Bypassing Cylance: Part 3 – Netcat & Nishang ICMP C2 Channel
ID: d38ed445-a1ec-5854-a80f-a7b8bf4a0dab
STIX ID: report--d38ed445-a1ec-5854-a80f-a7b8bf4a0dab
Feed Name: Black Hills Infosec Blog
This report demonstrates several command-and-control (C2) techniques that successfully bypassed Cylance endpoint protections in a tested environment: raw netcat shells (with a note that Ncat/TLS would be harder to detect) and an ICMP-based PowerShell C2 using Nishang loaded and executed via PowerShell ISE. The authors attribute success largely to common deployment misconfigurations and urge defense-in-depth controls—application whitelisting, protocol inspection at boundaries, restricting PowerShell ISE/cmd.exe, and blocking unnecessary outbound ICMP—to mitigate these risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
