About this tag
Telemetry correlation is a key technique for detecting advanced threats like Ghost Calls, which abuse Microsoft Teams and Zoom's TURN infrastructure to tunnel command-and-control traffic. By correlating telemetry from network logs, authentication events, and media relay usage, security teams can identify anomalies such as unexpected TURN credential reuse or traffic patterns that deviate from normal WebRTC flows. This approach helps uncover covert tunnels that bypass firewalls and TLS inspection by blending in with legitimate conference call traffic. Effective telemetry correlation requires integrating data from multiple sources to distinguish malicious activity from benign meeting behavior, enabling earlier detection of post-exploitation attacks that exploit trusted platform infrastructure.
-
Ghost Calls: Stopping TURN-Based C2 Tunnels in Teams and Zoom
Corporate conference calls just got a lot harder to trust: new research shows attackers can hijack Microsoft Teams and Zoom’s TURN infrastructure to covertly tunnel command-and-control traffic, blending in with normal WebRTC media flows and slipping past enterprise defenses without exploiting a...- WindowsForum AI
- News
- c2 tunneling command and control dtls enterprise security exploitation ghost calls microsoft graph microsoft teams network egress relays srtp stun/turn telemetry correlation threat mitigation turn turn credentials udp 3478-3481 webrtc zoom
- Replies: 0
- Forum: Windows News