daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

mythic.md (24711B)


      1 ---
      2 title: "Mythic"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/mythic.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/mythic.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Mythic
     14 
     15 ## What is Mythic?
     16 
     17 Mythic is an open-source, modular, collaborative command and control (C2) framework designed for red teaming. It allows operators to manage and deploy agents (payloads) across different operating systems, including Windows, Linux, and macOS. Mythic provides a browser UI for multi-operator tasking, file handling, SOCKS/rpfwd management, and payload generation.
     18 
     19 Unlike monolithic frameworks, the Mythic repository itself does **not** ship payload types or C2 profiles. Agents, wrappers, and C2 profiles are typically installed as external components and can be updated independently from Mythic core.
     20 
     21 ### Installation
     22 
     23 To install Mythic, follow the instructions on the official **[Mythic repo](https://github.com/its-a-feature/Mythic)**. A common bootstrap from the Mythic directory is:
     24 
     25 ```bash
     26 sudo make
     27 sudo ./mythic-cli start
     28 ```
     29 
     30 If Mythic is already running, you can normally add a new agent or profile with `./mythic-cli install github ...` and then either restart Mythic or just start the new component directly.
     31 
     32 ### Agents
     33 
     34 Mythic supports multiple agents, which are the **payloads that perform tasks on the compromised systems**. Each agent can be tailored to specific needs and can run on different operating systems.
     35 
     36 By default Mythic doesn't have any agents installed. The open-source community agents live in [**https://github.com/MythicAgents**](https://github.com/MythicAgents), and the [**community feature matrix**](https://mythicmeta.github.io/overview/agent_matrix.html) is useful to quickly check supported operating systems, payload formats, wrappers, and C2 profiles.<sup>[[1]](#references)</sup>
     37 
     38 To install an agent from that org you can run:
     39 
     40 ```bash
     41 sudo ./mythic-cli install github https://github.com/MythicAgents/<agent-name>
     42 sudo ./mythic-cli install github https://github.com/MythicAgents/Apollo.git
     43 sudo -E ./mythic-cli install github https://github.com/MythicAgents/Apollo.git
     44 ```
     45 
     46 The `sudo -E` form is useful when you are installing from a non-root environment. You can add new agents with the previous command even if Mythic is already running.
     47 
     48 ### C2 Profiles
     49 
     50 C2 profiles in Mythic define **how agents communicate with the Mythic server**. They specify the communication protocol, encryption methods, and other settings. You can create and manage C2 profiles through the Mythic web interface.
     51 
     52 By default Mythic is installed with no profiles, however, it's possible to download some profiles from the repo [**https://github.com/MythicC2Profiles**](https://github.com/MythicC2Profiles) running:
     53 
     54 ```bash
     55 sudo ./mythic-cli install github https://github.com/MythicC2Profiles/<c2-profile>
     56 sudo ./mythic-cli install github https://github.com/MythicC2Profiles/http
     57 ```
     58 
     59 Current operator-relevant profiles to keep in mind:
     60 
     61 - [`http`](https://github.com/MythicC2Profiles/http): basic asynchronous GET/POST traffic.
     62 - [`httpx`](https://github.com/MythicC2Profiles/httpx): more flexible HTTP traffic with multiple callback domains, fail-over/round-robin rotation, custom headers/query parameters, and message transforms (`base64`, `base64url`, `xor`, `netbios`, `prepend`, `append`) placed in cookies, headers, query parameters, or body.
     63 - [`dynamichttp`](https://github.com/MythicC2Profiles/dynamichttp): JSON/TOML-driven HTTP message shaping when the static `http` profile is too recognizable.
     64 
     65 ### Current platform notes
     66 
     67 - Many public agents and profiles now install with pre-built remote container images.
     68   If you fork a component or patch it locally and Mythic keeps using the old
     69   behavior, inspect the generated `.env` entries for `*_REMOTE_IMAGE`,
     70   `*_USE_BUILD_CONTEXT`, and `*_USE_VOLUME`; enabling
     71   `*_USE_BUILD_CONTEXT="true"` is usually what makes Mythic rebuild from your
     72   local Docker context instead of silently reusing the remote image.
     73 - Browser scripts are one of Mythic's highest-value quality-of-life features
     74   for operators: they can turn raw command output into tables, screenshot
     75   viewers, download links, search links, and buttons that issue follow-on
     76   tasking directly from the UI. Current Mythic builds let each operator keep
     77   their own scripts, toggle them globally or per-task, and get the best results
     78   when agents return structured JSON instead of plaintext. This is especially
     79   useful for repetitive `ls`, `ps`, triage, and file-browser workflows.<sup>[[4]](#references)[[6]](#references)</sup>
     80 - Newer Mythic builds also support interactive tasking and Push C2 patterns
     81   that reduce the need for `sleep 0` polling during PTY/SOCKS/rpfwd-heavy
     82   operations. When an agent/profile supports it, this is usually lower-overhead
     83   than hammering the server with constant check-ins just to keep an interactive
     84   channel usable.<sup>[[3]](#references)</sup>
     85 - Current 3.4-era Mythic builders are more context-aware than older writeups
     86   imply: build parameters can now be grouped or hidden based on the selected OS
     87   or other build options, payload types can declare whether they support
     88   multiple C2 profiles or multiple instances of the same C2 in one build, and
     89   C2 parameter deviations let an agent hide fields it does not actually
     90   implement. This matters when you bounce between `http`, `httpx`, `smb`,
     91   `tcp`, and `websocket` because the safe/valid build surface is no longer a
     92   flat static form.<sup>[[5]](#references)</sup>
     93 - If you are building a custom agent/profile pair and you don't want Mythic's
     94   JSON message format or default crypto on the wire, use a
     95   `translation_container`: Mythic strips the UUID, hands the encrypted blob and
     96   key material to the translator over gRPC, and expects agent-native bytes
     97   back. This is the clean way to support binary protocols, custom framing, or
     98   agent-side encryption without rewriting the whole server.
     99 - Remember that linked/P2P callbacks do not just shuttle tasking. Mythic's
    100   `get_tasking` flow can also carry responses plus `delegates`, `socks`,
    101   `rpfwd`, and `interactive` data. In practice, one egress callback can service
    102   inner callbacks and pivot channels in the same polling loop; if the child
    103   agents perform their own periodic check-ins, `get_delegate_tasks=false` keeps
    104   the parent from accidentally consuming the inner callback's queued jobs.
    105 
    106 ### Wrapper payloads
    107 
    108 Wrapper payloads let you keep the same agent logic while changing the on-disk representation that gets delivered or persisted.
    109 
    110 - `service_wrapper`: turns another payload into a Windows service executable, which is useful when the execution path requires a valid service binary.
    111 - `scarecrow_wrapper`: wraps compatible shellcode with the ScareCrow loader to generate loader-backed outputs such as EXE/DLL/CPL.
    112 
    113 ## [Apollo Agent](https://github.com/MythicAgents/Apollo)
    114 
    115 Apollo is a Windows agent written in C# using the 4.0 .NET Framework designed to be used in SpecterOps training offerings.<sup>[[2]](#references)</sup>
    116 
    117 Install it with:
    118 
    119 ```bash
    120 ./mythic-cli install github https://github.com/MythicAgents/Apollo.git
    121 ```
    122 
    123 ### Current build/profile notes
    124 
    125 - Apollo can currently emit `WinExe`, `Shellcode`, `Service`, and `Source` payloads.
    126 - The commonly used Apollo profiles are `http`, `httpx`, `smb`, `tcp`, and `websocket`.
    127 - `httpx` is usually the more flexible option when you need domain rotation, proxy support, custom message placement, and message transforms instead of the older static `http` profile.
    128 - Apollo is one of the more feature-complete community agents and currently exposes Mythic-side integrations such as browser scripts, file/process browser views, screenshots, keylogging, SOCKS, rpfwd, Push C2, and P2P routing.
    129 - Apollo supports wrapper payloads such as `service_wrapper` and `scarecrow_wrapper`.
    130 - Apollo supports dynamic command loading, so you can keep the initial payload lean and load extra commands or Forge modules later instead of compiling every post-ex capability into the first build.
