
httpx is a Mythic C2 profile that gives authorized red teams a highly configurable, JSON/TOML-driven HTTP channel with domain rotation and message transforms for emulation exercises.
| Tool | MythicC2Profiles/httpx — community-driven, configurable HTTP C2 profile for the Mythic framework |
| Category | Command and control framework extension (Go) |
| Primary Use | Extending a Mythic instance with a flexible HTTP profile for authorized red-team and adversary-emulation engagements, configured via JSON or TOML at build time |
| Safe Use | Strictly for authorized penetration tests, red-team engagements, and adversary-emulation labs where operators have written permission to test the target environment |
| Telemetry Note | Generates HTTP traffic with customizable cookies, headers, query parameters, and body encoding; defenders can detect its callback patterns, jitter/sleep intervals, and transform artifacts (base64, netbios, XOR) in proxy and NDR logs |
MythicC2Profiles/httpx is a C2 profile rather than a standalone tool: it is a containerized extension that plugs into the Mythic command-and-control framework and replaces the stock HTTP transport with something far more malleable. Written in Go, the project positions itself explicitly as a community-requested profile, meaning its feature set was shaped by what operators in the Mythic ecosystem actually asked for — primarily configurability. For authorized red teams and adversary-emulation teams, that configurability matters, because the difference between a realistic emulation and an obviously synthetic one often comes down to how faithfully the traffic mimics legitimate enterprise HTTP.
The most operationally interesting capability listed in the README is callback domain handling. The profile accepts an array of callback domains and supports two rotation strategies: fail-over and round-robin. Fail-over is further tunable through a domain fallback threshold — the number of failed attempts tolerated before the profile moves to the next domain in the list. This mirrors how legitimate SaaS applications behave when endpoints fail, and from a defensive research standpoint it is a useful property to study: resilience engineering applied to C2 infrastructure produces traffic patterns that are statistically closer to benign client behavior than a single hard-coded endpoint ever could be.
Cryptographic posture is addressed up front in the feature list. The profile implements an encrypted key exchange followed by AES256 keyed-HMAC message protection. What that tells an analyst is that session establishment is designed so that post-exploitation messages are both confidential and integrity-checked, rather than relying on transport security alone. Because the negotiated key derives from the exchange, defenders cannot simply decrypt captured callback traffic from the wire; detection has to lean on metadata — timing, sizing, and header anomalies — rather than payload inspection.
Callback pacing is handled through configurable jitter and sleep intervals. This is standard hygiene in modern C2 design, but worth noting because it directly counters naive beaconing detection: a fixed-interval callback produces a Fourier-visible spike in proxy logs, while randomized jitter flattens that signature. Blue teams building detection analytics should assume jittered callbacks as the baseline for any contemporary adversary-emulation toolset, and tune their models toward distributional anomalies rather than exact periodicity.
The configuration model is where httpx earns its "dynamic and configurable" billing. Agent message and server response behavior is defined in JSON or TOML files consumed at build time, and the surface those files expose is broad. Message placement can be set to cookies, headers, query parameters, or the request body, and message transforms include base64, base64url, append, prepend, xor, netbios, and netbiosu encoding schemes. Custom client and server headers plus custom client query parameters round out the knobs. In practice, this means two httpx payloads generated from different configuration files can produce traffic that looks almost nothing alike, which is precisely the property emulation teams want when replicating distinct threat actors.
The transform list deserves a closer read. The netbios and netbiosu encodings are historically associated with older attacker tooling — they encode bytes into alphabetic sequences resembling NetBIOS names — so their presence here is a deliberate nod to legacy tradecraft that defenders may still encounter. XOR with a known key is trivially reversible but sufficient to defeat shallow signature matching, and stacked transforms (encode, then prepend junk) are the kind of composition that breaks naive regex-based DLP and IDS rules. Studying how these transforms compose is exactly the kind of educational exercise this profile enables in a lab.
Installation follows the standard Mythic extension workflow, and the README documents it plainly. The mythic-cli binary handles the three supported paths: pulling straight from GitHub, pinning to a specific branch, or installing from an already-cloned local folder — for example sudo ./mythic-cli install github https://github.com/MythicC2Profiles/httpx. Once installed, the profile's containers still need to be started, either individually with something like sudo ./mythic-cli start profileName or via a full sudo ./mythic-cli start, which stops and restarts all containers. None of this is weaponized capability; it is framework plumbing identical to installing any other Mythic agent or profile.
The lifecycle guidance in the README is worth a paragraph of its own because it reveals the architecture. Mythic runs profiles as Docker containers alongside the main server, and installing a profile mid-operation is explicitly supported — the README notes there is no wrong answer whether the framework is already running or not. This containerized modularity is the core design decision behind Mythic's ecosystem: transports, agents, and the UI are decoupled components that operators compose. httpx slots into that philosophy by treating the HTTP transport itself as a configurable artifact rather than fixed code.
From a defender's perspective, everything httpx exposes as a feature maps to a detection surface. Domain rotation produces DNS resolution and connection patterns across multiple hosts that correlate to a single client; fallback thresholds create burst-then-switch behavior visible in proxy logs; custom headers and query parameters show up verbatim in full-request captures; and encoded message bodies produce byte-distribution anomalies regardless of the transform chosen. Teams running purple-team exercises can use the profile deliberately, generating known-benign-but-adversarial-shaped traffic to validate that their pipelines catch each of these classes.
The repo is modest — around 28 stars, Go, default branch main, no license declared at the time of this writing, and no topic tags — which is typical for MythicC2Profiles organization repositories that serve as ecosystem components rather than headline projects. The README is installation-focused and does not document the JSON/TOML schema in detail, so operators will need to inspect the configuration files and profile source directly to fully exploit the transform and placement options. The absence of a license is worth flagging for anyone considering organizational adoption, since it leaves redistribution terms undefined.
Where httpx fits in an authorized workflow is straightforward: it is the transport layer choice for a Mythic-based engagement where the emulation plan calls for realistic, varied HTTP callbacks rather than a stock profile. Its value is highest in adversary-emulation programs that iterate — build a config per threat actor, run the exercise, measure detection, refine. For that loop, a profile whose entire behavioral surface is data-driven configuration is significantly more efficient than modifying agent code, and that is ultimately the pitch this repository makes: bring your own traffic shape, and let the framework handle the rest.
MythicC2Profiles/httpx.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.