mythic.md (24711B)
1 --- 2 title: "Mythic" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/mythic.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/mythic.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Mythic 14 15 ## What is Mythic? 16 17 Mythic is an open-source, modular, collaborative command and control (C2) framework designed for red teaming. It allows operators to manage and deploy agents (payloads) across different operating systems, including Windows, Linux, and macOS. Mythic provides a browser UI for multi-operator tasking, file handling, SOCKS/rpfwd management, and payload generation. 18 19 Unlike monolithic frameworks, the Mythic repository itself does **not** ship payload types or C2 profiles. Agents, wrappers, and C2 profiles are typically installed as external components and can be updated independently from Mythic core. 20 21 ### Installation 22 23 To install Mythic, follow the instructions on the official **[Mythic repo](https://github.com/its-a-feature/Mythic)**. A common bootstrap from the Mythic directory is: 24 25 ```bash 26 sudo make 27 sudo ./mythic-cli start 28 ``` 29 30 If Mythic is already running, you can normally add a new agent or profile with `./mythic-cli install github ...` and then either restart Mythic or just start the new component directly. 31 32 ### Agents 33 34 Mythic supports multiple agents, which are the **payloads that perform tasks on the compromised systems**. Each agent can be tailored to specific needs and can run on different operating systems. 35 36 By default Mythic doesn't have any agents installed. The open-source community agents live in [**https://github.com/MythicAgents**](https://github.com/MythicAgents), and the [**community feature matrix**](https://mythicmeta.github.io/overview/agent_matrix.html) is useful to quickly check supported operating systems, payload formats, wrappers, and C2 profiles.<sup>[[1]](#references)</sup> 37 38 To install an agent from that org you can run: 39 40 ```bash 41 sudo ./mythic-cli install github https://github.com/MythicAgents/<agent-name> 42 sudo ./mythic-cli install github https://github.com/MythicAgents/Apollo.git 43 sudo -E ./mythic-cli install github https://github.com/MythicAgents/Apollo.git 44 ``` 45 46 The `sudo -E` form is useful when you are installing from a non-root environment. You can add new agents with the previous command even if Mythic is already running. 47 48 ### C2 Profiles 49 50 C2 profiles in Mythic define **how agents communicate with the Mythic server**. They specify the communication protocol, encryption methods, and other settings. You can create and manage C2 profiles through the Mythic web interface. 51 52 By default Mythic is installed with no profiles, however, it's possible to download some profiles from the repo [**https://github.com/MythicC2Profiles**](https://github.com/MythicC2Profiles) running: 53 54 ```bash 55 sudo ./mythic-cli install github https://github.com/MythicC2Profiles/<c2-profile> 56 sudo ./mythic-cli install github https://github.com/MythicC2Profiles/http 57 ``` 58 59 Current operator-relevant profiles to keep in mind: 60 61 - [`http`](https://github.com/MythicC2Profiles/http): basic asynchronous GET/POST traffic. 62 - [`httpx`](https://github.com/MythicC2Profiles/httpx): more flexible HTTP traffic with multiple callback domains, fail-over/round-robin rotation, custom headers/query parameters, and message transforms (`base64`, `base64url`, `xor`, `netbios`, `prepend`, `append`) placed in cookies, headers, query parameters, or body. 63 - [`dynamichttp`](https://github.com/MythicC2Profiles/dynamichttp): JSON/TOML-driven HTTP message shaping when the static `http` profile is too recognizable. 64 65 ### Current platform notes 66 67 - Many public agents and profiles now install with pre-built remote container images. 68 If you fork a component or patch it locally and Mythic keeps using the old 69 behavior, inspect the generated `.env` entries for `*_REMOTE_IMAGE`, 70 `*_USE_BUILD_CONTEXT`, and `*_USE_VOLUME`; enabling 71 `*_USE_BUILD_CONTEXT="true"` is usually what makes Mythic rebuild from your 72 local Docker context instead of silently reusing the remote image. 73 - Browser scripts are one of Mythic's highest-value quality-of-life features 74 for operators: they can turn raw command output into tables, screenshot 75 viewers, download links, search links, and buttons that issue follow-on 76 tasking directly from the UI. Current Mythic builds let each operator keep 77 their own scripts, toggle them globally or per-task, and get the best results 78 when agents return structured JSON instead of plaintext. This is especially 79 useful for repetitive `ls`, `ps`, triage, and file-browser workflows.<sup>[[4]](#references)[[6]](#references)</sup> 80 - Newer Mythic builds also support interactive tasking and Push C2 patterns 81 that reduce the need for `sleep 0` polling during PTY/SOCKS/rpfwd-heavy 82 operations. When an agent/profile supports it, this is usually lower-overhead 83 than hammering the server with constant check-ins just to keep an interactive 84 channel usable.<sup>[[3]](#references)</sup> 85 - Current 3.4-era Mythic builders are more context-aware than older writeups 86 imply: build parameters can now be grouped or hidden based on the selected OS 87 or other build options, payload types can declare whether they support 88 multiple C2 profiles or multiple instances of the same C2 in one build, and 89 C2 parameter deviations let an agent hide fields it does not actually 90 implement. This matters when you bounce between `http`, `httpx`, `smb`, 91 `tcp`, and `websocket` because the safe/valid build surface is no longer a 92 flat static form.<sup>[[5]](#references)</sup> 93 - If you are building a custom agent/profile pair and you don't want Mythic's 94 JSON message format or default crypto on the wire, use a 95 `translation_container`: Mythic strips the UUID, hands the encrypted blob and 96 key material to the translator over gRPC, and expects agent-native bytes 97 back. This is the clean way to support binary protocols, custom framing, or 98 agent-side encryption without rewriting the whole server. 99 - Remember that linked/P2P callbacks do not just shuttle tasking. Mythic's 100 `get_tasking` flow can also carry responses plus `delegates`, `socks`, 101 `rpfwd`, and `interactive` data. In practice, one egress callback can service 102 inner callbacks and pivot channels in the same polling loop; if the child 103 agents perform their own periodic check-ins, `get_delegate_tasks=false` keeps 104 the parent from accidentally consuming the inner callback's queued jobs. 105 106 ### Wrapper payloads 107 108 Wrapper payloads let you keep the same agent logic while changing the on-disk representation that gets delivered or persisted. 109 110 - `service_wrapper`: turns another payload into a Windows service executable, which is useful when the execution path requires a valid service binary. 111 - `scarecrow_wrapper`: wraps compatible shellcode with the ScareCrow loader to generate loader-backed outputs such as EXE/DLL/CPL. 112 113 ## [Apollo Agent](https://github.com/MythicAgents/Apollo) 114 115 Apollo is a Windows agent written in C# using the 4.0 .NET Framework designed to be used in SpecterOps training offerings.<sup>[[2]](#references)</sup> 116 117 Install it with: 118 119 ```bash 120 ./mythic-cli install github https://github.com/MythicAgents/Apollo.git 121 ``` 122 123 ### Current build/profile notes 124 125 - Apollo can currently emit `WinExe`, `Shellcode`, `Service`, and `Source` payloads. 126 - The commonly used Apollo profiles are `http`, `httpx`, `smb`, `tcp`, and `websocket`. 127 - `httpx` is usually the more flexible option when you need domain rotation, proxy support, custom message placement, and message transforms instead of the older static `http` profile. 128 - Apollo is one of the more feature-complete community agents and currently exposes Mythic-side integrations such as browser scripts, file/process browser views, screenshots, keylogging, SOCKS, rpfwd, Push C2, and P2P routing. 129 - Apollo supports wrapper payloads such as `service_wrapper` and `scarecrow_wrapper`. 130 - Apollo supports dynamic command loading, so you can keep the initial payload lean and load extra commands or Forge modules later instead of compiling every post-ex capability into the first build. 131 - When generating shellcode output, Apollo's current builder also exposes Donut format choices (`Binary`, `Base64`, `C`, `Ruby`, `Python`, `Powershell`, `C#`, `Hex`) and Donut bypass behavior (`None`, `Abort on fail`, `Continue on fail`). This is useful if the end goal is to re-wrap the shellcode with `service_wrapper`, `scarecrow_wrapper`, or a custom loader. 132 - `register_file` and `register_assembly` are the staging primitives for `execute_assembly`, `execute_pe`, `inline_assembly`, `execute_coff`, `powershell_import`, and `powerpick`. In current Apollo builds, those staged artifacts are cached client-side as DPAPI-protected AES256 blobs. 133 - `ls` and `ps` results integrate especially well with Mythic's browser scripts and file/process browser, which makes operator triage noticeably faster in collaborative operations. 134 - Apollo's fork-and-run jobs inherit their sacrificial process settings from 135 `spawnto_x86` / `spawnto_x64`, inherit parent selection from `ppid`, and 136 then use the currently selected injection primitive. In practice, this means 137 your OPSEC tuning for one command often affects `execute_assembly`, 138 `powerpick`, `mimikatz`, `pth`, `dcsync`, `execute_pe`, and `spawn` at the 139 same time. 140 - Current documented Apollo injection backends include `CreateRemoteThread`, 141 `QueueUserAPC` (early-bird style), and `NtCreateThreadEx` via syscalls. Use 142 `get_injection_techniques` before noisy post-exploitation and 143 `set_injection_technique` if you need to swap away from a primitive that 144 clashes with the target or the command you want to run. 145 - `blockdlls` only affects sacrificial processes created for post-exploitation 146 jobs. Combined with a less suspicious `spawnto_x64` target than the default 147 bare `rundll32.exe`, this is one of the easiest Apollo-side changes to make 148 before running assembly/PowerShell-heavy tasking. 149 150 This agent has a lot of commands that makes it very similar to Cobalt Strike's Beacon with some extras. Among them, it supports: 151 152 ### Common actions 153 154 - `cat`: Print the contents of a file 155 - `cd`: Change the current working directory 156 - `cp`: Copy a file from one location to another 157 - `ls`: List files and directories in the current directory or specified path 158 - `ifconfig`: Get network adapters and interfaces 159 - `netstat`: Get TCP and UDP connection information 160 - `pwd`: Print the current working directory 161 - `ps`: List running processes on the target system (with added info) 162 - `jobs`: List all running jobs associated with long-running tasking 163 - `download`: Download a file from the target system to the local machine 164 - `upload`: Upload a file from the local machine to the target system 165 - `reg_query`: Query registry keys and values on the target system 166 - `reg_write_value`: Write a new value to a specified registry key 167 - `sleep`: Change the agent's sleep interval, which determines how often it checks in with the Mythic server 168 - And many others, use `help` to see the full list of available commands. 169 170 ### Privilege escalation 171 172 - `getprivs`: Enable as many privileges as possible on the current thread token 173 - `getsystem`: Open a handle to winlogon and duplicate the token, effectively escalating privileges to SYSTEM level 174 - `make_token`: Create a new logon session and apply it to the agent, allowing for impersonation of another user 175 - `steal_token`: Steal a primary token from another process, allowing the agent to impersonate that process's user 176 - `pth`: Pass-the-Hash attack, allowing the agent to authenticate as a user using their NTLM hash without needing the plaintext password 177 - `mimikatz`: Run Mimikatz commands to extract credentials, hashes, and other sensitive information from memory or the SAM database 178 - `rev2self`: Revert the agent's token to its primary token, effectively dropping privileges back to the original level 179 - `ppid`: Change the parent process for post-exploitation jobs by specifying a new parent process ID, allowing for better control over job execution context 180 - `printspoofer`: Execute PrintSpoofer commands to bypass print spooler security measures, allowing for privilege escalation or code execution 181 - `dcsync`: Sync a user's Kerberos keys to the local machine, allowing for offline password cracking or further attacks 182 - `ticket_cache_add`: Add a Kerberos ticket to the current logon session or a specified one, allowing for ticket reuse or impersonation 183 184 ### Process execution 185 186 - `assembly_inject`: Allows to inject a .NET assembly loader into a remote process 187 - `blockdlls`: Block non-Microsoft signed DLLs from loading into post-exploitation jobs 188 - `execute_assembly`: Executes a .NET assembly in the context of the agent 189 - `execute_coff`: Executes a COFF file in memory, allowing for in-memory execution of compiled code 190 - `execute_pe`: Executes an unmanaged executable (PE) 191 - `keylog_inject`: Injects a keylogger into another process and streams keystrokes back into Mythic's keylog view 192 - `screenshot` / `screenshot_inject`: Capture the current desktop directly or 193 by injecting a screenshot assembly into a target process/session 194 - `get_injection_techniques`: Show available injection techniques and the currently selected one 195 - `inline_assembly`: Executes a .NET assembly in a disposable AppDomain, allowing for temporary execution of code without affecting the agent's main process 196 - `register_assembly`: Register a .NET assembly for later execution 197 - `register_file`: Register a file in the agent cache for later `execute_*` or PowerShell tasking 198 - `run`: Executes a binary on the target system, using the system's PATH to find the executable 199 - `set_injection_technique`: Change the injection primitive used by post-exploitation jobs 200 - `shinject`: Injects shellcode into a remote process, allowing for in-memory execution of arbitrary code 201 - `inject`: Injects agent shellcode into a remote process, allowing for in-memory execution of the agent's code 202 - `spawn`: Spawns a new agent session in the specified executable, allowing for the execution of shellcode in a new process 203 - `spawnto_x64` and `spawnto_x86`: Change the default binary used in post-exploitation jobs to a specified path instead of using `rundll32.exe` without params which is very noisy. 204 205 ### Mythic Forge 206 207 This allows to **load COFF/BOF** files from the Mythic Forge, which is a repository of pre-compiled payloads and tools that can be executed on the target system. With all the commands that can be loaded it'll be possible to perform common actions executing them in the current agent process as BOFs (usually with better OPSEC than spawning a separate process). 208 209 Start installing them with: 210 211 ```bash 212 ./mythic-cli install github https://github.com/MythicAgents/forge.git 213 ``` 214 215 Then, use `forge_collections` to show the COFF/BOF modules from the Mythic Forge to be able to select and load them into the agent's memory for execution. By default, the following 2 collections are added in Apollo: 216 217 - `forge_collections {"collectionName":"SharpCollection"}` 218 - `forge_collections {"collectionName":"SliverArmory"}` 219 220 After one module is loaded, it'll appear in the list as another command like `forge_bof_sa-whoami` or `forge_bof_sa-netuser`. 221 222 For BOFs, remember that Forge does **not** just pass one flat argument string 223 to Apollo. It maps BOF parameters into Mythic's typed-array format and then 224 forwards them into Apollo's `execute_coff` flow. If a Forge-loaded BOF behaves 225 strangely, check the expected BOF argument types / entrypoint rather than only 226 the command line you typed. Also note that Apollo's newer BOF loader changed 227 argument handling relative to much older 2.3.1-era builds, so stale BOFs or 228 old collections can fail purely because the marshaling expectations changed. 229 230 ### PowerShell & scripting execution 231 232 - `powershell_import`: Imports a new PowerShell script (.ps1) into the agent cache for later execution 233 - `powershell`: Executes a PowerShell command in the context of the agent, allowing for advanced scripting and automation 234 - `powerpick`: Injects a PowerShell loader assembly into a sacrificial process and executes a PowerShell command (without powershell logging). 235 - `psinject`: Executes PowerShell in a specified process, allowing for targeted execution of scripts in the context of another process 236 - `shell`: Executes a shell command in the context of the agent, similar to running a command in cmd.exe 237 238 ### Lateral Movement 239 240 - `jump_psexec`: Uses the PsExec technique to move laterally to a new host by first copying over the Apollo agent executable (apollo.exe) and executing it. 241 - `jump_wmi`: Uses the WMI technique to move laterally to a new host by first copying over the Apollo agent executable (apollo.exe) and executing it. 242 - `link` and `unlink`: Create and tear down P2P links (for example over SMB/TCP) between callbacks. 243 - `wmiexecute`: Executes a command on the local or specified remote system using WMI, with optional credentials for impersonation. 244 - `net_dclist`: Retrieves a list of domain controllers for the specified domain, useful for identifying potential targets for lateral movement. 245 - `net_localgroup`: Lists local groups on the specified computer, defaulting to localhost if no computer is specified. 246 - `net_localgroup_member`: Retrieves local group membership for a specified group on the local or remote computer, allowing for enumeration of users in specific groups. 247 - `net_shares`: Lists remote shares and their accessibility on the specified computer, useful for identifying potential targets for lateral movement. 248 - `socks`: Enables a SOCKS 5 compliant proxy on the target network, allowing for tunneling of traffic through the compromised host. Compatible with tools like proxychains. 249 - `rpfwd`: Starts listening on a specified port on the target host and forwards traffic through Mythic to a remote IP and port, allowing for remote access to services on the target network. 250 - `listpipes`: Lists all named pipes on the local system, which can be useful for lateral movement or privilege escalation by interacting with IPC mechanisms. 251 252 For the lower-level WMI execution primitives used underneath `jump_wmi` or `wmiexecute`, check [WmiExec](/hacktricks/windows-hardening/lateral-movement/wmiexec). For broader pivoting patterns, check [Tunneling and Port Forwarding](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/tunneling-and-port-forwarding.md). 253 254 ### Miscellaneous Commands 255 - `help`: Displays detailed information about specific commands or general information about all available commands in the agent. 256 - `clear`: Marks tasks as 'cleared' so they can't be picked up by agents. You can specify `all` to clear all tasks or `task Num` to clear a specific task. 257 258 259 ## [Poseidon Agent](https://github.com/MythicAgents/poseidon) 260 261 Poseidon is a Golang agent that compiles into **Linux and macOS** executables. 262 263 ```bash 264 ./mythic-cli install github https://github.com/MythicAgents/poseidon.git 265 ``` 266 267 ### Current build/profile notes 268 269 - Current Poseidon builds target Linux and macOS on both `x86_64` and `arm64`. 270 - Supported output formats include native executables plus shared-library style outputs such as `dylib` and `so`. 271 - Poseidon supports `http`, `websocket`, `tcp`, and `dynamichttp`, and current builders expose multi-egress settings such as `egress_order` and failover thresholds. 272 - Poseidon's current capability metadata also advertises browser scripts, file/process browser integration, interactive tasking, keylogging, screenshots, Push C2, SOCKS, rpfwd, and P2P, so it can work as a real Linux/macOS pivot node rather than just a simple remote shell. 273 - Build-time options such as `proxy_bypass` and `garble` are worth checking when you need either cleaner network behavior or extra Go binary obfuscation. 274 - `pty` is one of the most useful newer-quality-of-life commands for Linux/macOS 275 operations because it opens an interactive PTY and can expose a Mythic-side 276 port for fuller terminal interaction without resorting to the older `sleep 0` 277 + SOCKS workaround. 278 - Poseidon's current docs are especially interesting for macOS-heavy 279 tradecraft: `jxa` executes JavaScript for Automation in-memory, 280 `screencapture` grabs the logged-in desktop, `clipboard_monitor` streams 281 pasteboard changes, `execute_library` loads a local dylib and calls a 282 function from it, and `libinject` forces a remote process to load an on-disk 283 dylib. 