#TheC2Matrix
Come with me on a quest to compare and contrast C2 frameworks for Red Teaming and Threat-Led Penetration Testing. My next talk will be the release of #TheC2Matrix at #SANSHackFest November 18-19 in Washington DC. #redteam #infosec #purpleteam @SANSPenTest ...
November 30, 2024 at 7:21 PM
CALDERA, created by @MITREcorp is part of #TheC2Matrix even though it's focus is on automation, it does command and control. It is free, actively maintained, and maps to @MITREattack #adversaryemulation https://github.com/mitre/caldera
GitHub - mitre/caldera: Automated Adversary Emulation Pla...
Automated Adversary Emulation Platform. Contribute to mit...
github.com
December 1, 2024 at 4:10 AM
Working on a project called #TheC2Matrix to evaluate and raise awareness of all the awesome Command and Control (C2) frameworks available, for free, by our community. It will be presented at #SANSHackFest November 18-19 #adversaryemulation #redteam http://ow.ly/ZrEX50wfzEj
December 1, 2024 at 4:15 AM
First up in #TheC2Matrix is ApFell by Cody, @its_a_feature_ I like the UI, the multi-user aspect "putting the Team in Red Team", agents for macOS and Linux, and the support on the Slack channel! http://ow.ly/PBIR50wfzCt #adversaryemulation #redteam
December 1, 2024 at 4:15 AM
The next one in the #TheC2Matrix is not in scope because it relies on a commercial framework #CobaltStrike But @mwrlabs C3 is a great custom C2 idea that deserves mention. If you use CS, look into C3! http://ow.ly/2kQ750wfxBR #adversaryemulation #redteam
December 1, 2024 at 4:15 AM
Commercial Command and Control (C2) frameworks are not part of #TheC2Matrix because the goal is to find a free, open source, replacement of Empire. However, tools like #CobaltStrike must be mentioned, right? http://ow.ly/k2kN50wfzFN #adversaryemulation #redteam
Cobalt Strike | Adversary Simulation and Red Team Operations
Cobalt Strike is an adversary simulation tool that can em...
ow.ly
December 1, 2024 at 4:10 AM
Another great Command and Control (C2) framework part of #TheC2Matrix is @cobbr_io Covenant. It has multi-user, a nice GUI, and very good documentation. #adversaryemulation http://ow.ly/8e9C50wi7xL
December 1, 2024 at 4:10 AM
Although the original developers of Empire are not supporting it anymore, there is a supported fork of it. The goal of #TheC2Matrix is to have factual capabilities compared to Empire as a baseline.
http://ow.ly/M9IH50wihOH
GitHub - BC-SECURITY/Empire: Empire is a post-exploitatio...
Empire is a post-exploitation and adversary emulation fra...
ow.ly
December 1, 2024 at 4:10 AM
Faction C2 is another entry in #TheC2Matrix It offers excellent documentation, multi-user, .NET agent, redirectors, jitter, and modular. Check it out at http://ow.ly/LUiS50wmsHq
December 1, 2024 at 4:10 AM
Flying A False Flag is a new framework presented at Blackhat 2019 by @monoxgas Modules include CloudRacoon for hunting orphaned DNS records; PostOffice for C2 via Exchange EWS services; and Addendum for C2 via VirusTotal. #TheC2Matrix #adversaryemulation...
December 1, 2024 at 4:10 AM
goDoH is a DNS-over-HTTPS command and control proof of concept released by @sensepost #TheC2Matrix #adversaryemulation #redteam Excellent post on their site: http://ow.ly/7dle50wmt9D
December 1, 2024 at 3:11 AM
ibombshell is a Python3 server with PowerShell 3+ agents by the team @ElevenPaths. It is also modular with a number of post-exploitation TTPs such as UACBypass, AMSI and Defender Bypass, and lateral movement through pass-the-hash.
#TheC2Matrix...
