Network Artifacts of Trusted Service Abuse
The ever-increasing adoption of trusted services and their interconnectivity with private resources provides new opportunities for malicious communication channels. Traditional indicators of compromise, such as IP/Domain reputation or beacon detection, are most effective against adversary-owned infrastructure but yield limited signals when communication channels run atop trusted services.
This study contrasts normal user traffic with known malicious activity to identify alternative indicators from four public C2 frameworks (DaaC2, DBC2, gdog, Callidus) operating on Dropbox, Discord, Gmail, and OneNote, using 51 packet captures (3 baselines, 6 automated browser tests and 6 framework tests per service).
Across four detection tiers, Reputation-based detection failed to identify any C2 channels; Beacon Detection was marginally viable when using clustering (2/4); Traffic Metadata was partially viable, with mixed results other than JA4 fingerprints (100% detection); and Traffic Patterns proved most viable, with both TLS session resumption near-zero (vs 22%+ for browser) and a 2.6x upload/download ratio gap (1.41 vs 0.55 means). Structural and behavioral indicators, such as TLS session resumption and JA4 fingerprinting, outperform reputation in detecting trusted service abuse.
SANS-Network-Artifacts-Trusted-Service-Abuse-080626 (PDF, 2.71MB)
6 Aug 2026Related Content
Dual-Module QR Codes: Bypassing QR Code Scanners in Enterprise Email Gateways
Research PaperBy exploiting the decoding algorithm and leveraging existing QR data-layering techniques, this research provides the security industry with a working proof-of-concept to bypass email security gateway detection systems.
- 6 Aug 2026
- Steven Legere
Post-Exploitation: C2 Framework Effectiveness Against Advanced Audit Logging
Research PaperThis research paper examines the effectiveness of a sample of open-source Commandand-Control (C2) frameworks in evading advanced audit logging during postexploitation.
- 20 Mar 2026
- Benjamin Evans
Enhancing Security Operations with Google Threat Intelligence
Research PaperThis product review examines how Google Threat Intelligence's extensive data sources, real-time insights, and investigative capabilities can elevate SecOps workflows and strengthen an organization’s defensive posture.
- 24 Nov 2025
- Dave Shackleford
The Mimic Octopus: Weaponizing File Corruption and Recoverability to Bypass Antivirus and Email Filtering
Research PaperThis paper investigates a novel tactic in phishing operations where threat actors intentionally corrupt document and archive files, such as DOCX, DOCM, PDF, and ZIP , to evade antivirus (AV) and email filtering systems.
- 3 Sep 2025
- Justin Gazick
From Crash to Compromise: Unlocking the Potential of Windows Crash Dumps in Offensive Security
Research PaperThis research explores how offensive security practitioners can incorporate crash dump analysis into their workflows to extract sensitive data such as plaintext credentials, encryption keys, and files from memory.
- 9 May 2025
- SANS Institute
CloudFront Real-Time Logs Rate Sampling and Detection
Research PaperAs businesses aim to optimize their AWS CloudFront expenses, some disable CloudFront Real-Time logs....
- 29 Jan 2024
- Merly Mathis
The Evolution of the Digital Predator: Using AI to Evade Security Controls
Research PaperSince the advent of the computer, there has been a never-ending game of cat and mouse between those...
- 20 Dec 2023
- Foster Nethercott
Who Needs a Pentest: Validating the Configuration of an EDR Solution Using the MITRE ATT&CK Framework
Research PaperIs that EDR suite fully configured, and providing the expected protection? Do we have a scalable way...
- 7 Nov 2023
- Adam Fowler
Tearing up Smart Contract Botnets
Research PaperThe distributed resiliency of smart contracts on private blockchains is enticing to bot herders as a...
- 22 Oct 2018
- Jonathan Sweeny
Clickbait: Owning SSL via Heartbleed, POODLE, and Superfish
Research PaperIn the twilight of SSL's effectiveness as a method of secure communication,demonstration of...
- 23 Dec 2015
- SANS Institute
