Command and Control (C2)
I'll sum up what C2s are again here, too lazy to do it for now
C2 over DNS
network.protocol: dns AND NOT dns.question.name: *arpa AND dns.question.registered_domain:whatever.xyz AND host.name: WKSTN-1 

Last updated