C2 Beacon Detection Calculator
C2 beacons are mathematically distinctive — they call home at regular intervals with low variance. This tool explains the statistics, lets you configure your thresholds, and generates the exact SIEM query to find beaconing behaviour across your entire network in one query.
Configure beacon detection parameters
Connections below this count are ignored — too few to calculate reliable statistics. Typical beacon: 500+ connections per day.
Lower = stricter. Beacons have low std dev (2–15s). Normal browsing has high std dev (hundreds of seconds). Start with 15, tune down.
Exclude very frequent connections (CDN, streaming). Typical C2 beacon: 60s, 300s, or 600s intervals.
Exclude very slow beacons that look like normal background traffic. 3600s (1hr) is a good ceiling.
Understanding beacon statistics
Why standard deviation works
A C2 beacon calls home every N seconds ± jitter. The jitter makes individual connections look normal, but mathematically, the variance (standard deviation) of the inter-connection intervals is very low. Normal web traffic has chaotic timing — very high standard deviation. A beacon to 185.x.x.x every 60 seconds ± 3 seconds has a std dev of ~3. A user browsing the web has a std dev of hundreds of seconds.
Connections: 847 over 14 hours
Mean interval: 59.8 seconds
Std deviation: 2.1 seconds → BEACON
Normal browsing:
Connections: 234 over 8 hours
Mean interval: 122 seconds
Std deviation: 847 seconds → Normal
Common beacon profiles to hunt
| Tool | Default interval | Jitter |
|---|---|---|
| Cobalt Strike | 60s | ±10% |
| Metasploit Meterpreter | 1–5s | ±varies |
| Sidewinder RAT | 120–300s | ±20% |
| CrimsonRAT (APT36) | 300s | ±varies |
| Emotet | 5–10 min | ±varies |
| Custom APT beacon | Variable | Low |
Cobalt Strike default sleep time is 60 seconds with 0% jitter — the easiest beacon to detect. Operators add jitter to evade detection but even 50% jitter produces detectable statistical patterns.