logo

Bypassing Cylance: Part 3 – Netcat & Nishang ICMP C2 Channel

ID: d38ed445-a1ec-5854-a80f-a7b8bf4a0dab

STIX ID: report--d38ed445-a1ec-5854-a80f-a7b8bf4a0dab

Feed Name: Black Hills Infosec Blog

Threat Score
60/100

Date Published: 2017-03-29

Date Updated: 2026-04-27

Author: BHIS

...
...

This report demonstrates several command-and-control (C2) techniques that successfully bypassed Cylance endpoint protections in a tested environment: raw netcat shells (with a note that Ncat/TLS would be harder to detect) and an ICMP-based PowerShell C2 using Nishang loaded and executed via PowerShell ISE. The authors attribute success largely to common deployment misconfigurations and urge defense-in-depth controls—application whitelisting, protocol inspection at boundaries, restricting PowerShell ISE/cmd.exe, and blocking unnecessary outbound ICMP—to mitigate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.