Skip to content
StrikeCyberStrikeCyber
Red Teaming

Command & Control

The stage where we set up covert communication with the compromised environment and test whether your monitoring notices anything at all. This is where detection and response are put under genuine pressure.

How it works

Inside Command & Control

01

Covert C2 Channels

Once inside, an attacker needs to communicate without being seen. Whether your tooling spots that traffic is a real test of your defences.

Our methodology

We establish stealthy command and control channels that blend with normal traffic, testing whether your monitoring detects covert communication, mapped to the MITRE ATT&CK Command and Control tactic.

  • C2
  • Covert channels
  • MITRE ATT&CK
02

Endpoint and EDR Evasion

Modern defences centre on endpoint detection. An adversary who slips past EDR operates freely.

Our methodology

We apply endpoint and EDR evasion techniques to stay below detection thresholds, showing exactly where your endpoint tooling would and would not catch a capable attacker.

  • EDR evasion
  • Defense Evasion
  • Stealth
03

Testing Detection and Response

The point is not just to evade, but to measure how and when your team would notice and respond.

Our methodology

Where in scope we apply log manipulation and timed actions to exercise the Defense Evasion tactic, giving a clear read on your detection coverage and response speed.

  • Detection
  • Response
  • Log manipulation
FAQ

Command & Control FAQs

What is the command and control stage?

It is where we set up covert communication with the compromised environment and test whether your monitoring notices. We establish stealthy C2 channels, apply endpoint and EDR evasion and, in scope, log manipulation to stay below detection thresholds, exercising the MITRE ATT&CK Command and Control and Defense Evasion tactics.

Will this trigger our security alerts?

That is precisely what we are testing. Part of the value is learning which activity your monitoring catches and which it misses, so both outcomes are useful and are documented for your blue team.

Is EDR evasion safe to run?

Yes. Techniques are applied under controlled rules of engagement without damaging systems or data. Anything higher-risk is agreed in advance.

How does this help our SOC?

The results show your detection gaps in concrete terms and feed directly into detection tuning, which is taken further in purple team collaboration.

Talk to an operator about your engagement

Scope this with a senior operator. Fixed scope, fixed price, no obligation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation