Azure Application Proxy C2
ID: 2591679a-41c6-50eb-a586-77ddf75cb92f
STIX ID: report--2591679a-41c6-50eb-a586-77ddf75cb92f
Feed Name: TrustedSec blog
### Executive Summary This report provides a step-by-step technical walkthrough and proof-of-concept for abusing Azure AD Application Proxy (which leverages Azure Service Bus) to create an inbound, certificate-authenticated C2 tunnel into an environment. It covers creating OAuth tokens and a client certificate, generating a CSR, interacting with the registration endpoint, establishing Service Bus-based WebSocket signaling channels, retrieving request payloads, and returning responses—demonstrating a stealthy technique that could be used by red teams or threat actors to tunnel C2 traffic through commonly trusted cloud infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
