LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S0699: Mythic

Mythic is an open source, cross-platform post-exploitation/command and control platform. Mythic is designed to "plug-n-play" with various agents and communication channels.[1][2][3] Deployed Mythic C2 servers have been observed as part of potentially malicious infrastructure.[4]

EnterpriseS0699ToolObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Mythic matters because it is an open source, cross-platform post-exploitation and command-and-control framework that can be extended with different agents and communication channels. For leaders, the risk is not the tool name alone; it is whether the organization can recognize resilient C2 patterns across Windows, Linux, and macOS before they support collection, tunneling, proxying, or exfiltration activity.

Executive priority

Treat Mythic as a validation case for C2 and post-exploitation readiness. Security leaders should ask whether network, endpoint, DNS, proxy, and web telemetry can show suspicious command-and-control behavior even when traffic uses common protocols, alternate channels, proxies, encoding, encryption, or size-limited transfers. This supports incident response preparedness, SOC coverage decisions, and audit evidence for monitoring controls across major operating system platforms.

Technical view

MITRE provides no tool-specific detection text for Mythic, so defenders should validate coverage through the related behaviors: fallback channels, web/file/DNS C2, internal and external proxying, domain fronting, non-application-layer protocols, protocol tunneling, data encoding, asymmetric cryptography, automated collection, and transfer size limits. SOC and IR teams should focus on behavior-driven detections rather than simple tool signatures, especially because Mythic is designed to support varied agents and communication channels.

Likely telemetry

  • Endpoint process execution and command-line telemetry from Windows, Linux, and macOS systems
  • Network connection metadata, including destination, protocol, volume, timing, and session patterns
  • HTTP/S and WebSocket logs where available, including host, user-agent, URI, SNI, and certificate context
  • DNS query and response logs, including unusual frequency, length, entropy, and destination patterns
  • Proxy, firewall, and secure web gateway logs showing direct, internal, external, or tunneled connections

Detection direction

  • Validate behavior-based detections for C2 over common application protocols rather than relying on the Mythic name or static indicators.
  • Hunt for resilient C2 patterns such as fallback destinations, alternate protocols, repeated beacon-like connections, and traffic that shifts channels after blocking or interruption.
  • Tune DNS and web detections for encoded, tunneled, or fronted traffic while accounting for legitimate CDN, proxy, and SaaS usage to reduce false positives.
  • Correlate network anomalies with endpoint activity, because protocol-level evidence alone may be ambiguous in environments with heavy encrypted web traffic.
  • Review internal proxy and tunneling detection coverage, since C2 may be relayed through compromised systems rather than connecting directly outbound.

Mitigation priorities

  • Prioritize egress control and monitoring for systems that should not initiate arbitrary outbound web, DNS, file transfer, or non-application-layer communications.
  • Ensure endpoint detection and response coverage is deployed and logging consistently across Windows, Linux, and macOS assets.
  • Restrict and monitor proxy paths, DNS resolution, and permitted outbound protocols according to business need.
  • Build IR playbooks that preserve endpoint, DNS, proxy, firewall, and packet/session metadata needed to reconstruct C2 and collection activity.
  • Use ATT&CK relationship-driven tests to validate detections for C2 resiliency, tunneling, encoding, proxying, and data transfer limits without depending on a specific Mythic agent implementation.
Additional notes and limits

The strongest decision value is to use Mythic as a coverage benchmark for modern, modular C2 behavior. Its open source and plug-and-play nature means local detections should be mapped to communications, proxying, tunneling, collection, and exfiltration behaviors rather than to a single fixed network pattern.

