H3AD-REF / PLAYBOOKS / COMMAND & CONTROL ALERT

The Beacon
That Won't Stop Calling Home.

Beacon detection, C2 framework fingerprints, and the difference between a legitimate check-in and a live implant phoning out on a schedule. Triage from detection source to containment. For capturing and confirming the traffic itself, see the tcpdump Command Reference.

Alert Overview

C2 alerts arrive from several different layers, each catching a different part of the same behavior.

Common Trigger Sources

IDS/IPS/NDR Beacon Detection
Regular-interval outbound connections flagged by network-layer behavioral analysis

Threat Intel IOC Match
Destination IP or domain matches a known-bad indicator on a feed

EDR Behavioral Detection
Host-side agent behavior matching a known C2 framework's implant, e.g. Cobalt Strike, Sliver, Metasploit

DNS Pattern Match
Query names matching a DGA pattern, or excessive TXT/NULL record queries consistent with DNS tunneling

TLS Fingerprint Match
JA3/JA4 client fingerprint or certificate matches a known C2 framework's default profile
    // each of these can fire alone; the strongest cases have two or more agreeing on the same host

Initial Triage Steps

Confidence in a C2 verdict comes from stacking several of these, not any single one.

Five Checks, In Order

1. Identify detection source and confidence
Signature match, threat intel IOC, or behavioral heuristic each carry different confidence levels
└── A raw heuristic alone is weaker evidence than a signature match against a known IOC

2. Identify the responsible process
EDR process-to-connection mapping shows exactly which binary is making the traffic

3. Check the destination
Reputation, registration age, hosting provider/ASN, and whether it matches a known C2
framework's default infrastructure profile

4. Check the traffic pattern
Beacon interval regularity, jitter, and payload size consistency
└── Near-fixed intervals with small jitter, sustained over time, is the classic beaconing shape

5. Check for correlated host activity
Process injection, credential access, or lateral movement attempts around the same time

True Positive Indicators

What separates a live implant from a chatty but legitimate service.

TRUE POSITIVE

Framework Fingerprint Match

The traffic looks like a known tool, not just unusual traffic
The destination or the traffic itself matches a known C2 framework's default profile or JA3/JA4 fingerprint, such as a Cobalt Strike malleable profile or a Sliver implant's default behavior.
TRUE POSITIVE

Sustained Regular Beacon

Fixed interval, small jitter, low-reputation destination
A near-fixed check-in interval with only small jitter, sustained over a meaningful period, to a domain with a low reputation score or very recent registration date.
TRUE POSITIVE

Process Has No Business Reason To Reach That Infrastructure

A workstation talking to something only a server should ever touch
The responsible process is unexpected for the host's role, such as a standard workstation process making sustained outbound connections to infrastructure with no legitimate tie to the business.
TRUE POSITIVE

DGA Or DNS Tunneling Pattern

The DNS traffic itself is the channel
Query names matching an algorithmically generated pattern (T1568.002), or an unusually high volume of TXT/NULL record queries (T1071.004), consistent with using DNS as a covert command channel rather than for name resolution.
TRUE POSITIVE

Correlates With Other Host Activity

The beacon isn't happening in isolation
The suspected C2 traffic lines up in time with process injection, credential dumping, or lateral movement attempts on the same host, which is exactly what a live implant checking in for further instructions looks like.

False Positive Indicators

Plenty of legitimate software beacons too.

FALSE POSITIVE

Legitimate Telemetry Or Update Check-In

Regular intervals aren't unique to malware
Many legitimate agents beacon on a naturally regular schedule too: EDR agents, monitoring tools, and update services all check in at fixed intervals as part of normal operation.
FALSE POSITIVE

Fingerprint Collision With A Common Library

JA3/JA4 hashes aren't unique to malicious tooling
The TLS fingerprint matches a widely-used library, framework, or CDN rather than the specific C2 tool the fingerprint was originally associated with.
FALSE POSITIVE

One-Off Connection, No Sustained Pattern

A single hit isn't a beacon
A single connection with no recurring interval and no other correlated indicators on the host, which doesn't match the sustained shape a real beacon needs to establish.

Escalation Criteria

A confirmed C2 channel is one of the clearest "stop and escalate" signals in this whole set of playbooks.

ESCALATE

Confirmed Framework Or IOC Match

Treat the host as compromised, not suspicious
A confirmed match to a known C2 framework signature or threat intel indicator escalates immediately, with the host treated as compromised rather than merely flagged for review.
ESCALATE

Multiple Hosts, Same Infrastructure

Lateral spread, not several unrelated alerts
More than one host beaconing to the same C2 infrastructure means the compromise has already spread. Escalate as a coordinated incident, not a set of individual tickets.
ESCALATE

Volume Suggests Data Leaving, Not Just Check-Ins

A beacon that's carrying payload, not just polling
Traffic volume or timing on the C2 channel that looks like data being sent outbound in bulk, not just periodic check-ins, is a time-critical escalation: exfiltration may already be in progress.

Containment Actions

Cut the channel, preserve what's left of the implant, then hunt for its siblings.

CONTAIN

Isolate The Host Immediately

Cuts the channel without destroying evidence
Isolate the affected host from the network right away, disabling the NIC rather than powering the machine off, since many C2 implants live in memory only and a reboot can lose them entirely.
CONTAIN

Block The Infrastructure At Every Layer

Network edge and DNS both, not just one
Block the C2 IP, domain, and JA3/JA4 fingerprint where the tooling supports it, at both the network edge and the DNS layer, so a blocked channel can't simply resolve through an unmonitored path.
CONTAIN

Capture Memory Before Remediation

The implant may not exist anywhere else
Capture memory and traffic evidence from the host before any remediation step, since many C2 implants are memory-resident only and disappear the moment the process is killed or the host is cleaned.
CONTAIN

Hunt For The Same Infrastructure Environment-Wide

One confirmed beacon is rarely the only one
Search the entire environment for the same C2 infrastructure, fingerprint, or beacon signature, since a working C2 channel is typically deployed to more than the single host that happened to alert first.