PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although PoshC2 is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
PoshC2 contains an implementation of Mimikatz to gather credentials from memory. |
| T1007 System Service Discovery |
PoshC2 can enumerate service and service permission information. |
| T1016 System Network Configuration Discovery |
PoshC2 can enumerate network adapter information. |
| T1040 Network Sniffing |
PoshC2 contains a module for taking packet captures on compromised hosts. |
| T1046 Network Service Discovery |
PoshC2 can perform port scans from an infected host. |
| T1047 Windows Management Instrumentation |
PoshC2 has a number of modules that use WMI to execute tasks. |
| T1049 System Network Connections Discovery |
PoshC2 contains an implementation of netstat to enumerate TCP and UDP connections. |
| T1055 Process Injection |
PoshC2 contains multiple modules for injecting into processes, such as |
| T1056.001 Keylogging |
PoshC2 has modules for keystroke logging and capturing credentials from spoofed Outlook authentication messages. |
| T1068 Exploitation for Privilege Escalation |
PoshC2 contains modules for local privilege escalation exploits such as CVE-2016-9192 and CVE-2016-0099. |
| T1069.001 Local Groups |
PoshC2 contains modules, such as |
| T1071.001 Web Protocols |
PoshC2 can use protocols like HTTP/HTTPS for command and control traffic. |
| T1082 System Information Discovery |
PoshC2 contains modules, such as |
| T1083 File and Directory Discovery |
PoshC2 can enumerate files on the local file system and includes a module for enumerating recently accessed files. |
| T1087.001 Local Account |
PoshC2 can enumerate local and domain user account information. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.