lsgxeva

开源远控/C&C工具

https://github.com/alphaSeclab/awesome-rat/blob/master/Readme.md

 

所有收集类项目

RAT

  • 250+ 开源远控/C&C工具,1200+ RAT分析报告\C&C相关文章等。
  • English Version

目录

开源工具


pupy

工具

  • [5265星][1m] [Py] n1nj4sec/pupy Python编写的远控、后渗透工具,跨平台(Windows, Linux, OSX, Android)

文章


Covenant

工具

  • [1147星][6d] [C#] cobbr/covenant Covenant is a collaborative .NET C2 framework for red teamers.
  • [95星][9d] [C#] cobbr/elite Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack surface of .NET, make the use of offensive .NET tradecraft easier, and serve as a collaborative command and control platform for red teamers.
  • [31星][4m] [C#] cobbr/c2bridge C2Bridges allow developers to create new custom communication protocols and quickly utilize them within Covenant.

文章


Slackor

工具

文章


QuasarRAT

工具

文章


EvilOSX

工具

  • [1376星][2y] [Py] marten4n6/evilosx An evil RAT (Remote Administration Tool) for macOS / OS X.

文章


Merlin

工具

  • [2568星][6m] [Go] ne0nd0g/merlin Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

文章

商业软件


Team Viewer

工具

文章

恶意软件(部分)


Gh0st

工具

  • [301星][7d] [C++] yuanyuanxiang/simpleremoter 基于gh0st的远程控制器:实现了终端管理、进程管理、窗口管理、远程桌面、文件管理、语音管理、视频管理、服务管理、注册表管理等功能
  • [273星][7y] [C++] sin5678/gh0st a open source remote administrator tool
  • [91星][6y] [C++] igh0st/gh0st3.6_src
  • [90星][1m] [C++] zibility/remote 参考Gh0st源码,实现的一款PC远程协助软件,拥有远程Shell、文件管理、桌面管理、消息发送等功能。
  • [21星][5m] [C++] holmesian/gh0st-light 精简之后的老东西

文章


NanoCore

工具

文章


NjRat

工具

文章


Revenge RAT

工具

文章


PlugX

工具

文章


RemcosRAT


L0rdixRAT


LodaRAT


GulfRAT


NetWireRAT


JhoneRAT


Dacls


BlackRemote


Orcus


NukeSped


DarkComet


WarZone RAT


BlackShades


DenesRAT


WSH RAT


Qrypter RAT


Adwind


CannibalRAT


jRAT


jsRAT


CrossRat


ArmaRat


RokRAT


CatKARAT


TheFatRat


OmniRAT


LuminosityLink


其他

利用公开服务


Telegram

工具

文章


Twitter

工具

  • [658星][4y] [Py] paulsec/twittor A fully featured backdoor that uses Twitter as a C&C server
  • [186星][3y] [Go] petercunha/goat a trojan created in Go, using Twitter as a the C&C server

文章


GMail

工具

  • [1117星][1y] [Py] byt3bl33d3r/gcat A PoC backdoor that uses Gmail as a C&C server
  • [353星][3y] [Py] maldevel/gdog Python 编写的后门,使用 Gmail 做 C&C
  • [22星][1y] [Py] pure-l0g1c/keylogger A simple keylogger that uses Gmail as a C&C

文章


Github

工具

文章


DropBox

工具

  • [134星][1y] [Py] 0x09al/dropboxc2c DropboxC2C is a post-exploitation agent which uses Dropbox Infrastructure for command and control operations.

文章


区块链

工具

  • [46星][1y] [Go] xpn/blockchainc2 A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2
  • [35星][3m] [Py] geek-repo/c2-blockchain This is a concept poc of command and control server implemented over blockchain

