
Agentless Network Threat Hunting That Surfaces Command-and-Control Activity
Active Countermeasures builds network threat hunting software for security teams that need to know whether their preventive controls have already failed. The company sits inside John Strand's group of information security businesses, alongside Black Hills Information Security, Antisyphon Infosec Training and Wild West Hackin' Fest, and frames its work as bridging the gap between protection-focused tooling such as firewalls and multi-factor authentication and the response-focused world of incident handling. Its stated audience runs from junior analysts to seasoned security professionals.
The flagship product, AC-Hunter, uses two components: the open-source Zeek sensor to capture traffic at the firewall's internal interface, and its own engine to analyze the resulting connection records. Detection rests on behavior rather than signatures, weighing connection intervals, data size and dispersion, port usage, DNS queries and patented beaconing algorithms to isolate likely command-and-control channels. The system re-hunts the previous 24 hours of traffic on an hourly cycle and archives each day's database for retrospective investigation.
Because analysis happens on the wire, no endpoint agents are needed, so IoT, IIoT and BYOD devices are covered regardless of operating system or hardware, and encrypted sessions are inspected without breaking data privacy. Supporting features include cyber deception tokens, granular safelisting and syslog alerting into a SIEM. The vendor also publishes free tools including RITA, BeaKer, espy, Passer, SMUDGE and zcutter, plus a no-cost Community Edition and free webcasts, anchoring a community-first market position.



