Red › Module 5 › Lesson 1
C2 Named
C2 frameworks are named for literacy — Sliver, Mythic, Cobalt Strike — lab-only on $LAB_RT under RoE, never production or classmates.
Visual · rt_c2_named
C2 named literacy. $LAB_RT only. Original Cyberlium.
Opening
Knowing C2 names helps blue hunt — running C2 outside $LAB_RT RoE helps nobody legally.
Command-and-control frameworks — Sliver, Mythic, Cobalt Strike (commercial), Havoc, and others — provide operator consoles and agent/beacon channels for authorized adversary simulation. Defenders signature C2 traffic, parent-child process chains, and certificate patterns tied to these names in ATT&CK (T1071, T1573). Cyberlium names frameworks for detection literacy and lab-only use on $LAB_RT. You will NOT deploy C2 against production, classmates, or internet strangers. No weapon cookbooks. Next: Beacon Concepts.
1. Framework names defenders recognize
Sliver: open-source C2 used in lab purple teams. Mythic: modular agent platform with API-driven tasks. Cobalt Strike: commercial adversary simulation suite requiring license — often emulated by attackers, hunted by blue via JA3, named pipes, and beacon patterns.
Literacy = name recognition + detection mapping on $LAB_RT — not deployment guides against unauthorized targets.
Command guide
Try these commands — Framework names defenders recognize
═══ LINUX / macOS (Terminal Practice) ═══
Check system state and user context
Command — copy this
id whoami uname -a
Inspect network sockets listening for connections
Command — copy this
ss -tuln 2>/dev/null || netstat -tuln
Audit active processes
Command — copy this
ps aux | grep -v "\[" | head -15
═══ WINDOWS (POWERSHELL) ═══ Query user identity and system information
Command — copy this
whoami /all Get-ComputerInfo | Select-Object CsName, OsName, OsVersion
Primary tools to practice this lesson: ss, curl. Reference sites: Command and Control (https://attack.mitre.org/tactics/TA0011/); Sliver docs (https://github.com/BishopFox/sliver/wiki). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Lab-only C2 binding
C2 listeners bind to $LAB_RT IP ranges and lab DNS only. RoE names allowed framework, listener ports, and stop time. Egress firewall blocks callbacks to stranger networks.
Production C2 — even 'just testing' — violates engagement rules and law without signed authorization.
3. C2 named is not C2 authorized everywhere
Forbidden: CS cracks, stranger C2 campaigns, beaconing on classmate VMs, long-haul C2 on employer laptops. Allowed: document framework names in plan pack for $LAB_RT detection exercise.
Ship: three C2 framework names + one detection idea each for blue on $LAB_RT. Next: Beacon Concepts.
4. What you ship: C2 framework name table for $LAB_RT
Sliver/Mythic/CS named with detection notes. $LAB_RT lab-only. NEVER production/classmates. chmod 600.
5. What you record before the next lesson
Date. C2 name table. $LAB_RT named. File t21-m05-l01-c2-named.txt chmod 600.
6. Wrong vs right: stranger phishing vs authorized RT lab
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Deploy Cobalt Strike crack on production. Beacon classmate hackathon VM.
Right
Write C2 name table with detection notes for $LAB_RT. Next: Beacon Concepts.
Mission: name C2 frameworks for defender literacy
1) Name Sliver, Mythic, Cobalt Strike in one line each. 2) Add one blue detection idea per name. 3) Write lab-only $LAB_RT binding note. 4) chmod 600. Never deploy C2 outside RoE.
Stuck? Ask Cyberlium AI Mentor
Blue hunts names and patterns — give them literate debrief material.
Knowledge Check
APPLY: C2 Named on Cyberlium teaches:
Multiple choice
Knowledge Check
APPLY: True or False: Cobalt Strike may be used on any host for homework.
True or False
Knowledge Check
APPLY: C2 listeners on $LAB_RT should bind to:
Multiple choice