logo

Bring Your Own Trusted Binary (BYOTB) – BSides Edition

ID: d0bbdc8e-6911-5b88-b61c-05633eb6ba60

STIX ID: report--d0bbdc8e-6911-5b88-b61c-05633eb6ba60

Feed Name: JUMPSEC Labs

Threat Score
70/100

Date Published: 2025-02-06

Date Updated: 2026-04-28

Author: David Kennedy

...
...

This post explains how adversaries (or red teams) can abuse trusted binaries—primarily Cloudflare's cloudflared and Win32-OpenSSH—to create HTTPS/SOCKS tunnels over port 443 (and work around Cloudflared's default 7844 egress) for covert remote access, EDR evasion, and port forwarding (including NTLM relaying), provides concrete commands and a double-tunnel technique to improve firewall friendliness, and concludes with detection and mitigation recommendations (process telemetry, DNS and firewall logging, file monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.