C2

Top 23 C2 Open-Source Projects

  • sliver

    Adversary Emulation Framework

  • Project mention: With VPN's such as Twin Gate and TailScale, why open ports to expose services to the internet? | /r/selfhosted | 2023-07-05

    IDK if you are too young to remember the fallout from Snowden, but the Kremlin threw out entire rooms computers and for a time used actual typewriters. Because those computers had, more or less, twingate connectors on them. That's a bit of a rich example, but you're essentially installing what sliver calls an implant, what meterpreter calls a payload, and what Cobalt Strike calls a beacon. It's cool if you want to, but there's no need when you can just open a port with the same technology a Fortune 50 does.

  • merlin

    Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang. (by Ne0nd0g)

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • Covenant

    Covenant is a collaborative .NET C2 framework for red teamers.

  • Project mention: Effective Adversary Emulation | dev.to | 2023-11-27

    Covenant C2: https://github.com/cobbr/Covenant

  • Empire

    Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers. (by BC-SECURITY)

  • Project mention: Opinion on best c2 to learn for resume (open sourced) | /r/redteamsec | 2023-05-12
  • Villain

    Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells, enhance their functionality with additional features (commands, utilities etc) and share them among connected sibling servers (Villain instances running on different machines).

  • black-hat-rust

    Applied offensive security with Rust - https://kerkour.com/black-hat-rust

  • Project mention: Cloudflare for Speed and Security | /r/CloudFlare | 2023-10-20

    Bonuses: If you purchase Cloudflare for Speed and Security before November 4, 2023, you'll get my bestseller, Black Hat Rust, for free! Yes, you read it right, two books for less than the price of one!

  • shad0w

    A post exploitation framework designed to operate covertly on heavily monitored environments

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • PoshC2

    A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

  • Starkiller

    Starkiller is a Frontend for PowerShell Empire.

  • kubesploit

    Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

  • manjusaka

    牛屎花 一款基于WEB界面的远程主机管理工具

  • Octopus

    Open source pre-operation C2 server based on python and powershell

  • Heroinn

    A cross platform C2/post-exploitation framework.

  • MicroBackdoor

    Small and convenient C2 tool for Windows targets. [ Русский -- значит нахуй! ]

  • GC2-sheet

    GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet and exfiltrate data using Google Drive.

  • AlanFramework

    A C2 post-exploitation framework

  • PSRansom

    PowerShell Ransomware Simulator with C2 Server

  • Nebula

    Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to allow testing other Cloud Providers and DevOps Components. (by gl4ssesbo1)

  • dystopia-c2

    Windows Remote Administration Tool that uses Discord, Telegram and GitHub as C2s

  • Nimbo-C2

    Nimbo-C2 is yet another (simple and lightweight) C2 framework

  • PhoenixC2

    Command & Control-Framework created for collaboration in python3

  • SharpGmailC2

    Our Friendly Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol

  • RedditC2

    Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic look legit.

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

C2 related posts

Index

What are some of the best open-source C2 projects? This list will help you:

Project Stars
1 sliver 7,551
2 merlin 4,932
3 Covenant 3,950
4 Empire 3,907
5 Villain 3,563
6 black-hat-rust 3,047
7 shad0w 1,981
8 PoshC2 1,692
9 Starkiller 1,264
10 kubesploit 1,071
11 manjusaka 746
12 Octopus 710
13 Heroinn 618
14 MicroBackdoor 547
15 GC2-sheet 486
16 AlanFramework 458
17 PSRansom 441
18 Nebula 354
19 dystopia-c2 340
20 Nimbo-C2 296
21 PhoenixC2 287
22 SharpGmailC2 252
23 RedditC2 250

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com