C2 Intelligence
get_c2Query live C2 intelligence for active beacons, configs, operators, watermarks, correlations, timelines, and stats. Get current command-and-control data for threat analysis.
Instructions
Query the live C2 (command-and-control) intelligence center. Pick a view: 'beacons' (active C2 beacon snapshots — default), 'configs' (full extracted C2 configs), 'operators' (operator clusters), 'watermarks' (Cobalt Strike watermark index), 'correlations' (cross-C2 correlations), 'timeline' (activity over time), 'stats' (aggregate counts). Use generate_c2_blocklist when you want firewall-ready output rather than raw records.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| view | No | Which C2 dataset to return (default 'beacons') | |
| limit | No | Max records for paginated views like beacons (default 50, max 100) |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| asns | No | ||
| data | No | ||
| items | No | ||
| total | No | ||
| months | No | ||
| beacons | No | ||
| configs | No | ||
| clusters | No | ||
| versions | No | ||
| countries | No | ||
| aggregates | No | ||
| watermarks | No | ||
| correlations | No |