The Beacon
That Won't Stop Calling Home.
Beacon detection, C2 framework fingerprints, and the difference between a legitimate check-in and a live implant phoning out on a schedule. Triage from detection source to containment. For capturing and confirming the traffic itself, see the tcpdump Command Reference.
Alert Overview
C2 alerts arrive from several different layers, each catching a different part of the same behavior.
Common Trigger Sources
IDS/IPS/NDR Beacon Detection Regular-interval outbound connections flagged by network-layer behavioral analysis Threat Intel IOC Match Destination IP or domain matches a known-bad indicator on a feed EDR Behavioral Detection Host-side agent behavior matching a known C2 framework's implant, e.g. Cobalt Strike, Sliver, Metasploit DNS Pattern Match Query names matching a DGA pattern, or excessive TXT/NULL record queries consistent with DNS tunneling TLS Fingerprint Match JA3/JA4 client fingerprint or certificate matches a known C2 framework's default profile // each of these can fire alone; the strongest cases have two or more agreeing on the same host
Initial Triage Steps
Confidence in a C2 verdict comes from stacking several of these, not any single one.
Five Checks, In Order
1. Identify detection source and confidence Signature match, threat intel IOC, or behavioral heuristic each carry different confidence levels └── A raw heuristic alone is weaker evidence than a signature match against a known IOC 2. Identify the responsible process EDR process-to-connection mapping shows exactly which binary is making the traffic 3. Check the destination Reputation, registration age, hosting provider/ASN, and whether it matches a known C2 framework's default infrastructure profile 4. Check the traffic pattern Beacon interval regularity, jitter, and payload size consistency └── Near-fixed intervals with small jitter, sustained over time, is the classic beaconing shape 5. Check for correlated host activity Process injection, credential access, or lateral movement attempts around the same time
True Positive Indicators
What separates a live implant from a chatty but legitimate service.
TRUE POSITIVE
Framework Fingerprint Match
The traffic looks like a known tool, not just unusual traffic
The destination or the traffic itself matches a known C2 framework's default profile or JA3/JA4 fingerprint, such as a Cobalt Strike malleable profile or a Sliver implant's default behavior.
TRUE POSITIVE
Sustained Regular Beacon
Fixed interval, small jitter, low-reputation destination
A near-fixed check-in interval with only small jitter, sustained over a meaningful period, to a domain with a low reputation score or very recent registration date.
TRUE POSITIVE
Process Has No Business Reason To Reach That Infrastructure
A workstation talking to something only a server should ever touch
The responsible process is unexpected for the host's role, such as a standard workstation process making sustained outbound connections to infrastructure with no legitimate tie to the business.
TRUE POSITIVE
DGA Or DNS Tunneling Pattern
The DNS traffic itself is the channel
Query names matching an algorithmically generated pattern (T1568.002), or an unusually high volume of TXT/NULL record queries (T1071.004), consistent with using DNS as a covert command channel rather than for name resolution.
TRUE POSITIVE
Correlates With Other Host Activity
The beacon isn't happening in isolation
The suspected C2 traffic lines up in time with process injection, credential dumping, or lateral movement attempts on the same host, which is exactly what a live implant checking in for further instructions looks like.
False Positive Indicators
Plenty of legitimate software beacons too.
FALSE POSITIVE
Legitimate Telemetry Or Update Check-In
Regular intervals aren't unique to malware
Many legitimate agents beacon on a naturally regular schedule too: EDR agents, monitoring tools, and update services all check in at fixed intervals as part of normal operation.
FALSE POSITIVE
Fingerprint Collision With A Common Library
JA3/JA4 hashes aren't unique to malicious tooling
The TLS fingerprint matches a widely-used library, framework, or CDN rather than the specific C2 tool the fingerprint was originally associated with.
FALSE POSITIVE
One-Off Connection, No Sustained Pattern
A single hit isn't a beacon
A single connection with no recurring interval and no other correlated indicators on the host, which doesn't match the sustained shape a real beacon needs to establish.
Escalation Criteria
A confirmed C2 channel is one of the clearest "stop and escalate" signals in this whole set of playbooks.
ESCALATE
Confirmed Framework Or IOC Match
Treat the host as compromised, not suspicious
A confirmed match to a known C2 framework signature or threat intel indicator escalates immediately, with the host treated as compromised rather than merely flagged for review.
ESCALATE
Multiple Hosts, Same Infrastructure
Lateral spread, not several unrelated alerts
More than one host beaconing to the same C2 infrastructure means the compromise has already spread. Escalate as a coordinated incident, not a set of individual tickets.
ESCALATE
Volume Suggests Data Leaving, Not Just Check-Ins
A beacon that's carrying payload, not just polling
Traffic volume or timing on the C2 channel that looks like data being sent outbound in bulk, not just periodic check-ins, is a time-critical escalation: exfiltration may already be in progress.
Containment Actions
Cut the channel, preserve what's left of the implant, then hunt for its siblings.
CONTAIN
Isolate The Host Immediately
Cuts the channel without destroying evidence
Isolate the affected host from the network right away, disabling the NIC rather than powering the machine off, since many C2 implants live in memory only and a reboot can lose them entirely.
CONTAIN
Block The Infrastructure At Every Layer
Network edge and DNS both, not just one
Block the C2 IP, domain, and JA3/JA4 fingerprint where the tooling supports it, at both the network edge and the DNS layer, so a blocked channel can't simply resolve through an unmonitored path.
CONTAIN
Capture Memory Before Remediation
The implant may not exist anywhere else
Capture memory and traffic evidence from the host before any remediation step, since many C2 implants are memory-resident only and disappear the moment the process is killed or the host is cleaned.
CONTAIN
Hunt For The Same Infrastructure Environment-Wide
One confirmed beacon is rarely the only one
Search the entire environment for the same C2 infrastructure, fingerprint, or beacon signature, since a working C2 channel is typically deployed to more than the single host that happened to alert first.