awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

37 repositorios

Awesome GitHub RepositoriesCommand and Control

Frameworks and infrastructure for managing remote access and communication.

Explore 37 awesome GitHub repositories matching part of an awesome list · Command and Control. Refine with filters or upvote what's useful.

Awesome Command and Control GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • bishopfox/sliverAvatar de BishopFox

    BishopFox/sliver

    10,707Ver en GitHub↗

    Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu

    Implant framework for red team operations.

    Goadversarial-attacksadversary-simulationc2
    Ver en GitHub↗10,707
  • malwaredllc/byobAvatar de malwaredllc

    malwaredllc/byob

    9,478Ver en GitHub↗

    This project is a post-exploitation framework and command and control platform designed for security research and penetration testing. It functions as a remote access tool consisting of a central command server and encrypted executable payloads that establish reverse shell connections. The system utilizes a web-based dashboard for multi-client administration, allowing for remote host monitoring and direct shell access through an in-browser terminal. It generates cross-platform, encrypted binaries that employ a multi-stage delivery chain and a key exchange mechanism to secure communications.

    Framework for building custom C2 implants.

    Python
    Ver en GitHub↗9,478
  • n1nj4sec/pupyAvatar de n1nj4sec

    n1nj4sec/pupy

    8,942Ver en GitHub↗

    Pupy is a command and control framework and post-exploitation suite used for remote administration and system management. It functions as a cross-platform tool for deploying payloads and controlling multiple remote agents through encrypted communication channels. The framework features a multi-platform payload generator that creates custom executable files using configurable network launchers. It employs a network traffic obfuscator that stacks encryption and obfuscation protocols to hide communication from observation. The system provides capabilities for in-memory code execution, remote pr

    Cross-platform remote administration and post-exploitation framework.

    Pythonandroidbackdoorlinux
    Ver en GitHub↗8,942
  • empireproject/empireAvatar de EmpireProject

    EmpireProject/Empire

    7,813Ver en GitHub↗

    Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It serves as a centralized platform for coordinating remote agent communication and automating the delivery of security testing payloads to target systems. The project provides a suite of modules for host reconnaissance, lateral movement, and credential harvesting across corporate environments. It functions as a remote administration tool to maintain persistence and execute commands on compromised hosts. The framework incorporates capabilities for agent orchestration and the executio

    Post-exploitation and C2 framework.

    PowerShell
    Ver en GitHub↗7,813
  • ne0nd0g/merlinAvatar de Ne0nd0g

    Ne0nd0g/merlin

    5,555Ver en GitHub↗

    Merlin is a cross-platform command and control framework and remote access tool. It provides a server and agent system for post-exploitation coordination, utilizing an HTTP/2 framework for secure communication and the execution of commands across multiple operating systems. The project features an in-memory code execution engine that runs assemblies and shellcode directly within a process to avoid writing files to disk. It implements a decentralized communication architecture through a peer-to-peer network, allowing agents to exchange data via direct bind or reverse connections. To evade det

    HTTP/2-based cross-platform C2 framework.

    Go
    Ver en GitHub↗5,555
  • bc-security/empireAvatar de BC-SECURITY

    BC-SECURITY/Empire

    5,045Ver en GitHub↗

    Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and manages agents written in PowerShell, Python, C#, Go, and C across Windows, Linux, and macOS, using encrypted communication channels over HTTP, HTTPS, and SMB. The framework executes over 400 built-in modules for reconnaissance, privilege escalation, credential theft, and lateral movement, and provides a modular engine for authoring custom attack modules. What sets Empire apart is its multi-language agent deployment system, which allows operators to choose implants that suit each

    Maintained version of Empire with AMSI bypass.

