Blackhat 2020 Arsenal - C2 Matrix

jorgeorchilles 422 views 14 slides Aug 05, 2020
Slide 1
Slide 1 of 14
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14

About This Presentation

Slides from @jorgeorchilles and @brysonbort talk at Blackhat 2020 - Arsenal covering the C2 Matrix.

Website: https://thec2matrix.com
Blackhat: https://www.blackhat.com/us-20/arsenal/schedule/#c-matrix-comparison-of-command-and-control-frameworks-20768
Video: https://youtu.be/2i9KjHCR6ik

Command a...


Slide Content

C2 Matrix
@JorgeOrchilles
@BrysonBort

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
•Chief Technology Officer -SCYTHE
•C2 Matrix Co-Creator
•Purple Team Exercise Framework (PTEF)
•10 years @ Citi leading offensive security team
•Certified SANS Instructor: SEC560, SEC504
•Author SEC564: Red Team Exercises and
Adversary Emulation
•CVSSv3.1 Working Group Voting Member
•GFMA: Threat-Led Pen Test Framework
•ISSA Fellow
•NSI Technologist Fellow
T1033 –Jorge Orchilles

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
•CEO/Founder -SCYTHE
•C2 Matrix Co-Creator
•Founder –GRIMM
•Co-Founder –ICS Village
•R Street Senior Fellow, National and Cybersecurity
•Advisor to the Army Cyber Institute
•NSI Senior Fellow
T1033 –Bryson Bort

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
•Proliferation of Offensive Security Tools
•Empire went EOL (it is now maintained by BC-
Security)
•Compendium of C2 frameworks
•Added other capabilities
•Began evaluating them to find the ideal one for red
team engagement
•Realized it can be used by Red and Blue Teams
Why did we build this?

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
•Comparison of Command and Control (C2)
Frameworks
•Google Sheet of C2s
•GUI: https://www.thec2matrix.com/
•Find ideal C2 for your needs:
https://ask.thec2matrix.com
•Gitbookon how to install and use the C2; setup
lab environment; contribute; and defend:
https://howto.thec2matrix.com
•SANS Slingshot C2 Matrix Virtual Machine
•@C2_Matrix & #C2Matrix on Twitter
C2 Matrix

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
TheC2Matrix.com

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
GUI

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
Golden Source: Google Sheet
https://docs.google.com/spreadsheets/d/1b4mUxa6cDQuTV2BPC6aA-GR4zGZi0ooPYtBe4IgPsSc/edit#gid=0

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
Ask.thec2matrix.com

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
Howto.thec2matrix.com

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
SANS Slingshot C2 Matrix Edition

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
howto.thec2matrix.com/contribute

@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
Feedback

C2 Matrix
Demo
@JorgeOrchilles
@BrysonBort