

Anatomy of a C2 Framework: Why Your Agent Leaves the Traces It Does
Anatomy of a C2 Framework: Why Your Agent Leaves the Traces It Does
This is a free teaser lightning session for Operating C2 for Red Team Operations: Pivoting & Beacon Object Files, running on 1 October 2026.
A C2 agent has to check in, reach your infrastructure, run code, and survive a reboot. Every one of those requirements leaves a trace. That is not a flaw in your framework, it is the cost of the requirement.
Once you can see which traces come from a config value and which come from the job itself, you stop guessing about your own footprint.
What you will learn:
What every C2 is actually made of, and why each piece exists
Where the signatures come from, mapped back to the requirement that creates them
Which traces are configuration, and which no setting can remove
How to inventory the footprint of your own setup, with AI doing the heavy lifting
What to expect from the full workshop
Who this class is for:
Operators who use a C2 daily but have never looked at how one is built
Anyone who has had a session go loud and never worked out which trace gave them away
Blue teamers who want the offensive side of the telemetry they triage
What is included:
Live, instructor-led teaser session
Both views of the same session, attacker and defender
The footprint map we build during the class, yours to keep
Learn directly from:
Ariz Soriano, Senior Content Engineer at TryHackMe and Associate Director of Red Team Operations at THEOS Cyber. Ariz built the Theos red team from the ground up and now runs a practice delivering multiple concurrent APT simulation and purple teaming engagements a year. At TryHackMe he creates hands-on cybersecurity labs based on real-world attack techniques.
Andrea Brosio, Senior Content Engineer at TryHackMe. Offensive security engineer with 6+ years of experience in red teaming: malware development, EDR evasion techniques, and building offensive tooling. Currently building AI driven pipelines for automated vulnerability discovery and exploitation. Speaker at DEF CON and multiple BSides events.