Command and Control · Learn

What is living-off-trusted-services C2?

Run command and control through platforms the network already trusts, paste sites, code hosts, dataset hubs, request-capture services, so the traffic goes to allowlisted domains and blends in.

Command and Control · LearnAll services Download PDF
TL;DR

Living-off-trusted-services is running command-and-control and exfiltration through legitimate platforms a network already trusts, such as paste sites, code hosts, dataset hubs, or request-capture services. Because the traffic goes to allowlisted, reputable domains, blocklists and reputation filters do not flag it. A single C2 message envelope can be carried interchangeably over HTTP, dataset commits, error messages, or raw sockets. Defend with behavioural detection, not domain reputation.

By John Dill, Red Team Lead, SecureLayer7Updated

What living-off-trusted-services C2 is

Rather than stand up attacker infrastructure that can be blocked, the operator routes C2 and data theft through services the target already uses and trusts. The traffic is indistinguishable at the domain level from normal developer or workload activity, which defeats controls built on domain reputation and allowlists.

How it works and example

The attacker layers a message envelope, with type, channel, sequence, and checksum fields, over trusted services, and carries the same protocol over whatever transport is available: an HTTP request to a paste site, a commit to a dataset, text hidden in an error message, or a raw socket. In a 2026 intrusion this multi-transport approach kept C2 alive as individual channels were closed.

What to do about it

Do not rely on domain reputation. Detect on behaviour and volume: unusual programmatic use of content and capture services from server workloads, abnormal request timing, and data leaving through error channels or raw sockets. Restrict which workloads may reach these services, apply data-loss controls, and treat the ability to carry the same protocol over many transports as a strong signal.

References

  1. [1]MITRE ATT&CK: Command and Control (TA0011)(MITRE ATT&CK)
  2. [2]HuggingFace, Agent intrusion technical timeline(HuggingFace)
  3. [3]MITRE ATT&CK: Web Service (T1102)(MITRE ATT&CK)
Related terms

Allowlisting a service you trust can allowlist an attacker's C2. Talk to a security expert about behavioural detection and egress control.

FAQ

Living-off-trusted-services C2, asked often

Scope an engagement

Find the C2 and exfiltration paths before an attacker does.

We test for this and many other techniques, and ship findings with a reproducible attack, the trust boundary that failed, and a fix a defender can implement.