offensive-tools/c2/poshc2/SKILL.md
PoshC2: proxy-aware Python C2 framework with implants in PowerShell, C#, Python, and C. Use when operating in environments with available PowerShell and network proxies, needing proxy-aware beacons, or performing post-exploitation with built-in credential access and lateral movement modules.
npx skillsauth add aeondave/malskill poshc2Install this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Proxy-aware C2 with PowerShell, C#, Python, C implants.
curl -sSL https://raw.githubusercontent.com/nettitude/PoshC2/master/Install.sh | bash
posh-project -n MyOp
posh-server
posh
posh-payloads
| Command | Purpose |
|---------|---------|
| listimplants | Show active implants |
| implant <id> | Interact with implant |
| run <cmd> | Run system command |
| loadmodule <module> | Load post-ex module |
| inject-shellcode | Inject shellcode into process |
| invoke-mimikatz | Run Mimikatz |
| sharphound | BloodHound collection |
| get-system | Attempt privilege escalation |
| File | When to load |
|------|--------------|
| references/ | Module list, proxy config, C implant usage |
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.