Hunting for C2 Traffic

#Threat Hunting #PCAP #CapLoader #NetworkMiner #NetworkMiner Professional #QBot #QakBot #51c64c77e60f3980eea90869b68c58a8 #IcedID #TA578

In this video I look for C2 traffic by doing something I call Rinse-Repeat Threat Hunting, which is a method for removing 'normal' traffic in order to look closer at what isn't normal. The video cannot be played in your browser. The video was recorded in a Windows Sandbox in order to avoid accidenta[...]

Read the full writeup in the blog post Hunting for C2 Traffic