284 - For long-running jobs, remember that Poseidon executes post-exploitation work 285 in goroutines/threads that are cooperative rather than hard-killable. The 286 docs also explicitly note that there is currently no built-in agent 287 obfuscation, so build/profile-level tradecraft matters more than with heavily 288 obfuscated commercial implants. 289 290 For macOS-specific tradecraft around Mythic-backed operations, JAMF abuse, or MDM-as-C2 ideas, check [macOS Red Teaming](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/macos-hardening/macos-red-teaming/README.md). 291 292 When used on Linux or macOS it has some interesting commands: 293 294 ### Common actions 295 296 - `cat`: Print the contents of a file 297 - `cd`: Change the current working directory 298 - `chmod`: Change the permissions of a file 299 - `config`: View current config and host information 300 - `cp`: Copy a file from one location to another 301 - `curl`: Execute a single web request with optional headers and method 302 - `upload`: Upload a file to the target 303 - `download`: Download a file from the target system to the local machine 304 - And many more 305 306 ### Search Sensitive Information 307 308 - `triagedirectory`: Find interesting files within a directory on a host, such as sensitive files or credentials. 309 - `getenv`: Get all of the current environment variables. 310 311 ### macOS-specific tradecraft 312 313 - `jxa`: Execute JavaScript for Automation in-memory via `OSAScript`, which is 314 useful for native macOS post-exploitation without dropping separate script 315 files. 316 - `clipboard_monitor`: Poll the pasteboard and report changes back to Mythic, 317 which is handy for credential/token theft workflows that rely on copy/paste. 318 - `screencapture`: Capture the user's desktop on macOS. 319 - `execute_library`: Load a dylib from disk and call a specific exported function. 320 - `libinject`: Inject a shellcode stub that forces another macOS process to load a dylib from disk. 321 - `persist_launchd`: Create LaunchAgent / LaunchDaemon persistence directly from the agent. 322 323 ### Move laterally 324 325 - `ssh`: SSH to host using the designated credentials and open a PTY without spawning ssh. 326 - `sshauth`: SSH to specified host(s) using the designated credentials. You can also use this to execute a specific command on the remote hosts via SSH or use it to SCP files. 327 - `link_tcp`: Link to another agent over TCP, allowing for direct communication between agents. 328 - `link_webshell`: Link to an agent using the webshell P2P profile, allowing for remote access to the agent's web interface. 329 - `rpfwd`: Start or Stop a Reverse Port Forward, allowing for remote access to services on the target network. 330 - `socks`: Start or Stop a SOCKS5 proxy on the target network, allowing for tunneling of traffic through the compromised host. Compatible with tools like proxychains. 331 - `portscan`: Scan host(s) for open ports, useful for identifying potential targets for lateral movement or further attacks. 332 333 ### Process execution 334 335 - `shell`: Execute a single shell command via /bin/sh, allowing for direct execution of commands on the target system. 336 - `run`: Execute a command from disk with arguments, allowing for the execution of binaries or scripts on the target system. 337 - `pty`: Open up an interactive PTY, allowing for direct interaction with the shell on the target system. 338 339 ## References 340 341 - [1] [Mythic Community Agent Feature Matrix](https://mythicmeta.github.io/overview/agent_matrix.html) 342 - [2] [Apollo README](https://github.com/MythicAgents/Apollo/blob/master/README.md) 343 - [3] [Mythic v3.2 Highlights: Interactive Tasking, Push C2, and Dynamic File Browser](https://posts.specterops.io/mythic-v3-2-highlights-interactive-tasking-push-c2-and-dynamic-file-browser-7035065e2b3d) 344 - [4] [Browser Scripts - Mythic Documentation](https://docs.mythic-c2.net/operational-pieces/browser-scripts) 345 - [5] [Mythic 3.3->3.4 Updates](https://docs.mythic-c2.net/updating/mythic-3.3-greater-than-3.4-updates) 346 - [6] [Transforming Red Team Ops with Mythic's Hidden Gems: Browser Scripting](https://specterops.io/blog/2025/08/21/transforming-red-team-ops-with-mythics-hidden-gems-browser-scripting/)