    131 - When generating shellcode output, Apollo's current builder also exposes Donut format choices (`Binary`, `Base64`, `C`, `Ruby`, `Python`, `Powershell`, `C#`, `Hex`) and Donut bypass behavior (`None`, `Abort on fail`, `Continue on fail`). This is useful if the end goal is to re-wrap the shellcode with `service_wrapper`, `scarecrow_wrapper`, or a custom loader.
    132 - `register_file` and `register_assembly` are the staging primitives for `execute_assembly`, `execute_pe`, `inline_assembly`, `execute_coff`, `powershell_import`, and `powerpick`. In current Apollo builds, those staged artifacts are cached client-side as DPAPI-protected AES256 blobs.
    133 - `ls` and `ps` results integrate especially well with Mythic's browser scripts and file/process browser, which makes operator triage noticeably faster in collaborative operations.
    134 - Apollo's fork-and-run jobs inherit their sacrificial process settings from
    135   `spawnto_x86` / `spawnto_x64`, inherit parent selection from `ppid`, and
    136   then use the currently selected injection primitive. In practice, this means
    137   your OPSEC tuning for one command often affects `execute_assembly`,
    138   `powerpick`, `mimikatz`, `pth`, `dcsync`, `execute_pe`, and `spawn` at the
    139   same time.
    140 - Current documented Apollo injection backends include `CreateRemoteThread`,
    141   `QueueUserAPC` (early-bird style), and `NtCreateThreadEx` via syscalls. Use
    142   `get_injection_techniques` before noisy post-exploitation and
    143   `set_injection_technique` if you need to swap away from a primitive that
    144   clashes with the target or the command you want to run.
    145 - `blockdlls` only affects sacrificial processes created for post-exploitation
    146   jobs. Combined with a less suspicious `spawnto_x64` target than the default
    147   bare `rundll32.exe`, this is one of the easiest Apollo-side changes to make
    148   before running assembly/PowerShell-heavy tasking.
    149 
    150 This agent has a lot of commands that makes it very similar to Cobalt Strike's Beacon with some extras. Among them, it supports:
    151 
    152 ### Common actions
    153 
    154 - `cat`: Print the contents of a file
    155 - `cd`: Change the current working directory
    156 - `cp`: Copy a file from one location to another
    157 - `ls`: List files and directories in the current directory or specified path
    158 - `ifconfig`: Get network adapters and interfaces
    159 - `netstat`: Get TCP and UDP connection information
    160 - `pwd`: Print the current working directory
    161 - `ps`: List running processes on the target system (with added info)
    162 - `jobs`: List all running jobs associated with long-running tasking
    163 - `download`: Download a file from the target system to the local machine
    164 - `upload`: Upload a file from the local machine to the target system
    165 - `reg_query`: Query registry keys and values on the target system
    166 - `reg_write_value`: Write a new value to a specified registry key
    167 - `sleep`: Change the agent's sleep interval, which determines how often it checks in with the Mythic server
    168 - And many others, use `help` to see the full list of available commands.
