Cyber Security Basics 📂 Slides · 20 of 20 37 min read

Installation & Command-and-Control: Persistence and Beaconing Explained

A visual, defense-first tutorial on two kill chain phases where a break-in becomes a lasting breach. Installation is the attacker's spare key — persistence via auto-start, services, and valid accounts. Command-and-Control is the secret radio home — beaconing, C2 channels, and current methods. Learn how footholds survive and how defenders cut the cord.

Installation & Command-and-Control

The exploit worked — now the attacker wants to stay and to steer. Installation digs in so a reboot won't evict them; C2 is the secret phone line home. Learn how footholds persist, how beacons whisper out, current methods — and how defenders cut the cord.
Persistence Beaconing C2 Channels Detect & Cut

Press Next → or use ← → arrow keys

The Big Picture

Phases 5 & 6 of the Kill Chain

Exploitation got the attacker in. But a foothold that vanishes on reboot is worthless, and a foothold you can't talk to is deaf. So two things happen next: the attacker installs to persist, and opens C2 to control.

4 · Exploitflaw fires 5 · Installationdig in, persist 6 · Command& Controlphone home 7 · Actions on Objectivessteal · encrypt · spread Stay (install) + Steer (C2) → then act
🧭
Two jobs, one goal: dwell time

Installation answers "how do I survive a reboot and keep my access?" C2 answers "how do I send commands and receive loot without being seen?" Together they turn a one-shot exploit into a long-term tenant in your network.

Story

The Spy Who Moved In

A spare key under the mat, and a radio to headquarters.

A spy breaks into a building once — that was exploitation. But breaking in every single time is risky and loud. So the first thing a good spy does is make a spare key and hide it under the mat — now they can walk back in whenever they like, even if the front lock is changed. That spare key is Installation / persistence.

The second thing? A quiet radio to headquarters — to receive orders and send back what they found, blending into normal radio chatter so nobody notices. That radio is Command-and-Control. Without the key, the spy gets locked out; without the radio, the spy is blind and useless. Every serious intrusion needs both.

⚠️
Why defenders care so much

This is where a break-in becomes a breach. The longer the spare key stays hidden and the radio keeps whispering, the more the attacker learns, steals, and spreads. Find the key, jam the radio — and the whole operation collapses.

Installation · Part 1

What "Installation" Really Means

Installation is establishing persistence — making sure the attacker's access survives reboots, logoffs, and the user simply closing the malicious file. The foothold becomes permanent furniture.

Fresh Footholdlives in memory only reboot = gone ✗ Anchor It Downauto-start entrysurvives reboot ✓ Persistent Accesscomes back every booteven if password changes Memory-only → anchored → permanent
🧭
The core idea

An exploit is a moment; persistence is a tenancy. Attackers invest heavily here because getting back in is far more expensive than staying in. Every persistence trick abuses a legitimate "run this automatically" feature the OS already provides.

Installation · Part 2

Where Attackers Hide the Spare Key

🔁
Auto-start entries
Run keys / startup
Registry Run keys, Startup folder — "launch me every login." The oldest trick, still everywhere.
⏰
Scheduled tasks / cron
time-based
"Run this every hour / at boot." Blends in with the hundreds of legitimate tasks already there.
⚙️
Services / daemons
system-level
Register as a background service so the OS itself relaunches it — often with high privilege.
🎭
DLL / library hijack
ride a real app
Drop a lookalike library a trusted program loads, so the good app carries the bad code.
🔑
Valid accounts
hardest to spot
Create or steal a real account. No malware file at all — just a legitimate login they now own.
🧬
Firmware / bootkit
deepest
Hide below the OS so even a wipe-and-reinstall doesn't remove it. Rare, high-end, very sticky.
🎯
The trend: fewer files, more "living off the land"

Modern persistence increasingly uses no malware file at all — a stolen account, a scheduled task calling a built-in tool, a tweaked config. Nothing for a signature scanner to catch. That's why defenders watch changes and behavior, not just files.

Installation · Part 2

Digging In Deeper

Persistence rarely stops at one low-privilege foothold. Attackers widen it — more power, more machines — so losing one door doesn't lock them out.

