Analyzing Command And Control Communication
Overview
Cybersecurity skill for analyzing command and control communication. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"analyzing command and control communication"
"Analyzes malware command-and-control (C2) communication protocols to understand "
Reverse engineering a malware sample has revealed network communication that needs protocol analysis
Building network-level detection signatures for a specific C2 framework (Cobalt Strike, Metasploit, Sliver)
Mapping C2 infrastructure including primary servers, fallback domains, and dead drops
Analyzing encrypted or encoded C2 traffic to understand the command set and data format
Attributing malware to a threat actor based on C2 infrastructure patterns and tooling
Do not use for general network anomaly detection; this is specifically for understanding known or suspected C2 protocols from malware analysis.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- PCAP capture of malware network traffic (from sandbox, network tap, or full packet capture)
- Wireshark/tshark for packet-level analysis
- Reverse engineering tools (Ghidra, dnSpy) for understanding C2 code in the malware binary
- Python 3.8+ with
scapy, dpkt, and requests for protocol analysis and replay
- Threat intelligence databases for C2 infrastructure correlation (VirusTotal, Shodan, Censys)
- JA3/JA3S fingerprint databases for TLS-based C2 identification
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Scope the Analysis — Define what command and control communication artifacts or data sources to examine and the investigation timeline.
- Preserve Evidence — Create forensic copies of relevant data. Maintain chain of custody documentation.
- Extract Key Indicators — Parse and extract relevant command and control communication data points from collected artifacts.
- Correlate Findings — Cross-reference extracted data with other sources (threat intel, logs, timelines).
- Build Timeline — Construct a chronological sequence of events related to command and control communication.
- Document Analysis — Write findings report with evidence, conclusions, and recommendations.
Tools
- Forensic Toolkit — Evidence collection and analysis
- Timeline Tools — Chronological event reconstruction
- Log Analysis Platform — Centralized log parsing and search
Process
- Scope — Define research questions, identify data sources, set time boundaries
- Gather — Collect data from primary sources, APIs, and public records
- Synthesize — Analyze findings, identify patterns, produce actionable report
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: analyzing-command-and-control-communication3description: Use when analyzing malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping.4license: Apache-2.05---67# Analyzing Command And Control Communication89## Overview1011Cybersecurity skill for analyzing command and control communication. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "analyzing command and control communication"16- "Analyzes malware command-and-control (C2) communication protocols to understand "171819- Reverse engineering a malware sample has revealed network communication that needs protocol analysis20- Building network-level detection signatures for a specific C2 framework (Cobalt Strike, Metasploit, Sliver)21- Mapping C2 infrastructure including primary servers, fallback domains, and dead drops22- Analyzing encrypted or encoded C2 traffic to understand the command set and data format23- Attributing malware to a threat actor based on C2 infrastructure patterns and tooling2425**Do not use** for general network anomaly detection; this is specifically for understanding known or suspected C2 protocols from malware analysis.262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- PCAP capture of malware network traffic (from sandbox, network tap, or full packet capture)38- Wireshark/tshark for packet-level analysis39- Reverse engineering tools (Ghidra, dnSpy) for understanding C2 code in the malware binary40- Python 3.8+ with `scapy`, `dpkt`, and `requests` for protocol analysis and replay41- Threat intelligence databases for C2 infrastructure correlation (VirusTotal, Shodan, Censys)42- JA3/JA3S fingerprint databases for TLS-based C2 identification4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Scope the Analysis** — Define what command and control communication artifacts or data sources to examine and the investigation timeline.622. **Preserve Evidence** — Create forensic copies of relevant data. Maintain chain of custody documentation.633. **Extract Key Indicators** — Parse and extract relevant command and control communication data points from collected artifacts.644. **Correlate Findings** — Cross-reference extracted data with other sources (threat intel, logs, timelines).655. **Build Timeline** — Construct a chronological sequence of events related to command and control communication.666. **Document Analysis** — Write findings report with evidence, conclusions, and recommendations.6768## Tools6970- **Forensic Toolkit** — Evidence collection and analysis71- **Timeline Tools** — Chronological event reconstruction72- **Log Analysis Platform** — Centralized log parsing and search737475## Process76771. **Scope** — Define research questions, identify data sources, set time boundaries781. **Gather** — Collect data from primary sources, APIs, and public records791. **Synthesize** — Analyze findings, identify patterns, produce actionable report8081## Verification8283- [ ] All command and control communication procedures executed completely and documented84- [ ] Findings validated against multiple data sources85- [ ] False positives identified and filtered86- [ ] Results documented with evidence and timestamps87- [ ] Recommendations provided with risk-based prioritization8889## Anti-Rationalization Table9091| Rationalization | Reality |92|---|---|93| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |94| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |95| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |