LazyOwn
LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Windows/Linux/Mac OSX, and self-configuring backdoors. With its Web interface and powerful Console Client, it is the best combination for your Autonomous RedTeam/APT campaigns.
File Explorer
- bug_report.md
- pull_request_template.md
- agent-contract.yml
- attack_surface_scan.yml
- audit.yml
- ci.yml
- codacy.yml
- docker-build.yml
- docker-smoke.yml
- lint.yml
- pre-commit.yml
- publish-pypi.yml
- security-scan.yml
- security.yml
- test.yml
- test_strict.yml
- dependabot.yml
- FUNDING.yml
- 2026-05-25_lazyown-architecture-improvements.md
- alien.png
- Crimen.png
- drhyde.png
- drhyde2.png
- KrackenLAzyOwn.png
- Lazy.png
- Lazy1.png
- Lazy2.png
- LazyOwn_Redteam_framework.png
- lazyowneye.png
- LazyOwnGris.png
- LazyOwnGris22.png
- LazyOwnGris3.png
- logo.png
- README.md
- __init__.py
- _base.py
- _dormancy.py
- active_directory.py
- ai.py
- anti_forensics.py
- applocker_bypass.py
- audit.py
- automation.py
- bitm.py
- bof_registry.py
- c2_profile.py
- caldera.py
- campaign.py
- catalog.py
- cicd.py
- cli_auth.py
- cloud.py
- cloud_attacks.py
- collaboration.py
- command_and_control.py
- command_and_control_migrated.py
- containers.py
- cred.py
- cred_migrated.py
- crystal_ball.py
- database.py
- diagnostics.py
- dns_exfil.py
- dpapi.py
- edr_detect.py
- enum.py
- estorides.py
- evasive_payload.py
- exfiltration.py
- exploit.py
- exploit_migrated.py
- lab.py
- lateral.py
- lateral_migrated.py
- marketplace.py
- mcp_bridge.py
- misc_migrated.py
- mobile_macos.py
- module_manager.py
- opsec_cleanup.py
- orchestration.py
- payload_arsenal.py
- payload_generation.py
- persist.py
- persist_migrated.py
- phishing_wizard.py
- pivoting.py
- postexp.py
- postexp_migrated.py
- privilege_escalation.py
- pwn.py
- README.md
- recon.py
- recon_migrated.py
- redteam_gym.py
- report.py
- report_enhanced.py
- report_migrated.py
- reporting.py
- resource_scripting.py
- scan.py
- scan_migrated.py
- security.py
- sleep_obfuscation.py
- socks_proxy.py
- supply_chain.py
- __init__.py
- aliases.py
- aliases.yaml
- assign.py
- auto_crypto.py
- autosuggest.py
- banner_config.py
- chain_mode.py
- cli_enhancements.py
- command_chain.py
- command_form.py
- command_index.json
- confirm.py
- dashboard_tui.py
- doctor.py
- engagement_hooks.py
- exploit_advisor.py
- exploration.py
- exploration_view.py
- fuzzy_picker.py
- graph_advisor.py
- graph_overlay.py
- headless.py
- killchain.py
- lazynmap_post.py
- marketplace_config.py
- noise_verbs.py
- ops_commands.py
- palette.py
- palette_command.py
- palette_graph.py
- palette_overlay.py
- palette_telemetry.py
- protips.py
- reactive_hints.py
- README.md
- reasoning_stream.py
- recommendation.py
- recommendation_signals.py
- recon_plan.py
- registry.py
- scope_guard.py
- sessions_browser.py
- show.py
- splash.py
- status_bar.py
- style.py
- surface_graph.py
- surface_tui.py
- themes.py
- timeline_browser.py
- tips_engine.py
- toast_bus.py
- tui_theme.py
- wizard.py
- __init__.py
- api_authz.py
- command_bridge.py
- config.py
- console.py
- credential_vault.py
- credentials.py
- crypto.py
- dependencies.py
- errors.py
- executor.py
- http.py
- llm_budget.py
- logging.py
- network.py
- parsers.py
- payload_schema.py
- process.py
- prompt.py
- protocols.py
- README.md
- safe_subprocess.py
- scheduler.py
- security.py
- validators.py
- bin_data.csv
- bin_data.csv.old
- bin_data_relevant.csv
- bin_data_relevant.csv.old
- lazyown-c2.yaml
- docker-compose.logging.yml
- fluent-bit.conf
- README.md
- htb-lame-walkthrough.md
- README.md
- api_docs.html
- ATTACK_MATRIX.md
- c2.md
- CHANGELOG.html
- CNAME
- command_chain.md
- COMMANDS.html
- cred.md
- enum.md
- exfil.md
- exploit.md
- favicon.ico
- index.html
- killchain_contracts.md
- lateral.md
- LAZYOWN.html
- openapi.yaml
- persist.md
- PORTING_BOFS_TO_LINUX.md
- postexp.md
- privesc.md
- README.html
- README.md
- recon.md
- report.md
- SECURITY_CONTRACTS.md
- SECURITY_PLAN.md
- style.css
- template.html
- UTILS.html
- WORLD_CLASS_PLAN.md
- install_external.sh
- readme
- README.md
- adaptixc2.yaml
- adcs_attacks.yaml
- agentzero.yaml
- applocker_bypass_csc.yaml
- applocker_bypass_installutil.yaml
- applocker_bypass_msbuild.yaml
- applocker_bypass_mshta.yaml
- applocker_bypass_presentationhost.yaml
- applocker_bypass_regsvcs.yaml
- applocker_bypass_rundll32.yaml
- argfuscator.yaml
- ATTPwn.yaml
- aurorapatch.yaml
- banner.yaml
- bbr.yaml
- beacon.yaml
- BlackObsidianC2.yaml
- blacksandbeacon.yaml
- blacksandbeacon_bof.yaml
- CGOblin.yaml
- cicd_build_secrets.yaml
- cicd_gitlab_enum.yaml
- cicd_jenkins_enum.yaml
- clean_local_history.yaml
- Clematis.yaml
- cloud_bucket_enum.yaml
- cloud_enum.yaml
- cloud_metadata.yaml
- cloudsploit.yaml
- commix2.yaml
- CompressLoader.yaml
- container_escape.yaml
- copyfail.yaml
- cPanelScanner.yaml
- curlfree.yaml
- CVE-2022-22077.yaml
- CVE-2026-25089.yaml
- CVE_2025_24071_PoC.yaml
- demiguise.yaml
- dirtyfrag.yaml
- dns_beacon.yaml
- dns_exfil_server.yaml
- docker_enum.yaml
- dpapi_harvester.yaml
- ebird3.yaml
- edr_detector.yaml
- estorides.yaml
- evilginx2.yaml
- fakesystemD.yaml
- Fragnesia.yaml
- FreeDom.yaml
- gcr.yaml
- gemini-cli.yaml
- gen_dll_rev.yaml
- Get_ReverseShell.yaml
- githubot.yaml
- gitleaks.yaml
- gomulti_loader_linux.yaml
- gomulti_loader_windows.yaml
- GoPEInjection.yaml
- gosearch.yaml
- grype.yaml
- gui.yaml
- gui2.yaml
- hack_browser_data.yaml
- hellbird.yaml
- hive.yaml
- hooka_linux_amd64.yaml
- hostdiscover.yaml
- Januscape.yaml
- k8s_enum.yaml
- keylogger.yaml
- kivi_revshell.yaml
- laps.yaml
- lazyaddon_creator.yaml
- lazyagentAi.yaml
- lazybinenc.yaml
- lazyftpsniff.yaml
- lazyllmchat.yaml
- LazyLoader.yaml
- lazymapd.yaml
- LAzyOwnBT.yaml
- LazyOwnExplorer.yaml
- LazyOwnOpenCodeAdapter.yaml
- mfa_bypass_toolkit.yaml
- nullgate.yaml
- oniux.yaml
- opencode_adapter.yaml
- opencode_agent.yaml
- opencode_c2.yaml
- opencode_exploit.yaml
- opencode_recon.yaml
- opencode_report.yaml
- orpheus.yaml
- OverRide.yaml
- OVSwrap.yaml
- packet_edit_meme.yaml
- peeko.yaml
- phantom2.yaml
- pretender.yaml
- prowler.yaml
- PTMultiTools.yaml
- PTMultiTools_scan.yaml
- pyinmemorype.yaml
- pyrit.yaml
- pytbackdoorch.yaml
- QuantumVault.yaml
- raven.yaml
- README.md
- report_full.yaml
- ridenum.yaml
- scoutsuite.yaml
- shad0w.yaml
- shadow.yaml
- ShadowLink.yaml
- shellcode_custom_win_rev_tcp_xored.yaml
- sigploit.yaml
- social-engineer-toolkit.yaml
- spoonmap.yaml
- stratus_detonate.yaml
- stratus_list.yaml
- toposwarm.yaml
- trivy.yaml
- unicorn.yaml
- upxdump.yaml
- vulnbot.yaml
- vulnbotgroq.yaml
- vulnhuntr.yaml
- vulns-2026-fatfs-chance.yaml
- watchguard.yaml
- websocket_beacon.yaml
- wspcoerce.yaml
- yara_scanner.yaml
- Zapscape.yaml
- amsi.yaml
- infect.yaml
- inject_shellcode.yaml
- lazynim.yaml
- malleable_beacon.yaml
- persist.yaml
- pid.yaml
- README.md
- rust_implant.yaml
- __init__.py
- addons.py
- api.py
- auth.py
- beacon.py
- operations.py
- phishing.py
- session_auth.py
- __init__.py
- decoy.py
- short_urls.py
- storage.py
- users.py
- __init__.py
- command_allowlist.py
- constants.py
- cors.py
- csrf.py
- html_sanitizer.py
- https_redirect.py
- README.md
- services.py
- trusted_proxy.py
- validators.py
- __init__.py
- addon_creator.py
- app_factory.py
- models.py
- README.md
- state.py
- __init__.py
- c2_credentials.py
- constants.py
- paths.py
- settings.py
- __init__.py
- base.py
- campaign_panel.py
- credentials_panel.py
- cve_panel.py
- event_log_panel.py
- graph_panel.py
- history_panel.py
- killchain_panel.py
- listeners_panel.py
- marketplace_panel.py
- registry.py
- sessions_panel.py
- terminal_panel.py
- __init__.py
- backend.py
- event_log.py
- factory.py
- local_backend.py
- models.py
- teamserver_backend.py
- __init__.py
- catppuccin_mocha.py
- cobalt_clone.py
- gruvbox_dark.py
- solarized_light.py
- tactical_green.py
- tokyo_night.py
- __init__.py
- manager.py
- qss_builder.py
- tokens.py
- __init__.py
- beacon_command_modal.py
- command_palette_list.py
- event_log_view.py
- filter_bar.py
- graph_view.py
- status_badge.py
- terminal_view.py
- __init__.py
- command_palette_window.py
- connect_dialog.py
- main_window.py
- __init__.py
- __main__.py
- app.py
- README.md
- version.py
- docker-compose.yml
- Dockerfile
- entrypoint.sh
- hostdiscover.sh
- init.sh
- mkdocker.sh
- README.md
- adversary.ls
- atomic_agent.ls
- atomic_agent_win.ls
- attack_surface.ls
- certipy_ad.ls
- cloud_enum.ls
- dploot.ls
- lazynmap.ls
- lazyquit.ls
- lazyscript.ls
- pyautomate.ls
- README.md
- smb.ls
- startup.ls
- supply_chain.ls
- backdoor.c
- keylogger.h
- README.md
- server.c
- lazywebshell.asp
- lazywebshell.cgi
- lazywebshell.py
- lazywebshell.sh
- README.md
- 002c68a5d8bd90a7afd87aece874d680919300f1749db5b5d36df429a570a90b.json
- 00ecc49cc353dd16819ae15aef9b3b46680fc675f7112a7b52a1b39a98ec8e86.json
- 04327718c76fb2a3741aa47d73ca88e78c3a71962f698a8d488f7fb73b35cb4e.json
- 04e1013cdaaa16e48fe97ce0da745d838b2963087cbe18df326273a1b067a67b.json
- 06af6e35a790c5008b76448abd7b073236aff4b25883e11489625ae0910fff1c.json
- 0bbe929d6546a52becc46c9e4b875f0fe6c2ab826bd8d06a20e859d27d3d4828.json
- 0f44dd3aed01b0cfd9edb77f3e14f479ffd7e67b1f31cc4bf9197a99d61e7e3d.json
- 1240e2f3c7f6db76f66c31f4c8f5212917c8d52a5ff5026a29be33173df21a08.json
- 15f5ea411edceabbb87bc68a151f14985dadbd6ecf1c3f58a0591af7d03b7172.json
- 1602bb923409cf9c74a2b063edef8968f719667512fa8888dc1ab713d239ad19.json
- 16229114939ee96a45da798388d20c45cade6f8ed4247be055c02bf69237e256.json
- 173ef6ac8ff8e0e09843ccd09ca73ab42f0db8d44a07bb24a3307c6e81abeabd.json
- 17810fa1289c575546ab2f1f5005444c63cadd9ea8a021ea8d68656c0b033fa6.json
- 17ada399ac59a81a4f5cbea33085c6277c456fc94a8e10e8dd5eabf5041f6775.json
- 1a775d2b403859e0d87a57cec46001b501e465c9ab3939df5b3e75f510801e1a.json
- 1a98e41dbc590c7859599703cb0bd0c5d9dc8baa5c216a37e0c5d6f5fd9f1c64.json
- 1ad87e74340150a792513e9bfeb89b0a10609ab8e0a8a92eb13b9b44ebbdb932.json
- 1af842a157aa6f74edc018441862e964dbcc1a39ca5dcdbdcda42d004569078a.json
- 1b85e94aedc492581a7ac727dabcd66947ac78a0272d4d3c771bdda076f171e9.json
- 1da6c32dc3f515e67cbc40d431154b41a6f60a6d1aa851d4f7ced9ddd6f102f6.json
- 1eebbfedaded8299f50771805bc0f2f8e4efd5c8159a0bbd8ee6eca1c712e27a.json
- 217095166ef54685f378475211949aea1a81e07542ebd435521d86f6fd181b4c.json
- 22c1a469eca462e83d029729c7e8fa7df8a3d2a968f8c71aa5fec80fa8f5ce36.json
- 28e9a0072539dbbecdd2a26918822d7a9d929269b57586b148957c43847f5bf7.json
- 2b430cf200f59cd303c10b8b6ecceac7bde2302d6b4bc88a82128fe00d633aa3.json
- 2d373033a4141265a1e0448fadce895b2158259f937064acce1366f21591967e.json
- 2f85d60d9e180d6f3933eecec738aceaf0656d4202424471a3309550a03acbc4.json
- 34322fbee784e41a6ca90964b027e1177ab762054ad8f995267bc1bae96d20af.json
- 34e46208e6f2f6b066dfb94a608e37ddec0f0b0a90bb083a78402a65fd969368.json
- 36b60cb588f4ff96b1f280370779ea4b9ef9f8cb1f162cf514e2acf862015ce9.json
- 38a3aac38041440f46bb2dceb0fb4ce47e5bc603635d52ae8195c5779d9ab2ea.json
- 3a7357d10f228b14fc3db9417d131551780d12e6fedc090d70cc98386b59411c.json
- 3a923525e21418fde5a5a93675c08ac383531190b9db8fcf42b31049d642c788.json
- 408177679da228f94487d47ca786bebedfe5650e7b67c53647b5b0597b14a68a.json
- 4197cba86ac7f19d2d5652c06730c0507f7153afb6b037b3ec1d42e6f16702e2.json
- 42b220d6c2c6e2efb968f7b7106c83ec3b9568d304bd411f57d2f67210e9d8d3.json
- 4322c36d359a6273a03dff0ac40cfec544b9eaa0a9f10a8d5295bc70023ae244.json
- 4519cda64701c6b26d6213e40745fb8aa06b4fc830a68f2e5c761a3151db30f0.json
- 466ee6e152eff9e68a42b04282828e29436a0a4b0243f5c7cdc70387858b4bd3.json
- 46b21d7e09994fc4234c13ddefe7266a190741000946fe68c6a8aa1472f68761.json
- 47d02fd7f0d7d47f4519d6a2fccd886c790cf6da80bbce6cff39f54847f4aacf.json
- 49a0bc55f8774a8a305e18e08d994b1be9b880c46360fffb09035cf5a71643a0.json
- 4aebc0020b1578b3fefab2ca3718cc844c5e7e3b0d88073af2e0dd8f2372c299.json
- 5071df243916840111a4022b5cadf74118d4654ded1e74b79ec9a8c38e06c5b0.json
- 510f0ffd637767b9f5188118ccf29dd139304e993becb31f3cf4c052524c98b2.json
- 5116e72308d4d31d070b11859c20610557340cbde74a2858f3a795b68528084f.json
- 52d705625d1dcd901f35270bae14d6831f6d9bc62331336cfbf2dcef8fc8ba2e.json
- 5361d757cad9d249b369d58b5cfa1d35ef5c3eaee89aff34138795b4a2d6d47e.json
- 56fc6f753a4e13a8de4907c6d27b5a513ecc864cf1ac965f60f7b922f790b198.json
- 58887cfe1a9520d0dab433302a97e848be70a3469e75716ef9924c7443e0c436.json
- 58d021c03e8752214f5ad6c2e01e31a31eb20d79452c054ee36d740b63ba5ac5.json
- 5afbe82cd60e8cabb41b500ed732de33ce3246431d7addbea7e780e7019ec3e1.json
- 5d73e2649547a6a099ba96902d6eb53a112f75e19cf5f85f7cb3d94672bb9b17.json
- 5efb0ea8dd163daa68c4d21ae159d96133fd2805e5df747b679ed05f3a8de356.json
- 605d1819d9abcbb225765dcb0779a31f49c6c5c69a29ca76abb5417924a1cccc.json
- 6066176534f92b2d7ae9045e222aba593e5f8286efc739b18d254934924208de.json
- 63408142131bd158b5200b62cd9b0f2f7d03b1e39b9c6034bb17b2824131d4d5.json
- 63b8d6f1458df5081248e316c32985ccc7a6e135d4b714a30b8960b97a29408e.json
- 648c948b138f7141cb6b3a0c819f16469230c393eb9c0ccd0316b3d7eac04150.json
- 69e5415663b5b7861dff3baebb776e4644d550bafb3ac5823fb0cad966c72e17.json
- 6ca1d7759f39555e2e00db547b4c52f65c20f262b8eb94a664bb8dc13b21e772.json
- 6d9c6072f81245d266b72ccb16e821f978975a575dfe7d4372f808cb444630e4.json
- 6f29d7b81fabdaa02e59340afae00093b9a994e2181e31cbc786ec30a2ff2406.json
- 6f5eae5ce5dd716ae47df4fd51c3ff69f27a553cc376c4bb0945624f1a643eb2.json
- 71a18dadbb78437aee707cb826c56fa10e169d2c281d2a4e1e7794d3266f3247.json
- 72872a4a27189f9b4707600eabe2895375a74d4b8a210c2dfee6981375ae3e0e.json
- 7471e366c1dc5e3edc6a1d31bbc6ca925dbe6b92eceef31dfe4b699da561daf6.json
- 7bde5bac4df2b23b2697bfb85cec8f53979059c5879845ce005f9d837ced4589.json
- 7d8e453d67d061bad9f84bd293152bff1eb4050a123fb85150df76118289b3ad.json
- 7e3596a9864b7c26b0d8aba0a4cb3b69eb67495239f205f49bbe772c160132ca.json
- 805702d3ee3179d7bbaec8d0c954befdbad0afb0f74bd49b8c6c634a9d1c8302.json
- 823023774e52e16043875084edfef93f5444300b93c89796075f0b71a036b67a.json
- 839a2edd861eeec008b44eb434f7197440b8e5ef3019dc8ca3fbb221b5f667b3.json
- 83eb1a5626da3cdb6d06d6f465e2cb97dbf900e6f54310c57ad5ae14963bc1fd.json
- 850851aa15fe06a5cdaf8b176788b39fbe3863d774da28ed2663d40898ca8808.json
- 86eab46102bd9380bb82a5481c2497e2b6062b9c0ab9de9bc8ffd42950140898.json
- 881d78fe853507992f05a39b625f00c75cb5df82f4524d56ccf97c3611f39671.json
- 889a916fa16398f5b5e7503ef1fa72b90a3bb5c73e5ded81e5e4032292214406.json
- 88cc7289fb8df07ebca345b22be4489a0c2c56f1b6fa747ad7feede29fc31e5e.json
- 8b9702b858995529aab6ca6b346f8c5db0d2fcb9f73ba3caf2897bed0529db80.json
- 8e0ca4cce67e3edd49950a43810731da6d146ba0e69424a784a06589d72aa1df.json
- 8e9691ab5ed837d3d651c72008d750fdc3235afe43a63c359b662efacaa57758.json
- 90c3c081d15ce2c80c1dc125a6c2d83d308b4b82ed2d829f40da7f5fa24f1a11.json
- 92396e6b4f0beae5ac18a178a76037224fd6b2c7fbec2201a3d2faf5f234785c.json
- 92f411f6b57e381b051cfdd964707b9f57c2b4a78923b247a6203cf2af6f66a0.json
- 93ce0702839c90b93232b3b7486b2caefe685ef922d7f01605a84c57b35b410d.json
- 93eadc5de363a15c3280189388ae9454b7f21e4d7137fa9a35804ff41fe2873b.json
- 945449a4a92bf55c447b3d284f80111a0e8fcafa1c30f93861f48353992c5e9d.json
- 972f2e035d7e88101a4124b2751451024b3991b02a9b5faeb6b9d6fd07098ea2.json
- 98feacb28ac6c89a88c44d7d71a79b659076fe2b3d47d116d2378fb231fc3364.json
- 9a8747718e6c012ac452e62c4e44f065d1647ea2c112c818e2ccc44d833ef60d.json
- 9f46ac40b755548247f580ff2e653d4fc6d80bf01b55fb3611337672e760ccc3.json
- a119edad95d9de167fd5a7d3167274c56134af46ad7737470038003942325fad.json
- a2049963b5043ba8f0b3df0cea49f957dc4f66c08dd94a6d7138bb9aa55935d2.json
- a2226de55076d9bd8fc98ac2568afa72afafdcf961907ce2efde2a6d29db7811.json
- a369d58a9bbe61e59fa17a6c82f207db975b78aa5af7dc8e3c156194eaf00102.json
- a7ee090c2c61ca65818136a592229be8ec4b94b3f0f5a1126aea845fff23cec1.json
- a84ecb42b3a272f3380a3126aed625ce2e4abbf176e0a1b2c357c178d2f9dbb1.json
- a908428c0934cec0a41ae0f1e1a3104a3333681e6a4e6eaaccb76be693b4b4b9.json
- a923eebc79af97ccd47a94b6ebd44a092032e8c69317ecf6c77f3b47f2043f0a.json
- a94463fd86743d98314e7b977a80dd7a68e4c78957dfe219d0b6436d44935449.json
- ab92ec10c9d627d4ffa11eddc486cd4e418bbe612f8baa2f947db376a294c0d4.json
- ad6c9a117bcdab8183df904bf0707e4b10d685268301a2f8616370f591612db4.json
- adb64c1eb2481ad46c63b879cd45483d8fd50970486258405f15e23359472c6b.json
- ae40bf729592bcc763d6b6c6c2bc74f09f1d60900b4fb259c149049a1a4879e2.json
- af84c676ec6acda789d2aeebfa8c83cb1055533517afa3ce871b8028b19f611b.json
- af85fd6a9f2a66ed659ec6fc14279b22604a5e8d742eee22652b97f571f1e277.json
- b1cbaa758bad3be21f364504c35744c832752a0958105efbd2c5de684009ebbb.json
- b2d37ed63d870a5cbb825120781e370e0c8eebef5cd34e8119bb6350bfa03c7f.json
- b453a2de799ff1d64b1f0ab50b1a658262da4854c918c4693e1d6b245891bbbc.json
- b4ee618517fc3b534a44e61447f7a48250faa687cd51eae9cc71b5a9ba0938f7.json
- b63a601002d9cd33a15547f866e591e44c513f3b8a26c26ff7d2337dd1c66fe9.json
- b65522ef72d7fbf8f6ff9d75ef63de89d2b5100368981a5d3e9d3d14a19c01b8.json
- b6cb63e710ddd5fc625bc67429a5964229a65c3e3a9879e676a8260bac7784ee.json
- bbe55f18365550f595b32e2654ac15a2bde025baf73d01c139e80fbb6c0b1b27.json
- bd62a8a248b08fb9ca0eb1a063d56d6894c7bda4e944bbd6d59958995ed2a469.json
- be43e925d3c08d53a7b1ec16ca45406873ea1d5c23211b750ad121a598e34c52.json
- c0141cc20d3a31cffb86a15e540a5841ef0c61ba47c30592c63e75f0d3dbd765.json
- c06d0c705f8f90394ca7085acb09163547cf5ffa94b2c669cff12171776118f0.json
- c09b785530f780284c4a037eec27baa6f7ec32aff4ae6fa70a24b77fb51b0faf.json
- c124403728199f515b9ac7876e1f73cd1771e876617ce7caec289a58c6ef6a39.json
- c18b9fcf7cd951d04bcb318a3b0f6cb95167add7717bc375414944aa0a693972.json
- c25f3433aac86587b2181688afaad2ac21dd57835dc1114b959ef5c84dcba139.json
- c28d6f5d3fa68bc2670117e5e87cb58937de2b5fe97e93f4473a6103851d7b1a.json
- c433ed6d78ad35c2701a439df1d6b7ed1e659c087f51fda6cdc0f9c43e632d72.json
- c63ad41bcafdab0d41440aa0c5151147c59118cef56d1a208a5de175768ae3cf.json
- ca44d706b30cc9b0142af6801a1c20cb1427ca88cc95fe7539526810fc86f8c7.json
- cd15886a1da91111a71b3d9dbbea2ca89670204da62c11906f5ae75b6da32472.json
- cd65efedb86f15ea7d52dc0112a424c44b60d3739dd30334f96e596c7bc1ad58.json
- cd999221c11cc82527bddb8ac2ac6ddb9170e852a58bf749a1ee28d6966ac313.json
- ce01861e6dbe2c0f8fc4f50044b1558965db96970e25098bae3c497035da908f.json
- cfbcd0136de144066266d4e693cba9f0d1d86359970a6a9b690049afc6d72880.json
- cfc035ecc1d70457c9b1869e84c609b6b96674931a904742f41210b072060f16.json
- cfda4436e68a22c8d7fb180154e83392b87cd3768c7da0170b5b9c62f8aee728.json
- d12dccf07d58d7c0a2b5ea5b6aa821aa419fdc8b34a48939ebf9c565bc439551.json
- d2886bb1b2c2a702c60f220715404b4d543642ffd3f33963e0f82a4c63ac2e3c.json
- d28bb51bb1ce8d20a6f3137ad35b14ffbc83b7364d6b7bb743933d0d922d332e.json
- d3bd2be384f28e6ec932b36487bdcca4c5966b8cd696d16f8b67ae59b7471f47.json
- d4848d774c2bc6e6c64f455b197ff2daf4fffb8fd262cd64a1dcb6b4bc9a725d.json
- d584bce9d8acb11ef59c235ac7d4d8d804745882d2dad48da56a538cf5a6a552.json
- d66147bf0f176df4d3b9dd65c8fce0193265160bc7f08689e90d35c9b5416a17.json
- d767e59fd8986c7e4e13b38bf5d766e3940d0b8346b27e29b4db5bb39cb1adfa.json
- d7c1275fbbe4449a0a3b42ebbabada2a51a2821ea80e2845e9ac8cc691f0c82c.json
- dad8ff12deeab5bb23754cc74ce4063f26039b3a1e0e49c4a971f1a3af238d01.json
- db20ee6958777ee0ad40668f2c5778a97dd313484b2c7522f120fd9544d7b475.json
- dbe8a98f87d00483d3d6531215c0acc33f6fc7b9ec8b01a778c446b54fe70d4c.json
- dd677b1ba4f494ee843125b5cc6e9b3e1821334a75f4ad95ee40e5fcb4986c1c.json
- de6345cb6f6f2c9121358c6890b656ddff1fde9eb9cfb59527162d791eb9437b.json
- df58a7d2670a99066cd4d31e2cc33d93f45a588667563b29d5176fe63245eafb.json
- e00df8727fe4ec9c5ee699e063e744f97d5fa5a1e77d6cfcc697e3eb7108a193.json
- e103b4a2d44b8535783229f5717e0f7d7c2f9f65e99c5f19078a0732e4153912.json
- e2c629e494b277e3fa004d432969b5f98aa49dda09e6e4ae7b6884a96495d339.json
- e8c82b59e3c0550f3af525820fd60aa4081a043dae5f2e1a7d3f13c8291030f0.json
- ed6748ad0384ed2ed9d66bc72ba2c133e184ead3dd93d6e377156701c0c6b60a.json
- f11472dd845abcbad58d1d6a11b65ea9d3d218577027608dedb4c8080d1bed16.json
- f1e7a02e36872b9fd6dd295039307e6dc9ae183ee6e88cbb4dac1b64df6577ac.json
- f8d2fc24e6fc86802b4e91296690ab3c8b31bbbfe70698532c05a90aa3bd486d.json
- fd2a60045d1899d661c492a7d4e5eefd1d010691f80aafcab0be5abf01348cdc.json
- fdcbc4cf5a17a1e3ce16cd550c9a16f7a6f12cb07fca92a0ad5bee7f77ed5470.json
- ff7170035f673bef01ade88b0768aa07502c88767c2db95705408cef8d005e16.json
- __init__.py
- misp_export.py
- nuclei_bridge.py
- nuclei_parser.py
- README.md
- searchsploit.py
- __init__.py
- lazy_http_bof.py
- lazy_packet_image_sniffer.py
- lazyaddon_creator.py
- lazyarpspoofing.py
- lazybinenc.py
- lazybotcli.py
- lazybotnet.py
- lazycam.py
- lazycreate_webshell.py
- lazydeepseekcli.py
- lazydisassebler.py
- lazyftpsniff.py
- lazygalazy.py
- lazygptcli.py
- lazygptcli_unified.py
- lazyhoneypot.py
- lazyhttpreverseshell.py
- lazykeygen.py
- lazylfi2rce.py
- lazyllmchat.py
- lazylogpoisoning.py
- lazymariadb_rce_cve_2016-662.py
- lazymidm.py
- lazymitmap.py
- lazynetbios.py
- lazyntlrelayx.py
- lazyopenssh77enum2.py
- lazyphishingai.py
- lazyproxy.py
- lazypwn.py
- lazypwnkit.py
- lazypyautogui.py
- lazyreversentlmv2.py
- lazysearch.py
- lazysearch_bot.py
- lazyseo.py
- lazysmbrelay.py
- lazysniff.py
- lazysqli.py
- lazyssh.py
- lazyvsftp.py
- lazywerkzeug.py
- sql.py
- .rootkit.o.cmd
- Makefile
- Module.symvers
- modules.order
- mr.c
- mrhyde.c
- mrhyde2.c
- mrhyde3.c
- README.md
- rootkit.asm
- rootkit.c
- rootkit.c.bkp.c
- rootkit.mod
- rootkit.mod.c
- rootkit.mod.o
- rootkit.o
- clean_history.sh.sh
- llm_budget.json
- plan.txt
- index.html
- backup.c
- mrhyde.c
- README.md
- win_rin3_rootkit.cs
- win_ring3_rootkit.c
- win_ring3_rootkit.cpp
- dns.txt
- prompt.txt
- subdomains.txt
- 49803.py
- __init__.py
- adcs_attacks.py
- admin_panels.txt
- agent_runner.py
- agent_tool.py
- ai_exploit_chain.py
- ai_fallback.py
- ai_model.py
- amsi.c
- amt_auth_bypass.py
- apt_playbooks.py
- atomic_enricher.py
- auto_pivot.py
- autonomous_exploit_engine.py
- aws_attacks.py
- batrat.bat
- beacon_config_builder.py
- beacon_history.py
- bin2img.py
- bitm_engine.py
- bof_registry.py
- bot.py
- c2_builder.py
- c2_messaging_base.py
- c2_profile.py
- c2_profile_engine.py
- cal.sh
- categories.py
- cicd_enumerator.py
- cli_auth.py
- client.png
- cloud_enum.py
- collab_bp.py
- colors.py
- command_executor.py
- compliance.py
- conditional_hooks.py
- config_store.py
- credential_reuse.py
- credentials.json
- cross_cloud.py
- CVE-2018-15133.php
- CVE-2023-28432.py
- cve_matcher.py
- dacl_abuse.py
- dashboard_bp.py
- dashboard_engine.py
- data.json
- db.py
- delegation_attacks.py
- detailed_search.py
- detection_feed.py
- detection_oracle.py
- digispark.ino
- digispark_android.ino
- digispark_win.ino
- dns_beacon.py
- domain_dominance.py
- dotnet_payload.py
- dpapi_harvester.py
- duckdns.sh
- edr_detector.py
- eegg.sh
- engagement_hooks.py
- entra_id_attacks.py
- estorides_importer.py
- evasion_engine.py
- evasive_payloads.py
- event_bus.py
- event_consumers.py
- event_engine.py
- evilhttprev.sh
- exp.c
- exploit_chain.py
- exploit_recommender.py
- fast_run_service.sh
- forensic_cleaner.py
- gcp_attacks.py
- generate_tools.py
- gpo_abuse.py
- gui_askpass.sh
- hash_cracker.py
- headers.json
- hive_invoke.py
- hostdiscover.sh
- ia_code_analysis.py
- ia_logs_analysis.py
- ia_network_analysis.py
- icmp_client.py
- icmp_server.py
- img2bin.py
- index.html
- intelligence_engine.py
- internal_discover.sh
- iptables_portforward.sh
- json_data.json
- jwtexploit.py
- k8s_attacks.py
- kerberoasting.py
- kerberos_core.py
- kerberos_tickets.py
- kill_chain_viz.py
- killchain.py
- kivi.py
- lazy_rbac.py
- lazyatack.sh
- lazybrutesshuserenum.sh
- lazyclonewars.sh
- lazycloud.py
- lazycurl.sh
- lazyencoder_decoder.py
- lazyevilwimrm.sh
- lazygat.sh
- lazyk8s.py
- lazylynis.sh
- lazymasscan.sh
- lazymobilerevshell.sh
- lazynmap.sh
- lazyown_bprfuzzer.py
- lazyown_bridge.py
- lazyown_metaextract0r.py
- lazyown_parquet_tool.py
- lazyownclient.py
- lazyownerweb.py
- LazyOwnExplorer.py
- lazyownserver.py
- lazypsexec.sh
- lazyreverse_shell.sh
- lazyrtpflood.sh
- lazyvpnshield.sh
- lazywps.sh
- lesson_ingestor.py
- lilsplunky.py
- linux.png
- linux_advanced_payloads.py
- listener_manager.py
- live_surface.py
- llm_adapter.py
- llm_client.py
- llm_evaluator.py
- llm_factory.py
- log_tamper.py
- logging_config.py
- mac.png
- macos_payloads.py
- mario.py
- mcp_agent_bridge.py
- memory_cleaner.py
- memory_store.py
- metrics.py
- mfa_bypass.py
- mkcloudflaretunnel.sh
- module_registry.py
- moe_router.py
- morse.py
- mysql_hookandroot_lib.c
- mysql_hookandroot_lib.so
- network_opsec.py
- nf
- nmap2csv.py
- NotoEmoji-Regular.ttf
- obs_parser.py
- ooficesod0woodo.py
- operation.py
- operator_profiles.py
- opsec_scorer.py
- opsec_scorer_v2.py
- output.txt
- params.json
- payload_factory.py
- phishing_orchestrator.py
- pipeline_engine.py
- planner.py
- playbook_engine.py
- playbook_executor.py
- polymorphic_engine.py
- privesc_predictor.py
- professional_report.py
- r.sh
- reactive_engine.py
- README.md
- recommender.py
- redteam_gym.py
- reflective_dll.py
- report_generator.py
- report_templates.py
- resource_script.py
- reverse-shell.c
- revshell.c
- rich_tui.py
- rl_trainer.py
- routes
- run
- run.bat
- saas_attacks.py
- search.py
- security_sanitizers.py
- session_rag.py
- session_reader.py
- session_state.py
- sleep_obfuscation.py
- smbver.sh
- socks_proxy.py
- staged_delivery.py
- state_manager.py
- sudo_tiocsti.py
- tel.py
- test_lazyencoder_decoder.py
- threat_model.py
- timeline_narrator.py
- timestomper.py
- tmp.sh
- tool_extractor.py
- toposwarm_bridge.py
- traffic_morpher.py
- ttp_coverage.py
- unified_bridge.py
- unified_dashboard.py
- unified_llm_client.py
- update_db.sh
- venator.py
- vuln_agent.py
- vuln_bot_cli.py
- vulnbot.py
- websocket_beacon.py
- windows.png
- wineconfig.sh
- world_model.py
- XssPayloads.txt
- yaml_generator.py
- yara_scanner.py
- RustRevMaker.sh
- README.md
- extended.yaml
- README.md
- binarios.parquet
- detalles.parquet
- lolbas_details.parquet
- lolbas_index.parquet
- README.md
- techniques.parquet
- techniques_enriched.parquet
- default_engagement.json
- README.md
- attack_surface.yaml
- cloud_assessment.yaml
- linux-initial-access.yaml
- post-exploit-loop.yaml
- README.md
- recon-quick.yaml
- supply_chain.yaml
- apt_apt28.yaml
- apt_apt29.yaml
- apt_apt41.yaml
- apt_azure_graph_api.yaml
- apt_cicd_poisoning.yaml
- apt_conti.yaml
- apt_entra_connect.yaml
- apt_fin7.yaml
- apt_lazarus.yaml
- apt_lockbit.yaml
- apt_macos_tcc.yaml
- apt_oauth_token_theft.yaml
- apt_sccm_mecm.yaml
- apt_vdi_breakout.yaml
- attack_plan.yaml
- attack_plan_apt29.yaml
- ExamplePlaybook.yaml
- LazyOwn_auto_20260321_014011.yaml
- README.md
- 01 - template_plugins_yaml.yaml
- amsi_bypass.yaml
- dotnet_reflection.yaml
- etw_bypass.yaml
- generate_c_reverse_shell.lua
- generate_c_reverse_shell.yaml
- generate_cleanup_commands.lua
- generate_cleanup_commands.yaml
- generate_html_payload.lua
- generate_html_payload.yaml
- generate_lateral_command.lua
- generate_lateral_command.yaml
- generate_linux_asm_reverse_shell.lua
- generate_linux_asm_reverse_shell.yaml
- generate_linux_raw_shellcode.lua
- generate_linux_raw_shellcode.yaml
- generate_lolbird.lua
- generate_lolbird.yaml
- generate_msfvenom_loader.lua
- generate_msfvenom_loader.yaml
- generate_msfvenom_loader_windows.lua
- generate_msfvenom_loader_windows.yaml
- generate_reverse_shell.lua
- generate_reverse_shell.yaml
- generate_stub.lua
- generate_stub.yaml
- init_plugins.lua
- kerberos_harvest.lua
- kerberos_harvest.yaml
- lolbas_bitsadmin_exe.lua
- lolbas_bitsadmin_exe.yaml
- lolbas_certutil_download_exec.lua
- lolbas_certutil_download_exec.yaml
- lolbas_certutil_exe.lua
- lolbas_certutil_exe.yaml
- lolbas_mshta_js.lua
- lolbas_mshta_js.yaml
- lolbas_mshta_reverse_shell.lua
- lolbas_mshta_reverse_shell.yaml
- lolbas_rundll32_dll.lua
- lolbas_rundll32_dll.yaml
- lolbas_wmic_xsl_execution.lua
- lolbas_wmic_xsl_execution.yaml
- parse_nmap_with_xmlstarlet.lua
- parse_nmap_with_xmlstarlet.yaml
- powershell_obfuscation.yaml
- README.md
- run_nuclei_on_nmap_files.lua
- run_nuclei_on_nmap_files.yaml
- run_python_rev_c2.lua
- run_python_rev_c2.yaml
- rundll32_sct_from_url.lua
- rundll32_sct_from_url.yaml
- validate_shellcode.lua
- validate_shellcode.yaml
- visualize_network.lua
- visualize_network.yaml
- attack_surface.yaml
- cloud_scan.yaml
- example.yaml
- README.md
- supply_chain_scan.yaml
- __init__.py
- activate_migrations.py
- backfill_addon_os_trigger.py
- build_command_index.py
- fix_migrated_classes.py
- migrate_commandsets.py
- migrate_lazyown.py
- patch_playbook_atomic_ids.py
- README.md
- setup_hermes_mcp.sh
- sync_doc_stats.py
- update_apt_atomic_ids.py
- validate_agent_contract.sh
- infect.c
- pid.c
- shell.c
- go.mod
- go.sum
- implant_crypt.go
- implant_nim.nim
- implant_rust.rs
- listener.go
- loader_linux.go
- loader_windows.go
- monrevlin.go
- png.go
- stub.c
- stub_lin.c
- blazormalware.sh
- configure_krb5.py
- invoke_multipart_form_data_upload.sh
- kern_downloader.sh
- lazync.sh
- load.sh
- payload.sh
- rev
- rev.c
- short_urls.json
- arabportable.php
- bru-jo.php
- pass.txt
- site.txt
- scan-LFI.php
- uploadshellLFI.php
- c2.sh
- shell.php
- user.php
- wp.php
- bin2shellcode.ps1
- enablewebpowershell.bat
- enablewebpowershell.ps1
- img2Exec.ps1
- Invoke-Chrome-Pass.ps1
- Invoke-MultipartFormDataUpload.ps1
- lazybot_avdetected.ps1
- lazycat.ps1
- LazyMemExec.cs
- LazyOwnEvilWMI.ps1
- msfsharp.cs
- netsh_sliver_c2.ps1
- PathExcludedFinder.ps1
- payload.ps1
- powercat.ps1
- PowerUp.ps1
- rev.c
- set-defender.ps1
- shellcode2base64.ps1
- stager.cs
- Tasksbackdoor.ps1
- timestomp.ps1
- upload.ps1
- winp.ps1
- WMIBackdoor.ps1
- download_resources.sh
- routes_to_templates.json
- sslscan-singleip.sh
- tor.sh
- users.txt
- www.py
- ci_strict_mode.md
- llm_budget_cap.md
- conftest.py
- test_orchestrator.py
- __init__.py
- bdd_agent.py
- boy_scout.py
- cicd_agent.py
- config.py
- documentation_agent.py
- models.py
- orchestrator.py
- parser.py
- README.md
- reviewer_agent.py
- sdd_agent.py
- SKILL.md
- SPECS.md
- tdd_agent.py
- validators.py
- __init__.py
- claudemd_rules.py
- config_bridge.py
- constants.py
- executor.py
- hermes_sync.py
- mcp_server.py
- output_compactor.py
- README.md
- SKILL.md
- README.md
- SKILL.md
- __init__.py
- README.md
- test_autonomous_daemon.py
- test_facts.py
- test_harness_e2e.py
- test_hive_mind.py
- test_mcp_smoke.py
- test_objectives.py
- test_parquet_db.py
- aci_planner.py
- autonomous_daemon.py
- autonomous_replay.py
- daemon_control.py
- daemon_health.py
- heartbeat.py
- hive_mind.py
- lazyown.md
- lazyown_automapper.py
- lazyown_campaign.py
- lazyown_claudemd.py
- lazyown_context.py
- lazyown_daemon.py
- lazyown_facts.py
- lazyown_groq_agents.py
- lazyown_hooks.py
- lazyown_llm.py
- lazyown_mcp.py
- lazyown_mcp_helpers.py
- lazyown_mcp_opencode.py
- lazyown_objective.py
- lazyown_parquet_db.py
- lazyown_permissions.py
- lazyown_policy.py
- lazyown_session.py
- mcp_generated_tools.py
- mcp_restart.sh
- mcp_tool_generator.py
- README.md
- sessions_watcher.py
- setup.sh
- swan_agent.py
- toposwarm_autonomous.py
- unified_orchestrator.py
- update_knowledge.py
- conf.py
- index.rst
- README.md
- bootstrap-4.5.2.min.css
- bootstrap-5.3.3.min.css
- icomoon.woff
- quill-bubble.css
- quill-core.css
- quill-snow.css
- select2-4.1.0.min.css
- style.css
- tippy-6.css
- vis-network-9.1.2.min.css
- xterm.css
- pixel.png
- bootstrap-4.5.2.min.js
- bootstrap-5.3.0.bundle.min.js
- chart.min.js
- html2pdf.bundle.min.js
- jquery-3.5.1.slim.min.js
- particles.js
- particles.json
- popper-2.5.4.min.js
- purify-3.0.9.min.js
- quill-2.0.3.js
- select2-4.1.0.min.js
- showdown-2.1.0.min.js
- socket.io-4.0.0.min.js
- socket.io-4.3.2.min.js
- tippy-6.js
- vis-network-9.1.2.min.js
- vis-network.min.js
- xterm-addon-fit-0.7.0.js
- xterm-addon-web-links-0.5.0.js
- xterm.js
- xterm.js.map
- body_report.json
- bot.png
- box.png
- c2.png
- client.png
- computer.png
- container.png
- domain.png
- favicon.ico
- gpo.png
- group.png
- heatmap.png
- host.png
- Linux.png
- Mac-icon.png
- ou.png
- pdf.ico
- port.png
- README.md
- security_dashboard.png
- user.png
- Windows.png
- ai_template_1749689434.2803116.yaml
- ai_template_1749689855.9138038.yaml
- ai_template_1749690366.3437135.yaml
- ai_template_1749690723.1136456.yaml
- ai_template_1749691010.0413928.yaml
- bank_alert.yaml
- README.md
- fake_login.html
- README.md
- ai_template_1749689434.2803116.yaml
- ai_template_1749689855.9138038.yaml
- ai_template_1749690366.3437135.yaml
- ai_template_1749690723.1136456.yaml
- ai_template_1749691010.0413928.yaml
- bank_alert.yaml
- README.md
- fake_login.html
- README.md
- campaigns.html
- create_multivector_campaign.html
- malicious_login.html
- new_campaign.html
- orchestrate_campaign.html
- README.md
- report.html
- 404.html
- 500.html
- addon_creator.html
- addon_view.html
- addons.html
- admin_tenants.html
- admin_users.html
- banners.html
- base.html
- bots.html
- campaigns.html
- change_password.html
- collab.html
- compliance.html
- connect.html
- create_multivector_campaign.html
- create_route.html
- create_tool.html
- cve.html
- cves.html
- decoy.html
- edit_cve.html
- edit_event.html
- edit_note.html
- edit_task.html
- edit_tool.html
- event_config_view.html
- fajeform.html
- fakebackup.html
- fakecam.html
- fakefile.html
- footer.html
- graph.html
- header.html
- header2.html
- index.html
- list_tools.html
- login.html
- malicious_login.html
- mfa_setup.html
- mfa_verify.html
- mitre.html
- nav.html
- new_campaign.html
- orchestrate_campaign.html
- palette.html
- profile.html
- README.md
- register.html
- report.html
- sample.html
- search_results.html
- surface.html
- surface_live.html
- task.html
- tasks.html
- teamserver.html
- terminal.html
- tracking_page.html
- upload.html
- verify.html
- view_note.html
- view_tool.html
- yaml_view.html
- config.py
- README.md
- screenshot.png
- test_commands.py
- __init__.py
- integration_autonomous_flow.py
- README.md
- run_mutation_addon_creator.py
- run_mutation_api_authz.py
- run_mutation_killchain.py
- run_mutation_phase1.py
- run_mutation_tests.py
- test_aci_planner.py
- test_addon_creator.py
- test_aes_key_propagation.py
- test_api_authz.py
- test_attack_surface_addons.py
- test_auto_crypto.py
- test_autonomous_replay.py
- test_autosuggest.py
- test_banner_config.py
- test_beacon_config_builder.py
- test_beacon_history.py
- test_blacksandbeacon_addon.py
- test_bof_registry.py
- test_bridge_catalog_filtered.py
- test_c2_profile_engine.py
- test_categories.py
- test_chain_mode.py
- test_ci_strict.py
- test_claudemd_consistency.py
- test_claudemd_size.py
- test_cli_assign.py
- test_cli_command_sets.py
- test_cli_enhancements.py
- test_collab_and_onboarding.py
- test_command_allowlist.py
- test_command_allowlist_behavior.py
- test_command_chain.py
- test_command_form.py
- test_command_palette.py
- test_command_set_migration.py
- test_conditional_hooks_extended.py
- test_core.py
- test_core_command_bridge.py
- test_core_config.py
- test_core_executor.py
- test_core_modules.py
- test_cors_behavior.py
- test_cors_policy.py
- test_cors_socketio_regression.py
- test_credential_vault.py
- test_credentials_rotation.py
- test_csrf_behavior.py
- test_csrf_policy.py
- test_daemon_control.py
- test_dashboard_routes.py
- test_dashboard_tui.py
- test_db.py
- test_dependencies.py
- test_detection_feed.py
- test_doctor.py
- test_engage_orchestrator.py
- test_engagement_and_ping.py
- test_engagement_command_gate.py
- test_engagement_elo_and_methodology.py
- test_evidence_hints.py
- test_exploration_and_addons.py
- test_fuzzy_picker.py
- test_graph_advisor.py
- test_graph_overlay.py
- test_hash_cracker.py
- test_html_sanitizer.py
- test_https_redirect.py
- test_improvements_spec.py
- test_intelligence_engine.py
- test_killchain.py
- test_killchain_auto_refresh.py
- test_killchain_gap_signal.py
- test_killchain_snapshot.py
- test_killchain_unified.py
- test_killchain_unified_v2.py
- test_lazygui_backend.py
- test_lazygui_graph_widget.py
- test_lazygui_models.py
- test_lazynmap_post.py
- test_lesson_ingestor.py
- test_lint_quality.py
- test_live_surface.py
- test_llm_budget.py
- test_mcp_improvements.py
- test_metrics.py
- test_metrics_aware_selector.py
- test_migrate_lazyown_generator.py
- test_module_registry.py
- test_moe_rl_swan.py
- test_moe_router_check_regression.py
- test_nuclei_parser.py
- test_ops_loot_phase.py
- test_opsec_scorer.py
- test_packaging.py
- test_palette_overlay.py
- test_payload_factory.py
- test_payload_schema.py
- test_phase1_data_gaps.py
- test_pipeline_engine.py
- test_reactive_engine_semantic.py
- test_reactive_hints.py
- test_reactive_hints_expanded.py
- test_reactive_lateral_data.py
- test_reasoning_stream.py
- test_recommendation.py
- test_recon_plan.py
- test_report_banners_endpoints.py
- test_resource_script.py
- test_safe_subprocess.py
- test_safe_subprocess_behavior.py
- test_scope_bound_auto_gate.py
- test_scope_guard.py
- test_scope_guard_integration.py
- test_security_lazyc2.py
- test_security_sanitizers.py
- test_sessions_browser.py
- test_sleep_obfuscation.py
- test_socks_proxy.py
- test_status_bar_operators.py
- test_structured_logging.py
- test_surface_graph.py
- test_themes.py
- test_timeline_browser.py
- test_tips_engine.py
- test_toast_bus.py
- test_trusted_proxy.py
- test_tui_splash.py
- test_tui_style.py
- test_tui_theme_command.py
- test_tui_themes.py
- test_unified_dashboard.py
- test_vuln_mitigations.py
- test_wizard_binary_check.py
- test_world_model_extended.py
- _example.tool
- asrep_roast.tool
- bigbang.tool
- bloodhound-python.tool
- crackmapexec-ldap.tool
- crackmapexec-smb.tool
- dig-reverse.tool
- dig.tool
- dirb.tool
- dirb_domain.tool
- dnsenum.tool
- dnsrecon_axfr.tool
- enum4linux.tool
- enum_rpcbind.tool
- enum_smb.tool
- eternal.tool
- evil-winrm.tool
- ffuf.tool
- ffuf_enum.tool
- finalrecon.tool
- getuserspns.tool
- gobuster-web.tool
- gobuster_dir.tool
- gosbuster_dns.tool
- havoc.tool
- hydrardp.tool
- hydrasmb.tool
- hydrassh.tool
- impacket-getnpusers.tool
- impacket-smbserver.tool
- impacket-userenum.tool
- kerberoast.tool
- kerbrute.tool
- kerbrute_passspray.tool
- ldapdomaindump.tool
- ldapsearch-anon.tool
- ldapsearch.tool
- medusa.tool
- nc-ldap.tool
- nfs.tool
- nikto.tool
- nikto_enum.tool
- nuclei-ad.tool
- nxc-idap.tool
- nxc-ldap.tool
- nxc-nullsession.tool
- nxc-passpol.tool
- nxc-rid.tool
- nxc-winrm.tool
- ollama_enum.tool
- README.md
- rpcclient.tool
- showmount_nfs.tool
- skipfish.tool
- smbclient.tool
- smbclient_list.tool
- smbghost-scanner.tool
- smbmap.tool
- smbmap_user.tool
- smbnmap.tool
- ssh-audit.tool
- sshcheckcve20246387.tool
- sshexploit.tool
- sslscan.tool
- sslyze.tool
- subwfuzz.tool
- swaks_smtp_test.tool
- vncviewer_connect.tool
- wfuzz.tool
- wkhtmltopdf.tool
- README.md
- A310Logger.yar
- AAR.yar
- AbubasbanditBot.yar
- AcidRain.yar
- ActionRAT.yar
- AdaptixBeacon.yar
- Adfind.yar
- adWind.yar
- Adzok.yar
- AgentRacoon.yar
- AgentTesla.yar
- AgnianeStealer.yar
- Agrius.yar
- Akira.yar
- Alfonso.yar
- AlienCrypter.yar
- AlienSpy.yar
- Alkhal.yar
- AllaKore.yar
- Amadey.yar
- Amatera.yar
- Andromeda.yar
- Ap0calypse.yar
- Apocalypse.yar
- APT27.yar
- Arcom.yar
- ARCrypt.yar
- Arechclient2.yar
- Arkei.yar
- ArrowRAT.yar
- Aspire.yar
- AsyncRAT.yar
- Atlas.yar
- AuraStealer.yar
- Aurora.yar
- AuroraStealer.yar
- Avaddon.yar
- Avalon.yar
- AvosLocker.yar
- AxolotlLoader.yar
- Azer.yar
- Azorult.yar
- Babuk.yar
- BackNet.yar
- BackOffLoader.yar
- BackOffPOS.yar
- BACKSPACE.yar
- BadJoke.yar
- BadRabbit.yar
- Bagle.yar
- Baldr.yar
- Bandit.yar
- Bandook.yar
- Banload.yar
- Bazar.yar
- BazarLoader.yar
- BazarLoaderNim.yar
- Beastdoor.yar
- BetaBot.yar
- BHunt.yar
- BioPass.yar
- BitCoinGrabber.yar
- BitPaymer.yar
- BitRAT.yar
- BitterRAT.yar
- BlackByte.yar
- BlackByteGo.yar
- BlackCat.yar
- BlackDropper.yar
- BlackHunt.yar
- BlackMatter.yar
- BlackNET.yar
- BlackNix.yar
- BlackShades.yar
- BlackshadesRAT.yar
- BlankStealer.yar
- Blister.yar
- BlitzGrabber.yar
- BlueBanana.yar
- BlueBot.yar
- Bobik.yar
- BoxCaon.yar
- Bozok.yar
- BrbBot.yar
- BreakStaf.yar
- BreakWin.yar
- BroEx.yar
- BruteRatel.yar
- BubbleLoader.yar
- BuerLoader.yar
- BumbleBee.yar
- Buran.yar
- ButeRAT.yar
- c2_framework_detection.yar
- Caliber.yar
- Carbanak.yar
- CargoBayLoader.yar
- CasperTroy.yar
- Cerber.yar
- ChaChaDDoS.yar
- Chaos.yar
- ChaosBot.yar
- ChChes.yar
- Chinotto.yar
- Chuwi.yar
- Cicada.yar
- ClientMesh.yar
- ClipBanker.yar
- Clop.yar
- cobalt_strike_beacon.yar
- CobaltStrikeBeacon.yar
- CobaltStrikeStager.yar
- CobianRAT.yar
- Codoso.yar
- CoinMiners.yar
- CoinMiningBot.yar
- CommonMagic.yar
- Confucius_B.yar
- Conti.yar
- CookieStealer.yar
- CoreBot.yar
- Covenant.yar
- CRAT.yar
- credential_theft.yar
- CrimsonRAT.yar
- Crown.yar
- CryLock.yar
- CryptBot.yar
- CryptoLocker.yar
- Cryptoshield.yar
- CryptoStealerGo.yar
- Cuba.yar
- Cutlet.yar
- CyberGate.yar
- CyberStealer.yar
- DanaBot.yar
- DarkCloud.yar
- DarkComet.yar
- DarkEye.yar
- DarkGate.yar
- DarkRAT.yar
- DarksideV1.yar
- DCRat.yar
- DeathRansom.yar
- DECAF.yar
- DecryptMyFiles.yar
- DeepRats.yar
- Dharma.yar
- Diavol.yar
- DiscoNightClub.yar
- DocConnect.yar
- DoejoCrypt.yar
- DoomedLoader.yar
- DoppelPaymer.yar
- Downloaders.yar
- Dreambot.yar
- Dridex.yar
- DridexLoader.yar
- DridexV4.yar
- DTstealer.yar
- DuckTail.yar
- Duke.yar
- Echelon.yar
- Egregor.yar
- Ekans.yar
- Emotet.yar
- EmotetLoader.yar
- Enfal.yar
- EnigmaStub.yar
- EpicenterRAT.yar
- Epsilon.yar
- EspioLoader.yar
- EternalRomance.yar
- EvilGrab.yar
- Exaramel.yar
- ExMatter.yar
- ExpressCMS.yar
- Fabookie.yar
- FakeWMI.yar
- Fareit.yar
- Farfli.yar
- FatalRAT.yar
- Fiber.yar
- Ficker.yar
- FirebirdRAT.yar
- Flagpro.yar
- FloodFix.yar
- FoggyWeb.yar
- Fonix.yar
- Formbook.yar
- Foxgrabber.yar
- FPSpy.yar
- FujinamaRAT.yar
- FYAnti.yar
- G0Crypt.yar
- Gandcrab.yar
- GarrantDecrypt.yar
- Gasket.yar
- Gaudox.yar
- GDriveRAT.yar
- Gelsemium.yar
- GetCrypt.yar
- GhostEmperor.yar
- GloomaneStealer.yar
- GoBrut.yar
- Godzilla.yar
- GoldenAxe.yar
- GoldenSpy.yar
- Gootkit.yar
- GraphicalProton.yar
- GravityRAT.yar
- Greame.yar
- GreetingGhoul.yar
- Guidlma.yar
- Guloader.yar
- Gulpix.yar
- HakunaMatata.yar
- Hancitor.yar
- HawkEye.yar
- HawkEyeV9.yar
- HDLocker.yar
- Hello.yar
- Heracles.yar
- Hermes.yar
- HiddenVNC.yar
- HiddenWasp.yar
- HijackLoader.yar
- Hive.yar
- HorusEyesRAT.yar
- Houdini.yar
- HttpBrowser.yar
- HyperBro.yar
- IAmTheKing.yar
- IAmTheKingKeylogger.yar
- IAmTheKingKingOfHearts.yar
- IAmTheKingQueenOfClubs.yar
- IAmTheKingQueenOfHearts.yar
- IAmTheKingScrCap.yar
- IcedID.yar
- IcedIDLoader.yar
- Imminent.yar
- Impacket.yar
- Infinity.yar
- InfinityLock.yar
- InvalidPrinter.yar
- IRCBot.yar
- ISRStealer.yar
- iTranslator.yar
- Jaff.yar
- JanelaRAT.yar
- JavaDropper.yar
- JennLog.yar
- JesterStealer.yar
- JoeGo.yar
- jRat.yar
- JSSLoader.yar
- Jupyter.yar
- Karagany.yar
- Karkoff.yar
- KdcSponge.yar
- KeyBase.yar
- Khonsari.yar
- KillMBR.yar
- Kimsuky.yar
- Kinsing.yar
- Kitty.yar
- KlingonRAT.yar
- KLogExe.yar
- KoadicBAT.yar
- KoadicDOC.yar
- KoadicJS.yar
- KoiLoader.yar
- Konni.yar
- Kovter.yar
- Koxic.yar
- KPortScan.yar
- Kpot.yar
- KrakenStealer.yar
- Kronos.yar
- KTLVdoor.yar
- Kutaki.yar
- LapLas.yar
- LastConn.yar
- Latrodectus.yar
- Laturo.yar
- LaZagne.yar
- LCPDot.yar
- LegionLocker.yar
- Leivion.yar
- LightHand.yar
- LilithRAT.yar
- LimeRAT.yar
- Lockbit.yar
- LockDown.yar
- Locked.yar
- LockFile.yar
- Locky.yar
- LokiBot.yar
- LokiLocker.yar
- LOLKEK.yar
- Lorenz.yar
- LostDoor.yar
- Lu0Bot.yar
- LuminosityLink.yar
- Lumma.yar
- LuxNet.yar
- M00nD3v.yar
- Macoute.yar
- Magniber.yar
- Maktub.yar
- Mangzamel.yar
- MargulasRAT.yar
- MarkiRAT.yar
- MassLogger.yar
- MatanbuchusLoader.yar
- Matiex.yar
- Maze.yar
- MB150.yar
- MediaPI.yar
- MedusaLocker.yar
- MegaCortex.yar
- Megumin.yar
- Mercurial.yar
- Meteorite.yar
- Meterpreter.yar
- Milan.yar
- Mimikatz.yar
- MiniTor.yar
- ModiLoader.yar
- MoDiRAT.yar
- Mole.yar
- MonsterV2.yar
- Motocos.yar
- MountLocker.yar
- MyKings.yar
- Mystic.yar
- NanoCore.yar
- NanoLocker.yar
- Nefilim.yar
- Nemty.yar
- Neptune.yar
- Nermer.yar
- Neshta.yar
- Neteagle.yar
- NetSupport.yar
- NetTraveler.yar
- Netwalker.yar
- NetWire.yar
- NGLite.yar
- Nighthawk.yar
- NightshadeC2.yar
- Niribu.yar
- Nitol.yar
- Nitro.yar
- NitroBunnyDownloader.yar
- NitrogenLoader.yar
- Njrat.yar
- NLBrute.yar
- Nodachi.yar
- NPPSpy.yar
- NWorm.yar
- Obfuscar.yar
- obfuscation_detection.yar
- ObliqueRAT.yar
- Octopus.yar
- OnlyLogger.yar
- OrcaRAT.yar
- OrcusRAT.yar
- Origin.yar
- Orion.yar
- Osno.yar
- Owowa.yar
- Oyster.yar
- OysterBed.yar
- OysterShell.yar
- OzoneRAT.yar
- Pafish.yar
- PandaStealer.yar
- Pandora.yar
- Paradox.yar
- Parallax.yar
- PatchWork.yar
- PCRat.yar
- persistence_mechanism.yar
- PetrWrap.yar
- Petya.yar
- PhantomStealer.yar
- PhemedroneStealer.yar
- Phobos.yar
- Phoenix.yar
- Phorpiex.yar
- PikaBot.yar
- PillowMint.yar
- PingBack.yar
- PirateStealer.yar
- Plasma.yar
- PLEAD.yar
- Plurox.yar
- PoisonIvy.yar
- Polar.yar
- PondRAT.yar
- PoolRAT.yar
- PoshKeylogger.yar
- Poullight.yar
- PovertyStealer.yar
- PowerPool.yar
- PredatorPain.yar
- privesc_detection.yar
- ProLock.yar
- Prometei.yar
- ProtonBot.yar
- Prynt.yar
- Punisher.yar
- PureLoader.yar
- Purge.yar
- PurpleWave.yar
- PWSHCUMII.yar
- Pyrogenic.yar
- PYSA.yar
- PythoRAT.yar
- QakBot.yar
- QiwxxRAT.yar
- QnapCrypt.yar
- QRat.yar
- Quantum.yar
- QuasarRAT.yar
- QuasarStealer.yar
- Quickbind.yar
- QuilClipper.yar
- QuiteRAT.yar
- Qulab.yar
- R77.yar
- Raccoon.yar
- RageStealer.yar
- RagnarLocker.yar
- Ramnit.yar
- RansomEXX.yar
- ransomware_detection.yar
- RanumBot.yar
- RanzyLocker.yar
- Rapid.yar
- Rasftuby.yar
- Ratty.yar
- RCSession.yar
- RDPWrap.yar
- README.md
- RedLeaf.yar
- RedLine.yar
- Redsip.yar
- Remcos.yar
- RemoteUtilitiesRAT.yar
- Renamer.yar
- Responder.yar
- Retefe.yar
- RevCodeRAT.yar
- RevengeRAT.yar
- reverse_shell_payload.yar
- ReverseRAT.yar
- REvil.yar
- Rhadamanthys.yar
- RHttpCtrl.yar
- Rhysida.yar
- Rietspoof.yar
- RisePro.yar
- Robbinhood.yar
- RokRat.yar
- RomCom.yar
- RootTeamStealer.yar
- Rozena.yar
- Rsjon.yar
- RunningRAT.yar
- RustyBuer.yar
- RustyLoader.yar
- RustyStealer.yar
- Ryuk.yar
- S05Kitty.yar
- Salat.yar
- Salfram.yar
- SapphireStealer.yar
- Satan.yar
- Satana.yar
- Scarab.yar
- ScoutElite.yar
- SectopRAT.yar
- Sedreco.yar
- Seduploader.yar
- Sfile.yar
- ShadowTech.yar
- SideWalk.yar
- SilentMoon.yar
- Simda.yar
- SimplePacker.yar
- SlackBot.yar
- Sliver.yar
- SlothfulMedia.yar
- SmallNet.yar
- SmokeLoader.yar
- Sn0wLogger.yar
- Snake.yar
- SNAKEImplant.yar
- Snatch.yar
- Socks5Systemz.yar
- SoftCNApp.yar
- SolarMarker.yar
- SoranoStealer.yar
- Spacecolon.yar
- SparkRAT.yar
- Spectre.yar
- SpyEye.yar
- SpyGate.yar
- Spyro.yar
- SquirrelWaffle.yar
- Stealc.yar
- STEALDEAL.yar
- Stealerium.yar
- SteamHook.yar
- STOP.yar
- StormKitty.yar
- StrelaStealer.yar
- StrifeWater.yar
- StrongPity.yar
- Strrat.yar
- STXRat.yar
- Sub7Nation.yar
- SunCrypt.yar
- SunShuttle.yar
- Surtr.yar
- SweetyStealer.yar
- SystemBC.yar
- T5000.yar
- Taidoor.yar
- Tardigrade.yar
- Taurus.yar
- TClient.yar
- Tefosteal.yar
- TeslaRevenge.yar
- Thanos.yar
- TigerRAT.yar
- TimeTime.yar
- TJKeylogger.yar
- TManager.yar
- Tofsee.yar
- TOITOIN.yar
- Tomiris.yar
- Torisma.yar
- ToxicEye.yar
- TRAT.yar
- TreasureHunter.yar
- TrickBot.yar
- TrickbotModule.yar
- TrueBot.yar
- TrustConnect.yar
- TSCookie.yar
- Turian.yar
- TWarBot.yar
- TYRAT.yar
- UDPRat.yar
- UltraSurf.yar
- UmbralStealer.yar
- Underground.yar
- Unicorn.yar
- UNKInfostealer.yar
- UnlockYourFiles.yar
- Unrecom.yar
- Ursnif.yar
- UrsnifV3.yar
- ValidAlpha.yar
