YoVDO

Abusing Webhooks for Command and Control

Offered By: NorthSec via YouTube

Tags

NorthSec Courses Cybersecurity Courses Network Security Courses Continuous Integration Courses Webhooks Courses

Course Description

Overview

Explore a technique for establishing outbound network connectivity using HTTP callbacks (webhooks) in this 25-minute NorthSec conference talk. Learn about webhooks, their organizational uses, and how to leverage approved sites as communication brokers. Discover methods for data transfers, asynchronous command execution, and creating command-and-control communication while bypassing strict defensive proxies and avoiding attribution. Examine a tool that utilizes broker websites to work with external C2 using webhooks. Cover topics including webhook users like GitHub and Octopus, delivery mechanisms, real-time communication, and continuous integration.

Syllabus

Intro
Who uses Webhooks
GitHub
Octopus
Delivery mechanism
Delivery demo
Realtime communication
Continuous integration


Taught by

NorthSec

Related Courses

An Introduction to Computer Networks
Stanford University via Independent
Computer Networks
University of Washington via Coursera
Computer Networking
Georgia Institute of Technology via Udacity
Cybersecurity and Its Ten Domains
University System of Georgia via Coursera
Model Building and Validation
AT&T via Udacity