awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
cobbr avatar

cobbr/Covenant

0
View on GitHub↗
4,699 stars·822 forks·C#·GPL-3.0·42 viewscobbr.io/Covenant.html↗

Covenant

Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It serves as a collaborative platform for coordinating security assessments, managing remote implants, and executing tasks on compromised systems through a centralized server.

The project is distinguished by its dynamic payload generator, which compiles and obfuscates executable binaries and scripts on the fly to bypass detection. It further separates itself through a collaborative environment that allows multiple authenticated operators to share a synchronized state, track operational indicators, and manage joint engagements within a single interface.

The framework provides extensive capabilities for traffic obfuscation, including the use of custom network profiles, data transformation pipelines, and bridge-based protocol translation to mask communications. It also covers post-exploitation needs such as remote file retrieval, centralized credential collection, and the development of custom remote task modules using a plug-in extension model.

The system secures communications between the server and agents using SSL certificate pinning and encrypted key exchanges to ensure forward secrecy.

Features

  • Command and Control Frameworks - A command and control platform for red team operations that manages remote agents and executes tasks using the .NET ecosystem.
  • Dynamic Binary Generation - Compiles and obfuscates source code on the fly to generate unique, non-static executable payloads.
  • Command and Control Platforms - Serves as a centralized .NET platform for managing remote agents and executing commands during security assessments.
  • Adversary Simulation - Provides a multi-user environment for coordinating adversary simulations and tracking operational indicators.
  • Software Implant Systems - Generates obfuscated payloads and manages the lifecycle and communication profiles of remote agents.
  • Agent-Based Task Queuing - Uses an agent-based queuing system where tasks are stored on the server and executed upon agent check-in.
  • Launcher Generation - Creates binaries, scripts, or one-liners using system executors to deploy and initialize remote agents.
  • Implant Lifecycle Management - Controls the behavior, polling intervals, and tasking of remote agents to maintain persistence.
  • C2 Communication Configuration - Allows precise management of polling intervals, jitter, and retry limits to tune agent-to-server contact behavior.
  • C2 Communication Protocols - Implements custom secure communication protocols for command and control between the server and remote agents.
  • C2 Listener Profiling - Provides listener profiles to customize the appearance and behavior of communications between agents and the server.
  • Traffic Masking Scripts - Configures HTTP headers and URLs to mask command-and-control traffic and blend it with legitimate network activity.
  • Payload Obfuscation Transformations - Implements custom transformation and inversion logic to obscure network payloads and evade detection.
  • Traffic Obfuscation Pipelines - Applies custom inversion and transformation logic to network traffic to obscure payloads and blend with legitimate traffic.
  • Collaborative Security Operations - Offers web and API interfaces for coordinating collaborative red team activities and joint security operations.
  • Agent-Server Key Exchanges - Implements encrypted key exchanges during the initial handshake to ensure forward secrecy between agents and the server.
  • Malleable C2 Traffic Profiles - Customizes network profiles and HTTP headers to hide C2 communications within legitimate network traffic.
  • Remote Code Execution Tools - Provides tools to execute arbitrary code snippets directly on remote implants for immediate task performance.
  • Remote Access Payloads - Generates and obfuscates dynamic .NET binaries to establish persistent remote access to target hosts.
  • Secure Network Communication - Implements SSL certificate validation and pinning to secure network communication between the server and remote agents.
  • Encrypted Communication Channels - Ensures forward secrecy through encrypted key exchanges and SSL implementations for agent-to-server communication.
  • Remote Task Management Interfaces - Provides a centralized control panel for assigning operational tasks to remote agents and monitoring progress.
  • Credential Collection - Provides automatic parsing and manual entry of passwords, hashes, and tickets from task output.
  • Communication Parameters - Provides tools to modify connection delays, jitter, and expiration dates to alter how agents communicate.
  • Post-Exploitation and Lateral Movement - Hosts listeners and manages the retrieval of credentials and files from compromised target systems.
  • Operational Task Coordination - Provides coordination tools for multiple users to manage joint operational tasks within a single server instance.
  • Tool Integration Plug-ins - Provides a plug-in extension model to compile custom functions into executable modules for remote execution.
  • Remote Task Execution Modules - Bundles reference assemblies and source libraries to create custom executable modules for remote task execution.
  • Callback Configurations - Provides network endpoint configurations and certificates for payloads to establish callbacks to the server.
  • Protocol Translation Bridges - Employs protocol translation bridges to route communication between remote agents and the server using custom protocols.
  • Remote File Downloads - Implements the capability to download files from remote hosts and store them locally for retrieval.
  • Collaborative State Synchronization - Synchronizes a shared operational environment and command history across multiple authenticated operators in real time.
  • Protocol Bridges - Implements protocol bridges that route agent traffic through external components to translate custom communication protocols.
  • Listener Certificate Injection - Allows the injection of custom SSL certificates into network listeners to authenticate and encrypt incoming agent connections.
  • Engagement Data Tracking - Records specific actions and artifacts throughout an engagement for deconfliction and reporting.
  • C2 Communication Profiles - Defines data formatting, transformation, and messenger code requirements for specific communication bridges.
  • Payload Hosting - Serves generated launchers from specified URLs to facilitate remote delivery to target systems.
  • Command History Trackers - Maintains a searchable record of all tasks assigned to agents and their resulting output for forensic review.
  • Operational Footprint Tracking - Provides tracking of compromised systems, active listeners, and uploaded files to monitor the operational footprint.
  • Status Monitors - Provides real-time tracking of active agents and retrieves detailed system and user information from hosts.
  • Command and Control - .NET-based command and control framework.
  • Command And Control Frameworks - Collaborative .NET-based framework for remote system control and task execution.
  • Execution and Persistence - Command and control framework built on .NET.
  • Exploitation Frameworks - Command and control framework for .NET environments.
  • Offensive Security - Collaborative .NET command and control framework for red teaming.
  • Offensive Security Tools - Collaborative .NET command and control framework.

