TechKnowSurge
VideoSecurityFree

Command and Control (C2)

Command and control (C2) is a technique used by attackers to remotely access and manipulate compromised systems within a target network. It appears as a phase in the Cyber Kill Chain, a tactic in the MITRE ATT&CK framework, and a category of malicious software.

Complete this video to capture a CTF flag worth 1 point.

About this video

Command and control, or C2, is one of the foundational concepts in understanding how cyberattacks are structured and executed. It describes the mechanism by which an attacker, typically operating from outside the target network, establishes persistent remote access to a compromised system and issues instructions to it. This relationship between attacker-controlled infrastructure and an infected host is what defines C2 as both a technique and a stage in an attack lifecycle. Within established security frameworks, C2 occupies a specific position as a phase in the Cyber Kill Chain and as a recognized tactic in the MITRE ATT&CK framework, reflecting how consistently it appears across real-world intrusions. It can also be understood as a category of malware, where purpose-built software on the attacker's system communicates with an agent or implant running on the victim's machine. Together, these two components create a remote control channel that allows the attacker to execute commands, exfiltrate data, and further their objectives inside the compromised environment.

What you'll learn

What's covered

Command and Control (C2)

Key terms

Command and Control
C2
Command and Control refers to the infrastructure and communication channels used by attackers to issue instructions to and receive data from compromised systems, enabling persistent access and coordinated attack operations.
Malware
Software specifically designed to disrupt, damage, or gain unauthorized access to a system.
Botnet
A network of compromised computers controlled by an attacker, often used to conduct distributed attacks.
Threat Actor
An individual or group responsible for a security incident or attack.

Topics

Command And Control Cyber Kill Chain Mitre Attack Threat Intelligence Malware Cybersecurity

Transcript

Command and control could be a type of malware, but it also could be other things as well.

We see that command and control is a phase inside the cyber kill chain. Not only is it a phase there, but we could also see it as a tactic in the MITRE ATT&CK.

Ultimately, we're probably outside of the network and we need to have access into the network and be able to control a resource inside the network. So we set up a command and control. A command and control is a way that we can control a computer that's on the network that we're trying to attack. So we use special software to carry out command and control.

So essentially, I like to think of command and control in several different ways. I like to think of it as a phase in the MITRE ATT&CK. I also like to think of it as a tactic, or an attack that I carry out. It's also a malware or software that can be categorized as command and control. That is, I'm going to have software on my machine that's going to control software on another machine. So it's remote control of another machine.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →