{"id":13639754,"url":"https://github.com/jm33-m0/emp3r0r","last_synced_at":"2026-04-28T03:06:52.628Z","repository":{"id":38210263,"uuid":"236146680","full_name":"jm33-m0/emp3r0r","owner":"jm33-m0","description":"Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Modular Post‑Exploitation, and OPSEC‑Focused Transport","archived":false,"fork":false,"pushed_at":"2026-04-27T02:35:24.000Z","size":151380,"stargazers_count":1702,"open_issues_count":1,"forks_count":275,"subscribers_count":34,"default_branch":"v4","last_synced_at":"2026-04-27T04:25:02.553Z","etag":null,"topics":["c2","emp3r0r","hacking-tool","linux","local-privilege-escalation","malware","penetration-testing-framework","post-exploitation","rat","redteam","redteaming","rootkit","stealth","trojan-malware"],"latest_commit_sha":null,"homepage":"https://infosec.exchange/@jm33","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jm33-m0.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"github":"jm33-m0"}},"created_at":"2020-01-25T08:55:08.000Z","updated_at":"2026-04-27T02:35:27.000Z","dependencies_parsed_at":"2023-02-02T05:45:45.347Z","dependency_job_id":"fdc7e99c-b988-4e72-afb4-7be24984f027","html_url":"https://github.com/jm33-m0/emp3r0r","commit_stats":{"total_commits":2053,"total_committers":10,"mean_commits":205.3,"dds":"0.10521188504627377","last_synced_commit":"89c402eeedb81701cff5614330033c5c74316190"},"previous_names":[],"tags_count":444,"template":false,"template_full_name":null,"purl":"pkg:github/jm33-m0/emp3r0r","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jm33-m0%2Femp3r0r","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jm33-m0%2Femp3r0r/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jm33-m0%2Femp3r0r/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jm33-m0%2Femp3r0r/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jm33-m0","download_url":"https://codeload.github.com/jm33-m0/emp3r0r/tar.gz/refs/heads/v4","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jm33-m0%2Femp3r0r/sbom","scorecard":{"id":523802,"data":{"date":"2025-08-11","repo":{"name":"github.com/jm33-m0/emp3r0r","commit":"83a9cd209d9cb7720d2bcd4e51b41f2a2cf4b960"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.9,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:28","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:29","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Warn: topLevel 'packages' permission set to 'write': .github/workflows/release-please.yml:9","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release-please.yml:7","Warn: no topLevel permission defined: .github/workflows/stale.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":0,"reason":"Found 0/26 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":0,"reason":"binaries present in source code","details":["Warn: binary detected: core/modules/bettercap/bettercap:1","Warn: binary detected: core/modules/elvish/elvish:1","Warn: binary detected: core/modules/elvish_win/elvish.exe:1","Warn: binary detected: core/modules/go_lpe/go_lpe:1","Warn: binary detected: core/modules/vaccine/bash:1","Warn: binary detected: core/modules/vaccine/find:1","Warn: binary detected: core/modules/vaccine/nano:1","Warn: binary detected: core/modules/vaccine/patchelf:1","Warn: binary detected: core/modules/vaccine/python3:1","Warn: binary detected: tor/tor:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: CLibFuzzer integration found: core/modules/stager/tinflate.c:597"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'v3'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v3.4.2 not signed: https://api.github.com/repos/jm33-m0/emp3r0r/releases/226389498","Warn: release artifact v3.4.1 not signed: https://api.github.com/repos/jm33-m0/emp3r0r/releases/226044138","Warn: release artifact v3.4.0 not signed: https://api.github.com/repos/jm33-m0/emp3r0r/releases/225710408","Warn: release artifact v3.3.2 not signed: https://api.github.com/repos/jm33-m0/emp3r0r/releases/225428569","Warn: release artifact v3.3.1 not signed: https://api.github.com/repos/jm33-m0/emp3r0r/releases/225327549","Warn: release artifact v3.4.2 does not have provenance: https://api.github.com/repos/jm33-m0/emp3r0r/releases/226389498","Warn: release artifact v3.4.1 does not have provenance: https://api.github.com/repos/jm33-m0/emp3r0r/releases/226044138","Warn: release artifact v3.4.0 does not have provenance: https://api.github.com/repos/jm33-m0/emp3r0r/releases/225710408","Warn: release artifact v3.3.2 does not have provenance: https://api.github.com/repos/jm33-m0/emp3r0r/releases/225428569","Warn: release artifact v3.3.1 does not have provenance: https://api.github.com/repos/jm33-m0/emp3r0r/releases/225327549"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/jm33-m0/emp3r0r/codeql-analysis.yml/v3?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/jm33-m0/emp3r0r/codeql-analysis.yml/v3?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/jm33-m0/emp3r0r/codeql-analysis.yml/v3?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/jm33-m0/emp3r0r/codeql-analysis.yml/v3?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-please.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/jm33-m0/emp3r0r/release-please.yml/v3?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-please.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/jm33-m0/emp3r0r/release-please.yml/v3?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-please.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/jm33-m0/emp3r0r/release-please.yml/v3?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/jm33-m0/emp3r0r/stale.yml/v3?enable=pin","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (4) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-20T03:47:50.977Z","repository_id":38210263,"created_at":"2025-08-20T03:47:50.977Z","updated_at":"2025-08-20T03:47:50.977Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32364117,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-27T20:07:02.737Z","status":"online","status_checked_at":"2026-04-28T02:00:07.250Z","response_time":56,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["c2","emp3r0r","hacking-tool","linux","local-privilege-escalation","malware","penetration-testing-framework","post-exploitation","rat","redteam","redteaming","rootkit","stealth","trojan-malware"],"created_at":"2024-08-02T01:01:04.436Z","updated_at":"2026-04-28T03:06:52.622Z","avatar_url":"https://github.com/jm33-m0.png","language":"Go","funding_links":["https://github.com/sponsors/jm33-m0"],"categories":["Go (531)","Go"],"sub_categories":[],"readme":"\u003cimg align=\"left\" width=\"150\" height=\"150\" alt=\"emp3r0r\" src=\"https://github.com/user-attachments/assets/65550dfb-ea5a-49e8-a036-8c7df349f5f4\" /\u003e\n\n### emp3r0r\n\n**Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Modular Post‑Exploitation, and OPSEC‑Focused Transport**\n\n\u003cbr clear=\"all\" /\u003e\n\n[![Discord](https://img.shields.io/badge/Discord-Join%20Server-7289da?style=for-the-badge\u0026logo=discord\u0026logoColor=white)](https://discord.gg/vU98aQtk9f)\n[![GitHub Sponsors](https://img.shields.io/badge/GitHub-Sponsor-ff69b4?style=for-the-badge\u0026logo=github\u0026logoColor=white)](https://github.com/sponsors/jm33-m0)\n[![Screenshots](https://img.shields.io/badge/View-Screenshots-blue?style=for-the-badge)](./Screenshots.md)\n\n[![Go Report Card](https://goreportcard.com/badge/gojp/goreportcard)](https://goreportcard.com/report/github.com/jm33-m0/emp3r0r/core)\n![GitHub go.mod Go version](https://img.shields.io/github/go-mod/go-version/jm33-m0/emp3r0r?filename=core%2Fgo.mod)\n[![Tests](https://github.com/jm33-m0/emp3r0r/actions/workflows/test.yml/badge.svg)](https://github.com/jm33-m0/emp3r0r/actions/workflows/test.yml)\n![GitHub License](https://img.shields.io/github/license/jm33-m0/emp3r0r)\n[![GitHub release](https://img.shields.io/github/release/jm33-m0/emp3r0r.svg)](https://github.com/jm33-m0/emp3r0r/releases)\n\n---\n\n\u003cimg width=\"2560\" height=\"1392\" alt=\"image\" src=\"https://github.com/user-attachments/assets/264e7752-aef6-4451-aca6-db29b1d45f78\" /\u003e\n\n## What is emp3r0r?