Terminology Index
Glossary
2953 terms
B14
C18
C2 Hunts
Threat hunts specifically aimed at finding command-and-control activity that detections missed, by searching telemetry for beaconing patterns, rare external connections, and other signs of an attacker's hidden communication channel.
Because attackers tune C2 to evade automated detection, hunters proactively look for it using techniques like frequency analysis of outbound connections and stacking of rare destinations. A successful C2 hunt uncovers an active foothold and feeds new detections back to the SOC.
Introduced in: Threat Hunting Fundamentals
Examples
- Hunting for low-and-slow beaconing hidden among normal web traffic.
- Stacking outbound connections to find rare, suspicious destinations.
- Searching for jittered check-ins that evaded interval-based detection.
