jm33-m0 / emp3r0r

Linux/Windows post-exploitation framework made by linux user
https://infosec.exchange/@jm33
MIT License
1.26k stars 232 forks source link

[Feature request] OneDrive and Google Drive C2 #148

Closed hbednar closed 1 year ago

hbednar commented 2 years ago

Cloud storage like OneDrive and Google Drive are very popular and are often installed by default on windows and android and seeing network traffic to either of these is not unusual. Could you add support for OneDrive and Google Drive as a command and control channel as its hard to block if its in use and there are no ip or domains that can be used as an IOC.

Example programs that use OneDrive or Google Drive as a C2: https://github.com/looCiprian/GC2-sheet https://github.com/ricardojoserf/covert-control https://www.bc-security.org/post/empire-dropbox-c2-listener/

jm33-m0 commented 2 years ago

This is useful indeed, I will try to implement it in the future

github-actions[bot] commented 1 year ago

Stale issue message

hbednar commented 1 year ago

@jm33-m0 Is this still planned

jm33-m0 commented 1 year ago

@hbednar There are a few more to do before implementing this, for example there's no staging yet. Also, this feature can be an independent project like go-cdn2proxy, perhaps you can help with that.

github-actions[bot] commented 1 year ago

Stale issue message