awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
k8gege avatar

k8gege/Ladon

0
View on GitHub↗
5,297 stele·885 fork-uri·C#·MIT·14 vizualizărik8gege.org/Ladon↗

Ladon

Ladon este un scanner de penetrare a rețelei interne și un instrument de evaluare a vulnerabilităților conceput pentru a identifica defectele de securitate cu risc ridicat și activele din segmentele de rețea. Operează ca un scanner de securitate fileless, executându-și motorul și modulele direct în memorie pentru a evita lăsarea unei amprente pe disc pe sistemele țintă.

Proiectul se distinge prin integrarea sa ca plugin pentru beacon-uri de comandă, specific în cadrul framework-ului Cobalt Strike. Acest lucru permite descoperirea rețelei și detectarea vulnerabilităților rezidente în memorie. Suportă, de asemenea, operațiuni stealth prin obfuscarea payload-urilor și a scripturilor, precum și tehnici de evitare a detectării de către sistemele de endpoint detection and response (EDR).

Instrumentul oferă o suită cuprinzătoare de capabilități pentru post-exploatare, inclusiv auditarea credențialelor, extracția și executarea atacurilor Kerberos pentru penetrarea domeniului. Gestionează descoperirea activelor prin scanare multi-protocol și fingerprinting-ul serviciilor pentru a identifica sistemele de operare și tehnologiile web. În plus, suportă automatizarea mișcării laterale, escaladarea privilegiilor și implementarea payload-urilor de execuție de cod la distanță.

Framework-ul este extensibil printr-o arhitectură de plugin-uri care permite încărcarea dinamică a ansamblurilor sau scripturilor externe pentru a adăuga module de scanare personalizate și dovezi de concept.

Features

  • Command and Control Plugin Integrations - Provides a specialized plugin for Cobalt Strike beacons to enable memory-resident network discovery and vulnerability detection.
  • Command Beacon Integrations - Runs network discovery and vulnerability detection as a memory-resident plugin within a command beacon framework.
  • Credential and Account Auditing - Tests for weak passwords across network services and extracts stored credentials from compromised hosts.
  • Fileless Execution - Loads execution modules directly into memory to avoid leaving forensic artifacts on the physical disk.
  • Lateral Movement - Provides capabilities to pivot between internal network systems using compromised credentials and remote execution.
  • Active Vulnerability Scanning - Performs intrusive network probing to identify high-severity security flaws in middleware and hardware.
  • Internal Network Penetration Testers - Scans internal network segments to discover live hosts, open services, and critical security vulnerabilities.
  • Service Fingerprinting - Identifies running software and operating systems by analyzing network response banners and headers.
  • Network Asset Discovery - Maps target environments by identifying hardware, middleware, and OS versions across multiple protocols.
  • Network Asset Scanning - Identifies active hosts and open services using multiple protocols to bypass firewall restrictions.
  • C2 Beacon Plugins - Acts as an extension for Cobalt Strike beacons to enable memory-loaded network scanning and vulnerability detection.
  • Multi-Protocol Network Discovery - Identifies active hosts and services using diverse network protocols to bypass firewall restrictions.
  • Operating System Detection - Analyzes network responses to determine the target operating system and version.
  • Memory-Loaded Scanners - Executes scanning engines and modules in memory to avoid leaving disk footprints on target systems.
  • C2 Framework Plugins - Integrates directly as a memory-resident plugin for command beacons within the Cobalt Strike framework.
  • Credential Extraction - Implements techniques for retrieving stored passwords and authentication tokens from the local system.
  • Privilege Escalation Techniques - Elevates process permissions to system level using a variety of exploit techniques.
  • In-Memory Payload Execution - Executes scanning engines and modules directly in volatile memory to avoid leaving disk-based footprints.
  • Network Vulnerability Scanning - Discovers network assets and identifies critical security weaknesses across internal network infrastructure.
  • Post-Exploitation Frameworks - Provides a script-based framework for auditing credentials and escalating privileges on Windows systems.
  • Windows Privilege Escalations - Escalates permissions from standard user to administrator using Windows-specific exploits and bypass techniques.
  • Vulnerability Assessment Tools - Detects middleware flaws and executes exploits to achieve remote code execution.
  • Service Fingerprinting - Detects specific software versions and hardware devices to determine the target technology stack.
  • In-Memory Loading - Executes scanning engines and payloads directly from memory to avoid leaving a disk footprint.
  • Proxy-Aware Routing - Directs network scanning traffic through intermediate proxies to enable pivoting and lateral movement.
  • Script Obfuscation - Applies encoding and binary conversion to scripts to hide logic and bypass security software.
  • Default Credential Auditing - Actively verifies network interfaces against databases of weak or default credentials.
  • Domain Penetration - Executes Kerberos attacks and privilege escalation to compromise directory environments.
  • Exploit Payload Deployments - Triggers specific vulnerability proofs of concept to achieve remote code execution or gain initial shells.
  • Exploit Payload Generators - Creates customized payloads to extend scanning capabilities and automate the process of obtaining remote shells.
  • Automated Kerberos Attacks - Automates Kerberos attacks including ticket requests and the creation of forged tickets.
  • Payload Obfuscators - Transforms executables and scripts into different formats to evade antivirus and EDR detection.
  • Reflective Memory Executions - Loads and executes binaries entirely in memory via reflective techniques to evade disk-based detection.
  • Remote Command Execution Tools - Runs commands on target systems via remote protocols in both interactive and non-interactive modes.
  • Remote System Exploitation - Deploys shells or executes commands on target systems to gain full system control.
  • Reverse Shells - Establishes outbound network connections from targets to listeners to provide remote command-line access.
  • EDR Evasion - Simulates human-like access patterns to circumvent endpoint detection and response security controls.
  • Credential Brute-Forcing - Provides an automated engine for testing usernames and passwords against network protocols to evaluate security.
  • Extensible Plugin Architectures - Loads external logic through assemblies or scripts to add custom proofs of concept and scanning modules.
  • Plugin-Based Architectures - Implements a plugin-based architecture that allows the dynamic loading of external assemblies and scripts at runtime.
  • Network Scanning - Multi-threaded, plugin-based network scanning and exploitation suite.
  • Offensive Security Tools - Large-scale network scanner for internal penetration testing.
  • Post Exploitation Frameworks - Large-scale network scanning and exploitation framework.

