1200KM / tool
PoshC2 — Attack Tool
PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although PoshC2 is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: PoshC2
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Sandworm Team · G0034 · Pinned relationship source (relationship--dbc0733e-b673-41fb-8c18-e037f7794a69)
- APT33 · G0064 · Pinned relationship source (relationship--27f3f0b2-4743-420d-a4dd-842de6cb9e70)
- HEXANE · G1001 · Pinned relationship source (relationship--f612ed23-f9c3-4527-b23a-3361f90f5fe1)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1007 · System Service Discovery · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1040 · Network Sniffing · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1068 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1069.001 · Local Groups · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1087.001 · Local Account · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1090 · Proxy · Detection rules & anomalies
- T1110 · Brute Force · Detection rules & anomalies
- T1119 · Automated Collection · Detection rules & anomalies
- T1134 · Access Token Manipulation · Detection rules & anomalies
- T1134.002 · Create Process with Token · Detection rules & anomalies
- T1201 · Password Policy Discovery · Detection rules & anomalies
- T1210 · Exploitation of Remote Services · Detection rules & anomalies
- T1482 · Domain Trust Discovery · Detection rules & anomalies
- T1546.003 · Windows Management Instrumentation Event Subscription · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1550.002 · Pass the Hash · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1555 · Credentials from Password Stores · Detection rules & anomalies
- T1557.001 · Name Resolution Poisoning and SMB Relay · Detection rules & anomalies
- T1560.001 · Archive via Utility · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Active Directory Object Access · DC0071
- Active Directory Object Modification · DC0066
- Application Log Content · DC0038
- Cloud Service Enumeration · DC0083
- Cloud Service Modification · DC0069
- Command Execution · DC0064
- Container Enumeration · DC0091
- Driver Load · DC0079
- File Access · DC0055
- File Creation · DC0039
- Firewall Rule Modification · DC0051
- Firmware Modification · DC0004
- Instance Enumeration · DC0075
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Script Execution · DC0029
- Service Creation · DC0060
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- WMI Creation · DC0008
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.