License & Deployment Mix: 12 tools – 7 OSS, 5 commercial.

Color: Red team.

What Is This Category?

An offensive framework combines the exploit, the C2 channel, and the post-exploitation toolkit in one platform. The operator (pentester or red-teamer) drives a campaign through the framework: gain a foothold (exploit), beacon home (C2), operate on the host (post-ex modules).

Modern frameworks are C2-first – they assume the initial foothold was achieved via phishing / supply- chain / social engineering and focus on what happens next. Metasploit remains the broad exploit library; Sliver / Havoc / Cobalt Strike lead on modern C2.

Distinct from neighbouring categories

The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.

Comparison

Category Scope

Offensive frameworks split into exploitation frameworks (Metasploit – the broad exploit library

  • C2) and C2-focused frameworks (Sliver, Mythic, Havoc, Empire, Covenant, PoshC2 OSS; Cobalt Strike, Brute Ratel, Core Impact, Immunity Canvas, Outflank OST commercial). A typical red-team practice combines: Metasploit for exploitation, Sliver / Havoc for OSS C2 work, Cobalt Strike for premier commercial engagements.

Capability Matrix

ToolExploit LibraryC2Multi-PlatformMulti-OperatorModern Evasion
Metasploityes (2000+)yes (Meterpreter)yespartial– (heavily fingerprinted)
Sliveryes (first-class)yesyesyes
Mythicyes (modular)yesyesvaries by agent
Havocyesyes (mostly Windows)yesyes (fresh 2023+)
Empireyesyesyes– (heavily fingerprinted)
Covenantyes (.NET)partial (Win-leaning)yes– (fingerprinted)
PoshC2yesyespartialpartial
Cobalt Strikeyes (Beacon)yesyesyes (Malleable C2)
Brute Ratelyes (Badger)yesyesyes (next-gen)
Core Impactyes (commercial)yesyesyes
Immunity Canvasyes (commercial)yesyes
Outflank OSTyesyesyesyes (bespoke / fresh)

License Comparison

ToolLicenseOSICost Tier
MetasploitBSD-3-ClauseyesFree
SliverGPL-3.0-onlyyesFree
MythicBSD-3-ClauseyesFree
HavocGPL-3.0-onlyyesFree
EmpireBSD-3-ClauseyesFree
CovenantGPL-3.0-onlyyesFree
PoshC2BSD-3-ClauseyesFree
Cobalt StrikeProprietary~$3,500 / operator / year
Brute RatelProprietary~$2,500 / operator / year
Core ImpactProprietary$50,000+ / seat / year
Immunity CanvasProprietary$50,000+ / seat / year
Outflank OSTProprietaryPer-engagement enterprise

Composition Patterns

1. OSS-only red-team practice

Metasploit -- exploitation library Sliver (primary OSS C2) -- modern OSS C2 for engagements Havoc (alternate OSS C2) -- when fresh-evasion matters more Empire / Covenant / PoshC2 -- training / legacy / edge cases

Output: full red-team operational coverage at zero license cost.

2. Commercial-tier engagements

Cobalt Strike -- premier commercial C2
+ Metasploit -- OSS exploit library (still)
+ Sliver as backup OSS C2 -- evasion / diversity

Output: Cobalt-grade engagement work. Per-operator license cost (~$3.5K/yr) typically justified.

3. Premier-tier (government / defence)

Core Impact or Immunity Canvas -- premier exploit framework
+ Cobalt Strike or Brute Ratel -- premier C2
+ Outflank OST -- bespoke fresh tradecraft

Output: high-end engagement tier for customers who mandate commercial-supported exploit library + fresh C2 tradecraft. Costs in the hundreds-of-K per operator-year range.


Tools

12 tools.

Brute Ratel C4

Chetan Nayak’s commercial red-team framework; next-gen Cobalt Strike alternative; emphasis on modern evasion + strict vetting.

License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none

Website

Cobalt Strike

Raphael Mudge’s premier commercial red-team framework (Fortra-owned post-2020); the category-defining C2 platform; widely deployed at all tiers of the industry.

License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none

Website

Core Impact

Fortra’s premier commercial exploitation + C2 framework; broader- than-Metasploit commercial exploit library; long-standing premier- tier pentest tool.

License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none

Website

Covenant

Ryan Cobb’s open-source .NET C2 framework; Grunt implants in C#; multi-operator team support; predates Sliver and Havoc as the OSS Cobalt alternative.

License: GPL-3.0-only (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC

Website · Source

Empire

BC Security’s maintained fork of the PowerShell Empire C2 framework; classic post-exploitation toolkit; widely fingerprinted but still useful for training.

License: BSD-3-Clause (OSS) · Kind: cli · Deploy: native, docker · SSO: none

Website · Source

Havoc

Modern OSS C2 framework from C5pider; Qt client + Go team server; emphasis on modern evasion + clean modern architecture.

License: GPL-3.0-only (OSS) · Kind: hybrid · Deploy: native, docker · SSO: none

Website · Source

Immunity Canvas

Dave Aitel’s premier commercial exploit framework; original commercial Metasploit alternative; CANVAS Strategic Cyber alongside the commercial exploit pack tradition.

License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none

Website

Metasploit Framework

The canonical open-source exploitation framework; 2,000+ exploits, 1,000+ auxiliary modules, the de-facto pentest standard.

License: BSD-3-Clause (OSS) · Kind: cli · Deploy: native, docker, package · SSO: none

Website · Source

Mythic

Cody Thomas’s open-source C2 framework with pluggable agents and translators; modern Docker-based architecture; popular in red-team training.

License: BSD-3-Clause (OSS) · Kind: web · Deploy: docker · SSO: OIDC

Website · Source

Outflank OST

Outflank’s commercial Offensive Security Toolset; curated collection of bespoke red-team tools from a Dutch pentest consultancy; premier- tier specialised use.

License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none

Website

PoshC2

Nettitude’s open-source proxy-aware C2 framework; PowerShell + Python / C# implants; professional pentest tool with consultancy heritage.

License: BSD-3-Clause (OSS) · Kind: cli · Deploy: native, docker · SSO: none

Website · Source

Sliver

BishopFox’s open-source adversary-emulation framework; the canonical OSS Cobalt Strike alternative; cross-platform implants.

License: GPL-3.0-only (OSS) · Kind: cli · Deploy: native, docker · SSO: none

Website · Source

ResorsIT Tools Catalog Search