cybersec-analyzing-command-and-control-communication - Analyze malware command-and-control traffic
Analyzes malware C2 protocols, beacon patterns, encoded data, infrastructure, and traffic indicators for detection and threat intelligence.
Tags
Updated: 2026-09-28Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Identify C2 channels
- Analyze beacon timing
- Decode protocol structures
- Identify C2 frameworks
- Map C2 infrastructure
- Create detection signatures
Inputs
- Malware network traffic captures
- Malware samples
- C2 indicators
- Threat intelligence queries
- Protocol analysis parameters
Outputs
- C2 protocol analysis findings
- Beacon pattern findings
- C2 infrastructure mapping
- Decoded protocol details
- Network detection signatures
Requirements
- Wireshark or tshark
- Ghidra or dnSpy
- Python 3.8 or later
- scapy, dpkt, and requests
- Threat intelligence database access
- JA3/JA3S fingerprint databases
