Command and Control with WebSockets WSC2
ID: 53ab97a0-0679-5248-b0cd-4099a0b77095
STIX ID: report--53ab97a0-0679-5248-b0cd-4099a0b77095
Feed Name: Black Hills Infosec Blog
This Black Hills InfoSec post demonstrates using WSC2 to establish a WebSocket-based command-and-control channel: configuring the controller, generating and executing a PowerShell one‑liner stager to obtain agent callbacks, and using an IE/Edge COM-based technique to make agent network traffic appear as IEXPLORE.EXE. The write-up shows Burp Suite captures of the HTTP->WebSocket upgrade and messages, highlights the agent's basic file transfer and shell capabilities, and discusses implications for penetration testers, red teams, and defenders regarding detection and monitoring of WebSocket C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