- VanillaRAT.yar
- Varenyky.yar
- VenomRAT.yar
- Vertex.yar
- Vidar.yar
- VIPKeyLogger.yar
- VirLock.yar
- VirusRat.yar
- Vovalex.yar
- VSSDestroy.yar
- Vulturi.yar
- W1RAT.yar
- WanaCry.yar
- Warezov.yar
- WarzoneRAT.yar
- WCE.yar
- webshell_advanced.yar
- webshell_detection.yar
- WellMess.yar
- WhiffyRecon.yar
- WinDealer.yar
- WinGo.yar
- WinosStager.yar
- WobbyChipMBR.yar
- WorldWind.yar
- WSHRAT.yar
- XenoRAT.yar
- XFiles.yar
- XiaoBa.yar
- Xorist.yar
- XorStringsNET.yar
- XpertRAT.yar
- xRAT.yar
- Xtreme.yar
- XWorm.yar
- Zegost.yar
- Zeoticus.yar
- Zeppelin.yar
- ZeroT.yar
- ZeusPanda.yar
- Ziggy.yar
- Zloader.yar
- ZombieBoy.yar
- ZXShell.yar
- .codacyrc
- .coverage
- .env.example
- .eslintignore
- .eslintrc.json
- .gitignore
- .mcp.json
- .pre-commit-config.yaml
- .pylintrc
- .readthedocs.yaml
- .secrets.baseline
- __init__.py
- adversary.json
- AGENTS.md
- app.spec.dist
- banner.py
- CHANGELOG.md
- CHEATSHEET.md
- CLAUDE.md
- CODE_OF_CONDUCT.md
- COMMANDS.md
- COMPARISON.md
- config.json
- CONTRIBUTING.md
- DEPLOY.sh
- discord_c2.py
- docker-compose.yml
- Dockerfile
- Dockerfile.sandbox
- ESSENTIALS.md
- event_config.json
- fast_run_as_r00t.sh
- gen_cert.sh
- install.sh
- key.py
- KNOWLEDGE_BASE.md
- lazy_sentinel4.py
- lazyc2.py
- lazyown.py
- LICENSE
- make.bat
- Makefile
- MANIFEST.in
- my_techniques.json
- opencode.json
- payload.example.json
- pull_request_template.md
- pwntomate.py
- py2elf.sh
- pyproject.toml
- pyvenv.cfg
- QUICKSTART.md
- README.md
- readmeneitor.py
- report.py
- requirements-dev.txt
- requirements-ml.txt
- requirements.txt
- run
- run.bat
- run.ps1
- run_telegram_hermes.sh
- SECURITY.md
- setup.py
- slack_c2_bot.py
- soul.md
- specs.md
- telegram_c2.py
- telegram_hermes.py
- testmeneitor.py
- TUTORIAL_LazyOwn.md
- user_aliases.json
- user_commands.json
- user_split.sh
- users.example.json
- utils.py
- version.json
# Use via CDN
jsDelivrjsDelivr serves any public GitHub repository as a CDN with zero setup. Pick a version and a file to get a ready-to-paste link and snippet.
Command Glossary
Commands referenced in this DOCs, explained below.
clock
View Details ▼
clock
Set the system clock.
clock set {{23}}:{{59}}:{{59}} {{31}} {{april}} {{2000}}
Enter privileged execution mode:
clock active prefer
Auto negotiate with the far end of the link, defaulting to active-clock:
clock passive prefer
Auto negotiate with the far end of the link, defaulting to passive-clock:
login
View Details ▼
login
Manage console and virtual line authentication.
Accessed in configuration mode under `line`.
login local
Use local username and password for authentication:
login {{user}}
Log in as a user:
login -f {{user}}
Log in as user without authentication if user is preauthenticated:
amass
View Details ▼
amass
In-depth Attack Surface Mapping and Asset Discovery tool.
Some subcommands such as `intel` have their own usage documentation.
amass {{intel|enum}} {{options}}
Execute an Amass subcommand:
amass -help
Display help:
amass {{intel|enum}} -help
Display help on an Amass subcommand:
apropos
View Details ▼
apropos
Search the manual pages for names and descriptions.
See also: `man`.
apropos {{regex}}
Search for a keyword using a `regex`:
apropos {{[-l|--long]}} {{regex}}
Search without restricting the output to the terminal width (long output):
apropos {{regex_1}} {{[-a|--and]}} {{regex_2}} {{[-a|--and]}} {{regex_3}}
Search for pages that match all the `regex` given:
arjun
View Details ▼
arjun
Discover HTTP parameters for web applications.
arjun -u {{https://example.com/page.php}}
Scan a URL for GET parameters:
arjun -u {{https://example.com/api}} -m POST
Scan using POST method:
arjun -u {{https://example.com}} -o {{path/to/output.json}}
Save discovered parameters to a JSON file:
arp-scan
View Details ▼
arp-scan
Send ARP packets to hosts (specified as IP addresses or hostnames) to scan the local network.
arp-scan {{[-l|--localnet]}}
Scan the current local network:
arp-scan {{10.0.0.1}}
Scan a specific host:
arp-scan {{192.168.1.1}}/{{24}}
Scan an IP network with a custom bitmask:
banner
View Details ▼
banner
Print the argument as a large ASCII art.
banner "{{Hello World}}"
Print the text message as a large banner (quotes are optional):
banner {{[-w|--width]}} 50 "{{Hello World}}"
Use a banner width of 50 characters:
banner
Read text from `stdin`:
chisel
View Details ▼
chisel
Create TCP/UDP tunnels, transported over HTTP, secured via SSH.
Includes both client and server in the same `chisel` executable.
chisel server
Run a Chisel server:
chisel server {{[-p|--port]}} {{server_port}}
Run a Chisel server listening to a specific port:
chisel server --auth {{username}}:{{password}}
Run a chisel server that accepts authenticated connections using username and password:
claude
View Details ▼
claude
An agent-based coding tool that understands your code base and helps you code faster through natural language commands.
claude prompt
Execute with prompt:
claude update
Update `claude`:
claude mcp list
Get the list of specified MCP servers:
cron
View Details ▼
cron
A system scheduler for running jobs or tasks unattended.
The command to submit, edit, or delete entries to `cron` is called `crontab`.
tldr crontab
View documentation for managing `cron` entries:
crunch
View Details ▼
crunch
Wordlist generator.
crunch {{1}} {{3}}
Output a list of words of length 1 to 3 with only lowercase characters:
crunch {{8}} {{8}} {{0123456789abcdef}}
Output a list of hexadecimal words of length 8:
crunch {{1}} {{1}} -p {{abc}}
Output a list of all permutations of abc (lengths are not processed):
dig
View Details ▼
dig
DNS lookup utility.
See also: `resolvectl`, `nslookup`, `host`.
dig +short {{example.com}}
Lookup the IP(s) associated with a hostname (A records):
dig +noall +answer {{example.com}}
Get a detailed answer for a given domain (A records):
dig +short {{example.com}} {{A|MX|TXT|CNAME|NS}}
Query a specific DNS record type associated with a given domain name:
dirsearch
View Details ▼
dirsearch
Web path scanner.
dirsearch {{[-u|--url]}} {{url}} --extensions-list
Scan a web server for common paths with common extensions:
dirsearch {{[-l|--url-list]}} {{path/to/url-list.txt}} {{[-e|--extensions]}} {{php,jsp,aspx,...}}
Scan a list of web servers for common paths with given file extensions:
dirsearch {{[-u|--url]}} {{url}} --extensions-list {{[-w|--wordlists]}} {{path/to/url-paths1.txt,path/to/url-paths2.txt,...}}
Scan a web server for user-defined paths with common extensions:
edit
View Details ▼
edit
A terminal-based text editor from Microsoft.
edit {{path/to/file}}
Open a file:
tldr run-mailcap
View documentation for the original command:
<Ctrl f>{{pattern}}<Enter>
Search for a pattern:
feroxbuster
View Details ▼
feroxbuster
Simple, fast, recursive content discovery tool written in Rust.
Used to brute-force hidden paths on web servers and more.
feroxbuster --url "{{https://example.com}}" --wordlist {{path/to/file}} --threads {{100}} --extensions "{{php,txt}}" --random-agent
Discover specific directories and files that match in the wordlist with extensions and 100 threads and a random user-agent:
feroxbuster --url "{{https://example.com}}" --wordlist {{path/to/file}} --no-recursion --proxy "{{http://127.0.0.1:8080}}"
Enumerate directories without recursion through a specific proxy:
feroxbuster --url "{{https://example.com}}" --extract-links
Find links in webpages:
ffuf
View Details ▼
ffuf
A fast web fuzzer written in Go.
The `FUZZ` keyword is used as a placeholder. `ffuf` will try to hit the URL by replacing the word `FUZZ` with every word in the wordlist.
ffuf -c -w {{path/to/wordlist.txt}} -u {{https://example.com/FUZZ}}
Enumerate directories using [c]olored output and a [w]ordlist specifying a target [u]RL:
ffuf -w {{path/to/subdomains.txt}} -u {{https://FUZZ.example.com}}
Enumerate webservers of subdomains by changing the position of the keyword:
ffuf -o -w {{path/to/wordlist.txt}} -u {{https://example.com/FUZZ}} -t {{500}} -x {{http://127.0.0.1:8080}}
Fuzz with specified [t]hreads (default: 40) and pro[x]ying the traffic and save [o]utput to a file:
ftp
View Details ▼
ftp
Tools to interact with a server via File Transfer Protocol.
ftp {{ftp.example.com}}
Connect to an FTP server and run in interactive mode:
ftp {{host}}
Connect to a remote FTP server interactively:
ftp {{ip_address}} {{port}}
Connect to an FTP server specifying its IP address and port:
gcc
View Details ▼
gcc
Preprocess and compile C and C++ source files, then assemble and link them together.
Part of GCC (GNU Compiler Collection).
gcc {{path/to/source1.c path/to/source2.c ...}} {{[-o|--output]}} {{path/to/output_executable}}
Compile multiple source files into an executable:
gcc {{path/to/source.c}} -Wall {{[-o|--output]}} {{output_executable}}
Activate output of all errors and warnings:
gcc {{path/to/source.c}} -Wall {{[-g|--debug]}} -Og {{[-o|--output]}} {{path/to/output_executable}}
Show common warnings, debug symbols in output, and optimize without affecting debugging:
git clone
View Details ▼
git clone
Clone an existing repository.
git clone {{remote_repository_location}} {{path/to/directory}}
Clone an existing repository into a new directory (the default directory is the repository name):
git clone --recursive {{remote_repository_location}}
Clone an existing repository and its submodules:
git clone {{[-n|--no-checkout]}} {{remote_repository_location}}
Clone only the `.git` directory of an existing repository:
git
View Details ▼
git
Distributed version control system.
