How To: C2 Over ICMP
ID: 77b1e18d-7c75-562d-941c-d051b3f4c246
STIX ID: report--77b1e18d-7c75-562d-941c-d051b3f4c246
Feed Name: Black Hills Infosec Blog
Threat Score
This blog post demonstrates how to set up a command-and-control (C2) channel over ICMP by running an 'icmpsh' listener on an attacker Kali machine and deploying a PowerShell ICMP client on a Windows victim. The author walks through tool acquisition, disabling machine-based ICMP restrictions, starting the listener, transferring and executing the PowerShell payload, and highlights that ICMP-encapsulated communication can evade proxy-based firewall rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
