Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Xenon — A Mythic agent for Windows written in C | Kitploit
Tools/GitHubGitHub/mythicagents/xenon
Defensive ToolsPenetration Testing FrameworksPrivilege EscalationPassword AttacksPersistence MechanismsLateral MovementData ExfiltrationPost-ExploitationCommand and ControlRed TeamingPayload Development
18318101 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Remote Access Trojan
GitHubmythicagents/xenon

Xenon

A Mythic agent for Windows written in C

View Repository
Share

Xenon


Xenon is a Cobalt Strike-like Windows agent for Mythic, created by @c0rnbread.




⚠️ Xenon is in an early state of release. It is not opsec safe and could contain memory issues causing crashes. Test thoroughly if planning to use in a live environment.

OPSEC Disclaimer

Xenon makes no claims about evasion. The default configuration will not be OPSEC safe. The goal for Xenon is to allow the operator to customize features in order to accomplish their goals.

Quick Start

Installing Xenon on an already existing Mythic server is very easy. If you do not have a Mythic server set up yet, to do that go to Mythic project page.

For further customizations and evasion refer to the Wiki.

From the Mythic install directory, use the following command to install Xenon as the root user:

./mythic-cli install github https://github.com/MythicAgents/Xenon.git

From the Mythic install directory, use the following command to install Xenon as a non-root user:

sudo -E ./mythic-cli install github https://github.com/MythicAgents/Xenon.git

Features

  • Modular command inclusion
  • Malleable C2 Profiles
  • Supported comms: httpx, smb, tcp
  • Uses forge for BOF modules and SharpCollections
  • Async BOF Support (async BeaconAPIs)
  • User-Defined Reflective Dll Loaders (based on Crystal Palace)
  • Compatible with CS Process Inject Kits

Supported Commands

CommandUsageDescription
pwdpwdShow present working directory.
lsls [path]List directory information for <directory>.
cdcd <directory>Change working directory.
cpcp <source file> <destination file>Copy a file to a new destination.
rmrm <path|file>Remove a directory or file.
mkdirmkdir <path>Create a new directory.
getuidgetuidGet the current identity.
make_tokenmake_token <DOMAIN> <username> <password> [LOGON_TYPE]Create a token and impersonate it using plaintext credentials.
steal_tokensteal_token <pid>Steal and impersonate the token of a target process.
rev2selfrev2selfRevert identity to the original process's token.
pspsList host processes.
shellshell <command>Runs {command} in a terminal.
remote_execremote_exec -Module [module] -Target [target] -Command [command + args] [-Domain [domain]] [-Username [username]] [-Password [password]]Execute a command on a remote machine using WMI, WinRM, or SCShell.
sleepsleep <seconds> [jitter]Change sleep timer and jitter.
inline_executeinline_execute -BOF [COFF.o] [-Arguments [optional arguments]]Execute a Beacon Object File in the current process thread and see output. Warning: Incorrect argument types can crash the Agent process.
async_executeasync_execute -BOF [COFF.o] [-Arguments [optional arguments]]Execute a Beacon Object File asynchronously in a background thread. Output streams via task updates. Supports BeaconWakeup / BeaconGetStopJobEvent.
jobsjobsList running async BOF jobs and their Mythic task UUIDs.
jobkilljobkill <task_uuid>Stop a running async BOF by Mythic agent task UUID (signals BeaconGetStopJobEvent).
usermonusermon [-Interval 3000]Async login monitor (WTS session poll). Live alerts stream on this task. Stop with jobkill <usermon_task_uuid>.
keyloggerkeylogger [-Interval 30000]Async keylogger: buffers keystrokes and dumps on an interval. Live output on this task. Stop with jobkill <keylogger_task_uuid>.
inline_execute_assemblyinline_execute_assembly -Assembly [file] [-Arguments [assembly args] [--patchexit] [--amsi] [--etw]]Execute a .NET Assembly in the current process using @EricEsquivel's BOF "Inline-EA" (e.g., inline_execute_assembly -Assembly SharpUp.exe -Arguments "audit" --patchexit --amsi --etw)
execute_assemblyexecute_assembly -Assembly [SharpUp.exe] [-Arguments [assembly arguments]]Execute a .NET Assembly in a remote processes and retrieve the output.
execute_dllexecute_dll -File [mimikatz.x64.dll]Execute a Dynamic Link Library as PIC. (e.g., execute_dll -File mimikatz.x64.dll)
spawntospawnto -path [C:\Windows\System32\svchost.exe]Set the full path of the process to use for spawn & inject commands.
powerchellpowerchell -Command <command>Execute PowerShell script using PowerChell post-ex DLL.
powershell_importpowershell_import -File [script.ps1] | --clearImport PowerShell script to cache.
downloaddownload -path <file path>Download a file off the target system (supports UNC path).
uploadupload (modal)Upload a file to the target machine by selecting a file from your computer.
statusstatusList C2 connection hosts and their status.
linklink <target> [<named pipe>|<tcp_port>]Connect to an SMB/TCP Link Agent.
unlinkunlink <Display Id>Disconnect from an SMB/TCP Link Agent.
sockssocks <start/stop> <port number>Enable SOCKS 5 compliant proxy to send data to the target network.
rportfwdrportfwd -Action {start|stop} -Port [port] -RemoteIP [ip] -RemotePort [port]Reverse port forward.
killkill [pid]Kill a process by PID.
register_process_inject_kitregister_process_inject_kit (pops modal)Register a custom BOF to use for process injection (CS compatible). See documentation for requirements.
exitexitTask the implant to exit.

Async BOF Commands

Long-running Beacon Object Files run in a background thread and stream output with task updates. Stop them with jobkill using the Mythic agent task UUID (see jobs).

Download Tool