Command and control (C2) is a technique used by attackers to remotely access and manipulate compromised systems within a target network. It appears as a phase in the Cyber Kill Chain, a tactic in the MITRE ATT&CK framework, and a category of malicious software.
Command and Control (C2)
Command and control could be a type of malware, but it also could be other things as well.
We see that command and control is a phase inside the cyber kill chain. Not only is it a phase there, but we could also see it as a tactic in the MITRE ATT&CK.
Ultimately, we're probably outside of the network and we need to have access into the network and be able to control a resource inside the network. So we set up a command and control. A command and control is a way that we can control a computer that's on the network that we're trying to attack. So we use special software to carry out command and control.
So essentially, I like to think of command and control in several different ways. I like to think of it as a phase in the MITRE ATT&CK. I also like to think of it as a tactic, or an attack that I carry out. It's also a malware or software that can be categorized as command and control. That is, I'm going to have software on my machine that's going to control software on another machine. So it's remote control of another machine.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →