Evasive File Smuggling with Skyhook
ID: dd40d0b0-0539-5511-b6aa-51871c5e7322
STIX ID: report--dd40d0b0-0539-5511-b6aa-51871c5e7322
Feed Name: Black Hills Infosec Blog
The report presents Skyhook, a red-team file transfer tool that automates on-the-fly obfuscation of HTTP(S) transactions to bypass network-based controls (e.g., TLS-intercepting IDPS) and facilitate chunked uploads/downloads. It explains the dual-service architecture (Admin for configuration and Transfer for operations), the obfuscation pipeline (Base64 by default with optional AES/XOR/Blowfish/Twofish via WebAssembly), and demonstrates how directory listings, file names, and content are transformed in transit. While useful for operator efficiency and exfiltration workflows, the author emphasizes it is not a privacy/E2EE tool and acknowledges operational limitations and potential detectability as usage grows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
