After gaining a foothold in an environment, attackers establish C2 channels to issue commands, receive data, and deploy additional tools on compromised machines. C2 communications are often disguised to blend in with normal traffic, making detection challenging. Identifying and blocking C2 activity is critical to disrupting an attack in progress, and is a key investigation step when a system is suspected to be compromised.