Some subcommands such as `commit`, `add`, `branch`, `switch`, `push`, etc. have their own usage documentation.
git init
Create an empty Git repository:
git clone {{https://example.com/repo.git}}
Clone a remote Git repository from the internet:
git status
View the status of the local repository:
gobuster
View Details ▼
gobuster
Brute-forces hidden paths on web servers and more.
gobuster dir {{[-u|--url]}} {{https://example.com/}} {{[-w|--wordlist]}} {{path/to/file}}
Discover directories and files that match in the wordlist:
gobuster dns {{[-do|--domain]}} {{example.com}} {{[-w|--wordlist]}} {{path/to/file}}
Discover subdomains:
gobuster s3 {{[-w|--wordlist]}} {{path/to/file}}
Discover Amazon S3 buckets:
hashcat
View Details ▼
hashcat
Fast and advanced password recovery tool.
hashcat {{[-m|--hash-type]}} {{hash_type_id}} {{[-a|--attack-mode]}} 3 {{hash_value}}
Perform a brute-force attack (mode 3) with the default hashcat mask:
hashcat {{[-m|--hash-type]}} {{hash_type_id}} {{[-a|--attack-mode]}} 3 {{hash_value}} "{{?d?d?d?d}}"
Perform a brute-force attack (mode 3) with a known pattern of 4 digits:
hashcat {{[-m|--hash-type]}} {{hash_type_id}} {{[-a|--attack-mode]}} 3 --increment {{hash_value}} "{{?a?a?a?a?a?a?a?a}}"
Perform a brute-force attack (mode 3) using at most 8 of all printable ASCII characters:
hello
View Details ▼
hello
Print "Hello, world!", "hello, world", or a customizable text.
hello
Print "Hello, world!":
hello {{[-t|--traditional]}}
Print "hello, world", the traditional type:
hello {{[-g|--greeting]}} "{{greeting_text}}"
Print a text message:
htop
View Details ▼
htop
Display dynamic real-time information about running processes.
An enhanced version of `top`.
See also: `top`, `atop`, `glances`, `btop`, `btm`.
htop
Start `htop`:
htop {{[-u|--user]}} {{username}}
Start `htop` displaying processes owned by a specific user:
htop {{[-t|--tree]}}
Display processes hierarchically in a tree view to show the parent-child relationships:
httprobe
View Details ▼
httprobe
Take a list of domains and probe for working HTTP and HTTPS servers.
cat {{input_file}} | httprobe
Probe a list of domains from a text file:
cat {{input_file}} | httprobe --prefer-https
Only check for HTTP if HTTPS is not working:
cat {{input_file}} | httprobe -p {{https:2222}}
Probe additional ports with a given protocol:
hydra
View Details ▼
hydra
Online password guessing tool.
Protocols supported include FTP, HTTP(S), SMTP, SNMP, XMPP, SSH, and more.
hydra-wizard
Start Hydra's wizard:
hydra -l {{username}} -P {{path/to/wordlist.txt}} {{host_ip}} {{ssh}}
Guess SSH credentials using a given username and a list of passwords:
hydra -L {{path/to/usernames.txt}} -P {{path/to/wordlist.txt}} {{host_ip}} {{https-post-form}} "{{url_without_host}}:{{https_post_request}}:{{login_failed_string}}"
Guess HTTPS webform credentials using two specific lists of usernames and passwords ("https_post_request" can be like "username=^USER^&password=^PASS^"):
ipinfo
View Details ▼
ipinfo
Official CLI for the IPinfo.io IP geolocation and network intelligence API.
Note: Some commands will require a token from IPinfo.io.
ipinfo myip
Display details for your current IP address:
ipinfo {{ip_address}}
Display details for a specific IP address:
ipinfo bulk {{path/to/ips.txt}}
Display details for multiple IP addresses in bulk from a file:
john
View Details ▼
john
Password cracker.
john {{path/to/hashes.txt}}
Crack password hashes:
john --show {{path/to/hashes.txt}}
Show passwords cracked:
john --show --users={{user_ids}} {{path/to/hashes1.txt path/to/hashes2.txt ...}}
Display users' cracked passwords by user identifier from multiple files:
lazygit
View Details ▼
lazygit
A simple terminal UI for Git commands, providing an intuitive interface for managing repositories.
lazygit
Open Lazygit in the current repository:
lazygit {{[-p|--path]}} {{path/to/repository}}
Open Lazygit for a specific Git repository:
lazygit {{status|branch|log|stash|...}}
Start Lazygit with focus on a specific panel:
ldapsearch
View Details ▼
ldapsearch
Query an LDAP directory.
ldapsearch {{[-D|--bindDN]}} '{{admin_DN}}' {{[-w|--bindPassword]}} '{{password}}' {{[-h|--hostname]}} {{ldap_host}} {{[-b|--baseDN]}} {{base_ou}} '{{memberOf=group1}}' displayName
Query an LDAP server for all items that are a member of the given group and return the object's displayName value:
ldapsearch {{[-D|--bindDN]}} '{{admin_DN}}' {{[-u|--keyStorePasswordFile]}} '{{password_file}}' {{[-h|--hostname]}} {{ldap_host}} {{[-b|--baseDN]}} {{base_ou}} '{{memberOf=group1}}' displayName
Query an LDAP server with a no-newline password file for all items that are a member of the given group and return the object's displayName value:
ldapsearch {{[-D|--bindDN]}} '{{admin_DN}}' {{[-w|--bindPassword]}} '{{password}}' {{[-h|--hostname]}} {{ldap_host}} {{[-b|--baseDN]}} {{base_ou}} '{{memberOf=group1}}' {{[-z|--sizeLimit]}} 5 displayName
Return 5 items that match the given filter:
logout
View Details ▼
logout
Exit a login shell.
logout
Exit a login shell:
logout {{exit_code}}
Exit a login shell and specify a return value:
medusa
View Details ▼
medusa
A modular and parallel login brute-forcer for a variety of protocols.
medusa -d
List all installed modules:
medusa -M {{ssh|http|web-form|postgres|ftp|mysql|...}} -q
Show usage example of a specific module (use `medusa -d` for listing all installed modules):
medusa -M ftp -h host -U {{path/to/username_file}} -P {{path/to/password_file}}
Execute brute force against an FTP server using a file containing usernames and a file containing passwords:
msfvenom
View Details ▼
msfvenom
Manually generate payloads for metasploit.
msfvenom {{[-l|--list]}} payloads
List payloads:
msfvenom {{[-l|--list]}} formats
List formats:
msfvenom {{[-p|--payload]}} {{payload}} --list-options
Show payload options:
nano
View Details ▼
nano
Text editor. An enhanced `pico` clone.
See also: `pico`, `rnano`.
nano {{path/to/file1 path/to/file2 ...}}
Open specific files, moving to the next file after closing the previous one:
nano {{[-I|--ignorercfiles]}}
Start the editor without using configuration files:
nano +{{line}},{{column}} {{path/to/file}}
Open a file and position the cursor at a specific line and column:
nbtscan
View Details ▼
nbtscan
Scan networks for NetBIOS name information.
nbtscan {{192.168.0.1/24}}
Scan a network for NetBIOS names:
nbtscan {{192.168.0.1}}
Scan a single IP address:
nbtscan -v {{192.168.0.1/24}}
Display verbose output:
netexec
View Details ▼
netexec
This command is an alias of `nxc`.
tldr nxc
View documentation for the original command:
next
View Details ▼
next
React framework that uses server-side rendering for building optimized web applications.
next dev
Start the current application in development mode:
next dev {{[-p|--port]}} {{port}}
Start the current application and listen on a specific port:
next build
Build the current application optimized for production:
ngrok
View Details ▼
ngrok
Reverse proxy that creates a secure tunnel from a public endpoint to a locally running web service.
ngrok http {{80}}
Expose a local HTTP service on a given port:
ngrok http {{example.com}}:{{80}}
Expose a local HTTP service on a specific host:
ngrok http https://localhost
Expose a local HTTPS server:
nikto
View Details ▼
nikto
Web server scanner which performs tests against web servers for multiple items.
perl nikto.pl {{[-h|-host]}} {{192.168.0.1}}
Perform a basic Nikto scan against a target host:
perl nikto.pl {{[-h|-host]}} {{192.168.0.1}} {{[-p|-port]}} {{443}}
Specify the port number when performing a basic scan:
perl nikto.pl {{[-h|-host]}} {{https://192.168.0.1:443/}}
Scan ports and protocols with full URL syntax:
npm run
View Details ▼
npm run
Run a script.
npm run
List available scripts:
npm run {{script_name}}
Run a script:
npm run {{script_name}} -- {{argument}} {{--option}}
Pass arguments to a script:
nuclei
View Details ▼
nuclei
Fast and customizable vulnerability scanner using a simple YAML-based DSL.
nuclei {{[-ut|-update-templates]}}
Update `nuclei` templates to the latest released version (downloaded to `~/nuclei-templates` on macOS/Linux or `%USERPROFILE%\nuclei-templates` on Windows):
nuclei -tl {{[-pt|-type]}} {{dns|file|http|headless|tcp|workflow|ssl|websocket|whois|code|javascript}}
[l]ist all [t]emplates by specific [p]rotocol [t]ype:
nuclei {{[-as|-automatic-scan]}} {{[-u|-target]}} {{example.com}}
Run an automatic web scan using Wappalyzer technology detection for a specific target [u]RL/host:
openssl s_client
View Details ▼
openssl s_client
Create TLS client connections.
openssl s_client -connect {{host}}:{{port}} 2>/dev/null | openssl x509 -noout -dates
Display the start and expiry dates for a domain's certificate:
openssl < /dev/null s_client -connect {{host}}:{{port}}
Display the certificate presented by an SSL/TLS server:
openssl s_client -connect {{host}}:{{port}} -servername {{hostname}}
Set the Server Name Indicator (SNI) when connecting to the SSL/TLS server:
pip install
View Details ▼
pip install
Install Python packages.
pip install {{package1 package2 ...}}
Install one or more packages:
pip install {{package1 package2 ...}} {{[-U|--upgrade]}}
Upgrade all specified packages to the latest version, installing any that are not already present:
pip install {{package}}=={{version}}
Install a specific version of a package:
pop
View Details ▼
pop
Send emails from your terminal.
pop
Launch the Text-based User Interface:
pop < {{path/to/message.md}} --from {{[email protected]}} --to {{[email protected]}} --subject "{{On the Subject of Ducks...}}" --attach {{path/to/attachment}}
Send an email using the content of a Markdown file as body:
pop --help
Display help:
pup
View Details ▼
pup
HTML parsing tool.
cat {{index.html}} | pup --color
Transform a raw HTML file into a cleaned, indented, and colored format:
cat {{index.html}} | pup '{{tag}}'
Filter HTML by element tag name:
cat {{index.html}} | pup '{{div#id}}'
Filter HTML by ID:
python3
View Details ▼
python3
This command is an alias of `python`.
tldr python
View documentation for the original command:
route
View Details ▼
route
Show and manipulate the route table.
route -n
Display the information of route table:
sudo route add "{{destination_ip_address}}" "{{gateway_address}}"
Add a route to a destination through a gateway:
sudo route add -net {{ip_address}} netmask {{netmask_address}} gw {{gw_address}}
Add route rule:
rsync
View Details ▼
rsync
Transfer files either to or from a remote host (but not between two remote hosts), by default using SSH.
To specify a remote path, use `user@host:path/to/file_or_directory`.
rsync {{path/to/source}} {{path/to/destination}}
Transfer a file (use `--dry-run` to simulate the transfer):
rsync {{[-a|--archive]}} {{path/to/source}} {{path/to/destination}}
Use archive mode (recursively copy directories, copy symlinks without resolving, and preserve permissions, ownership, and modification times):
rsync {{[-zvhP|--compress --verbose --human-readable --partial --progress]}} {{path/to/source}} {{path/to/destination}}
Compress the data as it is sent to the destination, display verbose and human-readable progress, and keep partially transferred files if interrupted:
scp
View Details ▼
scp
Secure copy.
Copy files between hosts using Secure Copy Protocol over SSH.
scp {{path/to/local_file}} {{remote_host}}:{{path/to/remote_file}}
Copy a local file to a remote host:
scp -P {{port}} {{path/to/local_file}} {{remote_host}}:{{path/to/remote_file}}
Use a specific port when connecting to the remote host:
scp {{remote_host}}:{{path/to/remote_file}} {{path/to/local_directory}}
Copy a file from a remote host to a local directory:
sherlock
View Details ▼
sherlock
Find usernames across social networks.
