You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
No
Describe the solution you'd like
Cloud storage like OneDrive and Google Drive are very popular and are often installed by default on windows and android and seeing network traffic to either of these is not unusual.
Could you add support for OneDrive and Google Drive as a command and control channel as its hard to block if its in use and there are no ip or domains that can be used as an IOC.
Is your feature request related to a problem? Please describe.
No
Describe the solution you'd like
Cloud storage like OneDrive and Google Drive are very popular and are often installed by default on windows and android and seeing network traffic to either of these is not unusual.
Could you add support for OneDrive and Google Drive as a command and control channel as its hard to block if its in use and there are no ip or domains that can be used as an IOC.
Describe alternatives you've considered
Additional context
Example programs that use OneDrive or Google Drive as a C2:
https://github.com/looCiprian/GC2-sheet
https://github.com/ricardojoserf/covert-control
https://www.bc-security.org/post/empire-dropbox-c2-listener/
The text was updated successfully, but these errors were encountered: