Netskope Threat Labs
Australian Cyber Conference

One Port to Serve Them All - GCP Cloud Shell Abuse (Australian Cyber Conference - Melbourne)

Melbourne Convention and Exhibition Centre (MCEC)
One Port to Serve Them All - GCP Cloud Shell Abuse (Australian Cyber Conference - Melbourne)
Presented by
About this talk

Join Hubert Lin at the Australian Cyber Conference - Melbourne for the session “Hunting in the dark: Detecting and disrupting DNS-based C2 traffic” where we unravel the covert tactics of threat actors leveraging DNS exploitation to breach networks unnoticed, offering practical strategies to fortify your defenses and safeguard against persistent attacks. Don’t miss out on this opportunity to enhance your knowledge and protect your organization from evolving cybersecurity threats.

Apart from the extensively exploited HTTP protocol, the DNS protocol plays a crucial role in network communication, capable of bypassing Layer-4 firewall restrictions commonly employed by many organizations. This presentation will delve into the misuse of DNS for establishing covert tunnels, circumventing L4 firewalls. We will explore several tunneling tools and Command and Control (C2) frameworks, uncovering how threat actors leverage DNS for unauthorized network access. Our analysis reveals persistent DNS abuse as an effective attack vector employed by malicious entities over an extended period. The session will conclude with practical strategies to fortify DNS security, providing concrete steps to mitigate potential threats.