    169 
    170 ### Privilege escalation
    171 
    172 - `getprivs`: Enable as many privileges as possible on the current thread token
    173 - `getsystem`: Open a handle to winlogon and duplicate the token, effectively escalating privileges to SYSTEM level
    174 - `make_token`: Create a new logon session and apply it to the agent, allowing for impersonation of another user
    175 - `steal_token`: Steal a primary token from another process, allowing the agent to impersonate that process's user
    176 - `pth`: Pass-the-Hash attack, allowing the agent to authenticate as a user using their NTLM hash without needing the plaintext password
    177 - `mimikatz`: Run Mimikatz commands to extract credentials, hashes, and other sensitive information from memory or the SAM database
    178 - `rev2self`: Revert the agent's token to its primary token, effectively dropping privileges back to the original level
    179 - `ppid`: Change the parent process for post-exploitation jobs by specifying a new parent process ID, allowing for better control over job execution context
    180 - `printspoofer`: Execute PrintSpoofer commands to bypass print spooler security measures, allowing for privilege escalation or code execution
    181 - `dcsync`: Sync a user's Kerberos keys to the local machine, allowing for offline password cracking or further attacks
    182 - `ticket_cache_add`: Add a Kerberos ticket to the current logon session or a specified one, allowing for ticket reuse or impersonation
    183 
    184 ### Process execution
    185 
    186 - `assembly_inject`: Allows to inject a .NET assembly loader into a remote process
    187 - `blockdlls`: Block non-Microsoft signed DLLs from loading into post-exploitation jobs
    188 - `execute_assembly`: Executes a .NET assembly in the context of the agent
    189 - `execute_coff`: Executes a COFF file in memory, allowing for in-memory execution of compiled code
    190 - `execute_pe`: Executes an unmanaged executable (PE)
    191 - `keylog_inject`: Injects a keylogger into another process and streams keystrokes back into Mythic's keylog view
    192 - `screenshot` / `screenshot_inject`: Capture the current desktop directly or
    193   by injecting a screenshot assembly into a target process/session
    194 - `get_injection_techniques`: Show available injection techniques and the currently selected one
    195 - `inline_assembly`: Executes a .NET assembly in a disposable AppDomain, allowing for temporary execution of code without affecting the agent's main process
    196 - `register_assembly`: Register a .NET assembly for later execution
    197 - `register_file`: Register a file in the agent cache for later `execute_*` or PowerShell tasking
    198 - `run`: Executes a binary on the target system, using the system's PATH to find the executable
    199 - `set_injection_technique`: Change the injection primitive used by post-exploitation jobs
    200 - `shinject`: Injects shellcode into a remote process, allowing for in-memory execution of arbitrary code
    201 - `inject`: Injects agent shellcode into a remote process, allowing for in-memory execution of the agent's code
    202 - `spawn`: Spawns a new agent session in the specified executable, allowing for the execution of shellcode in a new process
    203 - `spawnto_x64` and `spawnto_x86`: Change the default binary used in post-exploitation jobs to a specified path instead of using `rundll32.exe` without params which is very noisy.
    204 
    205 ### Mythic Forge
    206 
    207 This allows to **load COFF/BOF** files from the Mythic Forge, which is a repository of pre-compiled payloads and tools that can be executed on the target system. With all the commands that can be loaded it'll be possible to perform common actions executing them in the current agent process as BOFs (usually with better OPSEC than spawning a separate process).
    208 
    209 Start installing them with:
    210 
    211 ```bash
    212 ./mythic-cli install github https://github.com/MythicAgents/forge.git
    213 ```
    214 
    215 Then, use `forge_collections` to show the COFF/BOF modules from the Mythic Forge to be able to select and load them into the agent's memory for execution. By default, the following 2 collections are added in Apollo:
    216 
    217 - `forge_collections {"collectionName":"SharpCollection"}`
    218 - `forge_collections {"collectionName":"SliverArmory"}`
    219 
    220 After one module is loaded, it'll appear in the list as another command like `forge_bof_sa-whoami` or `forge_bof_sa-netuser`.
    221 
    222 For BOFs, remember that Forge does **not** just pass one flat argument string
    223  to Apollo. It maps BOF parameters into Mythic's typed-array format and then
    224  forwards them into Apollo's `execute_coff` flow. If a Forge-loaded BOF behaves
    225  strangely, check the expected BOF argument types / entrypoint rather than only
    226  the command line you typed. Also note that Apollo's newer BOF loader changed
    227  argument handling relative to much older 2.3.1-era builds, so stale BOFs or
    228  old collections can fail purely because the marshaling expectations changed.
    229 
    230 ### PowerShell & scripting execution
    231 
    232 - `powershell_import`: Imports a new PowerShell script (.ps1) into the agent cache for later execution
    233 - `powershell`: Executes a PowerShell command in the context of the agent, allowing for advanced scripting and automation
    234 - `powerpick`: Injects a PowerShell loader assembly into a sacrificial process and executes a PowerShell command (without powershell logging).
    235 - `psinject`: Executes PowerShell in a specified process, allowing for targeted execution of scripts in the context of another process
    236 - `shell`: Executes a shell command in the context of the agent, similar to running a command in cmd.exe
    237 
    238 ### Lateral Movement
    239 
    240 - `jump_psexec`: Uses the PsExec technique to move laterally to a new host by first copying over the Apollo agent executable (apollo.exe) and executing it.