文章


其他

工具

  • [513星][1y] [Go] mthbernardes/gtrs 使用Google翻译器作为代理将任意命令发送到受感染的计算机
  • [102星][4m] [Py] nccgroup/gitpwnd 网络渗透测试工具,可使攻击者向被攻击机器发送命令,并使用 git repo 作为 C&C 传输层接收结果
  • [97星][2y] [Py] arno0x/webdavc2 A WebDAV PROPFIND C2 tool
  • [93星][2y] [PS] bkup/slackshell PowerShell to Slack C2
  • [84星][2y] [Go] 0x09al/browser-c2 Post Exploitation agent which uses a browser to do C2 operations.
  • [69星][13d] [Py] itskindred/redviper redViper is a proof of concept Command & Control framework that utilizes Reddit for communications.
  • [66星][2y] [Py] lukebaggett/google_socks A proof of concept demonstrating the use of Google Drive for command and control.
  • [29星][2y] [Py] ajinabraham/xenotix-xbot Xenotix xBOT is a Cross Platform PoC Bot that abuse certain Google Services to implement it\'s C&C
  • [26星][3y] [Py] dsnezhkov/octohook Git Web Hook Tunnel for C2
  • [23星][10d] [PS] netspi/sqlc2 SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.
  • [22星][2y] [Py] woj-ciech/social-media-c2 Script is a proof of concept how to control your machine by using social media sites.
  • [16星][10d] [Py] securemode/trelloc2 Simple C2 over the Trello API
  • [14星][1y] [Py] j3ssie/c2s Command and Control server on Slack
  • [8星][2y] [Py] maldevel/dicerosbicornis A fully featured Windows backdoor that uses email as a C&C server
  • [7星][3y] [Py] killswitch-gui/flask_appengine_redirector Google App Engine Flask C2 redirector

文章

通信协议


DNS协议

Domain Generation Algorithm(DGA)

工具

文章

工具

  • [1855星][8m] [C++] iagox86/dnscat2 在 DNS 协议上创建加密的 C&C channel
  • [832星][6d] [Go] bishopfox/sliver 一个通用的跨平台植入程序框架,该框架C3支持Mutual-TLS,HTTP(S)和DNS
  • [386星][4y] [Py] ahhh/reverse_dns_shell 使用DNS作为c2通道的python反向shell
  • [277星][1y] [Py] trycatchhcf/packetwhisper Stealthily exfiltrate data and defeat attribution using DNS queries and text-based steganography. Avoid the problems associated with typical DNS exfiltration methods. Transfer data between systems without the communicating devices directly connecting to each other or to a common endpoint. No need to control a DNS Name Server.
  • [276星][4m] [Go] sensepost/godoh A DNS-over-HTTPS Command & Control Proof of Concept
  • [225星][2y] [PS] lukebaggett/dnscat2-powershell A Powershell client for dnscat2, an encrypted DNS command and control tool.
  • [176星][2y] [C++] 0x09al/dns-persist DNS-Persist is a post-exploitation agent which uses DNS for command and control.
  • [41星][2m] [Erlang] homas/ioc2rpz ioc2rpz is a place where threat intelligence meets DNS.
  • [38星][2m] [JS] inquest/threatkb Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

文章


ICMP

文章


WebSocket

工具

  • [245星][2y] [Py] arno0x/wsc2 A WebSocket C2 Tool
  • [131星][9d] [C++] xorrior/raven CobaltStrike External C2 for Websockets

