Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Sources for post-infection PCAP (C2 beaconing, exfiltration) - what am I missing?

0
Medium
Published: 08/03/2026 (08/03/2026, 01:55:26 UTC)
Source: Reddit BlueTeam

Description

This entry discusses the challenge of obtaining publicly available post-infection network traffic captures (PCAPs) showing command-and-control (C2) beaconing and data exfiltration from compromised hosts. While pre-infection traffic sources such as malware delivery URLs and exploit attempts are readily accessible, sustained post-infection traffic captures are scarce or limited to older datasets, small-scale analyst investigations, or short sandbox runs. The community-driven abuse.ch platform provides extensive threat intelligence but does not currently offer continuous post-infection PCAP data. The discussion highlights the difficulty in sourcing long-duration post-infection captures for research and detection development.

Reddit Discussion

r/blueteamsec·posted by u/khbjane
00

Been going in circles on this and want to check whether there's something obvious I've overlooked.

Pre-infection traffic is easy to collect. URLhaus gives you live malware delivery URLs daily, a honeypot gives you scanning, brute force and exploit attempts. Both free, both refresh constantly, both self-labeling.

Post-infection is where I'm stuck. C2 beaconing and exfiltration only exist if there's an actually compromised host emitting traffic, and nobody publishes captures of that at any useful cadence.

What I've checked so far:

  • abuse.ch across all platforms. Indicators only, no traffic. Feodo Tracker is empty post-Endgame. SSLBL cert and C2 IP lists are current and useful as labels but aren't packets. Sandnet exists behind the commercial feed but the dataset description says signals and metadata, contextual data only, so flow records rather than PCAP.
  • CTU/MCFP. Real long-duration captures with actual beaconing, which is exactly right, but new botnet captures stop around 2018. Recent directory timestamps are reprocessing, not new data.
  • malware-traffic-analysis.net. Best labels anywhere and current, includes a few FTP and SMTP exfiltration cases. Small volume by nature, it's one analyst posting individual investigations.
  • Sandboxes. Triage free researcher tier gives API access with PCAPNG including decrypted TLS. ANY.RUN needs a paid tier for bulk. Both are short runs so you get the initial check-in rather than sustained beaconing.
  • Running my own detonation. Ruled out. Normal hosting AUPs prohibit it and the ones that don't are bulletproof hosts, which isn't somewhere I'm willing to source data from.

So the question. Is there a source I'm not aware of, or is the honest answer that post-infection traffic just isn't publicly available and everyone working on this either has institutional telemetry or a sandbox subscription?

Also curious whether anyone has found a way to get sustained beaconing rather than just registration out of a commercial sandbox. Long-run options seem rare.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/03/2026, 19:33:29 UTC

Technical Analysis

The threat context centers on the scarcity of publicly available post-infection PCAP data that includes C2 beaconing and exfiltration traffic from compromised hosts. Pre-infection traffic data is widely available through platforms like abuse.ch, URLhaus, and honeypots, but post-infection captures are limited to older datasets (e.g., CTU/MCFP up to 2018), small analyst investigations (malware-traffic-analysis.net), or short sandbox executions (Triage, ANY.RUN). Commercial sandboxes provide some data but often require paid access and do not support long-term beaconing captures. The abuse.ch community and platforms focus on sharing indicators of compromise and metadata rather than continuous packet captures. This gap presents a challenge for researchers seeking sustained post-infection network traffic for analysis and detection.

Potential Impact

The lack of publicly available, sustained post-infection PCAP data limits the ability of security researchers and defenders to study real-world C2 beaconing and exfiltration behaviors comprehensively. This gap can hinder the development and validation of detection mechanisms for post-compromise activities. However, no direct vulnerability or exploit is described, and no known exploits in the wild are reported. The impact is primarily on threat intelligence research capabilities rather than immediate operational security risk.

Mitigation Recommendations

No direct mitigation is applicable as this is not a vulnerability but a discussion about data availability. Researchers and defenders are advised to leverage existing platforms like abuse.ch for indicators and metadata, use available sandbox services for initial infection traffic, and consider institutional telemetry or commercial sandbox subscriptions for more extensive post-infection data. There is currently no official fix or patch since this is an intelligence sourcing issue rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":38,"reasons":["external_link","newsworthy_keywords:rce","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["rce"],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a70ecf6bf32cb7a341591fc

Added to database: 08/03/2026, 19:33:10 UTC

Last enriched: 08/03/2026, 19:33:29 UTC

Last updated: 08/03/2026, 22:47:52 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses