Investigate Command and Control (C2) Communications
Investigation Overview
Compromised systems rarely operate in isolation. Once malware gains a foothold, it typically establishes communication with an external Command and Control (C2) server to receive instructions, download additional payloads, maintain persistence, or coordinate further malicious activity. These communications often occur long before any visible impact is observed on the network.
Unlike large data transfers or denial-of-service attacks, C2 traffic is designed to blend into legitimate network activity. Attackers frequently use common protocols such as DNS, HTTP, HTTPS, and TLS, communicate at regular intervals, or disguise traffic as normal application behavior. The objective of this investigation is to determine whether suspicious outbound communications represent legitimate application traffic or potential command and control activity, identify the affected systems, and assess the scope of the compromise.
Using Trisul Network Security Monitoring, analysts can investigate suspicious communications from the initial indicator through network flows, DNS activity, TLS metadata, packet evidence, and historical analysis without switching between multiple security tools.
When to Use This Investigation
Use this investigation when you need to:
- Investigate periodic outbound communications.
- Validate repeated connections to unfamiliar external destinations.
- Analyze suspicious DNS or TLS activity.
- Investigate alerts indicating potential malware or command and control activity.
- Determine whether a host has established persistent communication with external infrastructure.
Investigation Objectives
By completing this investigation, you should be able to:
- Identify the system communicating with the external host.
- Determine the destination and communication frequency.
- Understand the protocols and encrypted sessions involved.
- Validate whether the communication exhibits beaconing behavior.
- Determine whether the observed activity represents legitimate application traffic or potential command and control communication.
Investigation Workflow
Step 1: Identify Suspicious Communication Indicators
Command and control investigations rarely begin with high bandwidth usage. Instead, they often start with subtle indicators such as unusual DNS queries, unknown TLS fingerprints, recurring connections to unfamiliar destinations, or alerts generated by threat detection systems.
Begin by reviewing the indicator that initiated the investigation. This may originate from DNS activity, TLS metadata, threat intelligence, or a security alert identifying suspicious outbound communications.
Open DNS Analysis, TLS Metadata, or the relevant security alert associated with the investigation.
Review the available evidence to determine:
- Which destination is involved.
- Whether the communication uses DNS, HTTP, HTTPS, or another common protocol.
- Whether unusual JA3 or JA3S fingerprints are present.
- Whether the communication appears repetitive or automated.
- Whether the destination is known to your environment.
The objective at this stage is to establish whether the communication warrants further investigation before identifying the affected systems.
Evidence to Preserve
- Destination IP address.
- Domain name.
- JA3 and JA3S fingerprints.
- Server Name Indication (SNI).
- Alert information.
Continue the Investigation
Once the suspicious communication has been identified, determine which internal systems are responsible for establishing the connection.
Step 2: Identify the Communicating Hosts
After identifying a suspicious destination or encrypted session, determine which internal hosts are communicating with it.
From DNS Analysis or TLS Metadata, drill down into the associated communication to identify the internal source hosts.
Review the available communication details to determine:
- Which internal hosts contacted the destination.
- Whether multiple hosts communicated with the same destination.
- The frequency of communication.
- Whether communications are ongoing.
- Whether the affected hosts perform similar operational roles.
If multiple systems are involved, determine whether the activity represents widespread exposure or isolated host compromise.
Evidence to Preserve
- Source hosts.
- Destination infrastructure.
- Communication timeline.
- Number of affected systems.
- Associated alerts.
Continue the Investigation
Once the affected hosts have been identified, examine how they are communicating with the destination.
Step 3: Analyze Communication Behaviour
After identifying the communicating hosts, examine the network conversations to determine whether the activity exhibits characteristics commonly associated with command and control communication.
From the selected host, click the Actions menu and choose Host Conversations.
Review the conversations to identify:
- Whether the host repeatedly communicates with the same destination.
- The interval between successive connections.
- Whether communication continues outside normal business hours.
- The amount of data exchanged during each session.
- Whether multiple destinations exhibit similar communication patterns.
If additional detail is required, open Flow Details for the selected communication.
The Flow Details view provides detailed information including timestamps, session duration, protocols, applications, ports, and data transferred.
Look for characteristics such as:
- Regular communication intervals.
- Low-volume recurring sessions.
- Consistent connection durations.
- Persistent outbound communications.
- Protocol usage inconsistent with the host's expected role.
These patterns often provide stronger indicators of command and control activity than traffic volume alone.
Evidence to Preserve
- Communication frequency.
- Session duration.
- Flow timeline.
- Applications and protocols.
- Data transferred.
Continue the Investigation
If the communication uses encrypted protocols, examine the available TLS metadata and correlate the findings with additional network evidence.
Step 4: Correlate Multiple Evidence Sources
Command and control investigations should not rely on a single indicator. Correlating multiple sources of network evidence helps distinguish legitimate application traffic from malicious communications and provides greater confidence before initiating incident response.
Continue the investigation by correlating evidence from DNS Analysis, Packet Analysis, and Historical Investigation (Retro) to validate whether the observed communication is consistent across multiple sources.
Use this investigation to answer questions such as:
- Do DNS queries support the observed communication?
- Does the TLS metadata remain consistent across multiple sessions?
- Has the destination been contacted previously?
- Are additional hosts communicating with the same infrastructure?
- Does packet analysis validate the observed protocol behaviour?
- Has the communication frequency changed over time?
Review the historical activity to determine whether the communication represents a newly established connection or an existing communication pattern.
Evidence to Preserve
- DNS activity.
- TLS metadata.
- Packet captures.
- Historical communications.
- Additional affected hosts.
- Threat intelligence findings.
Continue the Investigation
Once the communication has been validated across multiple evidence sources, determine the scope and potential impact of the activity.
Step 5: Assess the Scope of the Activity
After confirming suspicious communication patterns, determine whether the activity is isolated to a single host or forms part of a broader compromise.
Review the investigation findings to identify:
- Whether multiple internal hosts communicate with the same destination.
- Whether similar JA3 fingerprints appear elsewhere in the network.
- Whether additional domains or IP addresses are associated with the activity.
- Whether communication is ongoing.
- Which systems require immediate containment or further investigation.
Understanding the scope of the activity allows analysts to prioritise response efforts and identify additional systems that may have been compromised.
Evidence to Preserve
- Affected hosts.
- Shared destinations.
- Communication timelines.
- Related infrastructure.
- Scope of exposure.
Continue the Investigation
After establishing the scope of the activity, prepare a summary of the investigation findings to support incident response.
Step 6: Summarize the Investigation with Trisul AI
Once the investigation is complete, open Trisul AI to review the investigation findings.
Trisul AI can generate a concise summary of the investigation, highlight the key observations, and assist with documenting the findings for operational review, incident reporting, or future reference.
Investigation Completion
This investigation can generally be considered complete when:
- The suspicious communication has been validated.
- The affected hosts have been identified.
- Communication behaviour has been analysed.
- DNS, TLS, flow, packet, and historical evidence have been correlated.
- The scope of the activity has been established.
- Appropriate containment or engineering actions have been identified.
- Whether the observed communication has been determined to be legitimate or potential command and control activity.
Best Practices
- Begin command and control investigations from the initial communication indicator rather than traffic volume.
- Correlate DNS, TLS metadata, flow records, and packet evidence before determining malicious activity.
- Investigate recurring low-volume communications in addition to high-bandwidth sessions.
- Compare current communications with historical network activity to identify persistent beaconing.
- Preserve investigation evidence before containment begins.
- Document investigation findings to support incident response and future threat hunting activities.