TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Using CloudFront to Relay Cobalt Strike Traffic

BHIS · 2019-08-15 · Read original ↗

ATT&CK techniques detected

5 predictions
T1055.001Dynamic-link Library Injection
93%
“work that has been done up to this point. the last step is to generate a payload to test that everything is working. i will state at this point that any cs payload that you generate and attempt to use without additional steps will almost certainly be caught by av engines. generat…”
T1090.004Domain Fronting
87%
“using cloudfront to relay cobalt strike traffic using cloudfront to relay cobalt strike traffic many of you have likely heard of domain fronting. domain fronting is a technique that can allow your c2 traffic to blend in with a target ’ s traffic by making it appear that it is cal…”
T1090.002External Proxy
44%
“generate ” button, choose a location to save the payload, and then run the payload by double - clicking on the file that was generated. you should observe in your cs - client window that a session has been established! protections preventing attackers from using cloudfront as a r…”
T1665Hide Infrastructure
34%
“using cloudfront to relay cobalt strike traffic using cloudfront to relay cobalt strike traffic many of you have likely heard of domain fronting. domain fronting is a technique that can allow your c2 traffic to blend in with a target ’ s traffic by making it appear that it is cal…”
T1071Application Layer Protocol
31%
“c2 kill date > the cs team server should now be up and running and we can move onto the final steps. 6. generate a cs payload to test the setup the final step is to start a cs listener and generate a cs payload. this step assumes you have installed the cs client on a system. open…”

Summary

Brian Fehrman // Many of you have likely heard of Domain Fronting. Domain Fronting is a technique that can allow your C2 traffic to blend in with a target’s traffic […]

The post Using CloudFront to Relay Cobalt Strike Traffic appeared first on Black Hills Information Security, Inc..