Summary
During this chapter, we discussed how to investigate C&C communications by using the proxy logs with the questions, answers, and hypotheses method to investigate some C&C communications attributes, such as the web domain reputation and suspicious target domain names, the requested web resources, the referrer URL, the communications user agent, the communications destination port, the received and sent bytes, the HTTP method, and the Content-Type. Finally, we discussed some command and control techniques.
In the next chapter, we will discuss how to investigate external threats.