Abusing Webhooks for Command and Control
Offered By: NorthSec via YouTube
Course Description
Overview
Explore a technique for establishing outbound network connectivity using HTTP callbacks (webhooks) in this 25-minute NorthSec conference talk. Learn about webhooks, their organizational uses, and how to leverage approved sites as communication brokers. Discover methods for data transfers, asynchronous command execution, and creating command-and-control communication while bypassing strict defensive proxies and avoiding attribution. Examine a tool that utilizes broker websites to work with external C2 using webhooks. Cover topics including webhook users like GitHub and Octopus, delivery mechanisms, real-time communication, and continuous integration.
Syllabus
Intro
Who uses Webhooks
GitHub
Octopus
Delivery mechanism
Delivery demo
Realtime communication
Continuous integration
Taught by
NorthSec
Related Courses
An Introduction to Computer NetworksStanford University via Independent Computer Networks
University of Washington via Coursera Computer Networking
Georgia Institute of Technology via Udacity Cybersecurity and Its Ten Domains
University System of Georgia via Coursera Model Building and Validation
AT&T via Udacity