Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is command and control?

Command and control is communication used to manage compromised software, devices or accounts. It may carry check-ins, configuration, tasks, payloads or results; one connection to suspicious infrastructure does not prove all of those functions occurred.

Establish the relationship

Identify the responsible process or account, destination, protocol, timing, frequency and data exchanged. Endpoint, DNS, proxy, firewall, capture and malware-configuration evidence can link network traffic to local activity.

Separate outbound contact, server response, tasking, command execution and result reporting. A connection establishes communication, while process or file changes after a response may support received commands.

Map the full control path

Channels can use relays, compromised servers or legitimate cloud services. The first visible destination may not be where an operator creates tasks, and shared infrastructure may host unrelated users.

Preserve each identified layer and whether contact continued after containment. Technical communication, infrastructure control and personal operation remain distinct attribution questions.

Key takeaway

Prove command and control as a relationship from compromised process through communication and tasking to resulting activity, not from destination reputation alone.

Reference: CIM-143Cyber Incidents & Offender Methods