MITRE ATT&CK Tactic
Command and Control
8 queries tagged with this tactic.
View on MITRE ATT&CK →
-
Analytics Rules
Detect Ci Build Egress To First Seen Domain
CI/CD build process reaching out to a domain never seen from your build fleet before — 'the build that called a stranger.'
-
Hunting
Hunt Blockchain Rpc C2 Dead Drop
C2 traffic hidden inside blockchain-RPC calls to public utilities (QuickNode, Alchemy) — 'the dead drop is a public utility.'
-
Hunting
Hunt C2 Beacon By Connection Window Rhythm
Low-and-slow C2 beacon hunt that counts distinct hourly time windows a process was connected in — not raw connection volume.
-
Hunting
Hunt Cav3rn Endpoint Local Log File Artifact
Endpoint-side hunt for Project CAV3RN's local file artifact (`logAzure.txt` and family) — config persistence written by the module.
-
Hunting
Hunt DNS Aaaa Record Covert Recovery Channel
Project CAV3RN's DNS AAAA-record recovery channel — IPv6 addresses returned in AAAA queries that decode as ASCII or structured config.
-
Hunting
Hunt Npm Postinstall Grandchild Network Payload
npm supply-chain worms where the payload runs two process generations down — 'sins of the grandfather' shape. Traces npm → sh -c → curl.
-
Hunting
Hunt Outlook Calendar C2 Far Future Standing Meeting
Project CAV3RN's Outlook calendar C2 — standing meetings scheduled decades in the future in fixed low-attention windows, carrying operator-agent traffic in the event body.
-
Pi-hole
New Or Rarely Seen Domains
Domains seen in the last 24h that haven't been seen recently — a classic new-domain-observed hunt.