    PowerShellc2empirehacktoberfest
    Ver en GitHub↗5,045
  • cobbr/covenantAvatar de cobbr

    cobbr/Covenant

    4,699Ver en GitHub↗

    Covenant es un framework de comando y control basado en .NET diseñado para operaciones de red team y simulación de adversarios. Sirve como plataforma colaborativa para coordinar evaluaciones de seguridad, gestionar implantes remotos y ejecutar tareas en sistemas comprometidos a través de un servidor centralizado. El proyecto se distingue por su generador de payloads dinámico, que compila y ofusca binarios ejecutables y scripts al vuelo para evadir la detección. Se separa aún más a través de un entorno colaborativo que permite a múltiples operadores autenticados compartir un estado sincronizado, rastrear indicadores operativos y gestionar compromisos conjuntos dentro de una única interfaz. El framework proporciona capacidades extensas para la ofuscación de tráfico, incluyendo el uso de perfiles de red personalizados, pipelines de transformación de datos y traducción de protocolos basada en puentes para enmascarar comunicaciones. También cubre necesidades de post-explotación como recuperación remota de archivos, recolección centralizada de credenciales y el desarrollo de módulos de tareas remotas personalizados utilizando un modelo de extensión de plug-in. El sistema asegura las comunicaciones entre el servidor y los agentes utilizando pinning de certificados SSL e intercambios de claves cifrados para asegurar el secreto hacia adelante (forward secrecy).

    .NET-based command and control framework.

    C#
    Ver en GitHub↗4,699
  • ridter/intranet_penetration_tipsAvatar de Ridter

    Ridter/Intranet_Penetration_Tips

    4,606Ver en GitHub↗

    Este proyecto es una guía técnica y referencia para pruebas de penetración en redes internas. Sirve como una colección de procedimientos para explotar y navegar por redes corporativas privadas durante evaluaciones de seguridad. El repositorio proporciona manuales especializados y hojas de referencia (cheat sheets) centradas en ataques a Active Directory, movimiento lateral y escalada de privilegios. Incluye un playbook de post-explotación para mantener la persistencia en el sistema y limpiar rastros forenses. La documentación cubre una amplia gama de capacidades de seguridad, incluyendo acceso inicial, pivoteo y tunelización de red, y reconocimiento interno. También detalla métodos para evadir la detección de seguridad y comprometer servicios de directorio para extraer hashes de dominio.

    Provides guidance on establishing communication channels between compromised hosts and a C2 controller.

    Ver en GitHub↗4,606
  • its-a-feature/mythicAvatar de its-a-feature

    its-a-feature/Mythic

    4,571Ver en GitHub↗

    Mythic es un framework de red teaming y servidor de comando y control diseñado para gestionar actividades post-explotación. Proporciona un sistema centralizado para emitir tareas y recibir telemetría de agentes desplegados en diversas plataformas y sistemas operativos objetivo. La plataforma cuenta con una interfaz de operador colaborativa que permite a múltiples investigadores de seguridad coordinar operaciones y rastrear la actividad del objetivo dentro de un entorno compartido. Admite el despliegue y actualización de diversos payloads de agentes a través de un gestor de payloads multiplataforma. El framework utiliza una arquitectura basada en plugins para extender la funcionalidad, permitiendo la integración de perfiles de comandos personalizados y definiciones de payloads desde repositorios remotos. Su estructura operativa emplea aislamiento de servicios basado en contenedores y un puente de mensajería para sincronizar datos y tareas entre componentes desacoplados.

    Multi-agent command and control framework.

    JavaScript
    Ver en GitHub↗4,571
  • zer0yu/awesome-cobaltstrikeAvatar de zer0yu

    zer0yu/Awesome-CobaltStrike

    4,419Ver en GitHub↗

    Este proyecto es una colección curada de herramientas, scripts y guías técnicas diseñadas para mejorar las operaciones de seguridad ofensiva utilizando Cobalt Strike. Sirve como un centro de recursos para gestionar la infraestructura de comando y control y desplegar compromisos de seguridad. La colección incluye toolkits para evadir sistemas de detección y respuesta de endpoints (EDR), junto con librerías para automatizar tareas de red team como reconocimiento y enumeración de hosts. Proporciona recursos para desarrollar frameworks de post-explotación, centrándose específicamente en la creación de librerías reflexivas y código residente en memoria. El repositorio cubre una amplia gama de capacidades operativas, incluyendo la personalización del tráfico de red para evitar la detección, análisis forense de memoria para análisis de infraestructura y varias técnicas de ofuscación de shellcode. También incluye guías para configurar servidores de comando y control y realizar inyección de procesos en el host.

    Serves as a comprehensive resource hub for deploying and managing Cobalt Strike command and control infrastructure.

