Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
OpenMalleableC2 — Open Source Implementation of Cobalt Strike's Malleable C2 | Kitploit
Tools/GitHubGitHub/codextf2/openmalleablec2
Penetration Testing FrameworksExploit FrameworksNetwork SecurityCommand and ControlRed TeamingPayload Development
GitHubcodextf2/openmalleablec2

OpenMalleableC2

Open Source Implementation of Cobalt Strike's Malleable C2

View Repository
10615143 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

OpenMalleableC2

Open Source Implementation of Cobalt Strike's Malleable C2

OpenMalleableC2 is a framework-agnostic library that implements Cobalt Strike's Malleable C2 profile format for HTTP transformations. It enables security researchers and red teams to easily implement malleable C2 communications in custom tools and C2 frameworks.

It allows wholesale usage of Malleable C2 profiles to send arbitrary data over HTTP, in a transparent, (hopefully) stable way.

Why did I make this?

There are many open source C2 frameworks that have varying degrees of HTTP traffic customization features. However, even the more developed frameworks such as Mythic, Havoc, Adaptix etc. still lack the depth of HTTP traffic customization that Cobalt Strike's Malleable C2 allows, in terms of embedding callback data within convincingly innocent looking HTTP requests. The goal of this project is to allow open source tooling to both benefit from the customization depth of the Malleable C2 system as well as the existing resources dependent on it (e.g. profiles, profile generator tools etc.)

Its mostly working, but I make no guarantees about its stability at this time. Do report bugs if found :)

Quick Start

The provided example is a simple "ping pong" agent and server that demonstrates the typical Beacon callback. The agent will send back a GET callback to check-in for taskings, then send a POST callback to post task output back to the server.

In this example, the taskings are just a placeholder random string, that the agent will retrieve, reverse and post back as the result. The server verifies that the reversed string is correct, and sends a response accordingly.

Run ping-pong example:

# Start Python server
python Server\Python\examples\pingpong_server.py profiles\gmail.profile

# Or start Go server
cd Server\Go
go run .\cmd\pingpong-server ..\..\profiles\gmail.profile

# Run agent (in another terminal)
.\Client\C\examples\pingpong_agent.exe profiles\gmail.profile

Build C client example:

cd Client\C\examples
build.bat

Repository layout:

Client\C\lib                 C client library
Client\C\examples             C ping-pong agent example
Server\Python\lib             Python server library
Server\Python\examples         Python ping-pong server example
Server\Go\openmalleable        Go server library
Server\Go\cmd\pingpong-server  Go ping-pong server example

Example output: pingpong_server.py: image

References

  • Cobalt Strike Malleable C2 Documentation
  • Malleable C2 Profiles Repository
  • Chet Jeepiti
Download Tool