Skip to main content

Technical Architecture & Overview

PoshC2 is a proxy-aware command and control framework originally built around PowerShell implants, with Python implant work carried on the current tree. It supports HTTP(S) communication, lateral movement helpers, payload generation, and a collaborative server console. Nettitude, now part of LRQA, maintains the project and publishes companion IOC repositories for defenders.

Targeted Technical Use Cases

Windows-centric authorized engagements where PowerShell-era tradecraft and proxy awareness matter.

Evaluation & Trade-offs

Core Strengths

  • +PowerShell ecosystem integration.
  • +Maintained by a commercial research team with detection publications.
  • +Documented IOC repos support defender validation.

Trade-Offs & Limitations

  • -Windows-heavy orientation.
  • -PowerShell telemetry is heavily logged on hardened estates.

Defensive Security Application

Emulating PowerShell-based adversary behavior to validate logging and AMSI-era controls.

Frequently Asked Questions

What is PoshC2?

PoshC2 is a proxy-aware command and control framework originally built around PowerShell implants, with Python implant work carried on the current tree. It supports HTTP(S) communication, lateral movement helpers, payload generation, and a collaborative server console. Nettitude, now part of LRQA, maintains the project and publishes companion IOC repositories for defenders.

What is PoshC2 used for?

Windows-centric authorized engagements where PowerShell-era tradecraft and proxy awareness matter.

What are the strengths of PoshC2?
  • +PowerShell ecosystem integration.
  • +Maintained by a commercial research team with detection publications.
  • +Documented IOC repos support defender validation.
What are the limitations of PoshC2?
  • +Windows-heavy orientation.
  • +PowerShell telemetry is heavily logged on hardened estates.
How is PoshC2 used defensively?

Emulating PowerShell-based adversary behavior to validate logging and AMSI-era controls.