    241 - `jump_wmi`: Uses the WMI technique to move laterally to a new host by first copying over the Apollo agent executable (apollo.exe) and executing it.
    242 - `link` and `unlink`: Create and tear down P2P links (for example over SMB/TCP) between callbacks.
    243 - `wmiexecute`: Executes a command on the local or specified remote system using WMI, with optional credentials for impersonation.
    244 - `net_dclist`: Retrieves a list of domain controllers for the specified domain, useful for identifying potential targets for lateral movement.
    245 - `net_localgroup`: Lists local groups on the specified computer, defaulting to localhost if no computer is specified.
    246 - `net_localgroup_member`: Retrieves local group membership for a specified group on the local or remote computer, allowing for enumeration of users in specific groups.
    247 - `net_shares`: Lists remote shares and their accessibility on the specified computer, useful for identifying potential targets for lateral movement.
    248 - `socks`: Enables a SOCKS 5 compliant proxy on the target network, allowing for tunneling of traffic through the compromised host. Compatible with tools like proxychains.
    249 - `rpfwd`: Starts listening on a specified port on the target host and forwards traffic through Mythic to a remote IP and port, allowing for remote access to services on the target network.
    250 - `listpipes`: Lists all named pipes on the local system, which can be useful for lateral movement or privilege escalation by interacting with IPC mechanisms.
    251 
    252 For the lower-level WMI execution primitives used underneath `jump_wmi` or `wmiexecute`, check [WmiExec](/hacktricks/windows-hardening/lateral-movement/wmiexec). For broader pivoting patterns, check [Tunneling and Port Forwarding](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/tunneling-and-port-forwarding.md).
    253 
    254 ### Miscellaneous Commands
    255 - `help`: Displays detailed information about specific commands or general information about all available commands in the agent.
    256 - `clear`: Marks tasks as 'cleared' so they can't be picked up by agents. You can specify `all` to clear all tasks or `task Num` to clear a specific task.  
    257 
    258 
    259 ## [Poseidon Agent](https://github.com/MythicAgents/poseidon)
    260 
    261 Poseidon is a Golang agent that compiles into **Linux and macOS** executables.
    262 
    263 ```bash
    264 ./mythic-cli install github https://github.com/MythicAgents/poseidon.git
    265 ```
    266 
    267 ### Current build/profile notes
    268 
    269 - Current Poseidon builds target Linux and macOS on both `x86_64` and `arm64`.
    270 - Supported output formats include native executables plus shared-library style outputs such as `dylib` and `so`.
    271 - Poseidon supports `http`, `websocket`, `tcp`, and `dynamichttp`, and current builders expose multi-egress settings such as `egress_order` and failover thresholds.
    272 - Poseidon's current capability metadata also advertises browser scripts, file/process browser integration, interactive tasking, keylogging, screenshots, Push C2, SOCKS, rpfwd, and P2P, so it can work as a real Linux/macOS pivot node rather than just a simple remote shell.
    273 - Build-time options such as `proxy_bypass` and `garble` are worth checking when you need either cleaner network behavior or extra Go binary obfuscation.
    274 - `pty` is one of the most useful newer-quality-of-life commands for Linux/macOS
    275   operations because it opens an interactive PTY and can expose a Mythic-side
    276   port for fuller terminal interaction without resorting to the older `sleep 0`
    277   + SOCKS workaround.
    278 - Poseidon's current docs are especially interesting for macOS-heavy
    279   tradecraft: `jxa` executes JavaScript for Automation in-memory,
    280   `screencapture` grabs the logged-in desktop, `clipboard_monitor` streams
    281   pasteboard changes, `execute_library` loads a local dylib and calls a
    282   function from it, and `libinject` forces a remote process to load an on-disk
    283   dylib.
    284 - For long-running jobs, remember that Poseidon executes post-exploitation work
    285   in goroutines/threads that are cooperative rather than hard-killable. The
    286   docs also explicitly note that there is currently no built-in agent
    287   obfuscation, so build/profile-level tradecraft matters more than with heavily
    288   obfuscated commercial implants.