⬆️
Privilege escalation

Go from a normal user to admin / SYSTEM / root — by abusing a local flaw, a misconfiguration, or harvested credentials. More power means stronger, stealthier persistence.

↔️
Lateral movement

Spread from the first machine to others using stolen credentials and trust relationships. Plant the spare key on many hosts, so eviction from one changes nothing.

🧠
Why this matters for defense

By the time an attacker has admin rights on several machines plus valid accounts, "remove the malware" is no longer enough. This is why fast detection in the early phases is worth so much more than cleanup later — the cost of eviction explodes with every machine they touch.

Installation · Defense

Finding the Hidden Key

🛡️ DENY, DETECT, AND LIMIT PERSISTENCE
1
Least privilege. Users aren't admins; apps run with only what they need. Shrinks what persistence can grab.
2
Monitor auto-start locations. Alert on new Run keys, scheduled tasks, services — the classic hiding spots.
3
Application allow-listing. Only approved programs run; a dropped binary simply won't execute.
4
Watch identities. New accounts, odd privilege grants, impossible logins — persistence often is an account.
5
EDR behavioral baselines. Flag "this host never ran that before." Catches fileless persistence.
6
Secure boot & firmware integrity. Raise the floor so the deepest, stickiest footholds can't take root.
The Radio Turns On

Now It Needs to Phone Home

A persistent foothold sitting silently is useless to the attacker. To receive orders and send back loot, it must reach out to infrastructure the attacker controls. That channel is Command-and-Control.

From "I'm inside" to "What are my orders?"

The installed implant wakes up and quietly asks: "Headquarters, I'm in — what now?" It must do this without tripping alarms, so it disguises its calls as ordinary traffic — a web request, a DNS lookup, a cloud API call — things that leave your network every second of every day.

🔑
The idea to hold onto

C2 almost always goes outbound, because firewalls trust traffic leaving far more than traffic coming in. Defenders win by scrutinizing what leaves as hard as what enters — the radio has to transmit, and transmission can be detected.

C2 · Part 1

What Command-and-Control Is

C2 is the two-way secret channel between the attacker's implant on your host and the attacker's server outside. Orders flow in; stolen data and status flow out.

Implanton your host firewall beacon out "any orders?" commands + loot back C2 Serverattacker-controlledoften behind proxies 🧑‍💻 A quiet two-way line, disguised as normal traffic
💡
Key vocabulary

Implant / agent = the attacker's code on your host. Beacon = its periodic check-in. C2 server = where it calls. The gap between beacons is the sleep interval — long sleeps mean stealth, short sleeps mean responsiveness.

C2 · Concept

Beaconing — the Heartbeat

Instead of a constant connection (easy to spot), most implants beacon: a brief check-in at intervals, then silence. Like a sleeper agent calling a payphone once a day, then disappearing.

time → + random "jitter" to look irregular check-incheck-incheck-in Short pulses, long silences — a faint heartbeat
🔎
The beacon's own weakness

Regularity betrays it. Even with random jitter, a host quietly calling the same destination at loosely-fixed intervals, forever, looks nothing like human browsing. Detecting that rhythm — "beacon analysis" — is one of the most reliable ways to find hidden C2.

C2 · Part 2

The Channels C2 Rides

Attackers pick channels that blend into normal traffic — the busier and more trusted, the better the camouflage.

ChannelWhy it's chosenDefender's angle
HTTPSEncrypted & everywhere — hides in normal web trafficTLS inspection, reputation, beacon timing
DNSRarely blocked; leaks out even locked-down networksWatch odd/long/high-volume lookups
Cloud / SaaSHides behind trusted domains (Drive, Slack, GitHub)Baseline normal app use; flag anomalies
Social / webmailCommands posted where traffic looks personalEgress policy, DLP on uploads
Domain frontingMakes traffic appear to go to a trusted siteProvider controls, SNI/host mismatch checks
🕶️
The arms race

As defenders inspect one channel, attackers shift to another that's harder to touch. There's no single port to block — which is exactly why C2 defense is about behavioral anomalies and egress control, not a firewall rule.

