Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

HTTP/HTTPS Malleable C2 is Cobalt Strike Beacon’s profile-driven method for shaping how command-and-control data is carried in web transactions and how the traffic appears on a network. A profile can make communications resemble typical application traffic, imitate known indicators for a defensive exercise, or deliberately stand out. None of those choices makes HTTP or HTTPS traffic inherently legitimate or invisible.

What Malleable C2 changes

Cobalt Strike describes a Malleable C2 profile as a program that specifies how data is transformed and stored in a transaction, and how the data is recovered in the reverse direction. It also controls Beacon’s network indicators. In practical terms, the profile affects the appearance and structure of communications; it does not change the fact that Beacon is exchanging command-and-control data.

The vendor describes three distinct simulation goals: blend with typical application traffic, emulate indicators associated with a known adversary to test defenses, or make traffic conspicuous to check whether monitoring detects it. “Malleable” therefore means configurable, not automatically stealthy. Cobalt Strike summarizes one possible use this way: “An operator can configure a Malleable C2 profile to disguise Beacon’s network signatures to blend in with typical traffic on a target network.” (Cobalt Strike: Malleable C2)

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How HTTP and HTTPS fit into Beacon communications

Beacon can send commands using HTTP or HTTPS GET and POST transactions. These are only some of its communication options: Cobalt Strike also describes DNS tunneling and linked Beacon peer-to-peer communications over SMB or TCP. An assessment of possible C2 should therefore consider the channel in use rather than assume all Beacon communication is web traffic. (Cobalt Strike: Beacon)

MITRE ATT&CK classifies web protocols as an application-layer protocol technique adversaries may use to blend communications with existing traffic or avoid network filtering. Its description includes Cobalt Strike as software that can encapsulate a custom C2 protocol in HTTP or HTTPS. This is threat-behavior context, not evidence that every web connection—or every authorized use of Cobalt Strike—is malicious. (MITRE ATT&CK: Web Protocols, T1071.001)

Why a familiar-looking request is not proof of legitimacy

A plausible hostname or User-Agent is only one piece of a connection’s story. Unit 42 documented a case in which a Beacon profile used a forged HTTP Host header to suggest an association with a reputable site, but the destination IP’s autonomous system number (ASN) owner did not fit that claimed identity. Public-cloud infrastructure can also complicate reputation and URL-filtering decisions: a benign cloud provider does not establish that a particular workload or connection is benign. These are contextual clues, not standalone detection rules. (Unit 42: Detecting Popular Cobalt Strike Malleable C2 Profile Techniques)

Defenders can compare several kinds of evidence rather than treating an individual header or protocol as a verdict:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Claimed identity and destination: Check whether the hostname in the request is consistent with the destination address and its network ownership.
  • Observed behavior: Evaluate the connection alongside relevant endpoint and network evidence, not just the request’s apparent web formatting.
  • Timing and interaction: Consider whether check-in timing and communication patterns fit the environment and the behavior under investigation.
  • Channel: Account for HTTP or HTTPS, DNS, and peer-to-peer SMB or TCP communication where relevant.

Timing can vary with the Beacon mode

Cobalt Strike describes asynchronous Beacon check-ins with configurable sleep and jitter, as well as an interactive mode that can check in several times per second. These are product behavior descriptions, not universal signatures: timing should be interpreted in context and cannot by itself identify a connection as Beacon. (Cobalt Strike: Beacon)

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Version details and profile validation

Cobalt Strike’s 4.9 release material describes WinInet and WinHTTP library options for HTTP(S) Beacon. It also describes host-specific HTTP characteristics—including URIs, headers, and parameters—as configurable through host profiles. These details are specific to the version and implementation described; consult documentation matching the installed Cobalt Strike version before relying on them. (Cobalt Strike 4.9: Take Me To Your Loader)

The vendor-provided c2lint utility checks profile syntax and performs additional checks before a profile is used. Passing those checks is a validation aid, not proof that a profile is safe, undetectable, or appropriate for every authorized engagement. (Cobalt Strike: Malleable C2)

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.