C2
Command and Control
Command and Control is the infrastructure and communication channel an attacker uses to send instructions to compromised systems and receive stolen data. C2 channels use protocols like HTTP, HTTPS, DNS, and custom encryption to blend with normal traffic and evade detection.
Cómo se usa en ciberseguridad
SOC analysts hunt for C2 beaconing patterns in network traffic and DNS logs to detect compromised hosts. Incident responders identify and block C2 channels to cut off attacker access during active breaches. Penetration testers set up C2 frameworks like Cobalt Strike and Sliver to simulate real adversary operations.
Término relacionado en el glosario: command and control
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.