
DEF CON 33 - Planting C4: Cross Compatible External C2 for Your Implants - Scott Taylor
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 16:21
[BLUF: Scott Taylor presents C4, a cross-compatible command and control (C2) tool that enables malware developers to use external C2 channels—like AWS S3, GitHub Gists, and Confluence—across multiple programming languages via WebAssembly and the Exism plugin system, improving portability and operational flexibility.]2:00
Key Takeaways:
• C4 enables external C2 using trusted websites like AWS S3, GitHub Gists, and Confluence by leveraging WebAssembly and the Exism plugin system 2:00.
• The tool supports multiple agents and languages through a universal WebAssembly plugin model, allowing seamless code sharing and execution 4:00.
• C4 handles operational requirements such as multi-agent communication, file naming via system time, and large file exfiltration via S3 compatibility 12:00.
• Developers can deploy C4 plugins in any language (e.g., Python, JavaScript) using pip or similar, with network access restricted via Exism manifest configurations 14:21.
External C2 doesn’t need to be complex—C4 simplifies access to widely-used platforms, making it a practical and flexible option for red team operations.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Everybody Scott stage is yours to go. >> All right. Thank you so much for coming to my talk, everyone. Uh, not only am I a first- time speaker, but it's also my first time attending Defcon. So, I'm really excited to be Yeah, that's right. Thank you. Yeah. So, I'm excited to be here and give you my talk C4. Uh, as a quick disclaimer, this is given on my personal behalf and does not reflect my uh, current employer, Sony Corporation. All right, so like I said, I'm Scott Taylor and I'm part of Sony's internal red team. Uh, prior to the Sony, I've done red team work with Tro Price and the MITER Corporation, but before all of the offensive security work, I started as a Linux system administrator because you have to learn how to build before you break things. Uh, additionally, I have a couple ofe…