Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S1063
MITRE ATT&CK Tool

Brute Ratel C4 (S1063)

BRc4
ShareXLinkedInRedditHN

[Brute Ratel C4](https://attack.mitre.org/software/S1063) is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. [Brute Ratel C4](https://attack.mitre.org/software/S1063) was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of [Brute Ratel C4](https://attack.mitre.org/software/S1063) was leaked in the cybercriminal underground, leading to its use by threat actors.(Citation: Dark Vortex Brute Ratel C4)(Citation: Palo Alto Brute Ratel July 2022)(Citation: MDSec Brute Ratel August 2022)(Citation: SANS Brute Ratel October 2022)(Citation: Trend Micro Black Basta October 2022)

Platforms: Windows

▪Techniques implemented (33)

T1055.002Portable Executable InjectionT1569.002Service ExecutionT1059.003Windows Command ShellT1021.006Windows Remote ManagementT1113Screen CaptureT1057Process DiscoveryT1027Obfuscated Files or InformationT1047Windows Management InstrumentationT1036.005Match Legitimate Resource Name or LocationT1021.002SMB/Windows Admin SharesT1005Data from Local SystemT1140Deobfuscate/Decode Files or InformationT1069.002Domain GroupsT1572Protocol TunnelingT1518.001Security Software DiscoveryT1685Disable or Modify ToolsT1036.008Masquerade File TypeT1087.002Domain AccountT1021Remote ServicesT1620Reflective Code LoadingT1046Network Service DiscoveryT1482Domain Trust DiscoveryT1106Native APIT1102Web ServiceT1071.004DNST1095Non-Application Layer ProtocolT1105Ingress Tool TransferT1027.007Dynamic API ResolutionT1497.003Time Based ChecksT1574.001DLLT1558.003KerberoastingT1204.002Malicious FileT1071.001Web Protocols
S1063on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.