Bring Your Own Trusted Binary (BYOTB) – BSides Edition
ID: d0bbdc8e-6911-5b88-b61c-05633eb6ba60
STIX ID: report--d0bbdc8e-6911-5b88-b61c-05633eb6ba60
Feed Name: JUMPSEC Labs
This post explains how adversaries (or red teams) can abuse trusted binaries—primarily Cloudflare's cloudflared and Win32-OpenSSH—to create HTTPS/SOCKS tunnels over port 443 (and work around Cloudflared's default 7844 egress) for covert remote access, EDR evasion, and port forwarding (including NTLM relaying), provides concrete commands and a double-tunnel technique to improve firewall friendliness, and concludes with detection and mitigation recommendations (process telemetry, DNS and firewall logging, file monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
