Covenant
.NET command and control framework for post-exploitation of Windows targets.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse network tools →What's next with Covenant?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Covenant?
Covenant is an open-source.NET command and control (C2) framework designed for red team operations. It provides a collaborative platform for security researchers and offensive security professionals to execute, manage, and analyze.NET-based attacks. The tool emphasizes the exploitation of.NET's attack surface, offering a structured approach to deploying payloads, maintaining persistence, and exfiltrating data. Covenant is built on ASP.NET Core, enabling cross-platform functionality and a web-based interface that supports multi-user collaboration. Its primary users include red teamers, penetration testers, and advanced threat hunters who need to simulate sophisticated attacks against.NET environments. By streamlining offensive.NET tradecraft, Covenant addresses the complexity of working with.NET's vast ecosystem, allowing users to focus on strategic attack planning and execution rather than infrastructure setup.
How it works
Covenant is a collaborative.NET C2 framework that enables red teamers to execute, manage, and analyze attacks within.NET environments. It leverages ASP.NET Core for cross-platform operation and provides a web-based interface for team collaboration. The tool's primary purpose is to simplify offensive.NET operations by highlighting potential attack vectors, reducing the overhead of setting up C2 infrastructure, and facilitating real-time collaboration among team members. Covenant supports multi-user collaboration through its web interface, allowing teams to share payloads, monitor activity, and coordinate attacks in real time. It includes features like module creation, payload generation, and session management, all tailored for.NET-based attacks.
How to use it
- 1Install.NET Core SDK and dependencies as outlined in the Installation and Startup guide. 2. Clone the Covenant repository from GitHub and navigate to the project directory. 3. Run the application using the provided build scripts to start the ASP.NET Core web server. 4. Access the web interface via a browser to configure payloads, manage sessions, and collaborate with team members. Practical tips include referencing the Wiki for detailed documentation, using the built-in module library for common attack vectors, and ensuring secure network configurations to prevent unauthorized access.
What it can do
- C2 framework
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/cobbr/Covenant
- license: GPL-3.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- Offensive tool — authorized penetration testing and lab use only; unauthorized use is illegal.
- Limited to .NET-based attack vectors, excluding other language ecosystems
- Requires advanced knowledge of .NET internals and C# for module development
- Depends on a stable web server infrastructure for the web interface
- Potential legal and ethical risks when used in unauthorized environments
Understanding the result
.NET command and control framework for post-exploitation of Windows targets.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (GPL-3.0).
- Built with
- (cobbr/Covenant)
- License
- GPL-3.0
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with cobbr/Covenant. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- GPL-3.0
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- GPL-3.0 License
Upstream project
Frequently asked
What is Covenant's primary use case?
Covenant is primarily used by red teamers and penetration testers to execute, manage, and analyze .NET-based attacks. It enables collaborative C2 operations, payload development, and session monitoring within .NET environments, making it ideal for simulating advanced persistent threats (APTs) and testing defensive measures against .NET-specific vulnerabilities.
How does Covenant handle cross-platform operation?
Covenant is built on ASP.NET Core, which allows it to run on Windows, Linux, and macOS. This cross-platform support enables users to deploy the framework on any operating system that meets the .NET Core SDK requirements, ensuring flexibility in both local and remote testing scenarios.
How do I create a custom payload in Covenant?
To create a custom payload, navigate to the 'Modules' section in the web interface, select 'New Module,' and define the payload's behavior using C# code. Save the module, then use it in a session by selecting it from the payload library. Detailed instructions are available in the Wiki under 'Module Development.'
How does Covenant compare to Cobalt Strike or Empire?
Covenant differs from Cobalt Strike and Empire by focusing exclusively on .NET-based attacks and providing a web-based collaborative interface. Cobalt Strike offers a GUI for Windows-based C2, while Empire uses PowerShell. Covenant's strength lies in its extensibility for .NET exploitation, whereas Cobalt Strike and Empire target broader attack surfaces with different payloads.
What should I do if the web interface is unreachable?
If the web interface is unreachable, verify that the ASP.NET Core server is running and check firewall settings to ensure port 5000 (or the configured port) is open. Confirm the server's IP address and try accessing it from the same network. Restarting the application or checking the logs for errors can also help diagnose connectivity issues.