offensive-c2-frameworks

Installation
SKILL.md

Offensive C2 Frameworks

Command and Control is the backbone of any sustained red team engagement. Your C2 framework manages implant communication, task distribution, post-exploitation, and lateral movement coordination. Selecting and configuring the right framework -- and layering proper infrastructure around it -- determines whether your operation survives the first 48 hours or burns within minutes of initial access.

This skill covers the major C2 frameworks you encounter in professional red teaming, their configuration for operational security, the infrastructure patterns that protect your backend servers, and the tradecraft decisions that separate detectable operations from resilient ones. You are expected to understand not just how to deploy these tools, but why specific configuration choices matter against modern EDR and network monitoring.

Quick Workflow

  1. Define your engagement's network constraints -- identify allowed egress protocols, proxy requirements, and monitoring posture.
  2. Select a primary C2 framework and transport based on target environment restrictions.
  3. Build redirector infrastructure between your implants and your team server -- never expose the team server directly.
  4. Configure communication profiles to mimic legitimate traffic patterns for the target organization.
  5. Generate implants with appropriate sleep intervals, jitter, and kill dates.
  6. Establish primary and fallback C2 channels using different transports and infrastructure.
  7. Monitor your C2 traffic against detection signatures before deploying to production targets.

Cobalt Strike

Installs
32
GitHub Stars
6.1K
First Seen
Aug 27, 2026
offensive-c2-frameworks — snailsploit/claude-red