Case 8827AF · Malware & intel · L3 Applied
C2 beaconing
Practise as: Explain it · Interview · Deep dive
Interview questionHow does command-and-control beaconing work, and how would you detect it on the network?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- An implant checks in to the C2 server at an interval (sleep) with jitter to fetch tasks and return output
- Common channels: HTTPS, DNS (TXT/A queries), and cloud services or CDNs to blend with normal traffic
- Detect periodicity: many connections to one host with similar interval and byte size (e.g. RITA, Zeek conn.log)
- Other signals: rare/new domains, odd JA3/JA4 TLS fingerprints, long or high-entropy DNS subdomains
- Cobalt Strike, Sliver and Havoc use malleable profiles to mimic legit traffic, so rely on behavior not strings
If the interviewer pushes back
- How does domain fronting or use of a trusted SaaS API change your detection strategy?
- Why does jitter make beacon detection harder, and how do statistical methods still catch it?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.