DEF CON 33 - Planting C4: Cross Compatible External C2 for Your Implants - Scott Taylor

DEF CON 33 - Planting C4: Cross Compatible External C2 for Your Implants - Scott Taylor

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 16:21

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

[BLUF: Scott Taylor presents C4, a cross-compatible command and control (C2) tool that enables malware developers to use external C2 channels—like AWS S3, GitHub Gists, and Confluence—across multiple programming languages via WebAssembly and the Exism plugin system, improving portability and operational flexibility.]2:00

Key Takeaways:
• C4 enables external C2 using trusted websites like AWS S3, GitHub Gists, and Confluence by leveraging WebAssembly and the Exism plugin system 2:00.
• The tool supports multiple agents and languages through a universal WebAssembly plugin model, allowing seamless code sharing and execution 4:00.
• C4 handles operational requirements such as multi-agent communication, file naming via system time, and large file exfiltration via S3 compatibility 12:00.
• Developers can deploy C4 plugins in any language (e.g., Python, JavaScript) using pip or similar, with network access restricted via Exism manifest configurations 14:21.

External C2 doesn’t need to be complex—C4 simplifies access to widely-used platforms, making it a practical and flexible option for red team operations.

Sources:

  • 2:00 Introduction to external C2 and C4’s purpose
  • 4:00 WebAssembly and Exism as the foundation for cross-language C2
  • 12:00 Operational design for multi-agent and file handling
  • 14:21 Python plugin usage and Exism manifest setup

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Everybody Scott stage is yours to go. >> All right. Thank you so much for coming to my talk, everyone. Uh, not only am I a first- time speaker, but it's also my first time attending Defcon. So, I'm really excited to be Yeah, that's right. Thank you. Yeah. So, I'm excited to be here and give you my talk C4. Uh, as a quick disclaimer, this is given on my personal behalf and does not reflect my uh, current employer, Sony Corporation. All right, so like I said, I'm Scott Taylor and I'm part of Sony's internal red team. Uh, prior to the Sony, I've done red team work with Tro Price and the MITER Corporation, but before all of the offensive security work, I started as a Linux system administrator because you have to learn how to build before you break things. Uh, additionally, I have a couple ofe…