logo

Command and Control with WebSockets WSC2

ID: 53ab97a0-0679-5248-b0cd-4099a0b77095

STIX ID: report--53ab97a0-0679-5248-b0cd-4099a0b77095

Feed Name: Black Hills Infosec Blog

Threat Score
50/100

Date Published: 2018-07-26

Date Updated: 2026-04-27

Author: BHIS

...
...

This Black Hills InfoSec post demonstrates using WSC2 to establish a WebSocket-based command-and-control channel: configuring the controller, generating and executing a PowerShell one‑liner stager to obtain agent callbacks, and using an IE/Edge COM-based technique to make agent network traffic appear as IEXPLORE.EXE. The write-up shows Burp Suite captures of the HTTP->WebSocket upgrade and messages, highlights the agent's basic file transfer and shell capabilities, and discusses implications for penetration testers, red teams, and defenders regarding detection and monitoring of WebSocket C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.