Beaconing is a command-and-control technique in which malware on a compromised system periodically sends outbound check-in requests to an attacker's server, bypassing firewall restrictions that block inbound connections.
Beaconing
One of the indicators that we are looking for is something called beaconing. Essentially, beaconing is that strange traffic that is going outside of our network. But it's a specific type of strange traffic, so let's take a look at what that is.
Beaconing is associated with command and control, where you have some sort of controlling software and maybe some sort of botnet on here. This laptop in this case right here -- it could be a server, it could be something else -- is controlling this computer.
But the thing is, maybe this adversary tricked somebody into installing malware on this computer. Maybe that was through a removable device, or through email, or whatever the case may be. The malware got installed on here, but this adversary doesn't actually have access to control that computer directly. It can't make it past the firewall -- it gets denied right there. That's what the firewall's job is to do.
But traffic usually can go out from the inside to the outside just fine. So what happens is that this computer reaches out and says, "Hey, do you have anything for me to do?" And it does that on some sort of interval. Maybe it's a second, maybe it's a minute, maybe it's every 10 minutes, maybe it's every day, maybe it's every 10 days. Whatever the interval is, it's going to check and say, "Hey, do you have anything for me to do? Hey, do you have anything for me to do? Hey, do you have anything for me to do?" And check in. So we call that beaconing.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →