awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
screetsec avatar

screetsec/TheFatRat

0
View on GitHub↗
11,038 stars·2,513 forks·C·gpl-3.0·39 views

TheFatRat

TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of payloads for penetration testing. It functions as a comprehensive toolkit that streamlines the exploitation lifecycle, enabling users to generate malicious executables, manage network listeners, and execute post-exploitation tasks through a unified command-line interface.

The framework distinguishes itself by integrating various third-party exploitation utilities into a single, orchestrated workflow. It provides specialized capabilities for embedding code into legitimate binaries and modifying file metadata to test system resilience against signature-based detection. Additionally, the tool supports physical security assessments by generating autorun configurations for removable media to evaluate automated execution behaviors on target systems.

Beyond core payload generation, the platform includes utilities for environment dependency validation to ensure all necessary components are configured correctly before testing begins. It also automates post-compromise actions, such as information gathering and credential extraction, to facilitate efficient security audits.

Features

  • Evasive Payload Generators - Builds and disguises malicious executables and scripts for multiple operating systems.
  • Penetration Testing Suites - Provides a comprehensive suite for automating security exploitation workflows, payload generation, and post-exploitation task management.
  • Security Payload Generators - Automates the creation, obfuscation, and deployment of malicious payloads for security testing.
  • Exploitation Frameworks - Implements a framework for embedding malicious code into binaries and preparing physical media for automated execution during security assessments.
  • Payload Injectors - Inserts malicious code directly into existing legitimate applications, libraries, or documents.
  • Executable Obfuscation Techniques - Modifies executable files and scripts to bypass security software detection and signature-based filters.
  • Exploitation Workflow Managers - Orchestrates the configuration of listeners and the creation of payloads to simplify security testing tasks.
  • Executable Obfuscators - Modifies file signatures and binary structures to evade detection by antivirus software and security filters.
  • Post-Exploitation Tools - Executes automated scripts on compromised systems to gather information and extract credentials.
  • Binary Injection Techniques - Embeds malicious code into legitimate software packages and binaries to test system resilience.
  • Binary Injection Templates - Embeds malicious code into legitimate binaries by modifying file structures and injecting custom execution hooks.
  • Exploitation and Payloads - Massive tool for generating backdoors and post-exploitation.
  • Payload Generation - Generates malicious payloads.
  • Post Exploitation - Generates backdoors and facilitates post-exploitation attacks.
  • Post Exploitation Frameworks - Tool for generating backdoors and post-exploitation attacks.
  • Executable Obfuscation Utilities - Modifies executable file signatures and structures to evade detection by antivirus software.
  • Exploitation Tool Wrappers - Integrates various third-party exploitation utilities into a single, orchestrated workflow.
  • Backdoor Listener Managers - Establishes and manages network listeners to capture incoming connections from deployed backdoors.
  • Autorun Exploitation Tools - Creates autorun configuration files for removable storage devices to facilitate automatic execution.
  • Binary Signature Modifiers - Modifies file headers and padding to alter signatures for testing system resilience against detection.
  • Automated Payload Execution - Triggers the automatic execution of files from removable media to evaluate system security controls.
  • Security Listener Profiles - Provides automated management of network listeners to capture incoming connections from deployed backdoors.
  • Physical Media Assessment Tools - Generates autorun configurations for removable media to test automated execution behaviors.
  • Security - Uses modular command-line scripts to automate the configuration and execution of external security tools.

Star history

Star history chart for screetsec/thefatratStar history chart for screetsec/thefatrat

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with TheFatRat

These projects share indexed features with TheFatRat. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • trustedsec/social-engineer-toolkittrustedsec avatar

    trustedsec/social-engineer-toolkit

    14,984View on GitHub↗

    The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience. The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information. The system includes capabilities for security awareness training and br

    Python
    View on GitHub↗14,984
  • z4nzu/hackingtoolZ4nzu avatar

    Z4nzu/hackingtool

    77,515View on GitHub↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    Pythonallinonehackingtoolbesthackingtoolctf-tools
    View on GitHub↗77,515
  • bishopfox/sliverBishopFox avatar

    BishopFox/sliver

    10,707View on GitHub↗

    Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu

    Goadversarial-attacksadversary-simulationc2
    View on GitHub↗10,707
  • rapid7/metasploit-frameworkrapid7 avatar

    rapid7/metasploit-framework

    38,415View on GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    Rubyhacktoberfest
    View on GitHub↗38,415
Compare all 30 related projects→

Frequently asked questions

What does screetsec/thefatrat do?

TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of payloads for penetration testing. It functions as a comprehensive toolkit that streamlines the exploitation lifecycle, enabling users to generate malicious executables, manage network listeners, and execute post-exploitation tasks through a unified command-line interface.

What are the main features of screetsec/thefatrat?

The main features of screetsec/thefatrat are: Evasive Payload Generators, Penetration Testing Suites, Security Payload Generators, Exploitation Frameworks, Payload Injectors, Executable Obfuscation Techniques, Exploitation Workflow Managers, Executable Obfuscators.

Which projects share features with screetsec/thefatrat?

Projects with overlapping indexed features include: trustedsec/social-engineer-toolkit — The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate… z4nzu/hackingtool — This project is a comprehensive cybersecurity tool collection designed to support security research, penetration… bishopfox/sliver — Sliver is a command and control framework designed for adversary emulation and security assessment operations. It… rapid7/metasploit-framework — The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of… powershellmafia/powersploit — PowerSploit is a collection of PowerShell modules designed for security assessment, penetration testing, and red team… samratashok/nishang — Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows…