logo

Using CloudFront to Relay Cobalt Strike Traffic

ID: 4fd8051f-3c67-5a7a-a0ae-a75b659d7daa

STIX ID: report--4fd8051f-3c67-5a7a-a0ae-a75b659d7daa

Feed Name: Black Hills Infosec Blog

Date Published: 2019-08-15

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog-style walkthrough explains how to configure AWS CloudFront as a proxy for a Cobalt Strike Team Server to hide C2 infrastructure and blend traffic with legitimate CDN HTTPS traffic; it covers setting up a Debian host with Cobalt Strike, registering a domain and obtaining a Let's Encrypt-based TLS certificate, creating a CloudFront distribution, building a custom Malleable C2 profile that embeds the certificate, generating listeners and payloads, and briefly discusses defensive recommendations such as strict application whitelisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.