37 रिपॉजिटरी
Frameworks and infrastructure for managing remote access and communication.
Explore 37 awesome GitHub repositories matching part of an awesome list · Command and Control. Refine with filters or upvote what's useful.
Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu
Implant framework for red team operations.
This project is a post-exploitation framework and command and control platform designed for security research and penetration testing. It functions as a remote access tool consisting of a central command server and encrypted executable payloads that establish reverse shell connections. The system utilizes a web-based dashboard for multi-client administration, allowing for remote host monitoring and direct shell access through an in-browser terminal. It generates cross-platform, encrypted binaries that employ a multi-stage delivery chain and a key exchange mechanism to secure communications.
Framework for building custom C2 implants.
Pupy is a command and control framework and post-exploitation suite used for remote administration and system management. It functions as a cross-platform tool for deploying payloads and controlling multiple remote agents through encrypted communication channels. The framework features a multi-platform payload generator that creates custom executable files using configurable network launchers. It employs a network traffic obfuscator that stacks encryption and obfuscation protocols to hide communication from observation. The system provides capabilities for in-memory code execution, remote pr
Cross-platform remote administration and post-exploitation framework.
Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It serves as a centralized platform for coordinating remote agent communication and automating the delivery of security testing payloads to target systems. The project provides a suite of modules for host reconnaissance, lateral movement, and credential harvesting across corporate environments. It functions as a remote administration tool to maintain persistence and execute commands on compromised hosts. The framework incorporates capabilities for agent orchestration and the executio
Post-exploitation and C2 framework.
Merlin एक क्रॉस-प्लेटफॉर्म कमांड एंड कंट्रोल फ्रेमवर्क और रिमोट एक्सेस टूल है। यह पोस्ट-एक्सप्लॉइटेशन समन्वय के लिए एक सर्वर और एजेंट सिस्टम प्रदान करता है, जो सुरक्षित संचार और कई ऑपरेटिंग सिस्टम पर कमांड निष्पादित करने के लिए HTTP/2 फ्रेमवर्क का उपयोग करता है। इस प्रोजेक्ट में एक इन-मेमोरी कोड निष्पादन इंजन है जो डिस्क पर फाइलें लिखे बिना सीधे प्रोसेस के भीतर असेंबली और शेलकोड चलाता है। यह पीयर-टू-पीयर नेटवर्क के माध्यम से एक विकेंद्रीकृत संचार आर्किटेक्चर लागू करता है, जिससे एजेंट डायरेक्ट बाइंड या रिवर्स कनेक्शन के माध्यम से डेटा का आदान-प्रदान कर सकते हैं। डिटेक्शन से बचने के लिए, फ्रेमवर्क में ट्रैफिक ऑब्फस्केशन टूल्स शामिल हैं जो TLS फिंगरप्रिंट को संशोधित करते हैं और संचार पैटर्न को छिपाने के लिए कॉन्फ़िगर करने योग्य पैकेट पैडिंग जोड़ते हैं। सुरक्षा को एन्क्रिप्टेड एजेंट संचार, सिमेट्रिक ट्रैफिक एन्क्रिप्शन और आइडेंटिटी वैलिडेशन के लिए एसिमेट्रिक क्रिप्टोग्राफिक हैंडशेक के माध्यम से मैनेज किया जाता है। सिस्टम कमांड लाइन इंटरफेस के माध्यम से मल्टी-यूज़र एक्सेस समन्वय का समर्थन करता है, जो रेड टीम इंफ्रास्ट्रक्चर के भीतर वितरित एजेंटों के प्रबंधन को सक्षम बनाता है।
HTTP/2-based cross-platform C2 framework.
Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and manages agents written in PowerShell, Python, C#, Go, and C across Windows, Linux, and macOS, using encrypted communication channels over HTTP, HTTPS, and SMB. The framework executes over 400 built-in modules for reconnaissance, privilege escalation, credential theft, and lateral movement, and provides a modular engine for authoring custom attack modules. What sets Empire apart is its multi-language agent deployment system, which allows operators to choose implants that suit each
Maintained version of Empire with AMSI bypass.
Covenant, रेड टीम ऑपरेशंस और एडवर्सरी सिमुलेशन के लिए डिज़ाइन किया गया एक .NET-आधारित कमांड एंड कंट्रोल फ्रेमवर्क है। यह सुरक्षा असेसमेंट के समन्वय, रिमोट इम्प्लांट्स को मैनेज करने, और एक सेंट्रलाइज्ड सर्वर के माध्यम से समझौता किए गए सिस्टम पर कार्यों को निष्पादित करने के लिए एक सहयोगी प्लेटफॉर्म के रूप में कार्य करता है। यह प्रोजेक्ट अपने डायनामिक पेलोड जनरेटर द्वारा प्रतिष्ठित है, जो डिटेक्शन को बायपास करने के लिए एग्जीक्यूटेबल बाइनरीज और स्क्रिप्ट्स को ऑन-द-फ्लाई कंपाइल और ऑबफस्केट (obfuscate) करता है। यह एक सहयोगी वातावरण के माध्यम से खुद को अलग करता है जो कई प्रमाणित ऑपरेटरों को एक सिंक्रोनाइज़्ड स्टेट साझा करने, परिचालन संकेतकों को ट्रैक करने, और एक ही इंटरफेस के भीतर संयुक्त जुड़ाव को मैनेज करने की अनुमति देता है। यह फ्रेमवर्क ट्रैफिक ऑबफस्केशन के लिए व्यापक क्षमताएं प्रदान करता है, जिसमें कस्टम नेटवर्क प्रोफाइल्स, डेटा ट्रांसफॉर्मेशन पाइपलाइन्स, और संचार को मास्क करने के लिए ब्रिज-आधारित प्रोटोकॉल ट्रांसलेशन का उपयोग शामिल है। यह रिमोट फाइल रिट्रीवल, सेंट्रलाइज्ड क्रेडेंशियल कलेक्शन, और प्लग-इन एक्सटेंशन मॉडल का उपयोग करके कस्टम रिमोट टास्क मॉड्यूल्स के विकास जैसी पोस्ट-एक्सप्लॉइटेशन आवश्यकताओं को भी कवर करता है। यह सिस्टम फॉरवर्ड सीक्रेसी सुनिश्चित करने के लिए SSL सर्टिफिकेट पिनिंग और एन्क्रिप्टेड की-एक्सचेंज का उपयोग करके सर्वर और एजेंट्स के बीच संचार को सुरक्षित करता है।
.NET-based command and control framework.
