
Adversary emulation and C2 framework for security research
Adversary emulation framework for offensive security research and purple team operations.
Glimmer is a custom C2 framework built from scratch to explore persistence, evasion, and detection engineering across workstation, cloud, and embedded environments.
This is a research and portfolio project. All testing is conducted against infrastructure I own and operate, with appropriate authorization.
Early development. Architecture and ADRs will be documented as the project evolves.
Currently has:
src/bin/beacon.rs - Implant entrypoint
src/bin/server.rs - C2 server entrypoint
src/bin/dump_browser.rs - Standalone test binary for browser collection
src/bin/dump_keyring.rs - Standalone test binary for keyring collection
src/bin/dump_keypress.rs - Standalone test binary for keylog collection
src/ - Core modules (agent, c2, crypto, collectors, syscalls)
docs/adr/ - Architecture decision records
This tool is intended for authorized security testing and research only.
Unauthorized use against systems you do not own or have explicit permission to test is illegal and unethical.
MIT. Copy it, steal it, modify it, learn from it, share your improvements with me. Or don't. It's code, do what you want with it.