Sources for post-infection PCAP (C2 beaconing, exfiltration) - what am I missing?
This entry discusses the challenge of obtaining publicly available post-infection network traffic captures (PCAPs) showing command-and-control (C2) beaconing and data exfiltration from compromised hosts. While pre-infection traffic sources such as malware delivery URLs and exploit attempts are readily accessible, sustained post-infection traffic captures are scarce or limited to older datasets, small-scale analyst investigations, or short sandbox runs. The community-driven abuse.ch platform provides extensive threat intelligence but does not currently offer continuous post-infection PCAP data. The discussion highlights the difficulty in sourcing long-duration post-infection captures for research and detection development.
AI Analysis
Technical Summary
The threat context centers on the scarcity of publicly available post-infection PCAP data that includes C2 beaconing and exfiltration traffic from compromised hosts. Pre-infection traffic data is widely available through platforms like abuse.ch, URLhaus, and honeypots, but post-infection captures are limited to older datasets (e.g., CTU/MCFP up to 2018), small analyst investigations (malware-traffic-analysis.net), or short sandbox executions (Triage, ANY.RUN). Commercial sandboxes provide some data but often require paid access and do not support long-term beaconing captures. The abuse.ch community and platforms focus on sharing indicators of compromise and metadata rather than continuous packet captures. This gap presents a challenge for researchers seeking sustained post-infection network traffic for analysis and detection.
Potential Impact
The lack of publicly available, sustained post-infection PCAP data limits the ability of security researchers and defenders to study real-world C2 beaconing and exfiltration behaviors comprehensively. This gap can hinder the development and validation of detection mechanisms for post-compromise activities. However, no direct vulnerability or exploit is described, and no known exploits in the wild are reported. The impact is primarily on threat intelligence research capabilities rather than immediate operational security risk.
Mitigation Recommendations
No direct mitigation is applicable as this is not a vulnerability but a discussion about data availability. Researchers and defenders are advised to leverage existing platforms like abuse.ch for indicators and metadata, use available sandbox services for initial infection traffic, and consider institutional telemetry or commercial sandbox subscriptions for more extensive post-infection data. There is currently no official fix or patch since this is an intelligence sourcing issue rather than a software vulnerability.
Sources for post-infection PCAP (C2 beaconing, exfiltration) - what am I missing?
Description
This entry discusses the challenge of obtaining publicly available post-infection network traffic captures (PCAPs) showing command-and-control (C2) beaconing and data exfiltration from compromised hosts. While pre-infection traffic sources such as malware delivery URLs and exploit attempts are readily accessible, sustained post-infection traffic captures are scarce or limited to older datasets, small-scale analyst investigations, or short sandbox runs. The community-driven abuse.ch platform provides extensive threat intelligence but does not currently offer continuous post-infection PCAP data. The discussion highlights the difficulty in sourcing long-duration post-infection captures for research and detection development.
Reddit Discussion
Been going in circles on this and want to check whether there's something obvious I've overlooked.
Pre-infection traffic is easy to collect. URLhaus gives you live malware delivery URLs daily, a honeypot gives you scanning, brute force and exploit attempts. Both free, both refresh constantly, both self-labeling.
Post-infection is where I'm stuck. C2 beaconing and exfiltration only exist if there's an actually compromised host emitting traffic, and nobody publishes captures of that at any useful cadence.
What I've checked so far:
- abuse.ch across all platforms. Indicators only, no traffic. Feodo Tracker is empty post-Endgame. SSLBL cert and C2 IP lists are current and useful as labels but aren't packets. Sandnet exists behind the commercial feed but the dataset description says signals and metadata, contextual data only, so flow records rather than PCAP.
- CTU/MCFP. Real long-duration captures with actual beaconing, which is exactly right, but new botnet captures stop around 2018. Recent directory timestamps are reprocessing, not new data.
- malware-traffic-analysis.net. Best labels anywhere and current, includes a few FTP and SMTP exfiltration cases. Small volume by nature, it's one analyst posting individual investigations.
- Sandboxes. Triage free researcher tier gives API access with PCAPNG including decrypted TLS. ANY.RUN needs a paid tier for bulk. Both are short runs so you get the initial check-in rather than sustained beaconing.
- Running my own detonation. Ruled out. Normal hosting AUPs prohibit it and the ones that don't are bulletproof hosts, which isn't somewhere I'm willing to source data from.
So the question. Is there a source I'm not aware of, or is the honest answer that post-infection traffic just isn't publicly available and everyone working on this either has institutional telemetry or a sandbox subscription?
Also curious whether anyone has found a way to get sustained beaconing rather than just registration out of a commercial sandbox. Long-run options seem rare.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat context centers on the scarcity of publicly available post-infection PCAP data that includes C2 beaconing and exfiltration traffic from compromised hosts. Pre-infection traffic data is widely available through platforms like abuse.ch, URLhaus, and honeypots, but post-infection captures are limited to older datasets (e.g., CTU/MCFP up to 2018), small analyst investigations (malware-traffic-analysis.net), or short sandbox executions (Triage, ANY.RUN). Commercial sandboxes provide some data but often require paid access and do not support long-term beaconing captures. The abuse.ch community and platforms focus on sharing indicators of compromise and metadata rather than continuous packet captures. This gap presents a challenge for researchers seeking sustained post-infection network traffic for analysis and detection.
Potential Impact
The lack of publicly available, sustained post-infection PCAP data limits the ability of security researchers and defenders to study real-world C2 beaconing and exfiltration behaviors comprehensively. This gap can hinder the development and validation of detection mechanisms for post-compromise activities. However, no direct vulnerability or exploit is described, and no known exploits in the wild are reported. The impact is primarily on threat intelligence research capabilities rather than immediate operational security risk.
Mitigation Recommendations
No direct mitigation is applicable as this is not a vulnerability but a discussion about data availability. Researchers and defenders are advised to leverage existing platforms like abuse.ch for indicators and metadata, use available sandbox services for initial infection traffic, and consider institutional telemetry or commercial sandbox subscriptions for more extensive post-infection data. There is currently no official fix or patch since this is an intelligence sourcing issue rather than a software vulnerability.
Technical Details
- Source Type
- Subreddit
- blueteamsec+AskNetsec+Information_Security
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":38,"reasons":["external_link","newsworthy_keywords:rce","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["rce"],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a70ecf6bf32cb7a341591fc
Added to database: 08/03/2026, 19:33:10 UTC
Last enriched: 08/03/2026, 19:33:29 UTC
Last updated: 08/03/2026, 22:47:52 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.