Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0378
MITRE ATT&CK Tool

PoshC2 (S0378)

ShareXLinkedInRedditHN

[PoshC2](https://attack.mitre.org/software/S0378) is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in [PowerShell](https://attack.mitre.org/techniques/T1059/001). Although [PoshC2](https://attack.mitre.org/software/S0378) is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.(Citation: GitHub PoshC2)

Platforms: Windows, Linux, macOS

▪Techniques implemented (32)

T1016System Network Configuration DiscoveryT1552.001Credentials In FilesT1557.001Name Resolution Poisoning and SMB RelayT1071.001Web ProtocolsT1047Windows Management InstrumentationT1049System Network Connections DiscoveryT1068Exploitation for Privilege EscalationT1007System Service DiscoveryT1134.002Create Process with TokenT1548.002Bypass User Account ControlT1569.002Service ExecutionT1087.001Local AccountT1119Automated CollectionT1082System Information DiscoveryT1056.001KeyloggingT1087.002Domain AccountT1560.001Archive via UtilityT1550.002Pass the HashT1069.001Local GroupsT1083File and Directory DiscoveryT1090ProxyT1110Brute ForceT1003.001LSASS MemoryT1055Process InjectionT1210Exploitation of Remote ServicesT1482Domain Trust DiscoveryT1134Access Token ManipulationT1046Network Service DiscoveryT1555Credentials from Password StoresT1040Network SniffingT1546.003Windows Management Instrumentation Event SubscriptionT1201Password Policy Discovery

▪Used by groups (3)

G0064APT33G0034Sandworm TeamG1001HEXANE
S0378on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.