CoordOps C2 Framework Plugin: Integrated Command and Control for Authorized Operations
RTFMv2 is now CoordOps, and the command-and-control component previously developed under the RTFMv2 name is now the CoordOps.Server.C2Plugin.
The C2 Framework Plugin brings command-and-control workflows directly into CoordOps Server. It gives authorized red teams a first-party control plane for managing listeners, agents, tasking, results, staged files, and operational history without requiring a separate management interface disconnected from the rest of the engagement.
Integrated with CoordOps Server
The C2 Framework is implemented as a native CoordOps Server plugin. It uses the platform’s plugin lifecycle, role-based access controls, operator and administrator workspaces, versioned APIs, and audit facilities.
Operators can review registered agents, create and follow tasks, inspect returned results, manage staged files, and work with interactive sessions from the CoordOps Server interface. Administrative controls cover listener configuration, governance settings, task approval, registration-key rotation, and audit history.
Multiple transport options
The plugin supports HTTP and host-managed WebSocket agent communication, including authenticated interactive shell sessions. Configurable listener support also includes raw TCP, DNS, SMB named pipes, and ICMP for environments where those transports are appropriate and explicitly authorized.
- HTTP supports agent registration, check-in, task results, heartbeat requests, and staged-file delivery.
- WebSocket supports persistent agent communication and authenticated interactive shell sessions.
- Raw TCP supports reverse-shell connections presented as managed agents and shell tasks.
- DNS supports registration, check-in, and bounded result delivery through the compatible DNS transport.
- SMB uses Windows named pipes and is available on supported Windows hosts.
- ICMP uses the compatible Echo Request and Reply transport and requires an elevated Windows host.
Transport availability depends on the server platform, permissions, listener configuration, and engagement requirements. Administrators can configure and monitor listeners while operators work within the access and governance policies established for the deployment.
Governance, evidence, and accountability
A command-and-control channel is only one part of a red team operation. CoordOps connects agent activity with task state, returned output, staged artifacts, terminal history, governance decisions, and audit events so the team can reconstruct what occurred during an authorized engagement.
Role-based controls separate administrative operations from everyday operator workflows. Higher-risk actions can require approval, and lifecycle events are recorded to support review, reporting, and cleanup.
Part of the CoordOps red team platform
The C2 Framework Plugin reflects the broader direction behind the RTFMv2-to-CoordOps transition. CoordOps is not simply a collection of scanners or an AI-generated alert feed. It is a red team platform built to coordinate tools, operators, evidence, and reporting across the full engagement lifecycle.
The C2 Framework Plugin is intended exclusively for systems and environments where testing has been explicitly authorized. Listener deployment, agent execution, tasking, file handling, and cleanup should always follow the approved scope and rules of engagement.