Skip to content
Open access

Unveiling hidden adversaries - detecting command & control servers

Jul 2026 · Peer-to-Peer Networking and Applications · Vol 19 · 0 citations · 31 references
Computer Science

TL;DR

This research examines the effectiveness of using Elasticsearch, Kibana, and Lucene for an intelligence-driven threat hunting to identify attack infrastructure or a Command & Control (C2) server.

Abstract

The increasingly advanced forms of cyber-attacks have highlighted the importance of advanced threat hunting as a necessary skillset. The current research examines the effectiveness of using Elasticsearch, Kibana, and Lucene for an intelligence-driven threat hunting to identify attack infrastructure or a Command & Control (C2) server. By aggregating all system traffic logs and security artifacts into a single data lake/warehouse, organizations are able to leverage centralized analysis of information from different sources on a corporate scale. Utilizing Kibana’s ability to perform network and log analysis, using Lucene’s rich syntax to make sophisticated queries will empower individuals to make valuable findings from log and network traffic logs that identify behaviours and patterns typical of C2 activities. A novel intelligence-based threat hunting approach is presented here that utilizes Elasticsearch, with domain-specific language additions to refine search queries and investigate for C2 related activity. A detailed analysis of the research based on real-world datasets is conducted to evaluation the threat hunting framework’s abilities in detecting C2 servers and minimize true/false positives in relation to organizational security concerns.

Read PDF

Similar papers

Open access Aug 2026

Explainability-driven adaptive cyber deception control system for autonomous network defense

The presented framework manages to incorporate explainable scoring, convergence of behavior analysis, adaptive control, environment mutation, and reinforcement learning into one cyber deception framework and manages to incorporate all of these features while still preserving transparency and adaptability during the whole process of deception.

S. Roy, G. Khekare, Sejal Chhajed · 0 citations
#small language model Review Sep 2026

A SoK for SoCs: Reading the TI Leaves on AI for Cyber Threat Intelligence Generation and Sharing

Three research directions for automating the production of shareable intelligence are derived from a literature survey of academic papers, organizing the CTI lifecycle into three stages: Threat Data Collection, CTI Generation and Sharing, and CTI Consumption.

Saastha Vasan, Hadjer Benkraouda, Jizhou Chen et al. · 0 citations
Review Open access 2026

LLM-Driven Security and Resilience in 6G Mission-Critical Communication Networks

Working baseline levels of capability are provided with respect to current LLM-based solutions in 6G mission-critical and public safety contexts, and specific research directions to advance LLM-driven cybersecurity toward robust, adaptable, explainable, and life-safety-aware solutions are mapped out.

Siva Sai, Bhuvan Arora, Vineet Suri et al. · 1 citation
Preprint Aug 2026

Operationalizing Cyber Threat Intelligence with GraphRAG

This project asks whether feeding a report into a knowledge-graph retrieval system, Microsoft GraphRAG, rather than a standard vector-similarity retrieval system (Naive RAG), produces detection plans that rely more on these durable, top-of-pyramid clues.

A. Kabra, Prakhar Paliwal, M. Hanawal · 0 citations

LADE: LLM-Assisted Advanced Persistent Threat Detection and Explanation

Experimental results show that LLMs, when guided by rubric-based prompts and supplemented with ATT&CK domain knowledge, achieve robust performance across detection, localization, and TTP mapping tasks.

Joon-Young Gwak, Aubrey Strier, Zhaohan Xi et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.