awesome-repositories.comCatégoriesBlog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to bats3c/shad0w

Open-source alternatives to Shad0w

30 open-source projects similar to bats3c/shad0w, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Shad0w alternative.

  • byt3bl33d3r/silenttrinityAvatar de byt3bl33d3r

    byt3bl33d3r/SILENTTRINITY

    2,340Voir sur GitHub↗

    An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR

    Boo
    Voir sur GitHub↗2,340
  • bishopfox/sliverAvatar de BishopFox

    BishopFox/sliver

    10,707Voir sur GitHub↗

    Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu

    Goadversarial-attacksadversary-simulationc2
    Voir sur GitHub↗10,707
  • ne0nd0g/merlinAvatar de Ne0nd0g

    Ne0nd0g/merlin

    5,555Voir sur GitHub↗

    Merlin is a cross-platform command and control framework and remote access tool. It provides a server and agent system for post-exploitation coordination, utilizing an HTTP/2 framework for secure communication and the execution of commands across multiple operating systems. The project features an in-memory code execution engine that runs assemblies and shellcode directly within a process to avoid writing files to disk. It implements a decentralized communication architecture through a peer-to-peer network, allowing agents to exchange data via direct bind or reverse connections. To evade det

    Go
    Voir sur GitHub↗5,555
  • n1nj4sec/pupyAvatar de n1nj4sec

    n1nj4sec/pupy

    8,942Voir sur GitHub↗

    Pupy is a command and control framework and post-exploitation suite used for remote administration and system management. It functions as a cross-platform tool for deploying payloads and controlling multiple remote agents through encrypted communication channels. The framework features a multi-platform payload generator that creates custom executable files using configurable network launchers. It employs a network traffic obfuscator that stacks encryption and obfuscation protocols to hide communication from observation. The system provides capabilities for in-memory code execution, remote pr

    Pythonandroidbackdoorlinux
    Voir sur GitHub↗8,942

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Find more with AI search
  • bc-security/empireAvatar de BC-SECURITY

    BC-SECURITY/Empire

    5,045Voir sur GitHub↗

    Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and manages agents written in PowerShell, Python, C#, Go, and C across Windows, Linux, and macOS, using encrypted communication channels over HTTP, HTTPS, and SMB. The framework executes over 400 built-in modules for reconnaissance, privilege escalation, credential theft, and lateral movement, and provides a modular engine for authoring custom attack modules. What sets Empire apart is its multi-language agent deployment system, which allows operators to choose implants that suit each

    PowerShellc2empirehacktoberfest
    Voir sur GitHub↗5,045
  • zerosum0x0/koadicZ

    zerosum0x0/koadic

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • nettitude/poshc2Avatar de nettitude

    nettitude/PoshC2

    2,112Voir sur GitHub↗

    PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement.

    PowerShell
    Voir sur GitHub↗2,112
  • nathanlopez/stitchAvatar de nathanlopez

    nathanlopez/Stitch

    3,532Voir sur GitHub↗

    Stitch is a command and control framework and post-exploitation toolkit designed for managing multiple remote systems from a central server. It functions as a remote administration tool and payload builder, enabling the execution of commands and the deployment of agents across different operating systems. The project features a cross-platform builder for generating custom executable agents with configurable network bindings and boot behaviors. It utilizes encrypted communication channels to secure traffic between the controller and remote clients, and it supports the execution of dynamic scri

    Pythoncross-platformkeyloggerlinux
    Voir sur GitHub↗3,532
  • zer0yu/awesome-cobaltstrikeAvatar de zer0yu

    zer0yu/Awesome-CobaltStrike

    4,419Voir sur GitHub↗

    This project is a curated collection of tools, scripts, and technical guides designed to enhance offensive security operations using Cobalt Strike. It serves as a resource hub for managing command and control infrastructure and deploying security engagements. The collection includes toolkits for evading endpoint detection and response systems, alongside libraries for automating red team tasks such as reconnaissance and host enumeration. It provides resources for developing post-exploitation frameworks, specifically focusing on the creation of reflective libraries and memory-resident code. Th

    Voir sur GitHub↗4,419
  • samratashok/nishangAvatar de samratashok

    samratashok/nishang

    9,951Voir sur GitHub↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    Voir sur GitHub↗9,951
  • empireproject/empireAvatar de EmpireProject

    EmpireProject/Empire

    7,813Voir sur GitHub↗

    Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It serves as a centralized platform for coordinating remote agent communication and automating the delivery of security testing payloads to target systems. The project provides a suite of modules for host reconnaissance, lateral movement, and credential harvesting across corporate environments. It functions as a remote administration tool to maintain persistence and execute commands on compromised hosts. The framework incorporates capabilities for agent orchestration and the executio

    PowerShell
    Voir sur GitHub↗7,813
  • sharpc2/sharpc2S

    SharpC2/SharpC2

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • chvancooten/nimplantAvatar de chvancooten

    chvancooten/NimPlant

    951Voir sur GitHub↗

    NimPlant - A light first-stage C2 implant written in Nim|Rust and Python

    Rust
    Voir sur GitHub↗951
  • nyan-x-cat/asyncrat-c-sharpAvatar de NYAN-x-CAT

    NYAN-x-CAT/AsyncRAT-C-Sharp

    2,837Voir sur GitHub↗
    C#adminasynchronousbackdoor
    Voir sur GitHub↗2,837
  • rapid7/metasploit-frameworkAvatar de rapid7

    rapid7/metasploit-framework

    38,415Voir sur GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    Rubyhacktoberfest
    Voir sur GitHub↗38,415
  • iagox86/dnscat2Avatar de iagox86

    iagox86/dnscat2

    3,839Voir sur GitHub↗

    dnscat2 is a DNS tunneling tool and covert command and control server that encapsulates encrypted traffic within DNS queries and responses. It functions as an encrypted DNS proxy designed to bypass network firewalls and establish communication paths when standard outbound ports are blocked. The project enables the creation of covert network channels by acting as an authoritative nameserver. It supports remote command execution through interactive shells and provides a mechanism for tunneling TCP network traffic to reach restricted remote hosts. The system includes capabilities for multiplexe