文章

C&C


Cobalt Strike

工具

文章


工具

新添加


文章

新添加

远控


工具

新添加

  • [1615星][9d] [Py] zerosum0x0/koadic 类似于Meterpreter、Powershell Empire 的post-exploitation rootkit,区别在于其大多数操作都是由 Windows 脚本主机 JScript/VBScript 执行
  • [1473星][3y] [Py] nathanlopez/stitch 一个跨平台的远控框架,可为Windows,Mac OSX和Linux构建自定义的Payload
  • [789星][4m] [Py] kevthehermit/ratdecoders Python Decoders for Common Remote Access Trojans
  • [764星][7d] [C] rdesktop/rdesktop rdesktop is an open source UNIX client for connecting to Windows Remote Desktop Services, capably of natively speaking Remote Desktop Protocol (RDP) in order to present the user\'s Windows desktop. rdesktop is known to work with Windows server version ranging from NT 4 terminal server to Windows 2012 R2.
  • [706星][1y] [PS] arvanaghi/sessiongopher 使用WMI为远程访问工具(如WinSCP,PuTTY,SuperPuTTY,FileZilla和Microsoft远程桌面)提取保存的会话信息。PowerShell编写
  • [538星][10d] [JS] mr-un1k0d3r/thundershell 通过HTTP请求进行通信的C#RAT
  • [392星][5m] [C++] werkamsus/lilith 基于C ++开发的基于控制台的超轻量RAT
  • [297星][2y] [Py] 0xislamtaha/python-rootkit Python远控,用于获取Meterpreter会话
  • [238星][6d] [C#] b4rtik/redpeanut RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.
  • [222星][9d] [C++] xdnice/pcshare 远程控制软件,可以监视目标机器屏幕、注册表、文件系统等。
  • [214星][2y] [C#] them4hd1/vayne-rat 用C#编码的免费和开源远程管理工具。
  • [205星][2y] [C++] ahxr/ghost a light RAT that gives the server/attacker full remote access to the user\'s command-line interprete
  • [201星][10d] [Py] pure-l0g1c/loki 远程访问工具, 使用 RSA-2048 + AES-256 保护通信安全
  • [195星][3m] [PHP] 0blio/caesar 基于HTTP的RAT,从浏览器远程控制设备
  • [175星][4y] [C#] alphadelta/secure-desktop Anti-keylogger/anti-rat application for Windows
  • [172星][3y] [C++] hussein-aitlahcen/blackhole C# RAT (Remote Administration Tool)
  • [157星][10d] [Visual Basic] mwsrc/plasmarat Remote Access Trojan(RAT), Miner, DDoS
  • [140星][1m] [Py] anhkgg/pyrat 基于python XmlRPC完成的远控开源项目,包括客户端和服务端(也叫控制端,后统称服务端)
  • [136星][25d] [C++] earthquake/universaldvc Universal Dynamic Virtual Channel connector for Remote Desktop Services
  • [129星][2y] [Py] dviros/rat-via-telegram 使用Telegram控制已经攻克的Windows主机
  • [115星][4y] [C#] leurak/trollrat 远程管理工具(RAT),该工具采用与其他RAT不同的方法,不做数据窃取等,只是为了trolling
  • [98星][4m] [JS] securityrat/securityrat OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development
  • [95星][7y] [C#] ilikenwf/darkagent DarkAgent Remote Administration Tool RAT by DragonHunter
  • [95星][2y] [Pascal] senjaxus/allakore_remote Delphi Seattle编写的远控
  • [80星][4y] [C++] rwhitcroft/dnschan 使用DNS通信的远程访问木马
  • [77星][4y] [Py] ahhh/reverse_https_bot A python based https remote access trojan for penetration testing
  • [66星][11d] [Visual Basic] thesph1nx/rt-101 VB.net Remote Administrator Tool (RAT)
  • [65星][7m] sh1n0g1/shinobot RAT / Botnet Simulator for pentest / education
  • [61星][28d] [Visual Basic] thesph1nx/slickermaster-rev4 NSA Hacking Tool Recreation UnitedRake
  • [61星][2m] [C#] nyan-x-cat/mass-rat Basic Multiplatform Remote Administration Tool - Xamarin
  • [58星][3y] [PS] killswitch-gui/persistence-survivability Powershell Persistence Locator
  • [57星][3y] [Py] m4sc3r4n0/spyrat Python Remote Access Trojan
  • [55星][4y] [Py] ahhh/ntp_trojan Reverse NTP remote access trojan in python, for penetration testers
  • [53星][8d] [Java] blackhacker511/blackrat Java编写的远控
  • [52星][12d] [Py] technowlogy-pushpender/technowhorse TechNowHorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.
  • [50星][11d] [C#] brunull/pace A Remote Access Tool for Windows.
  • [46星][1m] [Pascal] 0x48piraj/malwarex Collection of killers
  • [46星][1m] [PHP] davidtavarez/pinky pinky - The PHP mini RAT (Remote Administration Tool)
  • [46星][20d] [Shell] infosecn1nja/ycsm This is a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-Ex Tools (Cobalt Strike, Empire, Metasploit, PoshC2).
  • [46星][18d] [Java] m301/rdroid [Android RAT] Remotely manage your android phone using PHP Interface
  • [46星][2y] pentestpartners/ptp-rat Exfiltrate data over screen interfaces
  • [44星][2y] [Shell] taherio/redi Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)
  • [41星][3y] [C] killswitch-gui/hotload-driver C++
  • [40星][5y] [C++] lingerhk/0net 一个简单的Windows远程控制后门
  • [40星][3y] [Visual Basic .NET] mwsrc/betterrat Better Remote Access Trojan
  • [39星][1m] [Shell] samyk/easel-driver Easel driver for Linux (and Mac/Windows) + remote access to CNC controller
  • [37星][11d] [PS] 5alt/zerorat ZeroRAT是一款windows上的一句话远控
  • [36星][5m] [C#] blackvikingpro/aresskit Next Generation Remote Administration Tool (RAT)
  • [35星][3y] ritiek/rat-via-telegram Removed according to regulations
  • [29星][1m] [Py] the404hacking/windows-python-rat A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.
  • [26星][2y] [Py] thegeekht/loki.rat Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access Tool.
  • [25星][9m] [D] alexa-d/alexa-openwebif alexa skill to control your openwebif device
  • [24星][2y] [Py] rootm0s/casper 

分类:

技术点:

相关文章: