YoVDO

Flying a False Flag - Advanced C2, Trust Conflicts, and Domain Takeover

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses

Course Description

Overview

Explore advanced command and control (C2) techniques, trust exploitation, and domain takeover strategies in this 44-minute Black Hat conference talk. Delve into the methodology and challenges of modern C2, including recent HTTP/S advancements and cloud service primitives like SQS, AppSpot, S3, and CloudFront. Learn how to abuse trust for stealthy C2 through internal mail servers, defensive platforms, and trusted domains. Discover various domain takeover options and gain insights into newly released tools for exploiting takeover scenarios in major cloud platforms such as AWS, Azure, and GCP. Access the full abstract and presentation slides for a comprehensive understanding of these cutting-edge cybersecurity concepts.

Syllabus

Flying a False Flag: Advanced C2, Trust Conflicts, and Domain Takeover


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube