Command and Control is one of the most important tactics in the MITRE ATT&CK matrix as it allows the attacker to interact with the target system and realize their objectives. Organizations leverage Cyber Threat Intelligence to understand their threat model and adversaries that have the intent, opportunity, and capability to attack. Red Team, Blue Team, and virtual Purple Teams work together to understand the adversary Tactics, Techniques, and Procedures to perform adversary emulations and improve detective and preventive controls.
The C2 Matrix was created to aggregate all the Command and Control frameworks publicly available (open-source and commercial) in a single resource to assist teams in testing their own controls through adversary emulations (Red Team or Purple Team Exercises). Phase 1 lists all the Command and Control features such as the coding language used, channels (HTTP, TCP, DNS, SMB, etc.), agents, key exchange, and other operational security features and capabilities. This allows more efficient decisions making when called upon to emulate and adversary TTPs.
It is the golden age of Command and Control (C2) frameworks. Learn how these C2 frameworks work and start testing against your organization to improve detective and preventive controls.
The C2 Matrix currently has 41 command and control frameworks documented in a Google Sheet, web site, and questionnaire format.
Size: 3.16 MB
Language: en
Added: Aug 05, 2020
Slides: 14 pages
Slide Content
C2 Matrix
@JorgeOrchilles
@BrysonBort
@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
•Chief Technology Officer -SCYTHE
•C2 Matrix Co-Creator
•Purple Team Exercise Framework (PTEF)
•10 years @ Citi leading offensive security team
•Certified SANS Instructor: SEC560, SEC504
•Author SEC564: Red Team Exercises and
Adversary Emulation
•CVSSv3.1 Working Group Voting Member
•GFMA: Threat-Led Pen Test Framework
•ISSA Fellow
•NSI Technologist Fellow
T1033 –Jorge Orchilles
@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
•CEO/Founder -SCYTHE
•C2 Matrix Co-Creator
•Founder –GRIMM
•Co-Founder –ICS Village
•R Street Senior Fellow, National and Cybersecurity
•Advisor to the Army Cyber Institute
•NSI Senior Fellow
T1033 –Bryson Bort
@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
•Proliferation of Offensive Security Tools
•Empire went EOL (it is now maintained by BC-
Security)
•Compendium of C2 frameworks
•Added other capabilities
•Began evaluating them to find the ideal one for red
team engagement
•Realized it can be used by Red and Blue Teams
Why did we build this?
@C2_Matrix
thec2matrix.com
@JorgeOrchilles
@BrysonBort
#BHUSA
@BLACKHATEVENTS
•Comparison of Command and Control (C2)
Frameworks
•Google Sheet of C2s
•GUI: https://www.thec2matrix.com/
•Find ideal C2 for your needs:
https://ask.thec2matrix.com
•Gitbookon how to install and use the C2; setup
lab environment; contribute; and defend:
https://howto.thec2matrix.com
•SANS Slingshot C2 Matrix Virtual Machine
•@C2_Matrix & #C2Matrix on Twitter
C2 Matrix