find_c2_channels
Identify command-and-control channels by leveraging trusted services, binaries, and protocol abuse. Supports service-based, domain-based, tunneling, webhooks, DNS, and protocol abuse detection.
Instructions
Find C2 communication channels using LOL binaries and trusted services — LOLC2, LOTS, tunneling, webhooks, DNS, protocol abuse.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| mode | No | C2 channel mode: service (LOLC2), domain (LOTS), tunnel, webhook, dns, protocol abuse | service |
| domain | No | Domain to check for LOTS (Living off Trusted Sites) potential | |
| service_name | No | Specific service name to look up for C2 potential | |
| environment_id | No | Environment session ID returned by enumerate_host | |
| stealth_priority | No | Prioritize stealthier C2 channels | |
| available_binaries | No | List of available binaries on the target system |