For a post-exploitation toolkit, the strongest matches are bishopfox/sliver (Sliver is a command-and-control framework built specifically for adversary), guardicore/monkey (Infection Monkey is an adversary emulation platform that automates) and bc-security/empire (Empire is a mature post-exploitation C2 framework with multi-platform). rapid7/metasploit-framework and empireproject/empire round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
These open-source tools facilitate network traversal and privilege escalation during authorized security testing and lab exercises.
Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu
Sliver is a command-and-control framework built specifically for adversary emulation and red team operations, offering lateral movement, multi-protocol communication, credential harvesting, and cross-platform agents — exactly the post-exploitation toolkit this search targets.
Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv
Infection Monkey is an adversary emulation platform that automates lateral movement and credential harvesting, making it a direct fit for a post-exploitation framework in a penetration testing lab.
Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and manages agents written in PowerShell, Python, C#, Go, and C across Windows, Linux, and macOS, using encrypted communication channels over HTTP, HTTPS, and SMB. The framework executes over 400 built-in modules for reconnaissance, privilege escalation, credential theft, and lateral movement, and provides a modular engine for authoring custom attack modules. What sets Empire apart is its multi-language agent deployment system, which allows operators to choose implants that suit each
Empire is a mature post-exploitation C2 framework with multi-platform agents, encrypted communication, and hundreds of built-in modules covering lateral movement, credential harvesting, and session management — exactly the kind of tool this lateral-movement lab search is after.
The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to
Metasploit is a full-featured penetration testing framework that natively includes post-exploitation modules for lateral movement (e.g., psexec, wmi), integrated C2 through meterpreter sessions, credential harvesting, and cross-platform agents, making it the definitive tool for this use case.
Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It serves as a centralized platform for coordinating remote agent communication and automating the delivery of security testing payloads to target systems. The project provides a suite of modules for host reconnaissance, lateral movement, and credential harvesting across corporate environments. It functions as a remote administration tool to maintain persistence and execute commands on compromised hosts. The framework incorporates capabilities for agent orchestration and the executio
Empire is a classic post-exploitation framework with built-in C2 infrastructure, modular modules for lateral movement and credential harvesting, and agent orchestration, making it exactly the kind of tool this search is after.
Stitch is a command and control framework and post-exploitation toolkit designed for managing multiple remote systems from a central server. It functions as a remote administration tool and payload builder, enabling the execution of commands and the deployment of agents across different operating systems. The project features a cross-platform builder for generating custom executable agents with configurable network bindings and boot behaviors. It utilizes encrypted communication channels to secure traffic between the controller and remote clients, and it supports the execution of dynamic scri
Stitch is a C2 and post‑exploitation framework with cross‑platform agents and payload building, fitting the search for a lab tool, though its lateral movement capabilities are not explicitly highlighted.
This project is a post-exploitation framework and command and control platform designed for security research and penetration testing. It functions as a remote access tool consisting of a central command server and encrypted executable payloads that establish reverse shell connections. The system utilizes a web-based dashboard for multi-client administration, allowing for remote host monitoring and direct shell access through an in-browser terminal. It generates cross-platform, encrypted binaries that employ a multi-stage delivery chain and a key exchange mechanism to secure communications.
BYOB is a post-exploitation framework with a C2 server and encrypted payloads for remote host administration, making it the right category for lateral movement work, though its documentation does not explicitly highlight lateral movement techniques or credential harvesting.
Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a
Nishang is a PowerShell-based post-exploitation framework for Windows targets, offering modules for command-and-control, payload generation, and remote target management—it fits the post-exploitation category but is focused on Windows, so cross-platform agent support is absent.
Viper is a command and control infrastructure manager and post-exploitation framework designed for adversary attack simulation and security assessment. It functions as an orchestrator for penetration testing, combining a system for managing compromised hosts across multiple operating systems with tools for security workflow automation. The platform is distinguished by its use of large language model agents to coordinate red team tasks, automate data processing, and provide intelligent decision support. It includes a network pivot visualizer that uses directional graphs to map relationships an
Viper is a post-exploitation framework and C2 infrastructure manager with modular architecture and lateral movement visualization, fitting the search for a tool designed for lateral movement in network penetration testing.
CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize
CrackMapExec is a multi-protocol penetration testing framework that specifically supports lateral movement path discovery and credential harvesting within Active Directory environments, matching the core post-exploitation intent even though it does not feature built-in C2 or session/beacon management.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| bishopfox/sliver | 10.7K | Go | gpl-3.0 | |
| guardicore/monkey | 7K | Python | GPL-3.0 | |
| bc-security/empire | 5K | PowerShell | bsd-3-clause | |
| rapid7/metasploit-framework | 38.4K | Ruby | NOASSERTION | |
| empireproject/empire | 7.8K | PowerShell | bsd-3-clause | |
| nathanlopez/stitch | 3.5K | Python | other | |
| malwaredllc/byob | 9.5K | Python | GPL-3.0 | |
| samratashok/nishang | 10K | PowerShell | NOASSERTION | |
| funnywolf/viper | 5K | — | — | |
| byt3bl33d3r/crackmapexec | 9.1K | Python | BSD-2-Clause |