Screenshots
Overview
JustC2 supports capturing screenshots from compromised hosts. Screenshots are stored on the teamserver and viewable through the client’s Screenshots tab.
Capturing Screenshots
Issue a screenshot command through the agent console. The agent captures the current desktop state on the target machine and transmits the image back to the teamserver.
Screenshots Tab
The Screenshots tab provides a gallery view of all captured screenshots:
| Field | Description |
|---|---|
| Screen ID | Unique identifier |
| User | User context on the target |
| Computer | Target hostname |
| Date | When the screenshot was taken |
| Note | Operator-added annotation |
Viewing Screenshots
Click a screenshot entry to view the full-resolution image.
Adding Notes
Right-click a screenshot → Set Note to add annotations. Use notes to mark interesting findings, track which screenshots are relevant for reporting, or note what activity was captured.
Removing Screenshots
Right-click a screenshot → Remove to delete it from the server.
Use Cases
- Situational awareness — See what the user is currently doing
- Evidence collection — Capture proof of access for reporting
- Credential harvesting — Capture displayed passwords or sensitive information
- Activity monitoring — Periodic screenshots to track user behavior
Notes
- Screenshot capture requires appropriate permissions on the target (desktop access)
- On headless Linux servers, screenshot capture may fail or return a blank image
- Screenshots are transmitted through the C2 channel and may take multiple check-ins for high-resolution images
- Consider the OPSEC impact — screenshot capture may trigger security software