- Select a supported behavior test for discovery, file, process, memory, or network activity
- Evaluate Sigma-derived detections in the target SIEM or EDR
- Test Snort and related network rules against traffic captured by customer network tools
- Measure alert presence, latency, severity, and retained investigation context
Private-preview family overview
Exercise C2Looper post-connection behavior without live C2.
This C2Looper overview is based on one DLL variant documented in public threat research and analyzed in Proofmetry’s internal lab. For compatible samples, the customer-deployed platform recreates the server-side interaction the malware expects. Compatibility and available behavior tests are confirmed during the demo process.
Read the defensive research briefDetection and data outcomes
Observe what the sample does—and what your controls see.
Without its original tasking path, C2Looper may initialize without reaching the behavior a detection or model is intended to recognize. Proofmetry offers predefined behavior tests mapped to the covered variant, and the customer-held sample produces the endpoint and network activity.
- Collect endpoint and network telemetry with customer-operated tools while the customer-held sample runs
- Label those records with the sample, selected test, timing, and observed outcome
- Use customer-owned data for feature research, holdout evaluation, and model regression
- Keep raw telemetry and proprietary labels in customer-controlled systems
Internal research basis
Eight handlers mapped. Seven paths observed.
Static analysis mapped eight command handlers in one C2Looper DLL. Isolated execution observed seven handler paths; directory enumeration remained static-only. Those findings apply only to the analyzed variant. Implementation and protocol details remain private.
Observed behavior
The analyzed sample produced discovery, file, process, local-memory, and redirected-network activity in the internal lab.
Research scope
The findings describe the analyzed DLL variant and lab environment. Detection and model results depend on each customer’s sensors and configuration.
Private-preview workflow
Run a supported behavior test in your lab.
Proofmetry is in private preview. Compatibility and available behavior tests are confirmed before a customer run.
- 01
Prepare
Confirm sample authorization, containment, egress controls, and customer instrumentation.
- 02
Select
Choose a predefined behavior test available for the covered C2Looper variant.
- 03
Exercise
Proofmetry provides the expected server-side interaction; the customer-held sample performs the behavior defined by the selected test.
- 04
Evaluate
Assess detections or label customer-collected telemetry with the sample, selected behavior test, and observed outcome.
Responsibility boundary
Proofmetry provides the interaction. Your team controls execution and collection.
Proofmetry provides the behavior test and expected observations. Your team supplies the sample, runs the lab, and keeps the telemetry.
- Supported C2Looper variant
- Predefined behavior tests
- Expected host and network observations
- Known coverage limits
- Authorized, customer-held sample
- Isolation, egress policy, and operating supervision
- API traces, ETW, logs, PCAP, EDR, sandbox, or other instrumentation
- Rules, labels, storage, retention, and evaluation decisions
Private preview
Discuss your C2Looper testing objective.
Request a demo, and we’ll follow up to discuss your sample hash, the behavior you need to test, and the instrumentation you plan to use.