1200KM / tool
Brute Ratel C4 — Attack Tool
Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Brute Ratel C4, BRc4
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1005 · Data from Local System · Detection rules & anomalies
- T1021 · Remote Services · Detection rules & anomalies
- T1021.002 · SMB/Windows Admin Shares · Detection rules & anomalies
- T1021.006 · Windows Remote Management · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.007 · Dynamic API Resolution · Detection rules & anomalies
- T1036.005 · Match Legitimate Resource Name or Location · Detection rules & anomalies
- T1036.008 · Masquerade File Type · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1055.002 · Portable Executable Injection · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1069.002 · Domain Groups · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1071.004 · DNS · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1095 · Non-Application Layer Protocol · Detection rules & anomalies
- T1102 · Web Service · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1140 · Deobfuscate/Decode Files or Information · Detection rules & anomalies
- T1204.002 · Malicious File · Detection rules & anomalies
- T1482 · Domain Trust Discovery · Detection rules & anomalies
- T1497.003 · Time Based Checks · Detection rules & anomalies
- T1518.001 · Security Software Discovery · Detection rules & anomalies
- T1558.003 · Kerberoasting · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
- T1572 · Protocol Tunneling · Detection rules & anomalies
- T1574.001 · DLL · Detection rules & anomalies
- T1620 · Reflective Code Loading · Detection rules & anomalies
- T1685 · Disable or Modify Tools · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Active Directory Object Access · DC0071
- Application Log Content · DC0038
- Cloud Service Modification · DC0069
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Host Status · DC0018
- Image Metadata · DC0028
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Process Termination · DC0033
- Scheduled Job Creation · DC0001
- Script Execution · DC0029
- Service Creation · DC0060
- Service Metadata · DC0041
- Service Modification · DC0065
- WMI Creation · DC0008
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.