Azure Application Proxy C2
ID: 5e124803-cfbd-5a26-ab5f-4934af6514ff
STIX ID: report--5e124803-cfbd-5a26-ab5f-4934af6514ff
Feed Name: XPN Infosec Blog
This post demonstrates how an attacker (or red team) can abuse Azure AD Application Proxy and its underlying Service Bus transport to implement an OpSec-friendly inbound C2 channel. It covers generating the client authentication certificate via OAuth and CertEnroll, performing the bootstrap request to the msappproxy endpoints, establishing Service Bus/WebSocket signaling channels, retrieving request payloads, and returning C2 responses to /subscriber/connection, and includes a C# PoC implementation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
