Abyssos v2.1F
Abyssos v2.1F: from C2 tasking to endpoint evidence
One 64-bit Windows modular RAT sample, exercised through a fixed 25-scenario research matrix.
Proofmetry Research
Proofmetry research distinguishes analysis findings from execution evidence and current product support. A mapped handler is not an observed effect, and a research scenario is not automatically an available behavior test.
Publication library
Abyssos v2.1F
One 64-bit Windows modular RAT sample, exercised through a fixed 25-scenario research matrix.
C2Looper
One GitHub-C2 Windows DLL variant, with eight command handlers mapped and seven handler paths observed.
Evidence vocabulary
Research claims use the highest level actually supported, not the highest level available in the model.
A behavior or handler was identified through analysis.
Execution entered the intended code path.
A meaningful intermediate or returned result was observed.
The workflow reached a defined completion or stop condition.
The intended native endpoint or network effect was corroborated.
Guided evaluation
We confirm current variant and behavior-test fit before a customer-controlled run.
Get a demo