2026-10-02 –, STAGE 2 (Ghost in the Shellcode) Language: English
Modern red team operations rarely play out in friendly territory. The days of wide-open egress are fading, replaced by environments where defenders tighten every screw. Outbound traffic is inspected, filtered, and often blocked entirely. A shell on a public-facing server might feel like a win, but in many cases, it comes with no DNS, no HTTP, and no callbacks at all. In these conditions, the familiar C2 playbook runs out of pages, and operators are forced to adapt or stall.
In this session, we will flip the C2 model on its head. You will see how to turn "dead-end" footholds into fully functional command channels without a single outbound packet, blending covert tasking into legitimate inbound web traffic. We will break down the design choices, the stealth advantages, and the pitfalls you will want to avoid, then share tooling to make it work with your own implants and frameworks.
If you have ever been stuck behind a wall of egress controls, you will walk away with a new blueprint and a few tricks to make the unreachable reachable.
Why This Matters
This is original, never-before-published research that redefines how C2s can function under extreme network restrictions.
The technique has been tested in real red teams, proving both its stealth and reliability in complex environments.
We’re genuinely enthusiastic about sharing this research with the community. Not just as a technical talk and tooling, but as a fresh perspective on adversary resilience in a post-egress world.
Hatem is a Principal Red Team Consultant at Google Cloud, in the META region, with extensive experience in various domains of cybersecurity. He excels in planning and executing red team operations, identifying flaws and weaknesses in systems, and leveraging his experiences to identify and exploit hard-to-find vulnerabilities. His broad expertise in providing offensive security services enables him to quickly identify viable attack paths, assess their real risks, and devise effective mitigations at strategic, operational, and tactical levels. Currently, his focus is on performing Red Team operations and adversary simulations, emphasizing adversary strategy, operational design ,and enterprise post-exploitation.
Moataz is a cybersecurity expert with over a decade of extensive experience specialising in offensive security. Presently working as a Senior Consultant at Google APT66 advanced offensive security services. Moataz focus lies within the realms of red teaming and intelligence analysis.