Single-port C2 with SYSTEM-ready payloads. No migration protocol breaks.
Phoenix (ShellChain) is a research C2 framework focused on the migration problem — what happens when an implant loses its C2 server. It uses AES-256-CBC encryption, a sentinel-based command protocol, and stores redirect configuration (ip.txt/port.txt) so the implant can recover without re-compromise. The design prioritises operational resilience and traffic blending over raw feature count.
Dual-view demonstration: Attacker C2 panel and victim desktop during authorized engagement
Phoenix solves the SYSTEM shell problem. Previous C2 architectures used migration protocols that broke when running as NT AUTHORITY\SYSTEM - the process couldn't follow port redirection commands.
Phoenix uses a single-port architecture: connect once, stay connected. USER, ADMIN, and SYSTEM shells all work on the same connection.
No migration protocol. SYSTEM shells stay connected.
Admin → SYSTEM escalation that actually works.
Roaming + Local + ProgramFiles folders.
Survives Windows reset and reinstall.
ip.txt/port.txt for mid-session handoff.
Configurable lifetime timer.
Phoenix documentation is available to verified security professionals and authorized red team operators. Access requires NDA and proof of legitimate security research or penetration testing engagement.
Phoenix is a private framework for authorized penetration testing engagements only.
For access inquiries: Contact Us