awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
guardicore avatar

guardicore/monkey

0
View on GitHub↗
7,014 星标·820 分支·Python·GPL-3.0·9 次浏览www.guardicore.com/infectionmonkey↗

Monkey

Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials.

The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antivirus detection and employs relay-based traffic tunneling to bypass network firewalls.

The system includes a centralized command server for tracking simulation progress and visualizing the spread of adversarial agents across a network. Its capabilities cover network vulnerability assessment, security control validation, and the generation of security impact reports. To protect critical infrastructure, the platform incorporates target IP filtering to block interactions with specific subnets.

The project provides automated platform deployment scripts for operating system installation and supports binary packaging into container formats.

Features

  • Adversary Emulation Frameworks - Functions as a platform for simulating realistic cyber attacks to evaluate network security controls.
  • Lateral Movement - Simulates lateral movement across networks using stolen credentials and exploits to test security posture.
  • Vulnerability Exploitation Frameworks - Uses a library of plugins to propagate through known network vulnerabilities and test security perimeters.
  • Centralized Security Agents - Uses a central command server to manage agents and visualize the spread of the adversary.
  • Attack Simulations - Mimics attacker behaviors including ransomware encryption and cryptojacking to identify visibility gaps and data leakage risks.
  • Security Testing Tools - Evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials.
  • Vulnerability Assessment Frameworks - Identifies exploitable security gaps by automatically attempting to propagate through the network.
  • Adversary Spread Visualizations - Ships a centralized command server for tracking simulation progress and reporting the spread of adversarial agents across a network.
  • Adversarial Payload Execution - Runs malicious payloads on infected machines to test the depth and impact of a successful compromise.
  • Traffic Tunneling - Routes agent communications through intermediate relays to bypass network firewalls.
  • Attack Path Visualizations - Tracks simulation progress and reports agent activities through a command server to provide empirical security data.
  • Cryptojacking Simulations - Deploys mining payloads to simulate the presence and resource consumption of cryptocurrency malware.
  • Credential Extraction Utilities - Provides specialized collectors to extract browser credentials and SSH keys from targeted systems.
  • Ransomware Impact Analysis - Simulates ransomware deployment to identify which files and systems are vulnerable to encryption.
  • Security Software Evasion - Randomizes binary hashes and masquerades files to bypass antivirus and endpoint detection systems.
  • Security Control Validations - Tests if antivirus and detection systems can identify and block malicious payloads and unauthorized agent activity.
  • Security Report Generation - Produces detailed reports on ransomware impact and network security posture based on simulation data.
  • Binary Signature Modifiers - Modifies binary signatures and file metadata to evade antivirus and security monitoring tools.
  • Plugin Execution Engines - Employs a modular system of interchangeable plugins to execute attack simulations and vulnerability tests.
  • Threat Simulation Tools - Breach and attack simulation tool for cloud environment resiliency.
  • Malware And Defense Emulation - Tool for testing network segmentation and lateral movement.
  • Security And Forensics - Tool for testing datacenter resiliency against internal breaches.
  • Web Security Testing - Tool for semi-automated network penetration testing.

Star 历史

guardicore/monkey 的 Star 历史图表guardicore/monkey 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Monkey 的开源替代方案

相似的开源项目,按与 Monkey 的功能重合度排序。
  • redcanaryco/atomic-red-teamredcanaryco 的头像

    redcanaryco/atomic-red-team

    12,089在 GitHub 上查看↗

    Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors. It functions as a security control testing framework that uses a library of portable tests to verify if security monitoring and alerting systems correctly identify specific malicious techniques. The project serves as a MITRE ATT&CK emulation framework, mapping individual test executions to a standardized industry taxonomy of adversary behaviors. This mapping allows for the validation of security controls against the MITRE ATT&CK matrix to identify gaps in detection and respon

    Cmitremitre-attack
    在 GitHub 上查看↗12,089
  • specterops/bloodhoundSpecterOps 的头像

    SpecterOps/BloodHound

    2,789在 GitHub 上查看↗

    BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij

    Go
    在 GitHub 上查看↗2,789
  • samratashok/nishangsamratashok 的头像

    samratashok/nishang

    9,951在 GitHub 上查看↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    在 GitHub 上查看↗9,951
  • samsar4/ethical-hacking-labsSamsar4 的头像

    Samsar4/Ethical-Hacking-Labs

    3,397在 GitHub 上查看↗

    Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning penetration testing, network analysis, and offensive security techniques. It provides a structured environment for practicing the full attack lifecycle, from initial reconnaissance and scanning to exploitation and post-compromise analysis. The project provides instructional materials and guided exercises that cover specific technical domains, including open source intelligence research and network security courseware. It includes a practical workbook for identifying system vulnerabili

    ethical-hacking-labshackinglinux
    在 GitHub 上查看↗3,397
查看 Monkey 的所有 30 个替代方案→

常见问题解答

guardicore/monkey 是做什么的?

Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials.

guardicore/monkey 的主要功能有哪些?

guardicore/monkey 的主要功能包括:Adversary Emulation Frameworks, Lateral Movement, Vulnerability Exploitation Frameworks, Centralized Security Agents, Attack Simulations, Security Testing Tools, Vulnerability Assessment Frameworks, Adversary Spread Visualizations。

guardicore/monkey 有哪些开源替代品?

guardicore/monkey 的开源替代品包括: redcanaryco/atomic-red-team — Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors.… specterops/bloodhound — BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity… samratashok/nishang — Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows… samsar4/ethical-hacking-labs — Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning… empireproject/empire — Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It… malwaredllc/byob — This project is a post-exploitation framework and command and control platform designed for security research and…