C2 Hunts
Threat hunts specifically aimed at finding command-and-control activity that detections missed, by searching telemetry for beaconing patterns, rare external connections, and other signs of an attacker's hidden communication channel.
Concept Neighborhood
Explore this concept’s connections in the groups below.
Start here
Hunt Hypothesis
The foundation C2 Hunts builds on, worth understanding first.
Hunt HypothesisStart here
A specific, testable statement of what malicious activity might be present and how it would show up in data, that drives a threat hunt, giving it a clear question to investigate rather than aimless searching.
12
lessons
Beacons
The periodic check-ins a compromised host makes to an attacker's command-and-control server to receive instructions. Their regular, often-disguised pattern is a key signal defenders hunt for to find hidden footholds.
1
lesson
Related Lessons
1 lesson covers this conceptSign in to open lesson content directly.