Star history

Star history chart for cobbr/covenantStar history chart for cobbr/covenant

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does cobbr/covenant do?

Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It serves as a collaborative platform for coordinating security assessments, managing remote implants, and executing tasks on compromised systems through a centralized server.

What are the main features of cobbr/covenant?

The main features of cobbr/covenant are: Command and Control Frameworks, Dynamic Binary Generation, Command and Control Platforms, Adversary Simulation, Software Implant Systems, Agent-Based Task Queuing, Launcher Generation, Implant Lifecycle Management.

Which projects share features with cobbr/covenant?

Projects with overlapping indexed features include: bc-security/empire — Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and… mitre/caldera — Caldera is an adversary emulation platform and command and control framework designed to simulate cyber attack… x0rz/eqgrp — EQGRP is a remote access trojan framework and post-exploitation toolkit. It provides a centralized command and control… its-a-feature/apfell — Apfell is a red teaming framework and command and control server designed for collaborative adversary simulation. It… mantvydasb/redteaming-tactics-and-techniques — This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior.… skerkour/black-hat-rust — This project is an offensive security toolkit and development framework for creating memory-safe malware, network…

Projects sharing features with Covenant

These projects share indexed features with Covenant. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • bc-security/empireBC-SECURITY avatar

    BC-SECURITY/Empire

    5,045View on GitHub↗

    Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and manages agents written in PowerShell, Python, C#, Go, and C across Windows, Linux, and macOS, using encrypted communication channels over HTTP, HTTPS, and SMB. The framework executes over 400 built-in modules for reconnaissance, privilege escalation, credential theft, and lateral movement, and provides a modular engine for authoring custom attack modules. What sets Empire apart is its multi-language agent deployment system, which allows operators to choose implants that suit each

    PowerShellc2empirehacktoberfest
    View on GitHub↗5,045
  • mitre/calderamitre avatar

    mitre/caldera

    7,047View on GitHub↗

    Caldera is an adversary emulation platform and command and control framework designed to simulate cyber attack patterns. It functions as an automated red team tool and threat framework orchestrator, executing attack sequences based on standardized cybersecurity threat frameworks to validate security defenses and detection capabilities. The platform distinguishes itself through the dynamic compilation of customized executable payloads and the use of framework-mapped adversary modeling to structure attack techniques. It manages asynchronous agents on targeted endpoints via a central server acce

    Python
    View on GitHub↗7,047
  • x0rz/eqgrpx0rz avatar

    x0rz/EQGRP

    4,201View on GitHub↗

    EQGRP is a remote access trojan framework and post-exploitation toolkit. It provides a centralized command and control infrastructure for deploying persistent implants and managing remote agents across diverse operating systems. The project includes tools for digital forensic evasion, such as modifying system logs and filesystem timestamps to remove execution traces. It features a network interception system for capturing and reconstructing data streams by hooking into the system root, as well as exploits designed for kernel privilege escalation to elevate process permissions to administrativ

    Perl
    View on GitHub↗4,201
  • its-a-feature/apfellits-a-feature avatar

    its-a-feature/Apfell

    4,570View on GitHub↗

    Apfell is a red teaming framework and command and control server designed for collaborative adversary simulation. It provides a centralized infrastructure to manage remote agents and distribute tasking across multiple operating systems using a message broker for real-time synchronization. The system functions as a distributed agent orchestrator, allowing teams to coordinate complex attack chains and synchronize container data. It features a multi-platform payload manager that enables the downloading and integration of custom agents and command profiles from remote repositories. The platform

    JavaScript
    View on GitHub↗4,570
  • Compare all 30 related projects→