Cover Image for Anatomy of a C2 Framework: Why Your Agent Leaves the Traces It Does
Cover Image for Anatomy of a C2 Framework: Why Your Agent Leaves the Traces It Does
Avatar for TryHackMe
Presented by
TryHackMe

Anatomy of a C2 Framework: Why Your Agent Leaves the Traces It Does

YouTube
Registration
Registration Closed
This event is not currently taking registrations. You may contact the host or subscribe to receive updates.
About Event

​Anatomy of a C2 Framework: Why Your Agent Leaves the Traces It Does

​This is a free teaser lightning session for Operating C2 for Red Team Operations: Pivoting & Beacon Object Files, running on 1 October 2026.

​

​A C2 agent has to check in, reach your infrastructure, run code, and survive a reboot. Every one of those requirements leaves a trace. That is not a flaw in your framework, it is the cost of the requirement.

​Once you can see which traces come from a config value and which come from the job itself, you stop guessing about your own footprint.

​What you will learn:

  • ​What every C2 is actually made of, and why each piece exists

  • ​Where the signatures come from, mapped back to the requirement that creates them

  • ​Which traces are configuration, and which no setting can remove

  • ​How to inventory the footprint of your own setup, with AI doing the heavy lifting

  • ​What to expect from the full workshop

​Who this class is for:

  • ​Operators who use a C2 daily but have never looked at how one is built

  • ​Anyone who has had a session go loud and never worked out which trace gave them away

  • ​Blue teamers who want the offensive side of the telemetry they triage

​What is included:

  • ​Live, instructor-led teaser session

  • ​Both views of the same session, attacker and defender

  • ​The footprint map we build during the class, yours to keep

​Learn directly from:

​Ariz Soriano, Senior Content Engineer at TryHackMe and Associate Director of Red Team Operations at THEOS Cyber. Ariz built the Theos red team from the ground up and now runs a practice delivering multiple concurrent APT simulation and purple teaming engagements a year. At TryHackMe he creates hands-on cybersecurity labs based on real-world attack techniques.

​Andrea Brosio, Senior Content Engineer at TryHackMe. Offensive security engineer with 6+ years of experience in red teaming: malware development, EDR evasion techniques, and building offensive tooling. Currently building AI driven pipelines for automated vulnerability discovery and exploitation. Speaker at DEF CON and multiple BSides events.

Avatar for TryHackMe
Presented by
TryHackMe