December 1, 2024 at 3:11 AM
INNUENDO by @Immunityinc is an advanced C2 with many #adversaryemulation features. I recommend this one for the more mature organizations. It is not in scope of #TheC2Matrix because it is commercial but wanted to share it anyway. #redteam http://ow.ly/ll4h50wn5Bd
December 1, 2024 at 3:11 AM
For Windows targets, check out koadic, a COM Command & Control for Windows post-exploitation. Shout out to the developers: @Aleph___Naught @The_Naterz @JennaMagius @zerosum0x0 This one is part of #TheC2Matrix #adversaryemulation #redteam
http://ow.ly/JnlD50wn5DL
Build software better, together
GitHub is where people build software. More than 100 mill...
ow.ly
December 1, 2024 at 3:11 AM
Merlin is a cross-platform post-exploitation HTTP/2 command and control framework written by @Ne0nd0g in golang #TheC2Matrix What is HTTP/2? Your outbound controls are asking the same thing! Linux and Windows payloads. #adversaryemulation #redteam http://ow.ly/SKIM50wnC2Z
December 1, 2024 at 3:11 AM
Nuages is a modular C2 framework for more advanced operators as you have to create your own implants. It is an interesting view on defense evasion. #TheC2Matrix #adversaryemulation #redteam http://ow.ly/lJXx50wpiBy
December 1, 2024 at 3:11 AM
PoshC2_Python is the current supported version of PoshC2 It is proxy aware, written in Python3 and is modular. Comes with PowerShell/C# and Python3 implants. #TheC2Matrix #adversaryemulation #redteam http://ow.ly/DrWq50wpiQP
December 1, 2024 at 3:11 AM
I have posted about 15 different command and control (C2) frameworks using #TheC2Matrix Only half way through the list. Thanks again to all the developers sharing their code for #adversaryemulation and #redteam exercises. The results will be presented at...
December 1, 2024 at 3:11 AM
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) command and control framework written in Python by @n1nj4sec #TheC2Matrix #adversaryemulation #redteam https://github.com/n1nj4sec/pupy
GitHub - n1nj4sec/pupy: Pupy is an opensource, cross-plat...
Pupy is an opensource, cross-platform (Windows, Linux, OS...
github.com
December 1, 2024 at 1:46 AM
Project Prismatica is new and, I admit, I have not tried this one yet but will as part of #TheC2Matrix from fellow SANS instructor and author @0sm0s1z and @_OpenSecurity_ It promises to be modular and multi-platform and user #adversaryemulation #redteam http://ow.ly/3xij50wpGKI
Open Security Inc – Making Cybersecurity Accessible
ow.ly
December 1, 2024 at 1:46 AM
Slingshot, part of Red Team Toolkit, from the folks at @SilentBreakSec is an excellent C2 as well. It is not in scope of #TheC2Matrix because it is commercial but for completeness, now you know it exists. #adversaryemulation #redteam
December 1, 2024 at 1:46 AM
QuasarRAT is another open source C2 framework #TheC2Matrix that is Windows only. Will point out before @QW5kcmV3 does that this is used by malicious actors as well. Like most things, they may be used for bad or good. #adversaryemulation #redteam https://github.com/quasar/QuasarRAT
GitHub - quasar/Quasar: Remote Administration Tool for Wi...
Remote Administration Tool for Windows. Contribute to qua...
github.com
December 1, 2024 at 1:46 AM
redViper is a proof of concept C2 that uses Reddit for communication. Heard about this one recently as part of #TheC2Matrix Will try to include it but with lower priority. #adversaryemulation #redteam https://buff.ly/2mKpDd5
December 1, 2024 at 1:46 AM
Sliver is a general purpose cross-platform implant framework that supports C2 over Mutual-TLS, HTTP(S), and DNS. Implants for macOS, WIndows, and Linux written in Goland by @bishopfox #TheC2Matrix #adversaryemulation #redteam
https://buff.ly/2nf0rvK
December 1, 2024 at 1:46 AM
Powerhub uses PowerShell to send files back and forth written by @mr_mitm Not a complete C2 but lots of potential for bypassing controls. #TheC2Matrix #adversaryemulation #redteam https://buff.ly/2W6kvwh
December 1, 2024 at 1:46 AM