PoshC2 — Malware Profile

PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although PoshC2 is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.

MITRE ATT&CK techniques (32)

IntelFusions coverage

Attributed threat actors

Read the full analysis on IntelFusions