Command and control (C2) communication, while often designed to be stealthy, inevitably leaves statistical traces within macOS logs. This talk unveils a methodology for detecting these 'statistical shadows' to expose malicious activity. We will provide a concise overview of common C2 tactics and then dive into the statistical techniques used to identify tell-tale signs like consistent callbacks and irregular timing (jitter). On top of the generic approach, we discuss the to practical implementation leveraging OSQuery and Filebeat for log collection.