\n\nemp3r0r is a comprehensive post-exploitation framework designed from the ground up for Linux environments. While most C2 platforms treat Linux as an afterthought, emp3r0r implements a **zero-trust architecture** with ephemeral cryptographic identities, perfect forward secrecy, and autonomous mesh networking for penetration testing and red team operations.\n\n## What Makes emp3r0r Different?\n\n### 🔐 TOFU Identity Pinning (Immutable per Enrollment)\n\nemp3r0r enforces **Trust-on-first-use (TOFU)** with strict UUID/public-key pinning on first successful enrollment. After enrollment, the pinned identity is immutable for that lifecycle: if the same UUID appears with a different key, the connection is rejected as clone/impersonation. Re-enrollment with changed credentials requires a deliberate `forget_agent` first.\n\n**Why this matters:** This blocks silent identity drift and session hijacking patterns. Trust comes from CA-signed claims plus pinned DB state, not mutable runtime metadata.\n\n### 🔒 Perfect Forward Secrecy for All Communications\n\nEvery C2 session uses **ECDH key exchange** with **HKDF-derived session keys**. Past traffic remains secure even if long-term keys or agents are compromised. Each session's encryption keys are unique and cannot be derived from other sessions.\n\n**Why this matters:** Traditional C2s use static encryption keys. If those keys are recovered, historical network captures can be decrypted. emp3r0r's PFS ensures that compromising today's session keys doesn't reveal previous communications.\n\n### 🕸️ Peer-to-Peer (P2P) Mesh Network\n\nAgents in isolated network segments **autonomously discover and tunnel through internet-connected peers** via a gossip-based (memberlist) mesh network. The mesh hop transport is **pluggable**: the default is `mtls` — camouflage mTLS 1.3 using ephemeral, malleable certificates — with `kcp` (reliable UDP) also available. All hops are further wrapped in AES-GCM end-to-end encryption. **No unnecessary noise** in your C2 infrastructure: agents connect to each other instead of C2 server; **no broadcasting**; configurable bootstrap peers allowing granular control.\n\n**Why this matters:** Manual pivoting requires constant operator intervention and breaks when intermediate hosts fail. emp3r0r's agents automatically form redundant communication paths, ensuring persistence through resilient peer discovery and relay.\n\n### 🚪 Bring2CC: Reverse Tunneling for Isolated Targets\n\nWhen agents **cannot make outbound connections**, `Bring2CC` reverse-proxies them back to the C2 server using SSH + KCP tunneling. This inverts the connection model: instead of the C2 reaching into the network, isolated targets are tunneled out to the C2 infrastructure.\n\n**Why this matters:** Traditional C2s fail when egress filtering blocks outbound connections. Bring2CC enables access to air-gapped segments by having internet-connected hosts pull isolated targets out through reverse tunnels.\n\n### 💾 Memory-Only Operations with Transparent Encryption\n\nAgents use an **in-memory filesystem with AES-GCM encryption** for all file operations. Bash, PowerShell, Python, and ELF modules execute entirely from memory. Large files automatically spill to **encrypted disk storage** when memory is exhausted. The agent creates no dedicated directories or persistent configuration files.