Glossary term

Command and Control (C2)

The infrastructure an attacker uses to send instructions to compromised hosts and receive data back. Modern C2 blends into normal HTTPS traffic to avoid detection.

Browse Attack Techniques →

Related entries

More glossary terms

Zero-Day
A vulnerability being exploited before the vendor has a patch available, so defenders have had zero days to prepare. Once a patch exists it is no long...
Server-Side Request Forgery (SSRF)
Coercing the server into making a request to a destination of the attacker's choosing, typically to reach internal services or cloud metadata endpoint...
Principle of Least Privilege
Every account, process and token receives only the minimum permissions required for its task, for the minimum time required, and no more.
Attack Surface
The total set of points where an unauthorised user can attempt to enter or extract data: exposed ports, endpoints, features, credentials and physical...
CVE
Common Vulnerabilities and Exposures. A public identifier such as CVE-2021-44228 assigned to a specific vulnerability, giving everyone one unambiguous...
← Back to glossary

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used