{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/c2-beaconing/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["low"],"_cs_tags":["network","c2-beaconing","command-and-control","anomaly-detection"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis brief describes an Elastic Security detection rule designed to identify command-and-control (C2) beaconing activity with high confidence using a statistical model. C2 beaconing is a critical technique used by adversaries to maintain covert communication channels with compromised systems, enabling them to receive instructions, deploy additional payloads, exfiltrate sensitive data, and ensure persistence within a targeted network. The detection leverages Elastic's Network Beaconing Identification integration, which employs a statistical framework to analyze network logs and assign a beaconing score. A high score, specifically a \u003ccode\u003ebeacon_stats.beaconing_score\u003c/code\u003e of 3, indicates a strong likelihood of malicious C2 activity. This detection capability requires the Elastic Defend integration for network log collection and a Fleet Server for the Network Beaconing Identification integration.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003cp\u003eThis brief describes a detection mechanism for command-and-control beaconing, not a full attack chain from initial access to impact. The detection occurs during the command and control phase of an attack.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eIf C2 beaconing activity goes undetected, attackers can maintain a persistent foothold within the network, allowing for sustained control over compromised systems. This can lead to significant data exfiltration, deployment of further malicious payloads (such as ransomware or destructive malware), privilege escalation, and lateral movement across the organization's infrastructure. The long-term presence enabled by effective C2 communication can result in severe financial loss, reputational damage, and operational disruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Network Beaconing Identification integration and Elastic Defend to collect the necessary network logs for the detection rule.\u003c/li\u003e\n\u003cli\u003eReview the network traffic logs from the \u003ccode\u003eml_beaconing.all\u003c/code\u003e index to investigate the source and destination IP addresses associated with detected beaconing activity.\u003c/li\u003e\n\u003cli\u003eCorrelate identified IP addresses and domain names with known malicious IP databases or threat intelligence feeds.\u003c/li\u003e\n\u003cli\u003eAnalyze the frequency and pattern of beaconing activity to assess alignment with typical C2 communication patterns.\u003c/li\u003e\n\u003cli\u003eExamine payloads or data transferred during flagged communication sessions for sensitive information exfiltration or malicious instructions.\u003c/li\u003e\n\u003cli\u003eConsult the investigation guide provided in the source material for detailed triage steps.\u003c/li\u003e\n\u003cli\u003eIsolate affected systems from the network to prevent further communication with C2 servers and contain the threat.\u003c/li\u003e\n\u003cli\u003eConduct thorough analysis of network traffic logs to identify additional compromised systems or lateral movement within the network.\u003c/li\u003e\n\u003cli\u003eApply security patches and updates to all affected systems and change all associated credentials to prevent unauthorized access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T15:27:04Z","date_published":"2026-07-27T15:27:04Z","id":"https://feed.craftedsignal.io/briefs/2026-07-c2-beaconing-detection/","summary":"This Elastic detection rule identifies high-confidence command-and-control (C2) beaconing activity, a technique allowing threat actors to maintain stealthy communication, receive instructions, exfiltrate data, and sustain persistence in compromised networks.","title":"High Confidence Command and Control Beaconing Detected by Statistical Model","url":"https://feed.craftedsignal.io/briefs/2026-07-c2-beaconing-detection/"}],"language":"en","title":"CraftedSignal Threat Feed - C2-Beaconing","version":"https://jsonfeed.org/version/1.1"}