Istoric stele

Graficul istoricului de stele pentru k8gege/ladonGraficul istoricului de stele pentru k8gege/ladon

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Alternative open-source pentru Ladon

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu Ladon.
  • k8gege/k8toolsAvatar k8gege

    k8gege/K8tools

    6,167Vezi pe GitHub↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    PowerShell0daybrute-forcebypass
    Vezi pe GitHub↗6,167
  • samsar4/ethical-hacking-labsAvatar Samsar4

    Samsar4/Ethical-Hacking-Labs

    3,397Vezi pe GitHub↗

    Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning penetration testing, network analysis, and offensive security techniques. It provides a structured environment for practicing the full attack lifecycle, from initial reconnaissance and scanning to exploitation and post-compromise analysis. The project provides instructional materials and guided exercises that cover specific technical domains, including open source intelligence research and network security courseware. It includes a practical workbook for identifying system vulnerabili

    ethical-hacking-labshackinglinux
    Vezi pe GitHub↗3,397
  • hackerschoice/thc-tips-tricks-hacks-cheat-sheetAvatar hackerschoice

    hackerschoice/thc-tips-tricks-hacks-cheat-sheet

    3,853Vezi pe GitHub↗

    This project is a comprehensive command-line reference and toolkit designed for Linux system administration and network security assessment. It provides a collection of technical snippets and operational guides focused on managing remote environments, orchestrating shell sessions, and executing administrative tasks through native terminal utilities. The repository distinguishes itself by offering specialized techniques for stealthy operations and infrastructure manipulation. It covers methods for establishing encrypted tunnels to bypass firewalls, obfuscating process identities and command hi

    Shell
    Vezi pe GitHub↗3,853
  • samratashok/nishangAvatar samratashok

    samratashok/nishang

    9,951Vezi pe GitHub↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    Vezi pe GitHub↗9,951
Vezi toate cele 30 alternative pentru Ladon→

Întrebări frecvente

Ce face k8gege/ladon?

Ladon este un scanner de penetrare a rețelei interne și un instrument de evaluare a vulnerabilităților conceput pentru a identifica defectele de securitate cu risc ridicat și activele din segmentele de rețea. Operează ca un scanner de securitate fileless, executându-și motorul și modulele direct în memorie pentru a evita lăsarea unei amprente pe disc pe sistemele țintă.

Care sunt principalele funcționalități ale k8gege/ladon?

Principalele funcționalități ale k8gege/ladon sunt: Command and Control Plugin Integrations, Command Beacon Integrations, Credential and Account Auditing, Fileless Execution, Lateral Movement, Active Vulnerability Scanning, Internal Network Penetration Testers, Service Fingerprinting.

Care sunt câteva alternative open-source pentru k8gege/ladon?

Alternativele open-source pentru k8gege/ladon includ: k8gege/k8tools — K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port… samsar4/ethical-hacking-labs — Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning… hackerschoice/thc-tips-tricks-hacks-cheat-sheet — This project is a comprehensive command-line reference and toolkit designed for Linux system administration and… samratashok/nishang — Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows… joaomatosf/jexboss — jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit… ridter/intranet_penetration_tips — This project is a technical guide and reference for internal network penetration testing. It serves as a collection of…