logo

Discord as a C2 and the cached evidence left behind

ID: eab50dfa-b0a7-5e6a-b26d-41faf352b8e9

STIX ID: report--eab50dfa-b0a7-5e6a-b26d-41faf352b8e9

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2025-09-16

Date Updated: 2026-03-24

Author: Alex Wallace

...
...

This report explains how Discord webhooks can be abused as a lightweight C2 and data exfiltration channel using PowerShell, then details the persistent forensic artifacts left in Discord’s Chromium cache (attachments, webhook URLs, thumbnails, timestamps) that enable post-incident reconstruction. It introduces a purpose-built Discord Forensic Suite (CLI/GUI) that automates cache parsing, artifact extraction, hashing, and timeline/HTML/CSV reporting, helping DFIR teams recover evidence and rebuild attacker timelines even after servers or messages are deleted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.