Skip to content

Command and Control (C2)

Definition

The channel through which an attacker sends instructions to malware on a compromised host and receives data back. C2 channels range from direct TCP connections to domain-generation algorithm (DGA) traffic, DNS tunnelling, and traffic over legitimate platforms. Network logs recording C2 traffic are primary evidence in most malware investigations.

Abbreviation
C2, also written C&C
Common channels
Direct TCP/HTTPS, DNS tunnelling, DGA domains, legitimate platforms
Evidence type
Network logs, proxy logs, DNS query logs, firewall records
Investigative use
Identifies attacker infrastructure and timeline of compromise

Common questions

Why do attackers use domain-generation algorithms for C2?+

A DGA produces a large, changing set of candidate domains on a schedule known only to the attacker and the malware, so defenders cannot block C2 by blacklisting a single fixed domain, and takedown of any one registered domain has little effect.

How can investigators detect C2 traffic hidden in legitimate platforms?+

Analysts look for anomalies such as unusual API call patterns, beaconing intervals, or data volumes that do not match normal user behaviour on the platform, and correlate the timing with endpoint telemetry showing the malware process making the connection.

What happens once a C2 channel is identified during an investigation?+

The channel's indicators, such as destination IPs, domains, or JA3 fingerprints, are used to search historical logs for the full extent of communication and to identify other compromised hosts contacting the same infrastructure.

Related terms

Credential Stuffing
An automated attack that replays username-password pairs from previous data breaches against new target services, exploiting the widespread reuse of passwords across...
Double Extortion
A ransomware tactic in which the attacker exfiltrates data before encrypting it, then demands payment both for the decryption key and for...
Dropper
A malware component whose sole function is to deliver and install a secondary payload. The dropper itself may be a trojan, a...
FAFT Virtual Asset Guidance
Guidance from the Financial Action Task Force requiring member states to regulate virtual asset service providers (cryptocurrency exchanges) as financial institutions, applying...
Image-Based Sexual Abuse (IBSA)
The non-consensual creation, capture, or distribution of intimate sexual images. The term encompasses non-consensual intimate image sharing (formerly called revenge porn), upskirt...
Payload
The action the malware performs once active: data encryption (ransomware), credential theft (banking trojan), resource hijacking (cryptominer), or system destruction (wiper). The...
Persistence Mechanism
The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron...
Propagation Mechanism
The method by which malware copies itself to new hosts. Viruses attach to host files; worms exploit network services autonomously; trojans rely...
Rootkit
Malware designed to hide its own presence by subverting the operating system's reporting functions. User-mode rootkits hook API calls; kernel-mode rootkits modify...
Synthetic Identity Fraud
The creation of a fictitious identity by combining real and fabricated personal data elements, such as a genuine national ID number paired...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.