• Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

Merlin C&C HTTP Connection

Risk Factors

The Merlin framework is publicly available and has been associated with known attack campaigns. Command-and-control (C&C) connections generated by a Merlin agent indicate that an attacker could remotely control a device and gain an entry point for further attacks on the network.

Kill Chain

Command-and-Control

Risk Score

88

Detection diagram
Next in Command-and-Control: Metasploit C&C TLS Connection

Attack Background

Merlin is a post-exploit framework. An attacker installs a Merlin agent on the victim device. The agent establishes a connection with an attacker-controlled server and sends a specially designed HTTP POST request. These types of requests can contain command output and other information that is valuable to the attackers.

Mitigation Options

Quarantine the device while checking for the presence of malware
Monitor and investigate unusual network activity for lateral movement or data exfiltration

MITRE ATT&CK ID

What else can RevealX do for you?