01 / 06
Red Team · C2Scroll →
Custom C2, built from scratch in Rust.
Our red team operates with kaosh — a proprietary Command & Control framework. No off-the-shelf tools, no known signatures, no public IOCs.
~80KBstatic implant
0public signatures
14native modules
3platforms
02 / 06
Why we built it
Public C2s have public signatures.
No public signaturesNever submitted to VirusTotal.
Zero shared codeWritten from scratch in Rust.
Custom malleable C2Traffic mimics Slack, Teams, O365.
Continuous evasion R&DTested vs CrowdStrike, Defender, SentinelOne.
03 / 06
Per-beacon actions
Every operation a real adversary needs.
Interactive consoleshell
File operationsio
Surveillancescreen
Process & tokeninject
Credential capturelsa
Lateral movementpsexec
Persistenceboot
Pivotingsocks5
04 / 06
Biggest gap in other C2s
Network attacks, built into the beacon.
Inline ResponderLLMNR / NBT-NS poisoning.
Inline NTLM relaySMB, HTTP→LDAP, ADCS (ESC8/ESC11).
Authentication coercionPrinterBug, PetitPotam, DFSCoerce.
IPv6 takeovermitm6, rogue DHCPv6 / DNS.
05 / 06
How it compares
kaosh vs Cobalt Strike vs Sliver.
No public signaturesCobalt Strike & Sliver ship heavy ones.
Never on VirusTotalOthers are submitted and known.
Rust implant, ~80KBNo CRT, no .NET, no PowerShell.
Per-engagement keysNothing shared between clients.
06 / 06