logo

Azure Application Proxy C2

ID: 5e124803-cfbd-5a26-ab5f-4934af6514ff

STIX ID: report--5e124803-cfbd-5a26-ab5f-4934af6514ff

Feed Name: XPN Infosec Blog

Threat Score
70/100

Date Published: 2021-04-24

Date Updated: 2026-07-30

...
...

This post demonstrates how an attacker (or red team) can abuse Azure AD Application Proxy and its underlying Service Bus transport to implement an OpSec-friendly inbound C2 channel. It covers generating the client authentication certificate via OAuth and CertEnroll, performing the bootstrap request to the msappproxy endpoints, establishing Service Bus/WebSocket signaling channels, retrieving request payloads, and returning C2 responses to /subscriber/connection, and includes a C# PoC implementation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.