Back to Playbooks
CTF
ctf-malware-c2-protocols
CTF malware C2 traffic analysis. PCAP tshark protocol extraction, stream cipher shared keystream (ChaCha20 null-byte trick), RC4 WebSocket C2 decryption, AES-CBC key derivation from hardcoded strings, encryption algorithm identification by constants (AES S-box 0x637c777b, ChaCha20 'expand 32-byte k'
Slug
ctf-malware-c2-protocols
Category
CTF
Run Playbook
/gitest ctf-malware-c2-protocols