October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk3 min

HTTP/HTTPS Malleable C2: How Beacon Shapes Web Traffic

Cobalt Strike Malleable C2 can shape Beacon’s web communications, but plausible headers and HTTPS do not make traffic trustworthy. Context matters.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HTTP/HTTPS Malleable C2 is Cobalt Strike Beacon’s profile-driven method for shaping how command-and-control data is carried in web transactions and how its network indicators appear. That can make communications resemble ordinary web traffic, but it does not make them invisible or prove that a connection is legitimate. Defenders need to assess behavior and infrastructure alongside protocol and headers.

What Malleable C2 changes

Cobalt Strike describes a Malleable C2 profile as a program that specifies how data is transformed and stored in a transaction, with the reverse process used to recover it. The profile also controls Beacon network indicators. In other words, it shapes both the handling of data and aspects of how the communication looks on the network; it is not simply a choice of HTTP or HTTPS.

As an Amazon Associate I earn from qualifying purchases.

The vendor says profiles can be designed to blend with typical application traffic, emulate known adversary indicators during a defensive exercise, or deliberately make traffic stand out so a team can test whether detections fire. These are different goals. “Malleable” does not mean every profile is stealthy, or that using one defeats monitoring. Cobalt Strike summarizes one possible aim this way: “An operator can configure a Malleable C2 profile to disguise Beacon’s network signatures to blend in with typical traffic on a target network.” Cobalt Strike’s Malleable C2 overview describes the feature and its uses.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How HTTP and HTTPS fit into Beacon communications

Beacon can send GET and POST communications over HTTP or HTTPS. Those are only some of its communication options: Cobalt Strike also describes DNS tunneling and linked Beacon peer-to-peer communication over SMB or TCP. An assessment that assumes all Beacon traffic must be web traffic can therefore miss other channels.

MITRE ATT&CK’s T1071.001, Web Protocols, explains the broader adversary context: web-associated application protocols may be used to blend command-and-control communications with existing traffic or avoid network filtering. MITRE lists Cobalt Strike as software that can encapsulate a custom C2 protocol in HTTP or HTTPS. This describes a capability and a technique, not a verdict about any particular connection or use of the software.

Why a familiar-looking request is not proof of legitimacy

A plausible-looking header or web protocol is weak evidence on its own. Unit 42 documents a Beacon example with a forged HTTP Host header that suggested a reputable site, while the destination IP’s autonomous system number (ASN) owner did not fit that claimed identity. The defensive lesson is to compare the claimed host with destination ownership and the rest of the available network and endpoint evidence, rather than treating the header as authentication.

Infrastructure can complicate reputation checks, too. Unit 42 notes that command-and-control traffic hosted on public cloud platforms may be harder for reputation and URL-filtering products to identify because the provider itself is benign. Neither a mismatch nor cloud hosting is a standalone detection rule; each is a clue to weigh in context. See Unit 42’s analysis of Malleable C2 profile techniques.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What defenders should evaluate together

Rather than relying on a single protocol, header, or reputation result, consider how several kinds of evidence fit together:

  • Communication channel: Determine whether observed activity uses HTTP/HTTPS, DNS, or linked peer-to-peer communication over SMB or TCP.
  • Profile-shaped indicators: Treat familiar-looking network characteristics as configurable indicators, not as proof that the traffic belongs to a legitimate application.
  • Identity and infrastructure: Compare the claimed hostname with the destination address, ASN ownership, and available reputation information.
  • Behavior and timing: Examine the connection pattern and its relationship to endpoint activity. Cobalt Strike describes asynchronous Beacon check-ins with configurable sleep and jitter, as well as an interactive mode that can check in several times per second. These are vendor-described behaviors, not universal signatures or fixed detection thresholds.

These checks are most useful in combination. A destination mismatch may deserve investigation, for example, but it does not establish what generated the traffic without corroborating evidence.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Version-specific details and validation

Cobalt Strike’s 4.9 release material describes WinInet and WinHTTP as HTTP(S) Beacon library options. It also describes host-specific HTTP characteristics—such as URI, headers, and parameters—as configurable through host profiles. These details are tied to that release; behavior and available settings should be checked against documentation for the installed version rather than assumed to apply identically across versions or setups. See Cobalt Strike 4.9: Take Me To Your Loader.

Cobalt Strike also provides the c2lint utility to check profile syntax and perform additional checks before a profile is used. Passing those checks does not establish that a profile is safe, undetectable, or appropriate for every authorized engagement. The vendor’s Malleable C2 feature page describes the utility and profile functionality.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.