DETECTION OVERVIEW
Risk Factors
Botnet C&C servers associated with malware often have TLS certificates with known hashes. C&C server connections can be established through exploits that are available to the public and can be included in malware. If a C&C connection from a compromised device is established, the attacker might be able to maintain a persistent presence or launch additional attacks on your network.
Kill Chain
Risk Score
—
Block inbound and outbound traffic from suspicious hosts at the network perimeter
Implement network segmentation and the principle of least privilege on accounts to minimize the damage caused by a compromised device