166 terms · 75/46/45
Technique № 042 · class: C2

Encrypted C2 Channels

Using HTTPS, DNS-over-HTTPS, or other encrypted protocols for C2.

Term

description · examples · notes

Using HTTPS, DNS-over-HTTPS, or other encrypted protocols for C2.

Description

Encrypted traffic blends with legitimate web traffic.

Standard network inspection cannot read the communication content.

Requires TLS inspection or behavioral analysis for detection.

Most modern malware uses HTTPS for C2 communication.

Examples

  • Cobalt Strike beacon with HTTPS profiles
  • DNS-over-HTTPS for data exfiltration past firewalls

Notes

  • Most common form of C2 communication in modern malware.
Composite

Threats

used by 4

Threats that use it. Select one to open its page.

Defenses

countered by 5