GITEST
Back to Playbooks
CTF

ctf-malware-c2-protocols

CTF malware C2 traffic analysis. PCAP tshark protocol extraction, stream cipher shared keystream (ChaCha20 null-byte trick), RC4 WebSocket C2 decryption, AES-CBC key derivation from hardcoded strings, encryption algorithm identification by constants (AES S-box 0x637c777b, ChaCha20 'expand 32-byte k'

Slug

ctf-malware-c2-protocols

Category

CTF

Run Playbook

/gitest ctf-malware-c2-protocols