Data Exfiltration and C2: Post-exploitation abuse of legitimate channels
A comprehensive defense-perspective analysis of data exfiltration and C2 channels: DNS tunneling (iodine/dnscat2), HTTPS C2, beaconing and jitter, domain fronting (largely blocked by major CDNs), malleable C2 (Cobalt Strike), staging/compression/encryption, ICMP and cloud storage exfil, and DoH. For detection: NetFlow/Zeek, JA3/JARM/JA4+, RITA beacon analysis, DNS entropy; for prevention: egress filtering, DNS RPZ, and TLS inspection.