Data Exfiltration and C2 Channel Response
When an active C2 channel or data exfiltration indicator is detected, executes beacon/DNS tunnel identification, network isolation, C2 infrastructure blocking, affected data scoping, and implant eradication.
Prepare
7 steps- Network telemetry validation
Periodically verify that Zeek/NetFlow collection with Sysmon EID 3 (NetworkConnect) and EID 22 (DNSQuery) logs are flowing to SIEM; and that JA3/JA4+ fingerprint calculations are being written to Zeek ssl.log
- DNS monitoring infrastructure
Confirm that all DNS queries pass through the corporate resolver, that the DNS RPZ policy and DNS query logs are available in SIEM; verify that DoH traffic is tunneled through a proxy or disabled on endpoints
- Network isolation authorization
Document that the authorization chain for EDR console access and network isolation (SOC L2 → IR manager) is defined; the isolation decision can affect business continuity and therefore cannot be made by L1 alone
- C2 sinkhole procedure
Confirm that the DNS sinkhole and NGFW block procedure (specific to Windows DNS, Infoblox, or Umbrella environment) is documented in advance
- Evidence preservation infrastructure
Verify that immutable storage for pcap/NetFlow and a chain-of-custody form are ready; document the SHA-256 hash recording procedure
- DLP and proxy TLS inspection status