Using CloudFront to Relay Cobalt Strike Traffic
ID: 4fd8051f-3c67-5a7a-a0ae-a75b659d7daa
STIX ID: report--4fd8051f-3c67-5a7a-a0ae-a75b659d7daa
Feed Name: Black Hills Infosec Blog
This blog-style walkthrough explains how to configure AWS CloudFront as a proxy for a Cobalt Strike Team Server to hide C2 infrastructure and blend traffic with legitimate CDN HTTPS traffic; it covers setting up a Debian host with Cobalt Strike, registering a domain and obtaining a Let's Encrypt-based TLS certificate, creating a CloudFront distribution, building a custom Malleable C2 profile that embeds the certificate, generating listeners and payloads, and briefly discusses defensive recommendations such as strict application whitelisting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
