跳到主要内容
知仓学习社ZHICANG

hunting-for-command-and-control-beaconing

Detect C2 beaconing patterns in network traffic using frequency analysis,

读文件写文件无严重或高危命中mukul975/Anthropic-Cybersecurity-Skills

它会碰到什么

扫了多少8 个文本文件,47 KB
它会碰到什么读文件写文件
命中总数9 处
命中统计严重 0 · 高 0 · 中 9 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Hunting for Command and Control Beaconing

When to Use

  • When proactively hunting for compromised systems in the network
  • After threat intel indicates C2 frameworks targeting your industry
  • When investigating periodic outbound connections to suspicious domains
  • During incident response to identify active C2 channels
  • When DNS query logs show unusual patterns to specific domains

Prerequisites

  • Network proxy/firewall logs with full URL and timing data
  • DNS query logs (passive DNS, DNS server logs, or Sysmon Event ID 22)
  • Zeek/Bro network connection logs or NetFlow data
  • SIEM with statistical analysis capabilities (Splunk, Elastic)
  • Threat intelligence feeds for domain/IP reputation

Workflow

  1. Identify Beaconing Characteristics: Define what constitutes beaconing (regular intervals, small payload sizes, consistent destinations, jitter patterns).
  2. Collect Network Telemetry: Aggregate proxy logs, DNS queries, and connection metadata for analysis.
  3. Apply Frequency Analysis: Identify connections with regular intervals using statistical methods (standard deviation, coefficient of variation).
  4. Filter Known-Good Traffic: Exclude legitimate periodic traffic (Windows Update, AV updates, heartbeat services, NTP).
  5. Analyze Domain/IP Reputation: Check identified beaconing destinations against threat intel, WHOIS data, and certificate transparency logs.
  6. Investigate Endpoint Context: Correlate beaconing activity with process creation, user context, and file system changes on source endpoints.
  7. Confirm and Respond: Validate C2 activity, block communication, and initiate incident response.

Key Concepts

| Concept | Description |

|---------|-------------|

| T1071 | Application Layer Protocol (HTTP/HTTPS/DNS C2) |

| T1071.001 | Web Protocols (HTTP/S beaconing) |

| T1071.004 | DNS (DNS tunneling C2) |

| T1573 | Encrypted Channel |

| T1572 | Protocol Tunneling |

| T1568 | Dynamic Resolution (DGA, fast-flux) |

| T1132 | Data Encoding in C2 |

| T1095 | Non-Application Layer Protocol |

| Beacon Interval | Time between C2 check-ins |

| Jitter | Random variation in beacon interval |

| DGA | Domain Generation Algorithm |

| Fast-Flux | Rapidly changing DNS resolution |

Tools & Systems

| Tool | Purpose |

|------|---------|

| RITA (Real Intelligence Threat Analytics) | Automated beacon detection in Zeek logs |

| Splunk | Statistical beacon analysis with SPL |

| Elastic Security | ML-based anomaly detection for beaconing |

| Zeek/Bro | Network connection metadata collection |

| Suricata | Network IDS with JA3/JA4 fingerprinting |

| VirusTotal | Domain and IP reputation checking |

| PassiveDNS | Historical DNS resolution data |

| Flare | C2 profile detection |

Common Scenarios

  1. Cobalt Strike Beacon: HTTP/HTTPS beaconing with configurable sleep time and jitter to malleable C2 profiles.
  2. DNS Tunneling C2: Data exfiltration and command receipt via encoded DNS TXT/CNAME queries to attacker-controlled domains.
  3. Sliver C2 over HTTPS: Modern C2 framework using HTTPS with configurable beacon intervals and domain fronting.
  4. DGA-based C2: Malware generating random domains daily, with adversary registering upcoming domains for C2.
  5. Legitimate Service Abuse: C2 over legitimate cloud services (Azure, AWS, Slack, Discord, Telegram).

Output Format

Hunt ID: TH-C2-[DATE]-[SEQ]
Source IP: [Internal IP]
Source Host: [Hostname]
Destination: [Domain/IP]
Protocol: [HTTP/HTTPS/DNS/Custom]
Beacon Interval: [Average seconds]
Jitter: [Percentage]
Connection Count: [Total connections]
Data Volume: [Bytes sent/received]
First Seen: [Timestamp]
Last Seen: [Timestamp]
Domain Age: [Days]
TI Match: [Yes/No - source]
Risk Level: [Critical/High/Medium/Low]

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。