Offensive Security Research & Operations

Posts for: #Redteam

TURN, STUN, and the Blind Spot in Trusted Collaboration Traffic

TURN, STUN, and trusted collaboration traffic blind spot banner

Your collaboration allow rules can work exactly as designed and still hide command and control.

Real-time communications (RTC) need low-latency media, NAT traversal, and frequently changing vendor infrastructure. To keep calls working, organizations often allow broad UDP egress, bypass proxies, and exempt collaboration traffic from inspection. The destination is trusted, so the traffic inherits that trust.

[Read more]

NOCAP: Never Lose Scan Output Again

Every operator has the same dirty secret: a graveyard of unsaved scan output.

You ran NetExec against a subnet. Sprayed creds, got hits, saw Pwn3d! flash by. And then you realized you didn’t save it. Or you used --log but named it something useless and now it’s buried in the wrong directory alongside four other files with names you don’t recognize.

[Read more]