alphasoc / flightsim

A utility to safely generate malicious network traffic patterns and evaluate controls.
https://alphasoc.com
Other
1.27k stars 134 forks source link

Extend c2 module to generate malicious JARM fingerprints #27

Open chrisforce1 opened 3 years ago

chrisforce1 commented 3 years ago

It seems we can spoof JARM server fingerprints, i.e.

https://grimminck.medium.com/spoofing-jarm-signatures-i-am-the-cobalt-strike-server-now-a27bd549fc6b

The idea would be to set up a TLS server and have flightsim interact with it to generate the bad JARM fingerprint.