Back to Courses

CESH 350 Firmware: Develop a C2 Implant

Targeting · 5 days · Assessed

BG

About the course

This is the controlled implant development course in the firmware reverse engineering pathway. Students learn how command-and-control behaviour can be engineered inside an embedded target, using a contained lab implant rather than live malware. The focus is understanding offensive capability through safe construction: tasking, command handling, telemetry, operator feedback, reliability limits and the defensive signals that such behaviour creates.

Students design and build a small implant for a realistic embedded environment. They work through command parsing, transport choices, beaconing behaviour, task execution, result handling, persistence decisions, error handling and operator interaction. They also study the trade-offs that decide whether an implant is reliable, noisy, fragile, recoverable, detectable or likely to damage the target state.

Throughout the course, students use a design, build and constrain method: define the implant’s purpose, implement only the behaviour needed for the objective, observe how it behaves under failure, and assess how defenders would find or disrupt it. By the end, they understand how C2 behaviour is put together in firmware, how embedded constraints shape implant design, and how to assess the risks created by malicious or unauthorised command paths in real products.

Want to know what to expect in the classroom? Find out more about our training approach and how we turn technical concepts into practical, hands-on skills.

Skills and topics covered

This list shows the various main topics we cover during the course:

  • Command-and-control architecture concepts
  • Lab-safe implant scope and containment
  • Tasking model design
  • Command parsing and dispatch
  • Telemetry collection and reporting
  • Operator feedback and result handling
  • Beaconing behaviour and timing control
  • Transport selection for embedded environments
  • Working within resource constrained environments
  • Error handling and recovery behaviour
  • Persistence trade-offs and safety limits
  • Reliability testing under device failure conditions
  • Detectability, logging and defensive visibility

What will a new trainee gain?

A trainee learns what C2 behaviour actually looks like when it is engineered into a constrained embedded system, not just described in threat reports. That gives them a sharper understanding of attacker trade-offs, defensive indicators and the difference between a theoretical backdoor and a working control path.

What will an experienced team member gain?

An experienced engineer gains a practical way to reason about implant reliability, fragility and detection in firmware environments. For your organisation, that means stronger threat modelling, better assessment of suspicious command paths, and a more realistic understanding of how embedded devices can be controlled after compromise.

Who this course is for

This course is for firmware engineers, reverse engineers and security professionals who want to understand how command-and-control behaviour can be implemented within constrained embedded systems. Existing firmware analysis knowledge is recommended, as the course builds on those foundations to explore implant architecture, operation, reliability and defensive visibility in a controlled environment.

Not sure where you fit? Find out more about our training audience and prerequisites.

Required equipment, tools, and software

You will need a laptop with at least 8GB RAM, preferably 16GB, an up-to-date and stable operating system, and an Ethernet port or reliable Ethernet dongle. Your laptop must be fully under your control so that you can install tools and dependencies and run arbitrary code.

It is useful to have the ability to run virtual machines. Any VMs provided during the course will be suitable for importing into VirtualBox; if you use a different hypervisor, you should be comfortable importing VMs from OVF file formats.

Any sample targets, development environments and course-specific software required for the practical exercises will be provided. No specialist hardware is required.

We put together a goodie bag which directly relates to the activities in the course.  The free goodie bag is yours to keep at the end of the course, just make sure you have enough luggage space to take it home. The exact details of what is in it will vary depending on availability but we always make it a useful and interesting collection.  We provide any other tools needed to complete all the tasks set, aside from a laptop.

You don’t need to bring anything extra other than your enthusiasm!

Venue and travel information

The classroom

The classroom is well appointed, has good WiFi and hot and cold drinks, it’s spacious, comfortable, has plenty of power sockets, lots of natural light, and is wheelchair friendly. The course is delivered in English and digital versions of slides and handouts will be provided where appropriate.

Food and refreshments

Lunch and morning and afternoon snacks are provided so please make sure you let us know about any dietary needs at least a week before we get started. With the exception of the social night, all other meals are for you to organise. We suggest getting a hotel that provides breakfast, and there are many good restaurants in Manchester for your evening meals. We will try and facilitate additional social arrangements, but, this is down to the individuals present.

Staying in Manchester

There are a number of good and affordable hotels in the Manchester area. We are based in an area called Media City and we are in the same complex as the northern headquarters of the BBC. This means that there are lots of facilities locally and you could choose to not venture into the city centre.

Getting here

If you do choose to look further around there are good tram links that can take you into the city as well as to key travel hubs such as Piccadilly, the national railway station, and Manchester International Airport.

Please check the weather before you travel and bring suitable clothes for the season. If in doubt, assume you will need a waterproof coat and an umbrella. The locals will tell you that Manchester is one of the rainiest places in the world, its not actually true but it does drizzle more than you might expect, even in summer.

Ready to understand C2 from the inside?

Explore how command-and-control behaviour is designed for constrained embedded environments by building a contained lab implant. Over five days, you’ll work through tasking, telemetry, beaconing, reliability and persistence while examining the defensive signals this behaviour creates.

Hand plugging a Wi-Fi-enabled IoT microcontroller into a development board for embedded device testing and hardware security research.

Get in touch

Register interest