Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is command and control over web traffic?

Web-based command and control uses HTTP or HTTPS requests to carry check-ins, tasks or results. Common ports and encryption let it blend with browsing and application traffic but do not make it harmless.

Preserve request-level evidence

Identify the responsible process, domain and address, URL path, method, headers, user agent, certificate, request and response sizes, timing and proxy record. Full gateway metadata may be retained briefly and can be more discriminating than destination reputation.

Process origin matters: the same URL used by a browser, background service, script or injected process can have different meanings.

Work with encrypted traffic carefully

Where content was not logged or decrypted, metadata, periodicity and local effects still have value. A response followed by a new process, download or account change can support tasking, while an unusual request alone may be telemetry or an API call.

Shared or compromised websites can carry ordinary and control traffic together. State whether the conclusion rests on content, metadata or resulting behaviour and avoid inferring commands from HTTPS alone.

Key takeaway

Assess web control through the originating process, detailed request pattern and resulting system activity, including clear limits where encryption hides content.

Reference: CIM-150Cyber Incidents & Offender Methods