Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Medusa — Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows post-exploitation modules. | Kitploit
Tools/GitHubGitHub/mythicagents/medusa
Penetration Testing FrameworksPrivilege EscalationExploit FrameworksLateral MovementShellcodePost-ExploitationCommand and ControlRed TeamingRemote Access ToolShellcode GenerationPayload Development
20852692 months agoReviewed by Kitploit
GitHubmythicagents/medusa

Medusa

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows post-exploitation modules.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Medusa Logo

Medusa

Medusa is a cross-platform agent compatible with both Python 3.8 and Python 2.7.

Installation

To install Medusa, you'll need Mythic v3 installed on a remote computer. You can find installation instructions for Mythic at the Mythic project page.

From the Mythic install root, run the command:

./mythic-cli install github https://github.com/MythicAgents/Medusa.git

Once installed, restart Mythic to build a new agent.

RabbitMQ Config Notes

The file Payload_Type/medusa/rabbitmq_config.json is a template and must match your Mythic environment.

  • Set rabbitmq_password to your Mythic RABBITMQ_PASSWORD value (typically from Mythic .env).
  • Set rabbitmq_host to your RabbitMQ host/container name (often mythic_rabbitmq in docker-compose setups, or 127.0.0.1 for local binds).
  • Set mythic_server_host to your Mythic server host/container name (often mythic_server in docker-compose setups, or 127.0.0.1 for local binds).

Notable Features

  • Dynamic loading/unloading of agent functions to limit exposure of agent capabilities on-disk.
  • Loading of Python modules in-memory for use in custom scripts.
  • Cross-platform SOCKS5 proxy
  • macOS clipboard reader, screenshot grabber and TCC database parsing
  • File browser compatibility with upload/download
  • Eval() of dynamic Python code
  • Basic Authentication Proxy compatibility

Commands Manual Quick Reference

The base agent and included commands all use built-in Python libraries, so do not need additional packages to function. Agents will run the commands in threads, so long-running uploads or downloads won't block the main agent.

General Commands

CommandSyntaxDescription
catcat path/to/fileRead and output file content.
cdcd [.. dir]Change working directory (.. to go up one directory).
cpcp src_file_or_dir dst_file_or_dirCopy file or folder to destination.
cwdcwdPrint working directory.
downloaddownload [path]Download a file from the target system.
download_bulkdownload_bulk [path1] [path2] ...Download multiple files from the target system in one task.
exitexitExit a callback.
envenvPrint environment variables.
eval_codeeval_code [commands]Execute python code and return output.
jobkilljobkill [task id]Send stop signal to long running task.
jobsjobsList long-running tasks, such as downloads.
list_moduleslist_modules [module_name]Lists in-memory modules or the full file listing for a specific module.
loadload commandLoad a new capability into an agent.
load_moduleload_moduleLoad a zipped Python module into memory (adapted from here and here).
load_scriptload_scriptLoad and execute a Python script through the agent.
lsls [. path]List files and folders in [path] or use . for current working directory.
mvmv src_file_or_dir dst_file_or_dirMove file or folder to destination.
pip_freezepip_freezeProgrammatically list installed packages on system.
ptypty [/bin/bash] / pty self / pty forkOpen an interactive PTY session. Modes: spawn runs a program with a PTY, self opens an in-process Python REPL with live agent state, fork forks the agent into a Python REPL with snapshotted state (Linux/macOS only).
rmrm file_or_dirDelete file or folder.
shellshell [command]Run a shell command which will spawn using subprocess.Popen(). Note that this will wait for command to complete so be careful not to block your agent.
sockssocks start/stop [port]Start/stop SOCKS5 proxy through Medusa agent.
sleepsleep [seconds] [jitter percentage]Set the callback interval of the agent in seconds.
unloadunload commandUnload an existing capability from an agent.
unload_moduleunload_module module_nameUnload a Python module previously loaded into memory.
uploaduploadUpload a file to a remote path on the machine.
watch_dirwatch_dir path secondsWatch for changes in target directory, polling for changes at a specified rate.

macOS Commands

CommandSyntaxDescription
clipboardclipboardOutput contents of clipboard (uses Objective-C API, as outlined by Cedric Owens here. macOS only, Python 2.7 only).
list_appslist_appsList macOS applications (Python 2.7 only, macOS only).
list_tcclist_tcc [path]List entries in macOS TCC database (requires full-disk access and Big Sur only atm).
screenshotscreenshotTake a screenshot (uses Objective-C API, macOS only, Python 2.7 only).
spawn_jxaspawn_jxaSpawn an osascript process and pipe Javascript content to it.
vscode_list_recentvscode_list_recent [state_db]Lists files and folders recently opened with VSCode.
vscode_open_editsvscode_open_edits [backup_dir_path]Lists unsaved changes made to files in VSCode.
vscode_watch_editsvscode_watch_edits [path to remote dir] [poll_interval]Poll the VSCode backups directory at a given interval for unsaved edits.

Windows Commands

CommandSyntaxDescription
shinjectshinjectInject shellcode into target PID using CreateRemoteThread (Windows only - adapted from here).
load_dllload_dll dll_path dll_exportLoad an on-disk DLL and execute an exported function (NOTE: This DLL must return an int value on completion, an msfvenom-created DLL, for example, will kill your agent upon completion).
list_dllslist_dlls [pid]Read process memory (PEB) of local or target process to fetch list of loaded DLLs (Python 3 only)
pspsGet limited process information, e.g. PID, process names, architecture and binary paths (Python 3 only)
ps_fullps_fullGet full process information, including PPID, integrity level and command line (Python 3 only)
killkillTerminate a process by process ID (Python 3 only)

Python Versions

Both versions of the Medusa agent use an AES256 HMAC implementation written with built-in libraries (adapted from here), removing the need for any additional dependencies beyond a standard Python install. As such the agent should operate across Windows, Linux and macOS hosts. It's worth mentioning that this crypto implementation does introduce some overhead when handling large files (screenshotting, downloads, etc.) but it's workable.

Py2 vs Py3 Commands

Within the Payload_Type/Medusa/agent_code directory, you will see base_agent files with both py2 and py3 suffixes. Likewise, similar file extensions can be seen for individual function files too.

These are read by the builder.py script to firstly select the right base Python version of the Medusa agent. builder.py will then include commands that are specific to the chosen python version. In the case where a command only has a .py extension, this will be used by default, with the assumption being that no alternative code is needed between the Py2 and Py3 versions.

Threaded Jobs

Download Tool