Merlin 是一个跨平台的命令与控制框架及远程访问工具。它提供了一个用于渗透后协调的服务器和代理系统,利用 HTTP/2 框架进行安全通信,并在多个操作系统上执行命令。
ne0nd0g/merlin 的主要功能包括:HTTP/2 Transport Layers, C2 Communication Protocols, C2 Frameworks, Shellcode Loaders, Handshake Credential Validators, C2 Agents, Identity Validation, In-Memory Payload Execution。
ne0nd0g/merlin 的开源替代品包括: n1nj4sec/pupy — Pupy is a command and control framework and post-exploitation suite used for remote administration and system… byt3bl33d3r/offensivenim — OffensiveNim is a red teaming framework and post-exploitation toolkit developed in Nim. It provides a collection of… specterops/bloodhound — BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity… cobbr/covenant — Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It… its-a-feature/mythic — Mythic is a red teaming framework and command and control server designed for managing post-exploitation activities.… bats3c/shad0w — A post exploitation framework designed to operate covertly on heavily monitored environments.
Pupy is a command and control framework and post-exploitation suite used for remote administration and system management. It functions as a cross-platform tool for deploying payloads and controlling multiple remote agents through encrypted communication channels. The framework features a multi-platform payload generator that creates custom executable files using configurable network launchers. It employs a network traffic obfuscator that stacks encryption and obfuscation protocols to hide communication from observation. The system provides capabilities for in-memory code execution, remote pr
OffensiveNim is a red teaming framework and post-exploitation toolkit developed in Nim. It provides a collection of low-level primitives and a Windows API wrapper designed for offensive security operations, including malware development and shellcode loading. The project focuses on evasion and obfuscation through techniques such as API unhooking, direct system calls, and anti-debugging mechanisms. It features diverse payload delivery methods, including reflective binary loading, the execution of .NET assemblies via CLR hosting, and various shellcode injection techniques using fibers, COM obje
BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij
Mythic is a red teaming framework and command and control server designed for managing post-exploitation activities. It provides a centralized system for issuing tasks and receiving telemetry from agents deployed across diverse target platforms and operating systems. The platform features a collaborative operator interface that allows multiple security researchers to coordinate operations and track target activity within a shared environment. It supports the deployment and updating of diverse agent payloads through a multi-platform payload manager. The framework utilizes a plugin-based archi