Cobalt Strike's ExternalC2 framework Logo

Cobalt Strike's ExternalC2 framework

1
Free
Visit Website

ExternalC2 is a specification/framework introduced by Cobalt Strike, which allows hackers to extend the default HTTP(S)/DNS/SMB C2 communication channels offered. Essentially this works by allowing the user to develop a number of components: Third-Party Controller - Responsible for creating a connection to the Cobalt Strike TeamServer, and communicating with a Third-Party Client on the target host using a custom C2 channel. Third-Party Client - Responsible for communicating with the Third-Party Controller using a custom C2 channel, and relaying commands to the SMB Beacon. SMB Beacon - The standard beacon which will be executed on the victim host. Using the diagram from CS’s documentation, we can see just how this all fits together.

FEATURES

ALTERNATIVES

A guide on using Apache mod_rewrite to strengthen phishing attacks and bypass mobile device restrictions

CredMaster enhances password spraying tactics with IP rotation to maintain anonymity and efficiency.

A week-long series of articles and talks on evading Microsoft Advanced Threat Analytics (ATA) detection

TikiTorch offers advanced process injection capabilities to execute code stealthily in another process's space.

Cutting-edge open-source security tools for adversary simulation and threat hunting.

Generate a variety of suspect actions detected by Falco rulesets.

A powerful enumeration tool for discovering assets and subdomains.

A blog post about bypassing AppLocker using PowerShell diagnostic scripts