    Ver en GitHub↗4,419
  • iagox86/dnscat2Avatar de iagox86

    iagox86/dnscat2

    3,839Ver en GitHub↗

    dnscat2 is a DNS tunneling tool and covert command and control server that encapsulates encrypted traffic within DNS queries and responses. It functions as an encrypted DNS proxy designed to bypass network firewalls and establish communication paths when standard outbound ports are blocked. The project enables the creation of covert network channels by acting as an authoritative nameserver. It supports remote command execution through interactive shells and provides a mechanism for tunneling TCP network traffic to reach restricted remote hosts. The system includes capabilities for multiplexe

    Establishes stealthy C2 tunnels using legitimate DNS traffic.

    PHP
    Ver en GitHub↗3,839
  • nathanlopez/stitchAvatar de nathanlopez

    nathanlopez/Stitch

    3,532Ver en GitHub↗

    Stitch is a command and control framework and post-exploitation toolkit designed for managing multiple remote systems from a central server. It functions as a remote administration tool and payload builder, enabling the execution of commands and the deployment of agents across different operating systems. The project features a cross-platform builder for generating custom executable agents with configurable network bindings and boot behaviors. It utilizes encrypted communication channels to secure traffic between the controller and remote clients, and it supports the execution of dynamic scri

    Implements a central server to manage remote agents and secure communication via encrypted channels.

    Pythoncross-platformkeyloggerlinux
    Ver en GitHub↗3,532
  • t3l3machus/hoaxshellAvatar de t3l3machus

    t3l3machus/hoaxshell

    3,421Ver en GitHub↗

    Hoaxshell is a command and control system for Windows remote command execution. It provides a framework for generating and managing reverse shell payloads that utilize an HTTP beaconing protocol, where victim clients periodically poll a handler to receive and execute instructions. The project distinguishes itself through its ability to bypass PowerShell Constrained Language Mode using specialized payload generation. It supports encrypted command and control via TLS certificate injection and provides mechanisms for remote session recovery, allowing a handler to reestablish control over active

    Generates and handles Windows reverse shell payloads over HTTP.

    Pythonhackingopen-sourcepenetration-testing
    Ver en GitHub↗3,421
  • nyan-x-cat/asyncrat-c-sharpAvatar de NYAN-x-CAT

    NYAN-x-CAT/AsyncRAT-C-Sharp

    2,837Ver en GitHub↗

    Open-source remote administration tool for Windows.

    C#adminasynchronousbackdoor
    Ver en GitHub↗2,837
  • byt3bl33d3r/silenttrinityAvatar de byt3bl33d3r

    byt3bl33d3r/SILENTTRINITY

    2,340Ver en GitHub↗

    An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR

    Python-based post-exploitation framework.

    Boo
    Ver en GitHub↗2,340
  • bats3c/shad0wAvatar de bats3c

    bats3c/shad0w

    2,175Ver en GitHub↗

    A post exploitation framework designed to operate covertly on heavily monitored environments

    Covert post-exploitation framework.

    C
    Ver en GitHub↗2,175
  • nettitude/poshc2Avatar de nettitude

    nettitude/PoshC2

    2,112Ver en GitHub↗

    PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement.

    PowerShell-based command and control framework.

    PowerShell
    Ver en GitHub↗2,112
  • fsecurelabs/c3Avatar de FSecureLABS

    FSecureLABS/C3

    1,774Ver en GitHub↗

    C3 (Custom Command and Control) is a tool that allows Red Teams to rapidly develop and utilise esoteric command and control channels (C2). It's a framework that extends other red team tooling, such as the commercial Cobalt Strike (CS) product via ExternalC2, which is supported at release. It…

    Framework for prototyping custom C2 channels.

    C++
    Ver en GitHub↗1,774
  • rvrsh3ll/findfrontabledomainsAvatar de rvrsh3ll

    rvrsh3ll/FindFrontableDomains

    647Ver en GitHub↗

    Search for potential frontable domains

    Utility for identifying domains suitable for domain fronting techniques.

    Python
    Ver en GitHub↗647
  • mindpointgroup/cloudfruntAvatar de MindPointGroup

    MindPointGroup/cloudfrunt

    363Ver en GitHub↗

    A tool for identifying misconfigured CloudFront domains

    Tool for testing and identifying domain fronting capabilities on CloudFront.

    Python
    Ver en GitHub↗363
Ant.12Siguiente
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Command and Control