analyzing-command-and-control-communication

Featured

Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping.

AI & Automation 40 stars 10 forks Updated today MIT

Install

View on GitHub

Quality Score: 90/100

Stars 20%
54
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Analyzing Command-and-Control Communication ## When to Use - Reverse engineering a malware sample has revealed network communication that needs protocol analysis - Building network-level detection signatures for a specific C2 framework (Cobalt Strike, Metasploit, Sliver) - Mapping C2 infrastructure including primary servers, fallback domains, and dead drops - Analyzing encrypted or encoded C2 traffic to understand the command set and data format - Attributing malware to a threat actor based on C2 infrastructure patterns and tooling **Do not use** for general network anomaly detection; this is specifically for understanding known or suspected C2 protocols from malware analysis. ## Prerequisites - PCAP capture of malware network traffic (from sandbox, network tap, or full packet capture) - Wireshark/tshark for packet-level analysis - Reverse engineering tools (Ghidra, dnSpy) for understanding C2 code in the malware binary - Python 3.8+ with `scapy`, `dpkt`, and `requests` for protocol analysis and replay - Threat intelligence databases for C2 infrastructure correlation (VirusTotal, Shodan, Censys) - JA3/JA3S fingerprint databases for TLS-based C2 identification ## Workflow ### Step 1: Identify the C2 Channel Determine the protocol and transport used for C2 communication: ``` C2 Communication Channels: ━━━━━━━━━━━━━━━━━━━━━━━━━ HTTP/HTTPS: Most common; uses standard web traffic to blend in Indicators: Regular POST/GET requests, specific URI pattern...

Details

Author
26zl
Repository
26zl/cybersec-toolkit
Created
6 months ago
Last Updated
today
Language
Python
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category