Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
OST-C2-Spec — Open Source C&C Specification | Kitploit
Tools/GitHubGitHub/rasta-mouse/ost-c2-spec
ExploitationLateral MovementPost-ExploitationCommand and ControlRed Teaming
GitHubrasta-mouse/ost-c2-spec

OST-C2-Spec

Open Source C&C Specification

View Repository
28318171 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Draft: Request for Discussion

Abstract

This document provides an overview of Version 1 of the OST C&C Specification. It is intended to provide a detailed description of messages and the fields within those messages.

Introduction

The motivation behind this specification is to provide a C&C messaging protocol (including tasking, structured output, and peer-to-peer routing) that can be implemented verbatim, or simply serve as inspiration for project developers. This document is not intended to describe what C&C is. It is assumed the reader understands what it is and what it is used for.

The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" are to be interpreted as described in [RFC2119].

Environmental Assumptions

This specification makes the following assumptions:

  • Messages are sent over an unencrypted network.
  • Implant payloads are embedded with the public RSA key used by the team server it is intended to communicate with.

Glossary of Terms

Below is a list of terms used throughout this document.

  • Implant Metadata: Information that an implant reports about itself to a team server.

  • Task Request: A task given to an implant to perform.

  • Task Response: The status and output (if any) of a given task.

  • Session Key: A unique encryption key used by an implant to encrypt its messages.

Task Messages

Task Header

Each task request and response message MUST have the following 16-byte header.

| Byte |   0  |   1  |   2  |   3  |   4  |   5  |   6  |   7  |
| -------------------------------------------------------------|
|  0   | Type | Code |    Flags    |           Label           |
| -------------------------------------------------------------|
|  1   |         Identifier        |           Length          |
| -------------------------------------------------------------|
  • Type: 1-byte integer. The 'type' of task this is. See [Task Types and Codes].
  • Code: 1-byte integer. A 'sub code' for the given Type. See [Task Types and Codes].
  • Flags: 2-byte integer. A set of bitwise flags to describe the state of the message. See [Task Flags].
  • Label: 4-byte integer. A unique label to correlate multiple messages related to the same task.
  • Identifier: 4-byte integer. A sequential identifier used to construct fragmented messages in the correct order.
  • Length: 4-byte integer. The total length of the task data.

Task Types and Codes

|------------------|--------------------------|
| Type             | Code                     |
|------------------|--------------------------|
| 0 - NOP          | 0                        |
|------------------|--------------------------|
| 1 - Exit         | 0                        |
|------------------|--------------------------|
| 2 - Set          | 0 - Sleep/Jitter         |
|                  | 1 - SpawnTo              |
|                  | 2 - BlockDLLs            |
|                  | 3 - PPID                 |
|------------------|--------------------------|
| 3 - File         | 0 - Copy                 |
|                  | 1 - Move                 |
|                  | 2 - Delete               |
|                  | 3 - Upload               |
|                  | 4 - Download             |
|------------------|--------------------------|
| 4 - Directory    | 0 - Print                |
|                  | 1 - Change               |
|                  | 2 - Create               |
|                  | 3 - Copy                 |
|                  | 4 - Move                 |
|                  | 5 - List                 |
|                  | 6 - Delete               |
|------------------|--------------------------|
| 5 - WhoAmI       | 0                        |
|------------------|--------------------------|
| 6 - Process      | 0 - List                 |
|                  | 1 - Kill                 |
|                  | 2 - Inject Spawn         |
|                  | 3 - Inject Explicit      |
|------------------|--------------------------|
| 7 - Registry     | 0 - Query                |
|                  | 1 - Add                  |
|                  | 2 - Delete               |
|------------------|--------------------------|
| 8 - RPortFwd     | 0 - Start                |
|                  | 1 - Data                 |
|------------------|--------------------------|
| 9 - Environment  | 0 - Get                  |
|                  | 1 - Set                  |
|------------------|--------------------------|
| 10 - SOCKS       | 0 - Connect              |
|                  | 1 - Data                 |
|                  | 2 - Close                |
|------------------|--------------------------|
| 11 - Tokens      | 0 - List                 |
|                  | 1 - Make                 |
|                  | 2 - Steal                |
|                  | 3 - Use                  |
|                  | 4 - Revert               |
|                  | 5 - Delete               |
|                  | 6 - Purge                |
|------------------|--------------------------|
| 12 - Run         | 0                        |
|------------------|--------------------------|
| 13 - ItemStore   | 0 - List                 |
|                  | 1 - Add                  |
|                  | 2 - Delete               |
|                  | 3 - Purge                |
|------------------|--------------------------|
| 14 - LocalExec   | 0 - .NET                 |
|                  | 1 - BOF                  |
|                  | 2 - Managed PowerShell   |
|                  | 3 - Unmanaged PowerShell |
|------------------|--------------------------|
| 15 - PrintScreen | 0                        |
|------------------|--------------------------|
| 16 - RemoteExec  | 0 - WinRM                |
|                  | 1 - WMI                  |
|                  | 2 - PsExec               |
|                  | 3 - SSH                  |
|------------------|--------------------------|
| 17 - Link        | 1 - Link SMB             |
|                  | 2 - Link TCP             |
|------------------|--------------------------|
| 18 - Unlink      | 0                        |
|------------------|--------------------------|
| 19 - P2P         | 0 - Acknowledge          |
|                  | 1 - PassThru             |
|------------------|--------------------------|
| 20 - Jobs        | 0 - List                 |
|                  | 1 - Kill                 |
|---------------------------------------------|

Task Flags

Some flags are mutually exclusive and MUST NOT be set together. If no flags are set, a task SHOULD be assumed to have completed successfully and the associated output (if any) is NOT fragmented.

| Value | Description                              |
| ----- | ---------------------------------------- |
| 0     | No flags                                 |
| 1     | Task Error                               |
| 2     | Task Running (as job)                    |
| 4     | Message is fragmented, more to follow    |
| 8     | Message is fragmented, no more to follow |

Task Data

The task data is appended to the header and will consist of a binary structure, depending on the specific task type and code. Each task request and response message type are defined in [Message Definitions].

It is NOT MANDATORY for a task request or response to have any data if it is not required.

Download Tool