Staring into the Darkness: Compromised C2 Server Analysis for Network Threat Hunting
Network threat hunting has traditionally focused on what’s happening inside the network. We look for signatures in network traffic, behavioral anomalies, endpoint telemetry, and indicators that tell us an attacker is already present. But what if we’re looking in the wrong direction? Very little research has been done on the systems our users and applications are actually communicating with. What do compromised internet-facing endpoints look like? What characteristics do command and control infrastructure, compromised servers, and attacker-controlled systems share? More importantly, how can defenders use that information to make better decisions? In this presentation, John Strand will share research analyzing compromised endpoints across the internet and the unexpected patterns that emerge. While you’ll find many of the things you’d expect, including exposed services, known vulnerabilities, and misconfigured systems, you’ll also see surprising discoveries, including infostealer logs, large-scale data breach artifacts, and other indicators that dramatically increase the risk profile of these hosts. Attendees will learn practical techniques for incorporating external endpoint intelligence into network threat hunting, SOC operations, and AI-assisted detection playbooks. Rather than treating every outbound connection equally, you’ll learn how to build a risk-based understanding of the systems your organization communicates with and use that intelligence to improve detections, investigations, and response. If we’re serious about network threat hunting, we can’t just stare inward. Sometimes the most valuable indicators are hiding in the darkness on the other side of the connection.
Speaker

John Strand
Managing Intern BHIS
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.... read more