ENNAENNA

Covenant vs Merlin

GitHub Stats

4.7k
Stars
5.5k
825
Forks
837
88
Issues
21
1y ago
Updated
1y ago
GPL-3.0
License
GPL-3.0
C#
Language
Go

About Covenant

Covenant is a .NET-based command and control (C2) framework that offers a collaborative web-based interface for managing red team operations and implants. It facilitates comprehensive C2 tasks, including implant execution and management, through a user-friendly interface. Notable for its use in red team engagements, Covenant allows operators to execute complex attack scenarios with the flexibility of .NET, supporting both real-time and asynchronous communications.

About Merlin

Merlin is a cross-platform post-exploitation Command and Control (C2) server and agent written in Go. It communicates over HTTP/2 and HTTP/3 (QUIC), leveraging modern protocols that many security tools and network monitors do not inspect. The server provides an interactive CLI for managing multiple agents, executing commands, uploading/downloading files, and running post-exploitation modules. Agents compile to single static binaries for Windows, Linux, and macOS. Merlin supports encrypted JWE/JWT communications, domain fronting, and multiple listener types for operational flexibility.

Platform Support

๐Ÿงlinux๐ŸŽmacos๐ŸชŸwindows
๐Ÿงlinux๐ŸŽmacos๐ŸชŸwindows

Tags

Shared

c2

Covenant only

red-teamdotnetimplant

Merlin only

http2post-exploitationcross-platformquiccommand-and-control