Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added T1095 for Linux #3063

Merged
merged 7 commits into from
Feb 25, 2025
Merged

Added T1095 for Linux #3063

merged 7 commits into from
Feb 25, 2025

Conversation

vignesh-user
Copy link
Contributor

Added T1095 (Non-Application Layer Protocol) for linux

Details:
I have added T1095 (Non-Application Layer Protocol) for Linux, as this technique was previously only available for Windows.

Two systems are required to simulate this technique, due to its nature. Automation is not feasible with Invoke-AtomicTest, and the commands must be executed manually.

Testing:
Tested on Ubuntu 22.04.5 LTS, but not working on CentOS 9 Stream

01 - Ubuntu Version 02 - Binaries Downloaded 03 - ICMP-CNC 04 - ICMPDoor 05 - C2-Shell 06 - ICMP-Request 07 - ICMP-Reply

Associated Issues:
N/A

Added T1095 (Non-Application Layer Protocol) for linux
Changed the name and added important notes
@patel-bhavin
Copy link
Collaborator

Thank you for making this contribution and the updates!

@patel-bhavin patel-bhavin merged commit 1338527 into redcanaryco:master Feb 25, 2025
4 checks passed
@vignesh-user
Copy link
Contributor Author

Thank you for making this contribution and the updates!

Thank you @patel-bhavin for your time and support!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants