<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Hacker Hermanos</title>
  <subtitle>Cybersecurity articles on red teaming, cloud security, and defense.</subtitle>
  <id>https://hackerhermanos.com/feed.xml</id>
  <link rel="self" href="https://hackerhermanos.com/feed.xml"/>
  <link rel="alternate" href="https://hackerhermanos.com/"/>
  <updated>2026-08-21T00:00:00Z</updated>
  <author><name>Hacker Hermanos</name></author>
  <entry>
    <title>Traffic Filtering for C2 Redirectors</title>
    <id>https://hackerhermanos.com/posts/traffic-filtering-c2-redirectors/</id>
    <link href="https://hackerhermanos.com/posts/traffic-filtering-c2-redirectors/"/>
    <updated>2026-08-21T00:00:00Z</updated>
    <published>2026-05-07T00:00:00Z</published>
    <summary>Layered C2 redirector filtering uses network controls, User-Agent validation, HTTP methods, URI paths, headers, IP blocks, and cookie checks in order.</summary>
  </entry>
  <entry>
    <title>Splunk BOTS V1: Ransomware</title>
    <id>https://hackerhermanos.com/posts/splunk-bots-v1-ransomware/</id>
    <link href="https://hackerhermanos.com/posts/splunk-bots-v1-ransomware/"/>
    <updated>2026-08-21T00:00:00Z</updated>
    <summary>A walkthrough of Splunk&#x27;s Boss of the SOC (BOTS) V1 ransomware scenario: blue-team threat hunting with SPL across Windows, Sysmon, and network log data.</summary>
  </entry>
  <entry>
    <title>Serverless C2 Redirectors with AWS Lambda</title>
    <id>https://hackerhermanos.com/posts/serverless-c2-redirectors/</id>
    <link href="https://hackerhermanos.com/posts/serverless-c2-redirectors/"/>
    <updated>2026-08-21T00:00:00Z</updated>
    <published>2026-04-02T00:00:00Z</published>
    <summary>Build a serverless C2 redirector using AWS Lambda and API Gateway, deployed with Terraform. No persistent server, no attack surface, teardown in one command.</summary>
  </entry>
  <entry>
    <title>Layered Red Team C2 Infrastructure: Architecture</title>
    <id>https://hackerhermanos.com/posts/red-team-c2-infrastructure/</id>
    <link href="https://hackerhermanos.com/posts/red-team-c2-infrastructure/"/>
    <updated>2026-08-21T00:00:00Z</updated>
    <published>2026-02-20T00:00:00Z</published>
    <summary>A deep dive into layered red team C2 infrastructure design, covering CDNs, redirectors, and trust boundaries to protect your C2 server from defender discovery.</summary>
  </entry>
  <entry>
    <title>Three Ways to Hide C2 in Trusted Traffic</title>
    <id>https://hackerhermanos.com/posts/hiding-c2-in-trusted-traffic/</id>
    <link href="https://hackerhermanos.com/posts/hiding-c2-in-trusted-traffic/"/>
    <updated>2026-08-21T00:00:00Z</updated>
    <published>2026-03-23T00:00:00Z</published>
    <summary>Hide C2 communications in traffic a SOC already trusts with domain fronting, cloud service tunneling, and dead drops that reduce defender visibility.</summary>
  </entry>
  <entry>
    <title>When Azure Relay Becomes a Red Teamer&#x27;s Highway</title>
    <id>https://hackerhermanos.com/posts/azure-relay-red-teamer/</id>
    <link href="https://hackerhermanos.com/posts/azure-relay-red-teamer/"/>
    <updated>2026-08-21T00:00:00Z</updated>
    <summary>Learn how red teamers can leverage Microsoft&#x27;s Azure Relay Bridge for covert command and control channels that bypass enterprise security controls.</summary>
  </entry>
  <entry>
    <title>When AWS IoT Secure Tunneling Opens the Door From the Inside</title>
    <id>https://hackerhermanos.com/posts/aws-iot-secure-tunneling-red-teamer/</id>
    <link href="https://hackerhermanos.com/posts/aws-iot-secure-tunneling-red-teamer/"/>
    <updated>2026-08-21T00:00:00Z</updated>
    <summary>AWS IoT Secure Tunneling reaches a host inside a target network from a tunnel in the operator&#x27;s own AWS account, with no control-plane record in the target&#x27;s.</summary>
  </entry>
  <entry>
    <title>AWS IoT Core MQTT: A C2 Credential Measured in Years</title>
    <id>https://hackerhermanos.com/posts/aws-iot-mqtt-red-teamer/</id>
    <link href="https://hackerhermanos.com/posts/aws-iot-mqtt-red-teamer/"/>
    <updated>2026-08-21T00:00:00Z</updated>
    <summary>Running a C2 agent over AWS IoT Core MQTT: an X.509 certificate identity measured in years, MQTT over port 443 via ALPN, and the 128 KB message-size cap.</summary>
  </entry>
</feed>
