GreyNoise Launches C2 Detection for Exploited Edge Devices
ID: 135d6251-c8c0-56cd-b58a-5a128797b1cb
STIX ID: report--135d6251-c8c0-56cd-b58a-5a128797b1cb
Feed Name: GBHackers
GreyNoise launched a C2 Detection capability to identify compromised edge devices (firewalls, routers, VPNs) by extracting callback destinations from observed exploit payloads and building a continuously updated dataset of malicious callback IPs and malware hashes; defenders can correlate outbound traffic with this dataset and integrate detections into SIEM/SOAR for investigation and automated response, with callback IPs classified into Unconfirmed, Stage 1 (file downloaded), and Stage 2 (C2 suspected).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
