people sitting down near table with assorted laptop computers

AdaptixC2: The Open-Source C2 Framework in Kali Linux 2026

Metasploit MCP and WP Probe – both from the same Kali Linux 2026 tool wave – already have deep-dives on this blog. AdaptixC2 is the other tool from that release worth a proper look, because it fills a different, longer-standing gap: an open-source command-and-control framework in the same space Cobalt Strike, Sliver and Mythic already occupy.

What AdaptixC2 actually is

AdaptixC2 is an extensible post-exploitation and adversarial-emulation framework, built for authorised red-team engagements. The server side is written in Go, which keeps the operator tooling flexible and cross-platform, and the whole thing is designed around simulating advanced-persistent-threat-style behaviour in a controlled environment rather than one-off exploitation.

Core architecture

  • Team server – the central Go-based server that agents (beacons) check in to, and that operators connect their client to
  • Listeners – configurable channels (HTTP/HTTPS and others) that beacons use to communicate back to the team server
  • Agents/beacons – the payload running on a compromised host, checking in on an operator-defined interval
  • Modules – extensions that add specific post-exploitation capability (credential access, lateral movement, persistence) on top of the base agent

Setting it up on Kali

AdaptixC2 ships in the Kali 2026 repositories, so a standard install is the usual pattern:

sudo apt update
sudo apt install adaptixc2

# start the team server (run this on infrastructure you control)
adaptix-server --config /etc/adaptix/server.yaml

# connect the operator client
adaptix-client --server 127.0.0.1 --port 4444

The server config is where listeners, TLS certificates and operator credentials get defined – worth treating with the same care as any other piece of red-team infrastructure, since a poorly secured team server is itself a target.

A typical engagement workflow

  1. Stand up the team server on infrastructure isolated from the client environment
  2. Configure one or more listeners matching the engagement’s rules of engagement
  3. Generate an agent/beacon payload and deliver it through whatever initial-access vector is in scope
  4. Once a beacon checks in, use modules to demonstrate impact – credential access, lateral movement – exactly as scoped, then document everything for the report

How it compares to Cobalt Strike, Sliver and Mythic

  • Cobalt Strike – the long-established commercial standard, extensive Malleable C2 profile support, licensed per operator
  • Sliver – open-source, Go-based, strong at protocol flexibility and cross-platform implants
  • Mythic – open-source, plugin-driven, framework-agnostic (supports multiple agent languages via its API)
  • AdaptixC2 – open-source, newer, aimed squarely at teams wanting a free, actively developed alternative without a licensing conversation

The blue-team side of this is worth reading too

Every C2 framework that gets popular on the red-team side eventually gets its traffic patterns documented on the defensive side – AdaptixC2’s listener behaviour and beacon check-in patterns are already being written up for detection purposes. Running it in a lab specifically to capture and understand what its network traffic looks like is a legitimate, useful exercise for anyone doing detection engineering, independent of ever using it offensively.

Scope, always

Everything above assumes a lab environment or an engagement you’re explicitly authorised to run – a C2 framework is exactly the kind of tool where “I was just testing it” stops being a defensible sentence the moment it touches infrastructure you don’t have permission to touch. Build it in a VM, point it at nothing you don’t own, and it’s a genuinely useful thing to understand either way.


Leave a Reply