Azure ServiceBus WebSockets as a C2 Channel
ID: b26cee5b-b029-5e0d-bc73-556a77bfa792
STIX ID: report--b26cee5b-b029-5e0d-bc73-556a77bfa792
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
This report demonstrates how to modify Cobalt Strike's CobaltBus to use Azure Service Bus over WebSockets (AmqpWebSockets) so C2 traffic travels over HTTPS (port 443) instead of TCP/5671, allowing beacons to bypass firewall rules that block nonstandard outbound ports; it includes code snippets, a lab walkthrough, traffic captures, and defensive detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
