Open cardosec

Case 8827AF · Malware & intel · L3 Applied

C2 beaconing

Practise as: Explain it · Interview · Deep dive

Interview questionHow does command-and-control beaconing work, and how would you detect it on the network?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. An implant checks in to the C2 server at an interval (sleep) with jitter to fetch tasks and return output
  2. Common channels: HTTPS, DNS (TXT/A queries), and cloud services or CDNs to blend with normal traffic
  3. Detect periodicity: many connections to one host with similar interval and byte size (e.g. RITA, Zeek conn.log)
  4. Other signals: rare/new domains, odd JA3/JA4 TLS fingerprints, long or high-entropy DNS subdomains
  5. Cobalt Strike, Sliver and Havoc use malleable profiles to mimic legit traffic, so rely on behavior not strings

If the interviewer pushes back

  • How does domain fronting or use of a trusted SaaS API change your detection strategy?
  • Why does jitter make beacon detection harder, and how do statistical methods still catch it?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.