Remix.run Logo
mtlynch 4 hours ago

> Naturally, the next move was pivoting from defense to offense. I wanted to see if the attackers left any vulnerable services exposed on their IP.

Why not attack them through the C2 interface? That's where I'd expect them to slip up.

CITIZENDOT an hour ago | parent [-]

> C2 interface

do you mean the machine which is connected through the victim's machine? if so, i should put this in a VM, run and see where it's sending/receiving requests from. i'll do that.