awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
x0rz avatar

x0rz/EQGRP

0
View on GitHub↗
4,201 stars·2,079 forks·Perl·15 views

EQGRP

EQGRP is a remote access trojan framework and post-exploitation toolkit. It provides a centralized command and control infrastructure for deploying persistent implants and managing remote agents across diverse operating systems.

The project includes tools for digital forensic evasion, such as modifying system logs and filesystem timestamps to remove execution traces. It features a network interception system for capturing and reconstructing data streams by hooking into the system root, as well as exploits designed for kernel privilege escalation to elevate process permissions to administrative root.

The toolkit covers a broad range of capabilities, including remote code execution, shellcode packing for signature evasion, and the exfiltration and parsing of mobile device logs and telecommunications records. It also provides utilities for binding network ports and browsing decrypted archives.

Features

  • Remote Access Trojans - Implements a full remote access trojan framework for covert control of compromised systems.
  • Implant Lifecycle Management - Provides a centralized infrastructure for the operational control and tasking of remote security implants.
  • C2 Agent Lifecycle Management - Provides a centralized server to manage the operational state and command cycles of remote implants.
  • Command and Control Frameworks - Ships a centralized server architecture that orchestrates payload delivery and manages remote agent shells.
  • Kernel Privilege Escalation Exploits - Uses kernel vulnerabilities to elevate process permissions from a standard user to administrative root.
  • Post-Exploitation Toolkits - Provides a comprehensive toolkit for privilege escalation, forensic trace cleaning, and log exfiltration.
  • Kernel Privilege Escalations - Combines kernel exploits and service misconfigurations to elevate process privileges to root.
  • Remote Access Implants - Deploys persistent backdoors across multiple operating systems to maintain long-term remote access.
  • Anti-Forensics - Implements digital forensic evasion by modifying system logs and filesystem timestamps to remove traces of activity.
  • Mobile Forensics - Retrieves and exfiltrates log data from mobile devices for forensic examination.
  • Mobile Data Extraction Tools - Provides utilities for extracting and parsing telecommunications records and device logs from mobile hardware.
  • Network Traffic Analyzers - Captures and reconstructs network data streams by monitoring connections at the system root level.
  • Traffic Interception - Captures and reconstructs data streams by monitoring network connections at the system root level.
  • Traffic Interception Tools - Captures and reconstructs network traffic by hooking into the system root to monitor communications.
  • Evasive Shellcode Compression - Obscures and compresses payload code to bypass security scanners and fit within specific memory limits.
  • Kernel-Level Traffic Interceptors - Captures and reconstructs network packets by intercepting traffic at the kernel level.
  • Kernel-Level Hooking - Implements low-level kernel hooking to intercept and reconstruct network data streams at the system root.
  • Network Bind Interceptions - Intercepts system calls to bind network ports and redirect data streams to a proxy.
  • Timestamp Modification - Provides capabilities to manually update file access and modification timestamps to hide execution traces.
  • Anti-Forensic Metadata Manipulations - Modifies file timestamps and filesystem metadata to mislead forensic investigations and remove execution traces.
  • Anti-Forensic Trace Wiping - Erases system artifacts, logs, and caches to remove evidence of activity and evade security tools.
  • Shellcode - Includes shellcode packing and encryption to bypass signature-based security detection.
  • Forensic Artifact Removal - Alters system logs and filesystem timestamps to remove execution traces and evade forensic detection.
  • Payload Obfuscators - Compresses and obscures shellcode to bypass signature-based detection by antivirus and EDR software.
  • Remote Code Execution Tools - Includes tools to achieve and manage arbitrary code execution on remote target systems.
  • Anti-Forensic Utilities - Provides utilities for modifying logs and timestamps to remove execution traces and evade security analysis.
  • Bug Bounty Resources - Archive of decrypted security-related files and research.
  • Penetration Testing Toolkits - Decrypted content from the Equation Group auction files.

Star history

Star history chart for x0rz/eqgrpStar history chart for x0rz/eqgrp

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does x0rz/eqgrp do?

EQGRP is a remote access trojan framework and post-exploitation toolkit. It provides a centralized command and control infrastructure for deploying persistent implants and managing remote agents across diverse operating systems.

What are the main features of x0rz/eqgrp?

The main features of x0rz/eqgrp are: Remote Access Trojans, Implant Lifecycle Management, C2 Agent Lifecycle Management, Command and Control Frameworks, Kernel Privilege Escalation Exploits, Post-Exploitation Toolkits, Kernel Privilege Escalations, Remote Access Implants.

What are some open-source alternatives to x0rz/eqgrp?

Open-source alternatives to x0rz/eqgrp include: mantvydasb/redteaming-tactics-and-techniques — This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior.… cobbr/covenant — Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It… ridter/intranet_penetration_tips — This project is a technical guide and reference for internal network penetration testing. It serves as a collection of… trickster0/offensiverust — OffensiveRust is a red team toolkit and malware development kit written in Rust. It serves as an evasion framework and… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… hackerschoice/thc-tips-tricks-hacks-cheat-sheet — This project is a comprehensive command-line reference and toolkit designed for Linux system administration and…

Open-source alternatives to EQGRP

Similar open-source projects, ranked by how many features they share with EQGRP.
  • mantvydasb/redteaming-tactics-and-techniquesmantvydasb avatar

    mantvydasb/RedTeaming-Tactics-and-Techniques

    4,620View on GitHub↗

    This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior. It serves as a comprehensive collection of technical guides and tactics for executing red team operations. The repository provides detailed instructions for Active Directory exploitation, including Kerberos abuse and domain privilege escalation. It covers defense evasion through API unhooking and payload obfuscation, as well as Windows internals research involving the manipulation of kernel objects and system memory. The capability surface extends to network penetration testi

    PowerShelloffensive-securityoscppentesting
    View on GitHub↗4,620
  • cobbr/covenantcobbr avatar

    cobbr/Covenant

    4,699View on GitHub↗

    Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It serves as a collaborative platform for coordinating security assessments, managing remote implants, and executing tasks on compromised systems through a centralized server. The project is distinguished by its dynamic payload generator, which compiles and obfuscates executable binaries and scripts on the fly to bypass detection. It further separates itself through a collaborative environment that allows multiple authenticated operators to share a synchronized state, track operat

    C#
    View on GitHub↗4,699
  • ridter/intranet_penetration_tipsRidter avatar

    Ridter/Intranet_Penetration_Tips

    4,606View on GitHub↗

    This project is a technical guide and reference for internal network penetration testing. It serves as a collection of procedures for exploiting and navigating private corporate networks during security assessments. The repository provides specialized manuals and cheat sheets focused on active directory attacks, lateral movement, and privilege escalation. It includes a post-exploitation playbook for maintaining system persistence and clearing forensic traces. The documentation covers a broad range of security capabilities, including initial access, network pivoting and tunneling, and interna

    View on GitHub↗4,606
  • trickster0/offensiverusttrickster0 avatar

    trickster0/OffensiveRust

    2,984View on GitHub↗

    OffensiveRust is a red team toolkit and malware development kit written in Rust. It serves as an evasion framework and post-exploitation library, providing a collection of offensive security primitives and a Windows API wrapper for interacting with low-level system functions and undocumented APIs. The project focuses on bypassing security software through direct system calls, memory obfuscation, and stealthy payload execution. It implements techniques to defeat static binary analysis via compile-time string encryption and payload obfuscation, while avoiding detection using parent process ID s

    Rust
    View on GitHub↗2,984
See all 30 alternatives to EQGRP→