From Bits to Behavior: Detecting macOS Command and Control Through Statistical Analysis

No ratings

Presented at Objective by the Sea 8.0 by

Command and control (C2) communication, while often designed to be stealthy, inevitably leaves statistical traces within macOS logs. This talk unveils a methodology for detecting these 'statistical shadows' to expose malicious activity. We will provide a concise overview of common C2 tactics and then dive into the statistical techniques used to identify tell-tale signs like consistent callbacks and irregular timing (jitter). On top of the generic approach, we discuss the to practical implementation leveraging OSQuery and Filebeat for log collection.