BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Microsoft and Amazon are my Favorite C2 Providers\n 
   Tags: Red Team Village | Misc\n   When: Friday\, Aug 7\, 14:00 - 14:59 P
 DT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 1
  -\n   [1]Map\n\n   Description:\n\n   Cloud relay services check every bo
 x for C2 transport: outbound-only\n   HTTPS on 443\, cloud brokered connec
 tivity so the attacker never\n   touches the target directly\, and endpoin
 t domains that enterprises\n   literally cannot blocklist without breaking
  production. I validated\n   this at a Fortune 40\, you can't block *.serv
 icebus.windows.net or\n   *.iot.amazonaws.com without taking down dozens o
 f business critical\n   systems.\n\n   This research was accepted at Red T
 eam Village DC33 but I had to\n   withdraw due to a family emergency. The 
 work has continued since then\n   with the AWS IoT MQTT technique\, the My
 thic agent integrations\, and\n   the detection package as new additions. 
 The talk covers three\n   techniques I built\, validated\, and integrated 
 into Mythic C2:\n\n   Azure Relay Bridge — Microsoft's own open source r
 elay tool becomes\n   a LOLBin. It's Microsoft-signed\, supports persisten
 t service\n   installation on Windows/Linux/macOS\, and tunnels all C2 tra
 ffic\n   through *.servicebus.windows.net as standard HTTPS. I demo my cus
 tom\n   Mythic C2 profile end to end\, with agent check in\, post-ex\, all
 \n   traffic indistinguishable from legitimate Azure usage.\n\n   AWS IoT 
 Secure Tunneling — Tunnels created from the attacker's own\n   AWS accou
 nt\, zero CloudTrail in the target's environment. Great for\n   lateral mo
 vement and short duration pivots\, but I hit real operational\n   limits d
 uring testing (12-hour lifetime\, 1 Mbps ceiling\, distinctive\n   20s kee
 p-alive) that make it less ideal for persistent C2.\n\n   AWS IoT Core MQT
 T — Those Secure Tunneling limitations led me here.\n   MQTT pub/sub wit
 h X.509 mTLS auth\, no tunnel lifetime limits\,\n   indefinite persistence
  through *.iot.amazonaws.com. I built custom\n   Mythic agents: Poseidon (
 Go) for Linux/macOS\, Apollo (C#) for Windows\,\n   both validated on AMD6
 4 and ARM64.\n\n   All the material will be available at the time of the p
 resentation:\n   Mythic agents and translation containers for both transpo
 rts\,\n   infrastructure provisioning scripts\, and detection rules (Suric
 ata\,\n   Zeek\, Splunk). Both Microsoft and AWS were engaged before discl
 osure.\n   There's no vuln to patch\, this is an architectural problem wit
 h how\n   cloud relay services are designed.\n\n   SpeakerBio:  Robert Pim
 entel\, Hacker Hermanos\n\n   Robert is a seasoned offensive security prof
 essional with more than a\n   decade of experience in Information Security
 .\n\n   He began his career in the U.S. Marine Corps\, where he worked on\
 n   secure telecommunications. Robert holds a master's degree in\n   Cyber
 security\, numerous IT certifications\, and a background as an\n   instruc
 tor at higher education institutions like the New Jersey\n   Institute of 
 Technology and American University.\n\n   Robert is committed to sharing h
 is knowledge and experiences for the\n   benefit of others. He enjoys Braz
 ilian steakhouses and cuddling with\n   his pugs while writing Infrastruct
 ure as Code to automate Red Team\n   Infrastructure.\n\n   Robert is the D
 irector of Offensive Security at Humana\, Inc.\n\n   '\n\n   1. #LVCCW_Lev
 el1_Hall1\n\n\n
DTEND:20260807T215900Z
DTSTART:20260807T210000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Stage 1
SUMMARY:Microsoft and Amazon are my Favorite C2 Providers
END:VEVENT
END:VCALENDAR
