PULSAR22

AI-Driven C2 Detection
& Response Platform

Detects command-and-control by behavior, not signature.

TSCTI  ·  22 Innova Labs

Cloud-channel C2 Agentic / AI-driven C2 Statistics, not IOCs
The problem

The command channel moved. Detection didn't.

Modern command-and-control no longer needs a suspicious server. It hides inside the trusted services your organization already allows — Microsoft Graph API, GitHub, Slack, and cloud storage — so the traffic looks like ordinary business.

And the operator is disappearing too. In AI-driven agentic C2, a language model generates the commands and adapts the evasion in place of a human at a keyboard — faster, quieter, and without a fixed playbook. Signature- and IOC-based detection was built for neither. It misses both.

How it works

One pipeline, five stages

Normalized telemetry flows through a deterministic pipeline. Every stage is measurable, calibrated, and auditable end to end.

1

Ingest

Network egress and endpoint process telemetry normalized into a common schema per monitored entity.

2

Detect

Independent statistical detectors each emit a calibrated [0,1] score on a common scale.

3

Fuse

Per-entity fusion with temporal decay, correlation down-weighting, and false-alarm calibration.

4

Investigate

Incidents cluster into campaigns with the evidence, tactic chain, and rationale behind every score.

5

Respond

The reasoning layer emits intent; a deterministic policy engine and a human authorize action.

What it catches

Behavior gives it away

Beacon periodicity

Jitter-tolerant interval detection surfaces the rhythm of a callback — even when it is randomized or adaptively re-timed to look human.

AI-driven agentic C2

LLM-call detection flags egress to model-inference endpoints with tell-tale request shapes — the fingerprint of an implant reasoning in the loop.

Trusted-cloud channel abuse Coming

Per-entity baselines expose SaaS and cloud services being driven as covert control channels, against each host's own normal.

Defensible by design

Built for defenders, constrained on purpose

The guardrails are architecture, not policy. They are load-bearing constraints the system is built to respect.

Roadmap

From detection to defensible autonomy

Phase 1
MVP
Ingest, statistical detectors, calibrated fusion, analyst console.
Phase 2
Investigation
Campaign clustering, evidence drill-down, guided triage.
Phase 3
Response
Policy-gated, human-authorized containment actions.
Phase 4
Edge
Detection pushed closer to the sensor and the host.
Phase 5
Deception
Instrumented lures that surface adversary intent early.
Phase 6
Autonomy
Graduated autonomy under standing policy — still human-accountable.