    PHP
    Voir sur GitHub↗3,839
  • havocframework/havocAvatar de HavocFramework

    HavocFramework/Havoc

    8,182Voir sur GitHub↗

    Havoc is a post-exploitation framework used for red team operations. It provides a centralized command and control system for managing remote agents through persistent network connections and customizable communication profiles. The framework focuses on security evasion and stealth, utilizing indirect syscall execution, return address spoofing, and hardware-breakpoint patching to bypass endpoint detection and response tools. It includes a payload generation workflow to create executable shellcode or DLLs for initial remote access. The system covers a broad range of operational capabilities,

    Go
    Voir sur GitHub↗8,182
  • its-a-feature/mythicAvatar de its-a-feature

    its-a-feature/Mythic

    4,571Voir sur GitHub↗

    Mythic is a red teaming framework and command and control server designed for managing post-exploitation activities. It provides a centralized system for issuing tasks and receiving telemetry from agents deployed across diverse target platforms and operating systems. The platform features a collaborative operator interface that allows multiple security researchers to coordinate operations and track target activity within a shared environment. It supports the deployment and updating of diverse agent payloads through a multi-platform payload manager. The framework utilizes a plugin-based archi

    JavaScript
    Voir sur GitHub↗4,571
  • cobbr/covenantAvatar de cobbr

    cobbr/Covenant

    4,699Voir sur GitHub↗

    Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It serves as a collaborative platform for coordinating security assessments, managing remote implants, and executing tasks on compromised systems through a centralized server. The project is distinguished by its dynamic payload generator, which compiles and obfuscates executable binaries and scripts on the fly to bypass detection. It further separates itself through a collaborative environment that allows multiple authenticated operators to share a synchronized state, track operat

    C#
    Voir sur GitHub↗4,699
  • fsecurelabs/c3Avatar de FSecureLABS

    FSecureLABS/C3

    1,774Voir sur GitHub↗

    C3 (Custom Command and Control) is a tool that allows Red Teams to rapidly develop and utilise esoteric command and control channels (C2). It's a framework that extends other red team tooling, such as the commercial Cobalt Strike (CS) product via ExternalC2, which is supported at release. It…

    C++
    Voir sur GitHub↗1,774
  • powershellempire/empireAvatar de PowerShellEmpire

    PowerShellEmpire/Empire

    7,843Voir sur GitHub↗

    Empire is a post-exploitation framework and command and control server designed to manage remote access agents. It provides a centralized system for coordinating these agents and executing specialized scripts across target systems. The project functions as a security evasion tool by adapting network communication patterns to bypass firewalls and monitoring tools. It utilizes a multi-language agent runtime and a modular plugin architecture to execute payloads across different operating systems. The framework covers a broad range of operational capabilities, including remote agent orchestratio

    PowerShell
    Voir sur GitHub↗7,843
  • ridter/intranet_penetration_tipsAvatar de Ridter

    Ridter/Intranet_Penetration_Tips

    4,606Voir sur GitHub↗

    This project is a technical guide and reference for internal network penetration testing. It serves as a collection of procedures for exploiting and navigating private corporate networks during security assessments. The repository provides specialized manuals and cheat sheets focused on active directory attacks, lateral movement, and privilege escalation. It includes a post-exploitation playbook for maintaining system persistence and clearing forensic traces. The documentation covers a broad range of security capabilities, including initial access, network pivoting and tunneling, and interna

    Voir sur GitHub↗4,606
  • facebookincubator/weaselAvatar de facebookincubator

    facebookincubator/WEASEL

    732Voir sur GitHub↗

    WEASEL is a small in-memory implant using Python 3 with no dependencies. The beacon client sends a small amount of identifying information about its host to a DNS zone you control. WEASEL server can task clients to execute pre-baked or arbitrary commands.

    Python
    Voir sur GitHub↗732
  • cedowens/macshellswiftAvatar de cedowens

    cedowens/MacShellSwift

    125Voir sur GitHub↗

    Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedric Owens

    Swift
    Voir sur GitHub↗125
  • beefproject/beefAvatar de beefproject

    beefproject/beef

    10,728Voir sur GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    JavaScript
    Voir sur GitHub↗10,728
  • engindemirbilek/northstarc2Avatar de EnginDemirbilek

    EnginDemirbilek/NorthStarC2

    269Voir sur GitHub↗

    Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC #infosec #offensivesecurity #Trojan

    PHP
    Voir sur GitHub↗269
  • enkomio/alanframeworkE

    enkomio/AlanFramework

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • epinna/weevely3Avatar de epinna

    epinna/weevely3

    3,526Voir sur GitHub↗

    Weaponized web shell

    Python
    Voir sur GitHub↗3,526
  • emptymonkey/revshE

    emptymonkey/revsh

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • elevenpaths/ibombshellAvatar de ElevenPaths

    ElevenPaths/ibombshell

    323Voir sur GitHub↗

    Tool to deploy a post-exploitation prompt at any time

    Python
    Voir sur GitHub↗323