C2
Command and Control
Steuerung kompromittierter Systeme
C2 denotes the infrastructure and communication through which an attacker remotely controls compromised systems — issuing commands, exfiltrating data and downloading further malware. It is the umbilical cord between attacker and victim. Detecting it is one of the most effective levers for stopping an ongoing attack.
History & facts. After initial access an attacker needs a back channel to operate — that is exactly C2. To avoid standing out, this communication often disguises itself as legitimate traffic, for instance via common web protocols or well-known cloud services, and uses changing or obfuscated command servers. In threat data, C2 addresses and domains are central indicators (IoC).
Outlook & recommendation. Because C2 traffic plays out on the network, network visibility (Network Detection and Response (NDR)/NSM) is especially valuable here — particularly where no agent runs at the endpoint. Matching outbound traffic against curated indicator sources and behavioural patterns can reveal a compromise before the actual objective is reached. Severing the C2 connection is often the fastest containment measure.