M ManySignal
TA0011 ATT&CK Tactic

Command and Control

C2 channels allow adversaries to maintain communication with compromised systems, receive instructions, and exfiltrate data. Modern C2 traffic blends with legitimate HTTPS, DNS, and SaaS API traffic — making network-layer detection difficult without behavioural context.

Coverage

Techniques covered
16
Detection rules
29
DNS-based rules
11

Threat context

How adversaries establish and maintain C2 channels

C2 infrastructure has evolved far beyond simple reverse shells. Modern C2 frameworks (Cobalt Strike, Sliver, Havoc) support HTTPS beacons with domain fronting, malleable C2 profiles that mimic legitimate CDN traffic, and peer-to-peer mesh architectures that are resilient to takedowns. DNS tunnelling remains effective because many environments permit outbound DNS on port 53 without inspection.

ManySignal detects C2 through three complementary approaches: network flow beaconing analysis (detecting periodic connection patterns), DNS query analytics (DGA detection and high-entropy subdomain identification), and threat intelligence enrichment (Recorded Future, VirusTotal) for known C2 infrastructure IOCs.

Command and Control: frequently asked questions

What is ATT&CK Command and Control (TA0011)?

C2 covers the techniques adversaries use to communicate with and control compromised systems from the internet. Modern C2 frameworks disguise traffic as legitimate web traffic, making detection reliant on behavioural analysis rather than signature matching.

How does ManySignal detect C2 beaconing?

C2 beaconing is characterised by regular, periodic outbound connections to a fixed or rotating set of external endpoints. ManySignal's network flow analysis detects periodic connection patterns with unusually consistent inter-arrival times — a signature of automated C2 check-ins rather than human browsing.

Can attackers hide C2 traffic in legitimate SaaS services?

Yes. C2 over legitimate services (T1102) uses platforms like Slack, Dropbox, and GitHub as intermediaries. ManySignal correlates unusual API patterns from these services with other threat indicators — a compromised host that suddenly starts making Slack API calls it has never made before is a detection signal.

Detect C2 channels before adversaries issue their first command

ManySignal correlates network flows, DNS telemetry, and threat intelligence to surface C2 beaconing within minutes of deployment.