Overview

JustC2 supports capturing screenshots from compromised hosts. Screenshots are stored on the teamserver and viewable through the client’s Screenshots tab.

Capturing Screenshots

Issue a screenshot command through the agent console. The agent captures the current desktop state on the target machine and transmits the image back to the teamserver.

Screenshots Tab

The Screenshots tab provides a gallery view of all captured screenshots:

FieldDescription
Screen IDUnique identifier
UserUser context on the target
ComputerTarget hostname
DateWhen the screenshot was taken
NoteOperator-added annotation

Viewing Screenshots

Click a screenshot entry to view the full-resolution image.

Adding Notes

Right-click a screenshot → Set Note to add annotations. Use notes to mark interesting findings, track which screenshots are relevant for reporting, or note what activity was captured.

Removing Screenshots

Right-click a screenshot → Remove to delete it from the server.

Use Cases

  • Situational awareness — See what the user is currently doing
  • Evidence collection — Capture proof of access for reporting
  • Credential harvesting — Capture displayed passwords or sensitive information
  • Activity monitoring — Periodic screenshots to track user behavior

Notes

  • Screenshot capture requires appropriate permissions on the target (desktop access)
  • On headless Linux servers, screenshot capture may fail or return a blank image
  • Screenshots are transmitted through the C2 channel and may take multiple check-ins for high-resolution images
  • Consider the OPSEC impact — screenshot capture may trigger security software