Part 2 of the Zeek threat hunt: using SQL to detect C2 beaconing on a fixed cadence, internal reconnaissance across 771 hosts, and a confirmed SSH intrusion — plus the timeline that showed the network was compromised before the attacker I could see ever logged in.