License & Deployment Mix: 12 tools – 7 OSS, 5 commercial.
Color: Red team.
What Is This Category?
An offensive framework combines the exploit, the C2 channel, and the post-exploitation toolkit in one platform. The operator (pentester or red-teamer) drives a campaign through the framework: gain a foothold (exploit), beacon home (C2), operate on the host (post-ex modules).
Modern frameworks are C2-first – they assume the initial foothold was achieved via phishing / supply- chain / social engineering and focus on what happens next. Metasploit remains the broad exploit library; Sliver / Havoc / Cobalt Strike lead on modern C2.
Distinct from neighbouring categories
- Vulnerability Management – VM checks for the presence of vulns; offensive frameworks exploit them and operate post-foothold
- Reconnaissance & Asset Discovery – recon enumerates; offensive frameworks act
- Breach & Attack Simulation (BAS) – BAS is automated, low-and-known TTPs against your own infra; offensive frameworks are operator-driven against engagement targets
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
Category Scope
Offensive frameworks split into exploitation frameworks (Metasploit – the broad exploit library
- C2) and C2-focused frameworks (Sliver, Mythic, Havoc, Empire, Covenant, PoshC2 OSS; Cobalt Strike, Brute Ratel, Core Impact, Immunity Canvas, Outflank OST commercial). A typical red-team practice combines: Metasploit for exploitation, Sliver / Havoc for OSS C2 work, Cobalt Strike for premier commercial engagements.
Capability Matrix
| Tool | Exploit Library | C2 | Multi-Platform | Multi-Operator | Modern Evasion |
|---|---|---|---|---|---|
| Metasploit | yes (2000+) | yes (Meterpreter) | yes | partial | – (heavily fingerprinted) |
| Sliver | – | yes (first-class) | yes | yes | yes |
| Mythic | – | yes (modular) | yes | yes | varies by agent |
| Havoc | – | yes | yes (mostly Windows) | yes | yes (fresh 2023+) |
| Empire | – | yes | yes | yes | – (heavily fingerprinted) |
| Covenant | – | yes (.NET) | partial (Win-leaning) | yes | – (fingerprinted) |
| PoshC2 | – | yes | yes | partial | partial |
| Cobalt Strike | – | yes (Beacon) | yes | yes | yes (Malleable C2) |
| Brute Ratel | – | yes (Badger) | yes | yes | yes (next-gen) |
| Core Impact | yes (commercial) | yes | yes | yes | – |
| Immunity Canvas | yes (commercial) | yes | yes | – | – |
| Outflank OST | – | yes | yes | yes | yes (bespoke / fresh) |
License Comparison
| Tool | License | OSI | Cost Tier |
|---|---|---|---|
| Metasploit | BSD-3-Clause | yes | Free |
| Sliver | GPL-3.0-only | yes | Free |
| Mythic | BSD-3-Clause | yes | Free |
| Havoc | GPL-3.0-only | yes | Free |
| Empire | BSD-3-Clause | yes | Free |
| Covenant | GPL-3.0-only | yes | Free |
| PoshC2 | BSD-3-Clause | yes | Free |
| Cobalt Strike | Proprietary | – | ~$3,500 / operator / year |
| Brute Ratel | Proprietary | – | ~$2,500 / operator / year |
| Core Impact | Proprietary | – | $50,000+ / seat / year |
| Immunity Canvas | Proprietary | – | $50,000+ / seat / year |
| Outflank OST | Proprietary | – | Per-engagement enterprise |
Composition Patterns
1. OSS-only red-team practice
Metasploit -- exploitation library Sliver (primary OSS C2) -- modern OSS C2 for engagements Havoc (alternate OSS C2) -- when fresh-evasion matters more Empire / Covenant / PoshC2 -- training / legacy / edge cases
Output: full red-team operational coverage at zero license cost.
2. Commercial-tier engagements
Cobalt Strike -- premier commercial C2
+ Metasploit -- OSS exploit library (still)
+ Sliver as backup OSS C2 -- evasion / diversityOutput: Cobalt-grade engagement work. Per-operator license cost (~$3.5K/yr) typically justified.
3. Premier-tier (government / defence)
Core Impact or Immunity Canvas -- premier exploit framework
+ Cobalt Strike or Brute Ratel -- premier C2
+ Outflank OST -- bespoke fresh tradecraftOutput: high-end engagement tier for customers who mandate commercial-supported exploit library + fresh C2 tradecraft. Costs in the hundreds-of-K per operator-year range.
Tools
12 tools.
Brute Ratel C4
Chetan Nayak’s commercial red-team framework; next-gen Cobalt Strike alternative; emphasis on modern evasion + strict vetting.
License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none
Cobalt Strike
Raphael Mudge’s premier commercial red-team framework (Fortra-owned post-2020); the category-defining C2 platform; widely deployed at all tiers of the industry.
License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none
Core Impact
Fortra’s premier commercial exploitation + C2 framework; broader- than-Metasploit commercial exploit library; long-standing premier- tier pentest tool.
License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none
Covenant
Ryan Cobb’s open-source .NET C2 framework; Grunt implants in C#; multi-operator team support; predates Sliver and Havoc as the OSS Cobalt alternative.
License: GPL-3.0-only (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC
Empire
BC Security’s maintained fork of the PowerShell Empire C2 framework; classic post-exploitation toolkit; widely fingerprinted but still useful for training.
License: BSD-3-Clause (OSS) · Kind: cli · Deploy: native, docker · SSO: none
Havoc
Modern OSS C2 framework from C5pider; Qt client + Go team server; emphasis on modern evasion + clean modern architecture.
License: GPL-3.0-only (OSS) · Kind: hybrid · Deploy: native, docker · SSO: none
Immunity Canvas
Dave Aitel’s premier commercial exploit framework; original commercial Metasploit alternative; CANVAS Strategic Cyber alongside the commercial exploit pack tradition.
License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none
Metasploit Framework
The canonical open-source exploitation framework; 2,000+ exploits, 1,000+ auxiliary modules, the de-facto pentest standard.
License: BSD-3-Clause (OSS) · Kind: cli · Deploy: native, docker, package · SSO: none
Mythic
Cody Thomas’s open-source C2 framework with pluggable agents and translators; modern Docker-based architecture; popular in red-team training.
License: BSD-3-Clause (OSS) · Kind: web · Deploy: docker · SSO: OIDC
Outflank OST
Outflank’s commercial Offensive Security Toolset; curated collection of bespoke red-team tools from a Dutch pentest consultancy; premier- tier specialised use.
License: Proprietary (proprietary) · Kind: hybrid · Deploy: native · SSO: none
PoshC2
Nettitude’s open-source proxy-aware C2 framework; PowerShell + Python / C# implants; professional pentest tool with consultancy heritage.
License: BSD-3-Clause (OSS) · Kind: cli · Deploy: native, docker · SSO: none
Sliver
BishopFox’s open-source adversary-emulation framework; the canonical OSS Cobalt Strike alternative; cross-platform implants.
License: GPL-3.0-only (OSS) · Kind: cli · Deploy: native, docker · SSO: none