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["File Metadata Consistency Validation","Certificate Analysis","Application Protocol Command Analysis","Content Format Conversion","File Content Analysis"] |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Hunting For Beaconing With Frequency Analysis
Overview
Cybersecurity skill for hunting for beaconing with frequency analysis. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"hunting for beaconing with frequency analysis"
-
"Identify command-and-control beaconing patterns in network traffic by applying s"
-
When proactively searching for compromised endpoints calling back to C2 infrastructure
-
After threat intelligence reports indicate active C2 frameworks targeting your sector
-
When network logs show periodic outbound connections to unfamiliar destinations
-
During purple team exercises validating C2 detection capabilities
-
When investigating a potential breach and need to identify active C2 channels
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Network proxy/firewall logs with timestamps and destination data (minimum 24 hours)
- Zeek conn.log, dns.log, and ssl.log or equivalent NetFlow/IPFIX data
- SIEM platform with statistical analysis capability (Splunk, Elastic, Microsoft Sentinel)
- RITA (Real Intelligence Threat Analytics) or AC-Hunter for automated beacon analysis
- Threat intelligence feeds for domain/IP reputation enrichment
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v IOC_PATTERNS.items()}