{"id":30759,"url":"https://github.com/tcostam/awesome-command-control","name":"awesome-command-control","description":"A collection of awesome Command \u0026 Control (C2) frameworks, tools and resources for post-exploitation and red teaming assignments.","projects_count":62,"last_synced_at":"2026-07-29T02:00:20.740Z","repository":{"id":42133389,"uuid":"278743202","full_name":"tcostam/awesome-command-control","owner":"tcostam","description":"A collection of awesome Command \u0026 Control (C2) frameworks, tools and resources for post-exploitation and red teaming assignments.","archived":false,"fork":false,"pushed_at":"2021-02-26T06:54:44.000Z","size":182,"stargazers_count":976,"open_issues_count":3,"forks_count":101,"subscribers_count":16,"default_branch":"master","last_synced_at":"2026-07-10T03:03:45.486Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tcostam.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2020-07-10T22:15:05.000Z","updated_at":"2026-07-08T17:14:26.000Z","dependencies_parsed_at":"2022-07-20T05:47:32.587Z","dependency_job_id":null,"html_url":"https://github.com/tcostam/awesome-command-control","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/tcostam/awesome-command-control","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tcostam%2Fawesome-command-control","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tcostam%2Fawesome-command-control/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tcostam%2Fawesome-command-control/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tcostam%2Fawesome-command-control/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tcostam","download_url":"https://codeload.github.com/tcostam/awesome-command-control/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tcostam%2Fawesome-command-control/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36013746,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-29T02:00:04.910Z","response_time":95,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-01-13T12:58:15.781Z","updated_at":"2026-07-29T02:00:20.740Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Tools","Videos","Online Resources","Articles"],"sub_categories":["Commercial","Open Source"],"readme":"![shall we play a game?](https://github.com/tcostam/awesome-command-control/blob/master/images.jpeg?raw=true)\n\n\u003cbr/\u003e\n\u003cdiv align=\"center\"\u003e\n\n[![Awesome](https://awesome.re/badge.svg)](https://awesome.re)\n\n_List inspired by the [awesome](https://github.com/sindresorhus/awesome) list thing._\n\nMaintained by: @tcostam\n\u003c/div\u003e\n\u003cbr/\u003e\n\n# Awesome Command \u0026 Control\n\nA collection of awesome Command \u0026amp; Control (C2) frameworks, tools and resources for post-exploitation and red teaming assessments.\n\nIf you'd like to __contribute__ to this list, simply open a PR with your additions.\n\nMaintained by [@tcostam](https://twitter.com/tcostam). If you have contributions but can't pull request, give me a shout at twitter.\n\nTable of Contents\n=================\n\n   * [Tools](#tools)\n      * [Open Source](#open-source)\n      * [Commercial](#commercial)\n   * [Online Resources](#online-resources)\n   * [Articles](#articles)\n   * [Videos](#videos)\n\n\n## Tools\n\n### Open Source\n\n* [Apfell](https://github.com/its-a-feature/Apfell): cross-platform, post-exploit, red teaming framework built with python3, docker, docker-compose, and a web browser UI.\n* [AsyncRat C#](https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp): Remote Access Tool designed to remotely monitor and control other computers through a secure encrypted connection.\n* [Baby Shark](https://github.com/UnkL4b/BabyShark): basic C2 generic server written in Python and Flask.\n* [C3](https://github.com/FSecureLABS/C3): framework that extends other red team tooling, such as the commercial Cobalt Strike (CS) product via ExternalC2, which is supported at release.\n* [Caldera](https://github.com/mitre/caldera): built on the MITRE ATT\u0026CK™ framework and an active research project at MITRE.\n* [CHAOS](https://github.com/tiagorlampert/CHAOS): PoC that allow payloads generation and control remote operating systems\n* [Dali](https://github.com/h0mbre/Dali): image-based C2 channel which utilizes Imgur to host images and task agents.\n* [Empire](https://github.com/BC-SECURITY/Empire): post-exploitation framework that includes a pure-PowerShell2.0 Windows agent, and a pure Python 2.6/2.7 Linux/OS X agent\n* [Covenant](https://github.com/cobbr/Covenant): .NET command and control framework that aims to highlight the attack surface of .NET, make the use of offensive .NET tradecraft easier, and serve as a collaborative command and control platform for red teamers.\n* [Silent Trinity](https://github.com/byt3bl33d3r/SILENTTRINITY): post-exploitation agent powered by Python, IronPython, C#/.NET.\n* [Faction C2](https://github.com/FactionC2/): C2 framework which use websockets based API that allows for interacting with agents and transports.\n* [Flying A False Flag](https://github.com/monoxgas/FlyingAFalseFlag)\n* [FudgeC2](https://github.com/Ziconius/FudgeC2): Powershell C2 platform designed to facilitate team collaboration and campaign timelining.\n* [Godoh](https://github.com/sensepost/goDoH)\n* [iBombshell](https://github.com/ElevenPaths/ibombshell)\n* [HARS](https://github.com/onSec-fr/Http-Asynchronous-Reverse-Shell): HTTP/S Asynchronous Reverse Shell.\n* [Koadic (or COM Command \u0026 Control)](https://github.com/zerosum0x0/koadic): is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire.\n* [MacShellSwift](https://github.com/cedowens/MacShellSwift/)\n* [Ninja](https://github.com/ahmedkhlief/Ninja/): Open source C2 server created by Purple Team to do stealthy computer and Active directoty enumeration without being detected by SIEM and AVs.\n* [NorthStarC2](https://github.com/EnginDemirbilek/NorthStarC2): open-source command and control framework developed for penetration testing and red teaming purposes.\n* [EvilOSX](https://github.com/Marten4n6/EvilOSX): An evil RAT (Remote Administration Tool) for macOS / OS X.\n* [Nuages](https://github.com/p3nt4/Nuages)\n* [Octopus](https://github.com/mhaskar/Octopus): open source, pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S.\n* [PoshC2](https://github.com/nettitude/PoshC2): proxy aware C2 framework written completely in PowerShell to aid penetration testers with red teaming, post-exploitation and lateral movement\n* [Powerhub](https://github.com/AdrianVollmer/PowerHub): convenient post exploitation tool for PowerShell which aids a pentester in transferring data, in particular code which may get flagged by endpoint protection.\n* [Prismatica](https://github.com/Project-Prismatica): modular C2 Interface hooked into the Diagon Command and Control Toolkit.\n* [QuasarRAT](https://github.com/quasar/Quasar): fast and light-weight remote administration tool coded in C#. Providing high stability and an easy-to-use user interface, Quasar is the perfect remote administration solution for you.\n* [Merlin](https://github.com/Ne0nd0g/merlin): cross-platform post-exploitation HTTP/2 Command \u0026 Control server and agent written in golang.\n* [Sliver](https://github.com/BishopFox/sliver): general purpose cross-platform implant framework that supports C2 over Mutual-TLS, HTTP(S), and DNS.\n* [SK8PARK/RAT](https://github.com/slyd0g/SK8PARK)\n* [Throwback](https://github.com/silentbreaksec/Throwback)\n* [Trevor C2](https://github.com/trustedsec/trevorc2): legitimate website (browsable) that tunnels client/server communications for covert command execution.\n* [Metasploit Framework](https://github.com/rapid7/metasploit-framework): computer security project that provides information about security vulnerabilities and aids in penetration testing and IDS signature development\n* [Meterpreter](https://github.com/r00t-3xp10it/meterpeter)\n* [Pupy](https://github.com/n1nj4sec/pupy): opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python.\n* [PetaQ](https://github.com/fozavci/petaqc2): malware which is being developed in .NET Core/Framework to use websockets as Command \u0026 Control (C2) channels.\n* [Pinjectra](https://github.com/SafeBreach-Labs/pinjectra): C/C++ library that implements Process Injection techniques (with focus on Windows 10 64-bit) in a \"mix and match\" style.\n* [ReverseTCPShell](https://github.com/ZHacker13/ReverseTCPShell)\n* [SHAD0W](https://github.com/bats3c/shad0w): modular C2 framework designed to use a range of methods to evade EDR and AV.\n* [SharpC2](https://github.com/SharpC2/SharpC2/tree/dev)\n* [Gcat](https://github.com/byt3bl33d3r/gcat): stealthy Python based backdoor that uses Gmail as a command and control server.\n* [DNScat2](https://github.com/iagox86/dnscat2): tool is designed to create an encrypted command-and-control (C\u0026C) channel over the DNS protocol.\n* [EggShell](https://github.com/neoneggplant/EggShell): post exploitation surveillance tool written in Python. It gives you a command line session with extra functionality between you and a target machine.\n* [EvilVM](https://github.com/jephthai/EvilVM)\n* [Void-RAT](https://github.com/KadeDev/Void-RAT): pretty basic RAT written in c#.net.\n* [WEASEL](https://github.com/facebookincubator/WEASEL): small in-memory implant using Python 3 with no dependencies.\n\n\n### Commercial\n\n* [Innuendo](https://www.immunityinc.com/products/innuendo/)\n* [Scythe](https://github.com/scythe-io)\n* [Cobalt Strike](https://www.cobaltstrike.com/): software for Adversary Simulations and Red Team Operations.\n* [Red Team Toolkit (or Slingshot)](https://silentbreaksecurity.com/red-team-toolkit/slingshot/)\n* [Voodoo](https://www.voodooops.com/)\n\n## Online Resources\n\n* [The C2 Matrix](https://www.thec2matrix.com)\n* [C2 Agent Comparison (Aug 2019)](https://threatexpress.com/blogs/2019/c2-agent-comparison/)\n\n## Articles\n\n* [A comparisson of C2 frameworks](https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1574188899.pdf)\n* [Flying a False Flag](https://i.blackhat.com/USA-19/Wednesday/\\us-19-Landers-Flying-A-False-Flag-Advanced-C2-Trust-Conflicts-And-Domain-Takeover.pdf)\n* [MacShellSwift: PoC MacOS post exploitation tool in Swift](https://securityonline.info/macshellswift-poc-macos-post-exploitation-tool-in-swift/)\n* [Throwback Thursday – A Guide to Configuring Throwback](https://silentbreaksecurity.com/throwback-thursday-a-guide-to-configuring-throwback/)\n* [Voodoo CE Quickstart](https://medium.com/stage-2-security/voodoo-ce-quickstart-ba77eb37eda5)\n* [A first look at today’s Command and Control frameworks](https://www.foregenix.com/blog/a-first-look-at-todays-command-and-control-frameworks)\n\n## Videos\n\n* [RedViper](https://www.youtube.com/watch?v=rk4EMhq30-M)\n* [Command \u0026 Control tools course](https://www.youtube.com/watch?v=bUqu8fh7xUg), in Pt-Br language.\n* [How Hackers Use Discord To Control Victim PC’s](https://www.youtube.com/watch?v=_OXyb_Oxmjg)","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/tcostam%2Fawesome-command-control/projects"}