
Fawkes is a golang Mythic C2 Agent exclusively written by AI.
Fawkes is an entirely vibe-coded Mythic C2 agent. It started as an "I wonder" and has turned into a goal. My goal is to not write a single line of code for this agent, instead, exclusively producing it at a prompt.
I originally attempted to write the agent myself, but after cloning the example container, reading through mythic docs, watching the dev series youtube videos, and copying code from other agents like Merlin or Freyja, I decided I just didn't have time to develop my own agent. A prompt though, that I have time for.
Fawkes is a golang based agent with cross-platform capabilities. It supports Windows (EXE, DLL, and shellcode payloads), Linux (ELF binaries and shared libraries), and macOS (Mach-O binaries for Intel and Apple Silicon). 213 commands total: 113 cross-platform, 82 Windows-only, 21 Unix-only, 11 Linux-only, and 6 macOS-only (some commands have platform-specific implementations sharing one user-facing name, e.g. screenshot). Supports HTTP egress and TCP peer-to-peer (P2P) linking for internal pivoting.
To install Fawkes, you'll need Mythic installed on a remote computer. You can find installation instructions for Mythic at the Mythic project page.
From the Mythic install directory:
./mythic-cli install github https://github.com/galoryber/fawkes
| Command | Syntax | Description |
|---|---|---|
| acl-edit | acl-edit -action read -server dc01 -target user | Read/modify Active Directory object DACLs (add/remove ACEs, grant DCSync, GenericAll, backup/restore). Cross-platform (T1222.001, T1098, T1003.006). |
| adcs | adcs -action <cas|templates|find|request|auto-exploit> -server <DC> -username <user@domain> -password <pass> [-ca_name <CA>] [-template <name>] [-alt_name <UPN>] | Enumerate AD Certificate Services, find vulnerable templates (ESC1-ESC4, ESC6 via DCOM), request certificates via DCOM for ESC1/ESC6 exploitation, or auto-exploit (find → parse → request chain). Cross-platform (T1649). |
| ads | ads -action <write|read|list|delete> -file <path> [-stream <name>] [-data <content>] [-hex true] | (Windows only) Manage NTFS Alternate Data Streams — write, read, list, or delete hidden data streams. Supports text and hex-encoded binary. MITRE T1564.004. |
| amcache | amcache -action <query|search|delete|clear> [-name <pattern>] [-count <n>] | Query and clean forensic execution artifacts. Windows: Shimcache. Linux: recently-used.xbel, thumbnails, Tracker. macOS: recent items, KnowledgeC, quarantine (T1070.004). |
| apc-injection | apc-injection [-method <apc|hwbp>] -pid <PID> [-tid <TID>] [-target_api ntdll!NtDelayExecution] [-timeout_ms 30000] | (Windows only) Remote process injection. -method apc (default) queues shellcode via NtQueueApcThread into an alertable thread (use ts to find one). -method hwbp attaches via DebugActiveProcess, sets a DR0 hardware breakpoint on a target API (default ntdll!NtDelayExecution), and redirects Rip to the shellcode when the breakpoint fires — no TID required, no APC queue, no CreateRemoteThread (T1055.004, T1055). |
| audio-capture | audio-capture [-duration 10] [-sample_rate 16000] [-channels 1] [-device default] | Record audio from microphone and upload WAV file. Windows (waveIn), Linux (arecord/parecord), macOS (rec/ffmpeg). Cross-platform (T1123). |
| auditpol | auditpol -action <query|disable|enable|stealth> [-category <name|all>] | (Windows only) Query and modify Windows audit policies. Disable security event logging before sensitive operations. Stealth mode disables detection-critical subcategories. Uses AuditQuerySystemPolicy API (T1562.002). |
| argue | argue -command "cmd.exe /c whoami" -spoof "cmd.exe /c echo hello" | (Windows only) Execute a command with spoofed process arguments. Defeats Sysmon Event ID 1 and EDR command-line telemetry (T1564.010). |
| arp | arp [-ip <subnet>] or arp -action spoof -target <IP> -gateway <IP> | Display ARP table with filtering, or ARP cache poisoning for MITM positioning (T1557.002). Spoof: Linux only, restores on cleanup. |
| asrep-roast | asrep-roast -server <DC> -username <user@domain> -password <pass> [-account <target>] | Request AS-REP tickets for accounts without pre-authentication and extract hashes in hashcat format for offline cracking. Auto-enumerates via LDAP. Cross-platform (T1558.004). |
| av-detect | av-detect [-deep true] | Detect installed AV/EDR/security products by scanning running processes against a 130+ signature database. With --deep, also checks kernel modules, systemd units, and config directories for installed-but-not-running products (Linux). Reports product, vendor, type, and PID. Cross-platform. |
| autopatch | autopatch <dll_name> <function_name> <num_bytes> | (Windows only) Automatically patch a function by jumping to nearest return (C3) instruction. Useful for AMSI/ETW bypasses. |
| base64 | base64 -action <encode|decode|xor|hex|hex-decode|rot13|url|url-decode|caesar> -input <data> [-key <key>] [-shift <N>] [-file true] [-output <path>] | Data encoding toolkit: base64, XOR (with string/hex key), hex, ROT13, URL percent-encoding, Caesar cipher. All support file I/O. Cross-platform (T1132.001, T1140, T1027). |
| bits | bits -action <list|create|persist|cancel|suspend|resume|complete> [-name <job>] [-url <URL>] [-path <local>] [-command <exe>] | (Windows only) Manage BITS transfer jobs for persistence and stealthy file download. Create, suspend, resume, complete jobs and set notification commands for persistence. Jobs survive reboots (T1197). |
| browser | browser [-action <passwords|cookies|history|autofill|bookmarks|downloads>] [-browser <all|chrome|edge|chromium|firefox>] | Harvest browser data from Chromium, Firefox, and Safari. History, autofill, bookmarks, downloads cross-platform. Passwords: Chromium (DPAPI/Keychain/GNOME Keyring), Firefox (key4.db NSS decryption), Safari (macOS Keychain). Firefox cookies on all platforms. MITRE T1555.003, T1217. |
| cat | cat <file> or cat -path <file> -start N -end N -number true | Display file contents with optional line range, numbering, and 5MB size protection. |
| cd | cd <directory> | Change the current working directory. |
| chmod | chmod -path <file> -mode <permissions> [-recursive true] | Modify file/directory permissions with octal (755, 644) or symbolic (+x, u+rw, go-w) notation. Recursive support. Cross-platform (T1222). |
| chown | chown -path <file> -owner <user> [-group <group>] [-recursive true] | (Linux/macOS only) Change file/directory ownership by username/UID and group name/GID. Recursive support (T1222). |
| cert-check | cert-check -host <hostname> [-port 443] [-timeout 10] | Inspect TLS certificates on remote hosts — identifies CAs, self-signed certs, expiry, SANs, TLS version, cipher suites, and SHA256 fingerprints. Cross-platform (T1590.001). |
| certstore | certstore -action <list|find> [-store <MY|ROOT|CA|Trust|TrustedPeople>] [-filter <substring>] | (Windows only) Enumerate Windows certificate stores to find code signing certs, client auth certs, and private keys. Searches CurrentUser and LocalMachine. MITRE T1552.004, T1649. |
| clipboard | clipboard -action <read|write|monitor|dump|stop> [-data "text"] [-interval 3] | Read/write clipboard or continuously monitor for changes with credential pattern detection. Cross-platform (T1115). |