Netskope is expanding UEBA’s existing portfolio of 160 ML based policies with a new SOC Detections Pack that introduces a patented approach for C2 beacon detection. Command and Control (C2) tools, such as Cobalt Strike, employ malleable profiles (patterns that cannot be fingerprinted using tools such as IPS) to circumvent traditional defenses. The SOC Detections Pack enhances Advanced UEBA by providing early detection of compromised devices where C2 beacons have been deployed.
The new license includes 15 new C2 beacon detection policies today and many more forthcoming additional detections. These new C2 detection policies analyze web traffic to identify anomalous C2 callbacks and use machine learning models to isolate C2 frameworks (such as Mythic and Cobalt Strike) from benign callbacks (such as software update checks).
For customers who recognize the importance of C2 beacon detection, the SOC Detections Pack offers significant value for detecting early compromise.

The full list of UEBA C2 policies is visible to Netskope accounts with the SOC Detections Pack license enabled.
To learn more:

