| name | hunting-for-command-and-control-beaconing |
| description | Detect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure. Use when detecting c2 beaconing patterns in network traffic using frequency analysis,. |
| domain | cybersecurity |
| tags | ["threat-hunting","mitre-attack","c2","beaconing","network-analysis","proactive-detection"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["File Metadata Consistency Validation","Certificate Analysis","Application Protocol Command Analysis","Content Format Conversion","File Content Analysis"] |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Hunting For Command And Control Beaconing
Overview
Cybersecurity skill for hunting for command and control beaconing. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"hunting for command and control beaconing"
-
"Detect C2 beaconing patterns in network traffic using frequency analysis, jitter"
-
When proactively hunting for compromised systems in the network
-
After threat intel indicates C2 frameworks targeting your industry
-
When investigating periodic outbound connections to suspicious domains
-
During incident response to identify active C2 channels
-
When DNS query logs show unusual patterns to specific domains
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Network proxy/firewall logs with full URL and timing data
- DNS query logs (passive DNS, DNS server logs, or Sysmon Event ID 22)
- Zeek/Bro network connection logs or NetFlow data
- SIEM with statistical analysis capabilities (Splunk, Elastic)
- Threat intelligence feeds for domain/IP reputation
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Detection Scope — Identify the specific techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.