    289 
    290 For macOS-specific tradecraft around Mythic-backed operations, JAMF abuse, or MDM-as-C2 ideas, check [macOS Red Teaming](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/macos-hardening/macos-red-teaming/README.md).
    291 
    292 When used on Linux or macOS it has some interesting commands:
    293 
    294 ### Common actions
    295 
    296 - `cat`: Print the contents of a file
    297 - `cd`: Change the current working directory
    298 - `chmod`: Change the permissions of a file
    299 - `config`: View current config and host information
    300 - `cp`: Copy a file from one location to another
    301 - `curl`: Execute a single web request with optional headers and method
    302 - `upload`: Upload a file to the target
    303 - `download`: Download a file from the target system to the local machine
    304 - And many more
    305 
    306 ### Search Sensitive Information
    307 
    308 - `triagedirectory`: Find interesting files within a directory on a host, such as sensitive files or credentials.
    309 - `getenv`: Get all of the current environment variables.
    310 
    311 ### macOS-specific tradecraft
    312 
    313 - `jxa`: Execute JavaScript for Automation in-memory via `OSAScript`, which is
    314   useful for native macOS post-exploitation without dropping separate script
    315   files.
    316 - `clipboard_monitor`: Poll the pasteboard and report changes back to Mythic,
    317   which is handy for credential/token theft workflows that rely on copy/paste.
    318 - `screencapture`: Capture the user's desktop on macOS.
    319 - `execute_library`: Load a dylib from disk and call a specific exported function.
    320 - `libinject`: Inject a shellcode stub that forces another macOS process to load a dylib from disk.
    321 - `persist_launchd`: Create LaunchAgent / LaunchDaemon persistence directly from the agent.
    322 
    323 ### Move laterally
    324 
    325 - `ssh`: SSH to host using the designated credentials and open a PTY without spawning ssh.
    326 - `sshauth`: SSH to specified host(s) using the designated credentials. You can also use this to execute a specific command on the remote hosts via SSH or use it to SCP files.
    327 - `link_tcp`: Link to another agent over TCP, allowing for direct communication between agents.
    328 - `link_webshell`: Link to an agent using the webshell P2P profile, allowing for remote access to the agent's web interface.
    329 - `rpfwd`: Start or Stop a Reverse Port Forward, allowing for remote access to services on the target network.
    330 - `socks`: Start or Stop a SOCKS5 proxy on the target network, allowing for tunneling of traffic through the compromised host. Compatible with tools like proxychains.
    331 - `portscan`: Scan host(s) for open ports, useful for identifying potential targets for lateral movement or further attacks.
    332 
    333 ### Process execution
    334 
    335 - `shell`: Execute a single shell command via /bin/sh, allowing for direct execution of commands on the target system.
    336 - `run`: Execute a command from disk with arguments, allowing for the execution of binaries or scripts on the target system.
    337 - `pty`: Open up an interactive PTY, allowing for direct interaction with the shell on the target system.
    338 
    339 ## References
    340 
    341 - [1] [Mythic Community Agent Feature Matrix](https://mythicmeta.github.io/overview/agent_matrix.html)
    342 - [2] [Apollo README](https://github.com/MythicAgents/Apollo/blob/master/README.md)
    343 - [3] [Mythic v3.2 Highlights: Interactive Tasking, Push C2, and Dynamic File Browser](https://posts.specterops.io/mythic-v3-2-highlights-interactive-tasking-push-c2-and-dynamic-file-browser-7035065e2b3d)
    344 - [4] [Browser Scripts - Mythic Documentation](https://docs.mythic-c2.net/operational-pieces/browser-scripts)
    345 - [5] [Mythic 3.3->3.4 Updates](https://docs.mythic-c2.net/updating/mythic-3.3-greater-than-3.4-updates)
    346 - [6] [Transforming Red Team Ops with Mythic's Hidden Gems: Browser Scripting](https://specterops.io/blog/2025/08/21/transforming-red-team-ops-with-mythics-hidden-gems-browser-scripting/)