C2 · Current

How C2 Looks in 2024–2025

📈
On the rise

• Legit cloud as C2 — Slack, Discord, Telegram, GitHub, Drive
• Malleable / customizable profiles that mimic real apps
• Fast-flux & disposable domains, rotated constantly
• Encrypted DNS (DoH) to hide lookups from inspection

🧰
The ecosystem

• Commercial red-team frameworks, abused by criminals
• Open-source C2 kits lower the barrier to entry
• C2-as-a-service rented like any SaaS
Attackers rarely build from scratch anymore

🧠
The through-line

Every trend chases the same goal: make the radio sound exactly like everyone else's. When your malware talks over the same services your employees use all day, "block the bad domain" stops working — and behavior becomes the only tell.

C2 · Defense

Jamming the Radio

📊
Beacon analysis
Hunt the rhythm — regular check-ins to one destination, even with jitter. The heartbeat gives it away.
🚪
Egress control
Default-deny outbound; force traffic through proxies; allow only what's needed. The radio can't transmit freely.
🌐
DNS & TLS inspection
Watch for odd lookups, new/low-reputation domains, mismatched certificates.
🧾
Threat intelligence
Known C2 domains/IPs, JA3 fingerprints, framework signatures — block and alert on the known-bad.
📤
DLP on exfil
Watch large or unusual outbound uploads — the loot leaving is itself a signal.
✂️
Contain & cut
Isolate the host, kill the channel, then hunt every other foothold before declaring victory.
🎯
Cut the cord, then sweep

Killing one C2 channel is not winning — remember lateral movement. Assume multiple footholds and backup channels; investigate the full blast radius before you call it clean.

Case Study

When the Update Itself Was the Spy

Trusted software delivered the key — and the radio was patient.

In a landmark supply-chain intrusion, attackers slipped malicious code into a trusted software update. When organizations installed it themselves, the implant established persistence and then — crucially — stayed quiet for days before beaconing out, mimicking the vendor's own normal traffic so it blended perfectly into legitimate noise.

Three lessons the whole industry took away: persistence can arrive through software you trust; patient, low-and-slow C2 defeats "block the obvious"; and only behavioral baselines and egress scrutiny eventually surfaced traffic that didn't belong. It reframed C2 detection around anomaly, not signature.

🧭
The through-line to today

The exact tools change, but the pattern repeats: get in via trust, persist quietly, phone home in disguise. Defense that assumes breach — and watches what leaves — is what catches it.

Recap

Golden Rules — Both Phases

🏆 CARRY THESE OUT OF THE ROOM
1
Installation = the spare key. Persistence abuses legitimate "auto-run" features so access survives reboots.
2
Fileless is the trend. Stolen accounts and scheduled tasks beat dropped malware — watch changes, not just files.
3
C2 = the radio. A two-way channel, almost always outbound, disguised as normal traffic.
4
Beacons have a heartbeat. Regular check-ins — even with jitter — are a reliable tell.
5
Scrutinize what leaves. Firewalls trust outbound; egress control and DNS/TLS inspection are where C2 dies.
6
Assume more than one foothold. Cut one channel, then hunt the rest before declaring clean.
FINAL

Find the Key, Jam the Radio

PersistenceSurvive the reboot
BeaconThe faint heartbeat
OutboundWhere C2 hides
Dwell timeWhat you must cut
🎯
The whole idea

Installation hides a spare key so the attacker can return at will; C2 opens a quiet radio so they can command the foothold and carry out loot — both disguised as the ordinary. This is where an intrusion becomes a lasting breach. Defenders win by denying and detecting persistence and by scrutinizing everything that leaves the network. Find the key, jam the radio, and the attacker is both locked out and struck deaf.

🧠
One sentence to remember

Persistence is the spare key under the mat; C2 is the radio to headquarters — cut either one and the operation collapses. Final kill-chain phase: Actions on Objectives — steal, encrypt, destroy, or spread.

📡 End of tutorial · Press ← to review, or click Restart

You have completed Slides. View all sections →