![](/assets/headers/header-logo.png)

![](https://img.shields.io/badge/Tools%20%26%20Resources%20Available-14-757575?style=for-the-badge)

### Frameworks

* [C3](https://github.com/FSecureLABS/C3) - A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive toolkits. ![last-commit](https://img.shields.io/github/last-commit/FSecureLABS/C3?style=flat)
* [Cobalt Strike](https://www.cobaltstrike.com/) - Software for Adversary Simulation and Red Team Operations. 
* [Covenant](https://github.com/cobbr/Covenant) - Covenant is a collaborative .NET C2 framework for red teamers. ![last-commit](https://img.shields.io/github/last-commit/cobbr/Covenant?style=flat)
* [Loki](https://github.com/boku7/Loki) - Node.js Command & Control for Script-Jacking Vulnerable Electron Applications ![last-commit](https://img.shields.io/github/last-commit/boku7/Loki?style=flat)
* [Merlin](https://github.com/Ne0nd0g/merlin) - Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang. ![last-commit](https://img.shields.io/github/last-commit/Ne0nd0g/merlin?style=flat)
* [NightHawk](https://www.mdsec.co.uk/nighthawk/) - Built with operational security in mind, Nighthawk is a highly malleable implant designed to circumvent and evade the modern security controls often seen in mature, highly monitored environments.
* [OcraC2](https://github.com/Ptkatz/OrcaC2) - Multifunctional C&C framework for encrypted communication. ![last-commit](https://img.shields.io/github/last-commit/Ptkatz/OrcaC2?style=flat)
* [phpsploit](https://github.com/nil0x42/phpsploit) - Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor. ![last-commit](https://img.shields.io/github/last-commit/nil0x42/phpsploit?style=flat)
* [PoshC2](https://github.com/nettitude/PoshC2) - A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement. ![last-commit](https://img.shields.io/github/last-commit/nettitude/PoshC2?style=flat)
* [Pupy](https://github.com/n1nj4sec/pupy/) - Cross-platform C2 and post-exploitation framework written in python and C. ![last-commit](https://img.shields.io/github/last-commit/n1nj4sec/pupy?style=flat)
* [SILENTTRINITY](https://github.com/byt3bl33d3r/SILENTTRINITY) - An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR. ![last-commit](https://img.shields.io/github/last-commit/byt3bl33d3r/SILENTTRINITY?style=flat)
* [Sliver](https://github.com/BishopFox/sliver) - Sliver's implants support C2 over Mutual TLS (mTLS), WireGuard, HTTP(S), and DNS and are dynamically compiled with per-binary asymmetric encryption keys ![last-commit](https://img.shields.io/github/last-commit/BishopFox/sliver?style=flat)
* [Thanatos](https://github.com/MythicAgents/thanatos) - Mythic C2 agent targeting Linux and Windows hosts written in Rust. ![last-commit](https://img.shields.io/github/last-commit/MythicAgents/thanatos?style=flat)
* [TrevorC2](https://github.com/trustedsec/trevorc2) - TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution. ![last-commit](https://img.shields.io/github/last-commit/trustedsec/trevorc2?style=flat)