See also: `maigret`.
sherlock {{username}} --output {{path/to/file}}
Search for a specific username on social networks saving the results to a file:
sherlock {{username1 username2 ...}} --folderoutput {{path/to/directory}}
Search for specific usernames on social networks saving the results into a directory:
sherlock --tor {{username}}
Search for a specific username on social networks using the Tor network:
shred
View Details ▼
shred
Overwrite files to securely delete data.
shred {{path/to/file}}
Overwrite a file:
shred {{[-v|--verbose]}} {{path/to/file}}
Overwrite a file and show progress on the screen:
shred {{[-z|--zero]}} {{path/to/file}}
Overwrite a file, leaving zeros instead of random data:
smbclient
View Details ▼
smbclient
FTP-like client to access SMB/CIFS resources on servers.
smbclient {{[-L|--list]}} {{server}} --no-pass
List available shares on a server anonymously:
smbclient //{{server}}/{{share}}
Connect to a share (will prompt for a password):
smbclient {{[-U|--user]}} {{domain/username}} //{{server}}/{{share}}
Connect to a share as a specific user:
smbmap
View Details ▼
smbmap
Enumerate samba share drives across an entire domain.
smbmap --host-file {{path/to/file}}
Enumerate hosts with NULL sessions enabled and open shares:
smbmap {{[-u|--username]}} {{username}} --prompt -H {{ip_address}}
Display SMB shares and permissions on a [H]ost, prompting for user's password or NTLM hash:
smbmap {{[-u|--username]}} {{username}} --prompt -H {{ip_address}} -x {{command}}
Execute a shell command on a remote system:
snmpwalk
View Details ▼
snmpwalk
SNMP query tool.
snmpwalk -v 1 -c {{community}} {{ip_address}}
Query the system information of a remote host using SNMPv1 and a community string:
snmpwalk -v 2c -c {{community}} {{ip_address}}:{{port}} {{oid}}
Query system information on a remote host by OID using SNMPv2 on a specified port:
snmpwalk -v 3 -l {{authNoPriv}} -u {{username}} -a {{MD5|SHA}} -A {{passphrase}} {{ip_address}} {{oid}}
Query system information on a remote host by OID using SNMPv3 and authentication without encryption:
socat
View Details ▼
socat
Multipurpose relay (SOcket CAT).
sudo socat - TCP-LISTEN:8080,fork
Listen to a port, wait for an incoming connection and transfer data to STDIO:
sudo socat OPENSSL-LISTEN:4433,reuseaddr,cert=./cert.pem,cafile=./ca.cert.pem,key=./key.pem,verify=0 STDOUT
Listen on a port using SSL and print to `stdout`:
sudo socat - TCP4:www.example.com:80
Create a connection to a host and port, transfer data in STDIO to connected host:
sqlmap
View Details ▼
sqlmap
Detect and exploit SQL injection flaws.
python sqlmap.py {{[-u|--url]}} "{{http://www.example.com/vuln.php?id=1}}"
Run sqlmap against a single target URL:
python sqlmap.py {{[-u|--url]}} "{{http://www.example.com/vuln.php}}" --data="{{id=1}}"
Send data in a POST request (`--data` implies POST request):
python sqlmap.py {{[-u|--url]}} "{{http://www.example.com/vuln.php}}" --data="{{query=foobar;id=1}}" --param-del="{{;}}"
Change the parameter delimiter (& is the default):
ssh
View Details ▼
ssh
Secure Shell is a protocol used to securely log onto remote systems.
It can be used for logging or executing commands on a remote server.
ssh {{username}}@{{remote_host}}
Connect to a remote server:
ssh {{username}}@{{remote_host}} -i {{path/to/key_file}}
Connect to a remote server with a specific [i]dentity (private key):
ssh {{username}}@10.0.0.1 -p {{2222}}
Connect to a remote server with IP `10.0.0.1` and using a specific [p]ort (Note: `10.0.0.1` can be shortened to `10.1`):
sshd
View Details ▼
sshd
Secure Shell Daemon - allows remote machines to securely log in to the current machine.
Remote machines can execute commands as it is executed at this machine.
sshd
Start daemon in the background:
sshd -D
Run sshd in the foreground:
sshd -D -d
Run with verbose output (for debugging):
sslscan
View Details ▼
sslscan
Check SSL/TLS protocols and ciphers supported by a server.
sslscan {{example.com}}
Test a server on port 443:
sslscan {{example.com}}:{{465}}
Test a specified port:
sslscan --show-certificate {{example.com}}
Show certificate information:
tcpdump
View Details ▼
tcpdump
Dump traffic on a network.
tcpdump {{[-D|--list-interfaces]}}
List available network interfaces:
sudo tcpdump {{[-i|--interface]}} {{eth0}}
Capture the traffic of a specific interface:
sudo tcpdump -A tcp
Capture all TCP traffic showing contents ([A]SCII) in console:
time
View Details ▼
time
Measure how long a command took to run.
Note: `time` can either exist as a shell builtin, a standalone program, or both.
See also: `times`.
time {{command}}
Run the `command` and print the time measurements to `stdout`:
time
Display the current system time and prompt to enter a new time (leave empty to keep unchanged):
time read
Create a very simple stopwatch (only works in Bash):
tree
View Details ▼
tree
Show the contents of the current directory as a tree.
tree -L {{num}}
Print files and directories up to `num` levels of depth (where 1 means the current directory):
tree
Display the tree for the current directory:
tree -d
Print directories only:
trufflehog
View Details ▼
trufflehog
Find and verify credentials in files, Git repositories, S3 buckets, and Docker images.
trufflehog git {{https://github.com/trufflesecurity/test_keys}} --only-verified
Scan a Git repository for verified secrets:
trufflehog github --org {{trufflesecurity}} --only-verified
Scan a GitHub organization for verified secrets:
trufflehog git {{https://github.com/trufflesecurity/test_keys}} --only-verified --json
Scan a GitHub repository for verified keys and get JSON output:
unzip
View Details ▼
unzip
Extract files/directories from Zip archives.
See also: `zip`.
unzip {{path/to/archive1.zip path/to/archive2.zip ...}}
Extract all files/directories from specific archives into the current directory:
unzip {{path/to/archive1.zip path/to/archive2.zip ...}} -d {{path/to/output}}
Extract files/directories from archives to a specific path:
unzip -c {{path/to/archive1.zip path/to/archive2.zip ...}}
Extract files/directories from archives to `stdout` alongside the extracted file names:
venv
View Details ▼
venv
Create lightweight virtual environments in Python.
python -m venv {{path/to/virtual_environment}}
Create a Python virtual environment:
{{[.|source]}} {{path/to/virtual_environment}}/bin/activate
Activate the virtual environment (Linux and macOS):
{{path\to\virtual_environment}}\Scripts\activate.bat
Activate the virtual environment (Windows):
wfuzz
View Details ▼
wfuzz
A web application bruteforcer.
wfuzz -w {{path/to/file}} -p {{127.0.0.1:8080:HTTP}} {{http://example.com/FUZZ}}
Directory and file bruteforce using the specified [w]ordlist and also [p]roxying the traffic:
wfuzz -w {{path/to/file}} -f {{filename}} {{http://example.com/FUZZ}}
Save the results to a [f]ile:
wfuzz -c -w {{path/to/file}} --sc {{200,301,302}} {{http://example.com/FUZZ}}
Show [c]olorized output while only showing the declared response codes in the output:
whatweb
View Details ▼
whatweb
Next-generation web scanner.
whatweb {{website1 website2 ...}}
Scan websites/targets for web technologies:
whatweb {{[-i|--input-file]}} {{targets_file}}
Read targets/websites from a file:
whatweb {{[-v|--verbose]}} {{example.com}}
Scan a website/target in verbose mode:
wpscan
View Details ▼
wpscan
WordPress vulnerability scanner.
wpscan --update
Update the vulnerability database:
wpscan --url {{url}}
Scan a WordPress website:
wpscan --url {{url}} --stealthy
Scan a WordPress website, using random user agents and passive detection:
apt install
View Details ▼
apt install
Install packages for Debian-based distributions.
sudo apt install {{package}}
Install a package, or update it to the latest version:
sudo apt install {{[-V|--verbose-versions]}} {{package}}
Display verbose package version information during installation or update:
cewl
View Details ▼
cewl
URL spidering tool for making a cracking wordlist from web content.
cewl {{[-d|--depth]}} 2 {{[-w|--write]}} {{path/to/wordlist.txt}} {{url}}
Create a wordlist file from the given URL up to 2 links depth:
cewl --with-numbers {{[-m|--min_word_length]}} 5 {{url}}
Output an alphanumeric wordlist from the given URL with words of minimum 5 characters:
cewl --debug {{[-e|--email]}} {{url}}
Output a wordlist from the given URL in debug mode including email addresses:
dnsmap
View Details ▼
dnsmap
The dnsmap command scans a domain for common subdomains e.g. smtp.domain.org.
dnsmap {{example.com}}
Scan for subdomains using the internal wordlist:
dnsmap {{example.com}} -w {{path/to/wordlist.txt}}
Specify a list of subdomains to check for:
dnsmap {{example.com}} -c {{path/to/file.csv}}
Store results to a CSV file:
enum4linux
View Details ▼
enum4linux
Enumerate Windows and Samba information from remote systems.
enum4linux -a {{remote_host}}
Try to enumerate using all methods:
enum4linux -u {{user_name}} -p {{password}} {{remote_host}}
Enumerate using given login credentials:
enum4linux -U {{remote_host}}
List usernames from a given host:
getcap
View Details ▼
getcap
Display the name and capabilities of each specified file.
getcap {{path/to/file1 path/to/file2 ...}}
Get capabilities for the given files:
getcap -r {{path/to/directory1 path/to/directory2 ...}}
Get capabilities for all the files recursively under the given directories:
getcap -v {{path/to/file1 path/to/file2 ...}}
Display all searched entries even if no capabilities are set:
ldapdomaindump
View Details ▼
ldapdomaindump
Dump users, computers, groups, OS, and membership information via LDAP to HTML, JSON, and greppable output.
See also: `ldapsearch`.
ldapdomaindump {{[-u|--user]}} {{domain}}\{{username}} {{[-p|--password]}} {{password|ntlm_hash}} {{hostname|ip}}
Dump all information using the given LDAP account:
ldapdomaindump {{[-r|--resolve]}} {{[-u|--user]}} {{domain}}\{{username}} {{[-p|--password]}}{{password}} {{hostname|ip}}
Dump all information, resolving computer hostnames:
ldapdomaindump {{[-r|--resolve]}} {{[-n|--dns-server]}} {{domain_controller_ip}} {{[-u|--user]}} {{domain}}\{{username}} {{[-p|--password]}}{{password}} {{hostname|ip}}
Dump all information, resolving computer hostnames with the selected DNS server:
links
View Details ▼
links
Command-line text-only web browser.
See also: `links2`.
links {{https://example.com}}
Visit a website:
links -anonymous {{https://example.com}}
Apply restrictions for anonymous account:
links -enable-cookies {{0|1}} {{https://example.com}}
Enable Cookies (`1` to enable):
lynis
View Details ▼
lynis
System and security auditing tool.
sudo lynis update info
Check that Lynis is up-to-date:
sudo lynis audit system
Run a security audit of the system:
sudo lynis audit dockerfile {{path/to/dockerfile}}
Run a security audit of a Dockerfile:
ntpdate
View Details ▼
ntpdate
Synchronize and set the date and time via NTP.
sudo ntpdate {{host}}
Synchronize and set date and time:
ntpdate -q {{host}}
Query the host without setting the time:
sudo ntpdate -u {{host}}
Use an unprivileged port in case a firewall is blocking privileged ports:
ports
View Details ▼
ports
Update/list the ports tree on a CRUX system.
ports -u
Update the ports tree:
ports -l
List the ports in the current tree:
ports -d
Check the differences between installed packages and the ports tree:
rev
View Details ▼
rev
Reverse a line of text or a file.
rev
Reverse text typed into terminal:
rev {{path/to/file}}
Reverse each line in a file to `stdout`:
echo "hello" | rev
Reverse the text string "hello":
rpcclient
View Details ▼
rpcclient
MS-RPC client tool (part of the samba suite).
rpcclient {{[-U|--user]}} {{domain}}\{{username}}%{{password}} {{ip_address}}
Connect to a remote host:
rpcclient {{[-U|--user]}} {{username}} {{[-W|--workgroup]}} {{domain}} {{[-N|--no-pass]}} {{ip_address}}
Connect to a remote host on a domain without a password:
rpcclient {{[-U|--user]}} {{domain}}\{{username}} --pw-nt-hash {{ip_address}}
Connect to a remote host, passing the password hash:
swaks
View Details ▼
swaks
Swiss Army Knife SMTP, the all-purpose SMTP transaction tester.
swaks {{[-t|--to]}} {{[email protected]}} {{[-s|--server]}} {{test-server.example.net}}
Deliver a standard test email to `[email protected]` on port 25 of `test-server.example.net`:
swaks {{[-t|--to]}} {{[email protected]}} {{[-f|--from]}} {{[email protected]}} {{[-a|--auth]}} {{CRAM-MD5}} {{[-au|--auth-user]}} {{[email protected]}} --header-X-Test "{{test_email}}"
Deliver a standard test email, requiring CRAM-MD5 authentication as user `[email protected]`. An "X-Test" header will be added to the email body:
swaks {{[-t|--to]}} {{[email protected]}} --attach - {{[-s|--server]}} {{test-server.example.com}} {{[-n|--suppress-data]}} {{path/to/eicar.txt}}
Test a virus scanner using EICAR in an attachment. Don't show the message DATA part:
tshark
View Details ▼
tshark
Packet analysis tool, CLI version of Wireshark.
tshark
Monitor packets from the default interface:
tshark -f '{{udp port 53}}'
Only capture packets matching a specific capture filter:
tshark -Y '{{http.request.method == "GET"}}'
Only show packets matching a specific output filter:
netsh
View Details ▼
netsh
Manage Windows network settings.
Some subcommands such as `wlan` have their own usage documentation.
netsh add helper {{path\to\file.dll}}
Add a helper Dynamic Link Library (DLL):
netsh show helper
Show all loaded helper DLLs:
netsh delete helper {{path\to\file.dll}}
Delete a helper DLL:
psexec
View Details ▼
psexec
Execute a command-line process on a remote machine.
This is an advanced command and it might potentially be dangerous.
psexec \\{{remote_host}} cmd
Execute a command using `cmd` in a remote shell:
psexec \\{{remote_host}} -u {{user_name}} -p {{password}}
Execute a command on a remote host (pre-authenticated):
psexec \\{{remote_host}} cmd /c {{command}} -an ^>{{path\to\file.txt}}
Execute a command remotely and output the result to a file:
