In this video I look for C2 traffic by doing something I call Rinse-Repeat Threat Hunting, which is a method for removing normal traffic in order to look closer at what isnt normal. The video cannot be played in your browser. The video was recorded in a Windows Sandbox in order to avoid accidentally[...]
Read the full writeup in the blog post Hunting for C2 Traffic.
Open full screen video player.