The supplied ATT&CK object does not include official detection guidance, aliases, labels, tactics on the software object, or procedure-level detail beyond related techniques. Any assessment of active exposure, exploitation, attribution, or detection effectiveness requires local telemetry and threat intelligence not provided here.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Mythic

Mythic is an open source, cross-platform post-exploitation/command and control platform. Mythic is designed to "plug-n-play" with various agents and communication channels.[1][2][3] Deployed Mythic C2 servers have been observed as part of potentially malicious infrastructure.[4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

13 rows
DomainIDNameRelationship / procedure
EnterpriseT1090.002External ProxySub-technique

Mythic can leverage a modified SOCKS5 proxy to tunnel egress C2 traffic.[3]

EnterpriseT1071.002File Transfer ProtocolsSub-technique

Mythic supports SMB-based peer-to-peer C2 profiles.[3]

EnterpriseT1573.002Asymmetric CryptographySub-technique

Mythic supports SSL encrypted C2.[3]

EnterpriseT1071.004DNSSub-technique

Mythic supports DNS-based C2 profiles.[3]

EnterpriseT1071.001Web ProtocolsSub-technique

Mythic supports HTTP-based C2 profiles.[3]

EnterpriseT1132Data Encoding

Mythic provides various transform functions to encode and/or randomize C2 data.[3]

EnterpriseT1090.001Internal ProxySub-technique

Mythic can leverage a peer-to-peer C2 profile between agents.[3]

EnterpriseT1095Non-Application Layer Protocol

Mythic supports WebSocket and TCP-based C2 profiles.[3]

EnterpriseT1030Data Transfer Size Limits

Mythic supports custom chunk sizes used to upload/download files.[3]

EnterpriseT1119Automated Collection

Mythic supports scripting of file downloads from agents.[3]

EnterpriseT1572Protocol Tunneling

Mythic can use SOCKS proxies to tunnel traffic through another protocol.[3]

EnterpriseT1090.004Domain FrontingSub-technique

Mythic supports domain fronting via custom request headers.[3]

EnterpriseT1008Fallback Channels

Mythic can use a list of C2 URLs as fallback mechanisms in case one IP or domain gets blocked.[3]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
ceb96df87505b565...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundleceb96df87505…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Mythic Github

    Thomas, C. (2018, July 4). Mythic. Retrieved March 25, 2022.

    Open source URL
  2. [2]
    Mythic SpecterOps

    Thomas, C. (2020, August 13). A Change of Mythic Proportions. Retrieved March 25, 2022.

    Open source URL
  3. [3]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  4. [4]
    RecordedFuture 2021 Ad Infra

    Insikt Group. (2022, January 18). 2021 Adversary Infrastructure Report. Retrieved March 25, 2022.

    Open source URL
  5. [5]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  6. [6]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  7. [7]
    Mythic Github

    Thomas, C. (2018, July 4). Mythic. Retrieved March 25, 2022.

    Open source URL
  8. [8]
    Mythic Github

    Thomas, C. (2018, July 4). Mythic. Retrieved March 25, 2022.

    Open source URL
  9. [9]
    Mythic SpecterOps

    Thomas, C. (2020, August 13). A Change of Mythic Proportions. Retrieved March 25, 2022.

    Open source URL
  10. [10]
    Mythic SpecterOps

    Thomas, C. (2020, August 13). A Change of Mythic Proportions. Retrieved March 25, 2022.

    Open source URL
  11. [11]
    RecordedFuture 2021 Ad Infra

    Insikt Group. (2022, January 18). 2021 Adversary Infrastructure Report. Retrieved March 25, 2022.

    Open source URL
  12. [12]
    RecordedFuture 2021 Ad Infra

    Insikt Group. (2022, January 18). 2021 Adversary Infrastructure Report. Retrieved March 25, 2022.

    Open source URL
  13. [13]
    mitre-attackS0699
    Open source URL
  14. [14]
    mitre-attackS0699
    Open source URL
  15. [15]
    mitre-attackS0699
    Open source URL
  16. [16]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  17. [17]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  18. [18]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  19. [19]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  20. [20]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  21. [21]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  22. [22]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  23. [23]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  24. [24]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  25. [25]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  26. [26]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  27. [27]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  28. [28]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  29. [29]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  30. [30]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  31. [31]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  32. [32]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  33. [33]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  34. [34]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  35. [35]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  36. [36]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  37. [37]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  38. [38]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  39. [39]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.