Command and control (C2)

The servers and communication channels an attacker uses to send instructions to compromised systems, such as the bots in a botnet, and to receive data back from them.

Command and control, usually shortened to C2, is the means by which an attacker directs systems already under their control. Malware on a compromised host contacts C2 infrastructure to fetch instructions and send out stolen data. In a botnet the same channel lets one operator direct many machines, for example to launch a distributed denial of service attack. The MITRE ATT&CK framework lists Command and Control as one of its tactics.

Designs vary. A central server is simple to run but also simple to take down, so attackers use peer-to-peer designs, rapidly changing domain names, and channels that blend with normal traffic such as HTTPS or DNS queries. C2 connections are commonly opened from inside the network outwards, which is why egress filtering and egress monitoring are controls that meet it. Signs include regular beaconing to one destination at fixed intervals, lookups of newly registered or random-looking domains, and unexpected DNS volume. Cutting the C2 channel does not clean the infected hosts, but it can cut the attacker off from them.

Exam relevance: a scenario is likely to describe outbound connections at regular intervals from an internal host and ask what they indicate. Candidates are expected to connect C2 with outbound traffic and with botnets, rather than with inbound attacks.