
This is such a cool C2 channel technique. Use network file share, RDP mapped drives and anywhere else more than one host sees the same filesystem as a C2 channel which really doesn't get logged. Simple but effective!
Scriptmonkey_
7.3K posts

@scriptmonkey_
Tester of Pens, Ex-Teamer of Red things, now with a more purpley shade. Biker and Recovering Eve-Online Addict. o7 [email protected] & https://t.co/QvMpQ3IQwQ

This is such a cool C2 channel technique. Use network file share, RDP mapped drives and anywhere else more than one host sees the same filesystem as a C2 channel which really doesn't get logged. Simple but effective!



Interviewer: How do some companies prevent employees from taking screenshots, coping or transferring files to other people unless within the same company?






I guess we'll talk a bit about modern red teaming. The difficulty has increased severely. Lots of people be like just vibe code a stage0 with legit code for your pretext. How are you delivering it to bypass app control? Lots of words, no substance.



















