{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T07:06:43Z","timestamp":1784185603419,"version":"3.55.0"},"reference-count":29,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T00:00:00Z","timestamp":1784160000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T00:00:00Z","timestamp":1784160000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"funder":[{"name":"Scientific Research Deanship, University of Ha\u2019il, Saudi Arabia","award":["RG-25 013"],"award-info":[{"award-number":["RG-25 013"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Peer-to-Peer Netw. Appl."],"DOI":"10.1007\/s12083-026-02278-8","type":"journal-article","created":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T06:37:40Z","timestamp":1784183860000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Unveiling hidden adversaries - detecting command &amp; control servers"],"prefix":"10.1007","volume":"19","author":[{"given":"Naif","family":"Alsharabi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7361-0465","authenticated-orcid":false,"given":"Akashdeep","family":"Bhardwaj","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Amr","family":"Jadi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shoayee","family":"Alotaibi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ali","family":"Alferaidi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Talal","family":"Alshammari","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,16]]},"reference":[{"key":"2278_CR1","unstructured":"What is a Command-and-Control, Server? (2023) Sysdig. https:\/\/sysdig.com\/learn-cloud-native\/what-is-a-command-and-control-server\/ (accessed Aug. 13, 2024)"},{"key":"2278_CR2","unstructured":"\u200cCloudflare (2023) What is the Mirai Botnet? | Cloudflare, Cloudflare, Available: https:\/\/www.cloudflare.com\/learning\/ddos\/glossary\/mirai-botnet\/"},{"key":"2278_CR3","unstructured":"\u200c, Europol (2021) World\u2019s most dangerous malware EMOTET disrupted through global action | Europol, Europol, Jan. 27. https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-action"},{"key":"2278_CR4","doi-asserted-by":"publisher","DOI":"10.4018\/ijcac.297106","author":"A Bhardwaj","year":"2024","unstructured":"Bhardwaj A, Kaushik K (2024) Predictive analytics-based cybersecurity framework for cloud infrastructure. International Journal of Cloud Applications and Computing. https:\/\/doi.org\/10.4018\/ijcac.297106","journal-title":"International Journal of Cloud Applications and Computing"},{"issue":"16","key":"2278_CR5","doi-asserted-by":"publisher","DOI":"10.3390\/s23167273","volume":"23","author":"S Saeed","year":"2023","unstructured":"Saeed S, Suayyid SA, Al-Ghamdi MS, Al-Muhaisen H, Almuhaideb AM (2023) A systematic literature review on cyber threat intelligence for organizational cybersecurity resilience. Sensors (Basel) 23(16):7273. https:\/\/doi.org\/10.3390\/s23167273","journal-title":"Sensors (Basel)"},{"key":"2278_CR6","doi-asserted-by":"publisher","first-page":"104956","DOI":"10.1109\/ACCESS.2020.2998983","volume":"vol. 8","author":"A Bhardwaj","year":"2020","unstructured":"Bhardwaj A, Al-Turjman F, Kumar M, Stephan T, Mostarda L (2020) Capturing-the-invisible (CTI): behavior-based attacks recognition in IoT-oriented industrial control systems. IEEE Access 8:104956\u2013104966. https:\/\/doi.org\/10.1109\/ACCESS.2020.2998983","journal-title":"IEEE Access"},{"key":"2278_CR7","doi-asserted-by":"publisher","first-page":"728","DOI":"10.1109\/ACCESS.2022.3233404","volume":"vol. 11","author":"A Dimitriadis","year":"2023","unstructured":"Dimitriadis A, Lontzetidis E, Kulvatunyou B, Ivezic N, Gritzalis D, Mavridis I (2023) Fronesis: digital forensics-based early detection of ongoing cyber-attacks. IEEE Access 11:728\u2013743. https:\/\/doi.org\/10.1109\/ACCESS.2022.3233404","journal-title":"IEEE Access"},{"key":"2278_CR8","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1016\/j.eij.2022.11.001","volume":"24","author":"E Irshad","year":"2023","unstructured":"Irshad E, Siddiqui AB (2023) Cyber threat attribution using unstructured reports in CTI. Egypt Inform J 24:43\u201359","journal-title":"Egypt Inform J"},{"key":"2278_CR9","doi-asserted-by":"publisher","DOI":"10.1016\/j.jestch.2024.101791","volume":"vol. 57","author":"B Gulbay","year":"2024","unstructured":"Gulbay B, Demirci M (2024) APT-scope: a novel framework to predict advanced persistent threat groups from enriched heterogeneous information network of cyber threat intelligence. Eng Sci Technol Int J 57:101791. https:\/\/doi.org\/10.1016\/j.jestch.2024.101791","journal-title":"Eng Sci Technol Int J"},{"key":"2278_CR10","doi-asserted-by":"publisher","DOI":"10.20944\/preprints202407.1408.v1","author":"M \u200cB. Gulbay","year":"2024","unstructured":"\u200cB. Gulbay M, Demirci (2024) A Framework for Developing Strategic Cyber Threat Intelligence from Advanced Persistent Threat Analysis Reports Using Graph-Based Algorithms. Jul. https:\/\/doi.org\/10.20944\/preprints202407.1408.v1","journal-title":"Jul"},{"key":"2278_CR11","doi-asserted-by":"publisher","first-page":"107546","DOI":"10.1016\/j.compeleceng.2021.107546","volume":"96","author":"A Bhardwaj","year":"2021","unstructured":"Bhardwaj A, Al-Turjman A, Sapra F, Kumar V, M., Stephan T (2021) Privacy-aware detection framework to mitigate new-age phishing attacks. Comput Electr Eng 96:107546. https:\/\/doi.org\/10.1016\/j.compeleceng.2021.107546","journal-title":"Comput Electr Eng"},{"key":"2278_CR12","doi-asserted-by":"publisher","DOI":"10.1145\/3587255","author":"M Asiri","year":"2023","unstructured":"Asiri M, Saxena N, Gjomemo R, Burnap P (2023) Understanding indicators of compromise against cyber-attacks in industrial control systems: a security perspective. ACM Trans Cyber-Phys Syst. https:\/\/doi.org\/10.1145\/3587255","journal-title":"ACM Trans Cyber-Phys Syst"},{"key":"2278_CR13","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1016\/s1353-4858(19)30074-1","volume":"6","author":"A Bhardwaj","year":"2019","unstructured":"Bhardwaj A, Goundar S (2019) A framework for effective threat hunting. Netw Secur 6:15\u201319. https:\/\/doi.org\/10.1016\/s1353-4858(19)30074-1","journal-title":"Netw Secur"},{"key":"2278_CR14","doi-asserted-by":"publisher","DOI":"10.1016\/j.dajour.2023.100364","volume":"9","author":"F Sufi","year":"2023","unstructured":"Sufi F (2023) A global cyber-threat intelligence system with artificial intelligence and convolutional neural network. Decision Analytics Journal 9:100364. https:\/\/doi.org\/10.1016\/j.dajour.2023.100364","journal-title":"Decision Analytics Journal"},{"key":"2278_CR15","doi-asserted-by":"publisher","unstructured":"Bhardwaj A, Bharany S, Almogren A, Rehman A, Hamam H (2024) Proactive threat hunting to detect persistent behaviour-based advanced adversaries. Egypt Inf J 27. https:\/\/doi.org\/10.1016\/j.eij.2024.100510","DOI":"10.1016\/j.eij.2024.100510"},{"key":"2278_CR16","doi-asserted-by":"publisher","unstructured":"Achuthan K Threat Modeling and Threat Intelligence System for Cloud using Splunk, 2022 10th International Symposium on Digital Forensics and Security (ISDFS), Istanbul, Turkey, 2022, pp. 1\u20136. https:\/\/doi.org\/10.1109\/ISDFS55398.2022.9800787","DOI":"10.1109\/ISDFS55398.2022.9800787"},{"issue":"4","key":"2278_CR17","doi-asserted-by":"publisher","DOI":"10.1016\/j.eij.2023.100409","volume":"24","author":"A Bhardwaj","year":"2023","unstructured":"Bhardwaj A, Kaushik K, Bharany S, Kim S (2023) Forensic analysis and security assessment of IoT camera firmware for smart homes. Egypt Inform J 24(4):100409. https:\/\/doi.org\/10.1016\/j.eij.2023.100409","journal-title":"Egypt Inform J"},{"key":"2278_CR18","doi-asserted-by":"publisher","unstructured":"Schlette D, Caselli M, Pernul G, A Comparative Study on Cyber Threat Intelligence (2021) The Security Incident Response Perspective, in IEEE Communications Surveys & Tutorials, vol. 23, no. 4, pp. 2525\u20132556, Fourthquarter, : https:\/\/doi.org\/10.1109\/COMST.2021.3117338","DOI":"10.1109\/COMST.2021.3117338"},{"key":"2278_CR19","doi-asserted-by":"publisher","unstructured":"Kannimoola JM, Guarding Against Command and Control (C2) Agents Utilizing Real-World Applications for Communication Channels, (2024) 5th International Conference for Emerging Technology (INCET), Belgaum, India, 2024, pp. 1\u20135. https:\/\/doi.org\/10.1109\/INCET61516.2024.10593568","DOI":"10.1109\/INCET61516.2024.10593568"},{"key":"2278_CR20","doi-asserted-by":"publisher","unstructured":"Bhardwaj A, Kaushik K, Alomari A, Alsirhani A, Alshahrani MM, Bharany S (Jan. 2022) BTH: Behavior-Based Structured Threat Hunting Framework to Analyze and Detect Advanced Adversaries. Electronics 11(19):2992. https:\/\/doi.org\/10.3390\/electronics11192992","DOI":"10.3390\/electronics11192992"},{"key":"2278_CR21","doi-asserted-by":"publisher","unstructured":"Pranav H, Suryaa E, Venugopalan M Comprehensive C2 Analysis and Anomaly Detection in HTTP Traffic: A MongoDB-Based Approach, (2024) International Conference on Advances in Computing, Communication and Applied Informatics (ACCAI), Chennai, India, 2024, pp. 1\u20136. https:\/\/doi.org\/10.1109\/ACCAI61061.2024.10602244","DOI":"10.1109\/ACCAI61061.2024.10602244"},{"key":"2278_CR22","doi-asserted-by":"publisher","unstructured":"Alsharabi N, Alqunun M, Murshed BA (2023) Detecting unusual activities in local network using Snort and