> For the complete documentation index, see [llms.txt](https://howto.thec2matrix.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://howto.thec2matrix.com/detection/basics.md).

# Basics

Detecting long connections:&#x20;

* <https://www.blackhillsinfosec.com/detecting-long-connections-with-zeek-bro-and-rita/>

Detecting beacons:&#x20;

* [https://www.activecountermeasures.com/threat-simulation-beacons](https://www.activecountermeasures.com/threat-simulation-beacons/)
* <https://www.blackhillsinfosec.com/detecting-malware-beacons-with-zeek-and-rita/>

Detecting TLS C2:

* Certificate Issues: <https://www.activecountermeasures.com/threat-simulation-certificate-issues/>
* <https://www.activecountermeasures.com/threat-simulation-client-signatures-tls-signature/>

DNS:

* <https://www.activecountermeasures.com/threat-simulation-dns/>
