Domain Fronting utilizes a known, good host (for example) Cloudflare. Cloudflare runs a business that provides enhanced metrics on HTTP connection details as well as caching HTTP connection requests to save bandwidth. Red Teamers can abuse this to make it appear that a workstation or server is communicating with a known, trusted IP Address. Geolocation results will show wherever the nearest Cloudflare server is, and the IP Address will show as ownership to Cloudflare.

*This diagram shows an example HTTP beacon from a compromised device.*
The diagram above depicts how Domain Fronting works:
1. The C2 Operator has a domain that proxies all requests through Cloudflare. 2. The Victim beacons out to the C2 Domain. 3. Cloudflare proxies the request, then looks at the Host header and relays the traffic to the correct server. 4. The C2 Server then responds to Cloudflare with the C2 Commands. 5. The Victim then receives the command from Cloudflare.