Skip to main content

Compromised Host

The plugin performs C2 campaign replay: the client emulates an infected host and the server emulates a C2 controller. Campaigns use IOCs, families, C2 commands, and multistep chains as network artifacts. They do not execute payloads or contact live C2 infrastructure. Scenarios come from the C2 Compromise Scenarios (PTI) library.

Figure 20 — Catalog: Compromised Host

Figure 20 — Compromised Host plugin in the catalog

Figure 21 — Compromised Host plugin settings

Figure 21 — Campaign selection and C2 settings

Table 189 — Compromised Host settings

NameDescriptionValue
C2 Compromise Scenarios (PTI)List of uploaded campaignsSelect one or more
Scenario coverageFirst scenario or all campaign scenariosSelect a mode
Bot ID modeSequential / Random / From listInfected-host identifiers used in events
Step timeoutTime to wait for a C2 response at a scenario step0–300 seconds (0 means unlimited; default: 30)
C2 beacon intervalDelay between C2 requests1–86400 seconds
Beacon interval jitterJitter applied to the base interval0–90%
HTTP Host / DNS query / URI / Request bodyOverride C2 artifactsEmpty uses the IOC from the campaign
Loop replayRepeat scenarios over open connectionsOne pass or loop for the configured duration
Sessions / CPSSession count and opening rateDefault: 100 sessions / 10 CPS

A typical topology places the client plugin on one agent and the server plugin on another, or runs both arms in the same test environment. Before starting, import the C2 campaign package and wait for it to synchronize with the agents; see Settings → Synchronization and the C2 (PTI) library.

Dashboard: compromised_host.