# DragoQCC/CrucibleC2

A C# Command & Control framework

Repository: https://github.com/DragoQCC/CrucibleC2
Canonical: https://ross.abutalabs.com/products/cruciblec2
Language: C#
License: BSD-3-Clause
License Family: permissive
Last push: 2024-03-28T02:30:02+00:00

## Health v2 (maintenance only)
Score: 22/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 0, release rhythm 8, longevity 97
- inputs: {"age_days": 1364, "days_push": 889, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1024, forks 132 (observed 2026-08-28T04:03:16.382020+00:00)

## What it is
HardHat C2 (CrucibleC2) is a cross-platform, multi-user Command & Control framework written in C#/.NET for red team engagements and penetration testing. It consists of an ASP.NET teamserver, a Blazor client, and built-in C# implants with support for third-party implants.

## Use cases
- run a command and control framework for red team engagements
- manage multi-operator C2 with role-based access control
- generate payloads like exe, dll, shellcode, and powershell
- create and edit C2 profiles during a penetration test
- collaborate with a team on a shared teamserver
- use third-party implants in other languages

## When to choose
- you need a free, open-source, cross-platform C2 framework in C#
- you want multi-user collaboration with RBAC during engagements
- you prefer an easy-to-use GUI client (Blazor) for C2 operations

## When to avoid
- you need a battle-tested, production-hardened C2 - it is in alpha with bugs and missing features
- you require implants in languages other than C# without extra setup
- you are not doing authorized security testing - this is a dual-use offensive tool

## Facets
- artifact type: application
- maturity: experimental
- function: security, gui, http-server, middleware
- domain: security, penetration-testing, developer-tools
- platform: cross-platform, dotnet, self-hosted
- tags: c2-framework, red-team, command-and-control, implants, teamserver, blazor, payload-generation, rbac, web-server

## Member repositories
- DragoQCC/CrucibleC2 (main) score 22

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:16.382020+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:08:06.700924+00:00, confidence not recorded.
  - readme: https://github.com/DragoQCC/CrucibleC2 (fetched 2026-08-28T04:03:16.382020+00:00, sha b1f5fc67da30)
- Data as of 2026-08-30T08:39:29.467469+00:00.