यह प्रोजेक्ट आंतरिक नेटवर्क पेनेट्रेशन टेस्टिंग के लिए एक तकनीकी गाइड और संदर्भ है। यह सुरक्षा आकलन के दौरान निजी कॉर्पोरेट नेटवर्क का फायदा उठाने और नेविगेट करने के लिए प्रक्रियाओं का एक संग्रह है। रिपॉजिटरी एक्टिव डायरेक्टरी हमलों, लेटरल मूवमेंट और प्रिविलेज एस्केलेशन पर केंद्रित विशेष मैनुअल और चीट शीट्स प्रदान करती है। इसमें सिस्टम पर्सिस्टेंस बनाए रखने और फॉरेंसिक निशान मिटाने के लिए एक पोस्ट-एक्सप्लॉइटेशन प्लेबुक शामिल है। डॉक्यूमेंटेशन में प्रारंभिक एक्सेस, नेटवर्क पिवोटिंग और टनलिंग, और आंतरिक टोही (reconnaissance) सहित सुरक्षा क्षमताओं की एक विस्तृत श्रृंखला शामिल है। यह सुरक्षा डिटेक्शन से बचने और डोमेन हैश निकालने के लिए डायरेक्टरी सेवाओं से समझौता करने के तरीके भी बताता है।
Provides guidance on establishing communication channels between compromised hosts and a C2 controller.
Mythic is a red teaming framework and command and control server designed for managing post-exploitation activities. It provides a centralized system for issuing tasks and receiving telemetry from agents deployed across diverse target platforms and operating systems. The platform features a collaborative operator interface that allows multiple security researchers to coordinate operations and track target activity within a shared environment. It supports the deployment and updating of diverse agent payloads through a multi-platform payload manager. The framework utilizes a plugin-based archi
Multi-agent command and control framework.
This project is a curated collection of tools, scripts, and technical guides designed to enhance offensive security operations using Cobalt Strike. It serves as a resource hub for managing command and control infrastructure and deploying security engagements. The collection includes toolkits for evading endpoint detection and response systems, alongside libraries for automating red team tasks such as reconnaissance and host enumeration. It provides resources for developing post-exploitation frameworks, specifically focusing on the creation of reflective libraries and memory-resident code. Th
Serves as a comprehensive resource hub for deploying and managing Cobalt Strike command and control infrastructure.
dnscat2 is a DNS tunneling tool and covert command and control server that encapsulates encrypted traffic within DNS queries and responses. It functions as an encrypted DNS proxy designed to bypass network firewalls and establish communication paths when standard outbound ports are blocked. The project enables the creation of covert network channels by acting as an authoritative nameserver. It supports remote command execution through interactive shells and provides a mechanism for tunneling TCP network traffic to reach restricted remote hosts. The system includes capabilities for multiplexe
Establishes stealthy C2 tunnels using legitimate DNS traffic.
Stitch is a command and control framework and post-exploitation toolkit designed for managing multiple remote systems from a central server. It functions as a remote administration tool and payload builder, enabling the execution of commands and the deployment of agents across different operating systems. The project features a cross-platform builder for generating custom executable agents with configurable network bindings and boot behaviors. It utilizes encrypted communication channels to secure traffic between the controller and remote clients, and it supports the execution of dynamic scri
Implements a central server to manage remote agents and secure communication via encrypted channels.
Hoaxshell is a command and control system for Windows remote command execution. It provides a framework for generating and managing reverse shell payloads that utilize an HTTP beaconing protocol, where victim clients periodically poll a handler to receive and execute instructions. The project distinguishes itself through its ability to bypass PowerShell Constrained Language Mode using specialized payload generation. It supports encrypted command and control via TLS certificate injection and provides mechanisms for remote session recovery, allowing a handler to reestablish control over active
Generates and handles Windows reverse shell payloads over HTTP.
Open-source remote administration tool for Windows.
An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR
Python-based post-exploitation framework.
A post exploitation framework designed to operate covertly on heavily monitored environments
Covert post-exploitation framework.
PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement.
PowerShell-based command and control framework.
C3 (Custom Command and Control) is a tool that allows Red Teams to rapidly develop and utilise esoteric command and control channels (C2). It's a framework that extends other red team tooling, such as the commercial Cobalt Strike (CS) product via ExternalC2, which is supported at release. It…
Framework for prototyping custom C2 channels.
Search for potential frontable domains
Utility for identifying domains suitable for domain fronting techniques.
A tool for identifying misconfigured CloudFront domains
Tool for testing and identifying domain fronting capabilities on CloudFront.