Wireshark tools, Journal of Advances in Information Technology, vol. 14, no. 4, pp. 616\u2013624, [Online]. Available: https:\/\/doi.org\/10.12720\/jait.14.4.616-624","DOI":"10.12720\/jait.14.4.616-624"},{"key":"2278_CR23","doi-asserted-by":"publisher","unstructured":"Yang Y, Zeng H, Chen T, Lv M, A command and control partition system based on unified access platform, (2022) 4th International Academic Exchange Conference on Science and Technology Innovation (IAECST), Guangzhou, China, 2022, pp. 1492\u20131498. https:\/\/doi.org\/10.1109\/IAECST57965.2022.10062274","DOI":"10.1109\/IAECST57965.2022.10062274"},{"key":"2278_CR24","doi-asserted-by":"publisher","unstructured":"Wang S, Zhu X, Sun Y, Yi K Evaluation Model and Method of Intelligent Level and Ability Level of Command and Control System, (2023) 9th International Conference on Big Data and Information Analytics (BigDIA), Haikou, China, 2023, pp. 818\u2013822. https:\/\/doi.org\/10.1109\/BigDIA60676.2023.10429248","DOI":"10.1109\/BigDIA60676.2023.10429248"},{"key":"2278_CR25","doi-asserted-by":"publisher","unstructured":"Zhou G-X, Yan J-J Exploration of the Application of ChatGPT in Command and Control, (2023) 9th International Conference on Big Data and Information Analytics (BigDIA), Haikou, China, 2023, pp. 807\u2013811. https:\/\/doi.org\/10.1109\/BigDIA60676.2023.10429554","DOI":"10.1109\/BigDIA60676.2023.10429554"},{"key":"2278_CR26","doi-asserted-by":"crossref","unstructured":"Radunovi\u0107 V, Veinovi\u0107 M Malware command and control over social media: Towards the server-less infrastructure, Serbian Journal of Electrical Engineering, vol. 17, no. 3, pp. 357\u2013375, 2024, Accessed: Aug. 13, 2024. [Online]. Available: https:\/\/doiserbia.nb.rs\/Article.aspx?ID=1451-48692003357R","DOI":"10.2298\/SJEE2003357R"},{"issue":"6","key":"2278_CR27","doi-asserted-by":"publisher","first-page":"11","DOI":"10.5815\/ijcnis.2013.06.02","volume":"5","author":"A Singh","year":"2013","unstructured":"Singh A, Toderici A, Ross K, Stamp M (2013) Social Networking for Botnet Command and Control. Int J Comput Netw Inform Security(IJCNIS) 5(6):11\u201317. https:\/\/doi.org\/10.5815\/ijcnis.2013.06.02","journal-title":"Int J Comput Netw Inform Security(IJCNIS)"},{"key":"2278_CR28","doi-asserted-by":"publisher","unstructured":"Tumma C, Reddy RA, Yadav R, Salati A S. S and K. A, Robust Jailbreak Detection in Large Language Models Using Behavioral Fingerprinting, (2025) International Conference on Modeling, Simulation & Intelligent Computing (MoSICom), Dubai, United Arab Emirates, 2025, pp. 284\u2013289. https:\/\/doi.org\/10.1109\/MoSICom67153.2025.11398297","DOI":"10.1109\/MoSICom67153.2025.11398297"},{"key":"2278_CR29","doi-asserted-by":"publisher","unstructured":"Lagisetty SK, Devarajulu P, Moka AK AI-Enhanced Telehealth Platforms: A Comprehensive Analysis of Automated Triage and Personalized Care Systems, (2025) 5th Intelligent Cybersecurity Conference (ICSC), Tampa, FL, USA, 2025, pp. 370\u2013377. https:\/\/doi.org\/10.1109\/ICSC65596.2025.11139916","DOI":"10.1109\/ICSC65596.2025.11139916"}],"container-title":["Peer-to-Peer Networking and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-026-02278-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s12083-026-02278-8","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-026-02278-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T06:37:41Z","timestamp":1784183861000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s12083-026-02278-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,16]]},"references-count":29,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2026,10]]}},"alternative-id":["2278"],"URL":"https:\/\/doi.org\/10.1007\/s12083-026-02278-8","relation":{},"ISSN":["1936-6450"],"issn-type":[{"value":"1936-6450","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,16]]},"assertion":[{"value":"20 March 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 July 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 July 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This study did not involve direct interaction with human participants. Any data used in the research was anonymized and contained no personal identifiable information. Therefore, informed consent was not required.","order":1,"name":"Ethics","label":"Informed consent","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"This research work did not involve any human or animals.","order":2,"name":"Ethics","label":"Research involving human and\/or animals","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":3,"name":"Ethics","label":"Competing interests","group":{"name":"EthicsHeading","label":"Declarations"}}],"article-number":"115"}}