HTTP-based C2 traffic that was originally categorized with the threat
name Inline Cloud Analyzed HTTP Command and Control Traffic
Detection and is associated with multiple Threat IDs, is now
separated into multiple unique threat names to correspond to the unique
Threat IDs and more accurately describe the detections made by Advanced
Threat Prevention:
Evasive HTTP C2 Traffic Detection (Threat
ID: 89950)
Evasive Cobalt Strike C2 Traffic Detection
(Threat ID: 89955, 89956, and 89957)
Evasive Empire C2 Traffic Detection
(Threat ID: 89958)
Evasive Sliver C2 Traffic Detection
(Threat ID: 89961)
If you do not install the update content or are reviewing HTTP-based C2
traffic logs generated prior to December 11, 2023 (the release date of
the content update), all HTTP-based C2 traffic will continue to be
categorized with the threat name Inline Cloud Analyzed HTTP Command
and Control Traffic Detection.