C2 Beaconing Detected (Cobalt Strike / Sliver / Generic)
Outbound C2 beacon confirmed. Profile the implant family (Cobalt Strike / Sliver / generic), isolate the host, hunt for peers on the same beacon profile.
What this playbook does
C2 Beaconing Detected (Cobalt Strike / Sliver / Generic) guides the responder from the initial signal through containment, evidence capture and verifiable close. Each step records who did what and when, so the work finishes with an audit trail you can hand to a regulator, an insurer, or your own board.
Cyber Toolbox does not detect the event — it assumes your monitoring tools, an external alert or a phone call already surfaced it. Once you have the signal, this playbook is the structured response: pick it, walk it across the affected assets, and promote it to a managed case the moment it earns one.
This is a Community playbook — free to walk against your own assets on every plan, including the free tier.
When you open it
A response is created in the app, linking the asset you're working to this playbook. The walker takes you step by step — you capture the inputs each step asks for (logs pulled, screenshots, decisions made), promote to a case if it earns one, and close with a defensible record you can export.
Cyber Toolbox launches 31 July 2026.
Get a heads-up the moment Community opens — free for a single operator.
At a glance
- Lifecycle
- Incident response
- Code
- PB-CIRP-112
- Category
- Enterprise IT
- ATT&CK techniques
- 7
- Tier
- Community (free)
Every playbook carries the methodology on rails — structured phases, severity rules, decision points and evidence capture. The tier sets where it unlocks, not how it walks.