Skip to content
days until launch · 31 July 2026 ·
Cyber Toolbox
Back to library
Incident responsePB-CIRP-112·Enterprise ITFree

C2 Beaconing Detected (Cobalt Strike / Sliver / Generic)

Outbound C2 beacon confirmed. Profile the implant family (Cobalt Strike / Sliver / generic), isolate the host, hunt for peers on the same beacon profile.

Browse more

What this playbook does

C2 Beaconing Detected (Cobalt Strike / Sliver / Generic) guides the responder from the initial signal through containment, evidence capture and verifiable close. Each step records who did what and when, so the work finishes with an audit trail you can hand to a regulator, an insurer, or your own board.

Cyber Toolbox does not detect the event — it assumes your monitoring tools, an external alert or a phone call already surfaced it. Once you have the signal, this playbook is the structured response: pick it, walk it across the affected assets, and promote it to a managed case the moment it earns one.

This is a Community playbook — free to walk against your own assets on every plan, including the free tier.

When you open it

A response is created in the app, linking the asset you're working to this playbook. The walker takes you step by step — you capture the inputs each step asks for (logs pulled, screenshots, decisions made), promote to a case if it earns one, and close with a defensible record you can export.

Cyber Toolbox launches 31 July 2026.

Get a heads-up the moment Community opens — free for a single operator.

At a glance

Lifecycle
Incident response
Code
PB-CIRP-112
Category
Enterprise IT
ATT&CK techniques
7
Tier
Community (free)

Every playbook carries the methodology on rails — structured phases, severity rules, decision points and evidence capture. The tier sets where it unlocks, not how it walks.