Terminology Index

Glossary

2953 terms

Open concept maps
B
14
C
18

C2 Hunts

Threat hunts specifically aimed at finding command-and-control activity that detections missed, by searching telemetry for beaconing patterns, rare external connections, and other signs of an attacker's hidden communication channel.

Because attackers tune C2 to evade automated detection, hunters proactively look for it using techniques like frequency analysis of outbound connections and stacking of rare destinations. A successful C2 hunt uncovers an active foothold and feeds new detections back to the SOC.

Introduced in: Threat Hunting Fundamentals

Examples

  • Hunting for low-and-slow beaconing hidden among normal web traffic.
  • Stacking outbound connections to find rare, suspicious destinations.
  • Searching for jittered check-ins that evaded interval-based detection.