C2 (command and control) is the infrastructure an attacker uses to communicate with devices it has already infected: from an external server it sends commands, receives stolen data and pushes additional malware. Detecting and blocking those outbound connections cuts off the attacker's control even if the malware is still inside the network.
How TecnetOne handles it: TecnetSOC
command and control, C&C, C2 server, beaconing
Related terms
Credential stuffing
Credential stuffing is an automated attack that tries usernames and passwords leaked from other services across many sites, taking advantage of people reusing their passwords. Unlike brute force, it does not guess passwords: it replays real ones. It is countered with unique passwords, MFA, bot detection and monitoring for mass login attempts or sign-ins from unusual locations.
Hacktivism
Hacktivism is the use of cyberattacks to promote a political, social or ideological cause, for example flooding sites with DDoS attacks, defacing web pages or leaking documents from governments and companies. Groups like Anonymous made it popular, and it tends to spike around geopolitical conflicts and high-profile events.
Port scanning
Port scanning is the technique of checking which ports on a device or server are open and which services answer on them, such as web, email or remote desktop. Attackers use it to look for entry points, and security teams use it to find services that are exposed when they should not be.
Typosquatting and cybersquatting
Typosquatting is registering domains that look like a brand's with common typos, such as tecnet0ne.com, to trick people who mistype and send them to a fake phishing or malware site. Cybersquatting is registering a domain with a brand's exact name in bad faith, to resell it or profit from its reputation.
Cyber threat
A cyber threat is any person, event or circumstance that can harm a company's systems or information, such as a cybercriminal, malware, human error or a power failure. Risk arises when a threat can exploit an existing vulnerability.
Supply chain attack
A supply chain attack compromises a company through a trusted vendor, for example by infecting a software update, a code library or a managed service provider's remote access. It works because the victim trusts what comes from that vendor, which is why third-party risk must be assessed.
Ready to put this into practice in your operation?
Tell us what you need and a TecnetOne engineer will get back to you.
Talk to an engineerTalk to an engineer
Tell us what you need and we’ll reply the same business day.