2 Months of Service
100%
Everyone's using DNS-over-HTTPS for C2 comms. It's getting noisy and blue teams are catching up with JARM/JA3 fingerprinting.
What's the next frontier for truly stealthy C2 channels?
I've been exploring using high-traffic, legitimate APIs (e.g., Slack status updates, GitHub gist comments). Low data rate, but nearly impossible to block without breaking business ops.
What are the wildest/most effective covert channels you've seen or theorized?
What's the next frontier for truly stealthy C2 channels?
I've been exploring using high-traffic, legitimate APIs (e.g., Slack status updates, GitHub gist comments). Low data rate, but nearly impossible to block without breaking business ops.
What are the wildest/most effective covert channels you've seen or theorized?