@@ -74,7 +74,29 @@ CS -》teamservers 1/2/3/... 前置层(SMTP/PAYLOAD/C2/隐蔽C2)
74
74
* tips:good domain + bad domain 包一层同时发过去
75
75
* 第三方服务用作C2
76
76
* Office365、Pastebin、Slack、Facebook、Dropbox、Gmail、Twitter..
77
- * 需要硬编码到第三方服务
77
+ * 缺点:需要硬编码到第三方服务
78
+ * 第三方服务用作C2相关资源汇总
79
+ https://pentestarmoury.com/2017/07/19/s3-buckets-for-good-and-evil/
80
+ https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/
81
+ https://github.com/daniel-infosec/wikipedia-c2
82
+ https://unit42.paloaltonetworks.com/aggah-campaign-bit-ly-blogspot-and-pastebin-used-for-c2-in-large-scale-campaign
83
+ https://www.harmj0y.net/blog/powershell/command-and-control-using-active-directory/
84
+ https://blog.netspi.com/databases-and-clouds-sql-server-as-a-c2/
85
+ https://outflank.nl/blog/2017/09/17/blogpost-cobalt-strike-over-external-c2-beacon-home-in-the-most-obscure-ways
86
+ https://labs.mwrinfosecurity.com/blog/tasking-office-365-for-cobalt-strike-c2
87
+ https://github.com/maldevel/canisrufus
88
+ https://unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can-use-google-drive-for-c2-communications
89
+ https://github.com/byt3bl33d3r/gcat
90
+ https://github.com/maldevel/gdog
91
+ https://www.welivesecurity.com/wp-content/uploads/2019/05/ESET-LightNeuron.pdf
92
+ https://github.com/bkup/SlackShell
93
+ https://github.com/j3ssie/c2s
94
+ https://github.com/praetorian-code/slack-c2bot
95
+ https://github.com/microsoft/skype-dev-bots
96
+ https://github.com/PaulSec/twittor
97
+ https://blog.talosintelligence.com/2017/04/introducing-rokrat.html
98
+ https://www2.fireeye.com/rs/848-DID-242/images/rpt-apt29-hammertoss.pdf
99
+ https://github.com/woj-ciech/Social-media-c2
78
100
79
101
* 邮件钓鱼(SMTP)
80
102
* 域名:同C2域名选择
0 commit comments