How should command-and-control evidence be reported?¶
Report command and control as layers: attempted contact, completed communication, automated beaconing, received tasking, local execution, returned results and attribution. The conclusion should stop at the highest layer the evidence proves.
State the evidential foundation¶
Identify the device and process, destination, time, repetition, responses and local effects. Say whether the assessment comes from decoded content, network metadata, resulting behaviour or intelligence association; those foundations carry different weight.
Precise language matters. Repeated connections do not necessarily mean remote control, and infrastructure previously associated with a group does not prove that group operated it in this incident. Explain shared hosting, encryption, missing content and retention gaps.
Avoid false corroboration¶
A threat-intelligence match, product alert and incident ticket may all derive from one connection. Make that dependency visible rather than presenting three descriptions of one event as independent facts.
Where only beaconing or blocked contact is supported, say so. Where commands and results are connected, describe that stronger finding directly. Keep technical infrastructure attribution separate from personal or group attribution.
Key takeaway
Report the strongest proved layer of command and control and identify whether it rests on content, metadata, behaviour or intelligence without overstating dependent evidence.