What problem does it solve?
This Skill eliminates the risk of accidental state modification when reviewing Mythic C2 operation data, allowing security analysts and red team operators to safely examine collected evidence like callbacks, task history, credentials, and files without executing commands or disrupting active operations.
Core Features & Use Cases
- Comprehensive Read-Only Data Access: Query all core Mythic data types including callbacks, task output, credentials, files, artifacts, keylogs, screenshots, process listings, file browser entries, and Windows token captures.
- Flexible Search and Filtering: Use cross-type search to find data across all categories, or filter results by callback ID, host, path, or active status to narrow down relevant information.
- Use Case: During a post-operation review, use this Skill to pull all credentials collected during a red team engagement, cross-reference them with associated task output, and export the data for reporting without risking accidental command execution on live agent callbacks.
Quick Start
Use the mythic-c2-readonly skill to retrieve a list of all active callbacks in the current Mythic operation, including their host, associated user, and last check-in timestamp.