C2 & Post-Exploitation
Command-and-control frameworks and what happens after the first session — Sliver, Havoc and Mythic, listener and implant profiles, and the detection surface that makes this the loudest phase of an engagement.
Post-exploitation is the loudest, most detectable phase of an engagement, and the one where tooling choice matters least and tradecraft matters most. A command-and-control framework is plumbing — implant generation, session management, tasking. Whether you get caught is decided by the infrastructure and OPSEC around it, not the framework name.
The frameworks
Section titled “The frameworks”Sliver, Havoc and Mythic are the open-source command-and-control frameworks in common use:
- Sliver — the pragmatic default. Cross-platform implants, mTLS/HTTP(S)/DNS/WireGuard transports, and a scriptable console. The usual starting point because it is capable without much setup.
- Havoc — a modern framework with an emphasis on evasion and a mature agent (Demon). Reached for when the detection bar is higher.
- Mythic — the extensible one: a framework where agents and C2 profiles are pluggable, so a team can run purpose-built agents behind a common interface. Worth the setup cost on a longer engagement.
The honest position: for most work the framework is interchangeable. The differentiator is the infrastructure — redirectors, domain selection, profile tuning — not which console you type into.
Listeners, implants and profiles
Section titled “Listeners, implants and profiles”The knobs that decide detectability, in rough order of impact:
- Transport: HTTPS traffic to a plausible domain blends in; DNS beaconing is slower but slips past controls that never inspect DNS. The choice is per-environment, informed by what the target’s egress control actually inspects.
- Sleep and jitter: beacon interval and randomisation are the single biggest tell. A tight, regular beacon is trivially detected on timing alone; long sleep with high jitter is what buys dwell time — at the cost of interactivity.
- Malleable profiles: shaping the C2 traffic to imitate a legitimate service (a CDN, an update check) is what defeats signature-based network detection. It is also the work — a default profile is a default signature.
- Implant format: staged versus stageless, and the loader around it, decide what endpoint detection sees at execution. This is where most implants actually die.
After the first session
Section titled “After the first session”Post-exploitation is a loop: establish, enumerate, escalate, move, repeat — quietly.
- Situational awareness first: who am I, what can I reach, what is watching. Loud enumeration here undoes a careful initial access.
- Credential access feeds lateral movement, and on Windows this hands off to the Active Directory toolkit — the C2 gives you a foothold, BloodHound and Impacket tell you where it goes.
- Pivoting — SOCKS proxies and port forwards through the implant reach segments you cannot touch directly, turning one session into access to a whole segment.
- Persistence only when the engagement calls for it, and always deconflicted — every persistence mechanism is an artifact a forensic investigation is built to find.
The detection surface is the point
Section titled “The detection surface is the point”In a red team engagement, being caught is data, not failure. Each of the above is a detection opportunity, and mapping which of your actions fired an alert — and which did not — is the deliverable that improves the defense. This is where an engagement hands off to detection quality: the timeline of what you did becomes the list of what should have been caught.
Where this connects
Section titled “Where this connects”This is the tooling behind red team operations, where the infrastructure and OPSEC that actually decide the outcome are covered in full. The artifacts it leaves are what malware analysis reverses, and its detectability is the raw material of detection quality — the same engagement read from the defender’s side.
Graph View
Spotted an error on this page? Report it.