Installation & Command-and-Control
Press Next → or use ← → arrow keys
Phases 5 & 6 of the Kill Chain
Exploitation got the attacker in. But a foothold that vanishes on reboot is worthless, and a foothold you can't talk to is deaf. So two things happen next: the attacker installs to persist, and opens C2 to control.
Installation answers "how do I survive a reboot and keep my access?" C2 answers "how do I send commands and receive loot without being seen?" Together they turn a one-shot exploit into a long-term tenant in your network.
The Spy Who Moved In
A spy breaks into a building once — that was exploitation. But breaking in every single time is risky and loud. So the first thing a good spy does is make a spare key and hide it under the mat — now they can walk back in whenever they like, even if the front lock is changed. That spare key is Installation / persistence.
The second thing? A quiet radio to headquarters — to receive orders and send back what they found, blending into normal radio chatter so nobody notices. That radio is Command-and-Control. Without the key, the spy gets locked out; without the radio, the spy is blind and useless. Every serious intrusion needs both.
This is where a break-in becomes a breach. The longer the spare key stays hidden and the radio keeps whispering, the more the attacker learns, steals, and spreads. Find the key, jam the radio — and the whole operation collapses.
What "Installation" Really Means
Installation is establishing persistence — making sure the attacker's access survives reboots, logoffs, and the user simply closing the malicious file. The foothold becomes permanent furniture.
An exploit is a moment; persistence is a tenancy. Attackers invest heavily here because getting back in is far more expensive than staying in. Every persistence trick abuses a legitimate "run this automatically" feature the OS already provides.
Where Attackers Hide the Spare Key
Modern persistence increasingly uses no malware file at all — a stolen account, a scheduled task calling a built-in tool, a tweaked config. Nothing for a signature scanner to catch. That's why defenders watch changes and behavior, not just files.
Digging In Deeper
Persistence rarely stops at one low-privilege foothold. Attackers widen it — more power, more machines — so losing one door doesn't lock them out.
Go from a normal user to admin / SYSTEM / root — by abusing a local flaw, a misconfiguration, or harvested credentials. More power means stronger, stealthier persistence.
Spread from the first machine to others using stolen credentials and trust relationships. Plant the spare key on many hosts, so eviction from one changes nothing.
By the time an attacker has admin rights on several machines plus valid accounts, "remove the malware" is no longer enough. This is why fast detection in the early phases is worth so much more than cleanup later — the cost of eviction explodes with every machine they touch.
Finding the Hidden Key
Now It Needs to Phone Home
A persistent foothold sitting silently is useless to the attacker. To receive orders and send back loot, it must reach out to infrastructure the attacker controls. That channel is Command-and-Control.
The installed implant wakes up and quietly asks: "Headquarters, I'm in — what now?" It must do this without tripping alarms, so it disguises its calls as ordinary traffic — a web request, a DNS lookup, a cloud API call — things that leave your network every second of every day.
C2 almost always goes outbound, because firewalls trust traffic leaving far more than traffic coming in. Defenders win by scrutinizing what leaves as hard as what enters — the radio has to transmit, and transmission can be detected.
What Command-and-Control Is
C2 is the two-way secret channel between the attacker's implant on your host and the attacker's server outside. Orders flow in; stolen data and status flow out.
Implant / agent = the attacker's code on your host. Beacon = its periodic check-in. C2 server = where it calls. The gap between beacons is the sleep interval — long sleeps mean stealth, short sleeps mean responsiveness.
Beaconing — the Heartbeat
Instead of a constant connection (easy to spot), most implants beacon: a brief check-in at intervals, then silence. Like a sleeper agent calling a payphone once a day, then disappearing.
Regularity betrays it. Even with random jitter, a host quietly calling the same destination at loosely-fixed intervals, forever, looks nothing like human browsing. Detecting that rhythm — "beacon analysis" — is one of the most reliable ways to find hidden C2.
The Channels C2 Rides
Attackers pick channels that blend into normal traffic — the busier and more trusted, the better the camouflage.
| Channel | Why it's chosen | Defender's angle |
|---|---|---|
| HTTPS | Encrypted & everywhere — hides in normal web traffic | TLS inspection, reputation, beacon timing |
| DNS | Rarely blocked; leaks out even locked-down networks | Watch odd/long/high-volume lookups |
| Cloud / SaaS | Hides behind trusted domains (Drive, Slack, GitHub) | Baseline normal app use; flag anomalies |
| Social / webmail | Commands posted where traffic looks personal | Egress policy, DLP on uploads |
| Domain fronting | Makes traffic appear to go to a trusted site | Provider controls, SNI/host mismatch checks |
As defenders inspect one channel, attackers shift to another that's harder to touch. There's no single port to block — which is exactly why C2 defense is about behavioral anomalies and egress control, not a firewall rule.
How C2 Looks in 2024–2025
• Legit cloud as C2 — Slack, Discord, Telegram, GitHub, Drive
• Malleable / customizable profiles that mimic real apps
• Fast-flux & disposable domains, rotated constantly
• Encrypted DNS (DoH) to hide lookups from inspection
• Commercial red-team frameworks, abused by criminals
• Open-source C2 kits lower the barrier to entry
• C2-as-a-service rented like any SaaS
Attackers rarely build from scratch anymore
Every trend chases the same goal: make the radio sound exactly like everyone else's. When your malware talks over the same services your employees use all day, "block the bad domain" stops working — and behavior becomes the only tell.
Jamming the Radio
Killing one C2 channel is not winning — remember lateral movement. Assume multiple footholds and backup channels; investigate the full blast radius before you call it clean.
When the Update Itself Was the Spy
In a landmark supply-chain intrusion, attackers slipped malicious code into a trusted software update. When organizations installed it themselves, the implant established persistence and then — crucially — stayed quiet for days before beaconing out, mimicking the vendor's own normal traffic so it blended perfectly into legitimate noise.
Three lessons the whole industry took away: persistence can arrive through software you trust; patient, low-and-slow C2 defeats "block the obvious"; and only behavioral baselines and egress scrutiny eventually surfaced traffic that didn't belong. It reframed C2 detection around anomaly, not signature.
The exact tools change, but the pattern repeats: get in via trust, persist quietly, phone home in disguise. Defense that assumes breach — and watches what leaves — is what catches it.
Golden Rules — Both Phases
Find the Key, Jam the Radio
Installation hides a spare key so the attacker can return at will; C2 opens a quiet radio so they can command the foothold and carry out loot — both disguised as the ordinary. This is where an intrusion becomes a lasting breach. Defenders win by denying and detecting persistence and by scrutinizing everything that leaves the network. Find the key, jam the radio, and the attacker is both locked out and struck deaf.
Persistence is the spare key under the mat; C2 is the radio to headquarters — cut either one and the operation collapses. Final kill-chain phase: Actions on Objectives — steal, encrypt, destroy, or spread.
📡 End of tutorial · Press ← to review, or click Restart