One of the last major components of a C2 Framework is its pivoting modules, making it easier to access restricted network segments within the C2 Framework. If you have Administrative Access on a system, you may be able to open up an “SMB Beacon”, which can enable a machine to act as a proxy via the SMB protocol. This may allow machines in a restricted network segment to communicate with your C2 server.

*This diagram depicts multiple victims with an SMB pivot calling back to a C2 server.*
The diagram above shows how hosts within a restricted network segment call back to the C2 Server:
1. The Victims call back to an SMB named pipe on another Victim in a non-restricted network segment. 2. The Victim in the non-restricted network segment calls back to the C2 Server over a standard beacon. 3. The C2 Server then sends commands back to the Victim in the non-restricted network segment. 4. The Victim in the non-restricted network segment then forwards the C2 instructions to the hosts in the restricted segment