\n\n**Why this matters:** EDR and forensic tools rely on disk artifacts for detection and analysis. emp3r0r's memory-first design minimizes disk writes. When disk spillover occurs, all data is encrypted and lacks identifying file extensions or headers.\n\n### 🧩 Native BOF Support (Cross-Platform)\n\nExecute **Windows COFF objects** on Windows agents with typed argument packing (LPSTR/LPWSTR/INT/BOOL/BINARY). On Linux, load **ELF object files (.o)** entirely in-memory with the same modularity. Modules use a standardized schema for cross-platform consistency.\n\n**Why this matters:** BOFs avoid process creation overhead and are difficult to detect. emp3r0r brings this capability to Linux, where most C2 frameworks rely on forking processes or interpreting shell scripts.\n\n### 🎭 Pluggable C2 Transport + JA3 Evasion + CBOR\n\nemp3r0r supports **pluggable C2 channel wrappers**. In v4, the default is `h2conn`, and `plain_http` is also available. `plain_http` runs over HTTP/1.1 and can be proxied by CDN/reverse proxies directly, without the websocket `--cdn2proxy` bridge.\n\nHTTP2/TLS connections use **uTLS** to randomize TLS Client Hello fingerprints, preventing static JA3 signature detection. All network traffic and data storage uses **CBOR** (binary) instead of JSON, reducing bandwidth by 30-40% and avoiding text-based parsing signatures.\n\n**Why this matters:** Network monitoring tools fingerprint TLS handshakes for application identification. Static TLS implementations create consistent signatures. emp3r0r randomizes these on every connection while using a compact binary protocol that lacks JSON's obvious structure.\n\n---\n\n## Quick Start\n\n### Docker Deployment\n\nPodman is used here, you can use Docker if you like. Just replace `podman` with `docker`.\n\n```bash\n# Clone the project\ngit clone --depth=1 https://github.com/jm33-m0/emp3r0r.git \u0026\u0026 cd emp3r0r\n\n# Step 1: Build the archive on the host using a throwaway container\npodman run --rm -v .:/src:z -w /src/core golang:1.26.2 \\\n    /bin/bash -c \"apt update \u0026\u0026 apt install -y sudo curl git jq tmux zstd libcap2-bin build-essential \u0026\u0026 ./build.sh --install\"\n\n# Step 2: Build your slim production image\npodman build -t emp3r0r:4.2.3 . # use any tag you like\n\n# Run the server. Be sure to change your port mappings to fit your environment\nmkdir ~/.emp3r0r\npodman run -it --rm --cap-add=NET_ADMIN --device /dev/net/tun:/dev/net/tun \\\n  -v \"$HOME/.emp3r0r:/root/.emp3r0r\" \\\n  -p 12345:12345 -p 13377:13377/udp \\\n  --name emp3r0r-server \\\n  emp3r0r:4.2.3 \\\n  server --c2-hosts 1.2.3.4 --http-port 12345 --operator-port 13377\n\n# Server prints C2 connection command\nemp3r0r client --c2-port 13377 --server-wg-key '0OKqMZmJfLDhAQLST4MKtKNa6MKxVkLn3UcOP14sMA8=' --server-wg-ip '10.88.14.158' --operator-wg-ip '10.88.14.236' --operator-wg-key 'LOe4sUyjyyIS3Kjnmz0SpKJwvDGle0880Q73qzsMg48=' --c2-host \u003cYOUR_PUBLIC_IP\u003e\n```\n\nAnd follow the on-screen instructions given by `emp3r0r server`. Transfer `emp3r0r-operator-kit.tar.zst` to your operator machine and install it.\n\n```bash\n# Run the command given by emp3r0r server on your operator machin after installation\nemp3r0r client --operator-port 13377 --server-wg-key '0OKqMZmJfLDhAQLST4MKtKNa6MKxVkLn3UcOP14sMA8=' --server-wg-ip '10.88.14.158' --operator-wg-ip '10.88.14.236' --operator-wg-key 'LOe4sUyjyyIS3Kjnmz0SpKJwvDGle0880Q73qzsMg48=' --c2-host 1.2.3.4\n```\n\n`emp3r0r client` automatically downloads and applies config files from C2 server via WireGuard tunnel.\n\n### Generate Agent Payloads\n\nUse the `generate` command from within the emp3r0r shell interface to create customized agent payloads.\n\nExample (standalone direct C2):\n\n```bash\ngenerate --type linux_executable --arch amd64 --cc your.domain.com\n```\n\nExample (mesh gateway):\n\nThe gateway peer:\n\n```bash\ngenerate --type linux_executable --arch amd64 --cc your.domain.com \\\n\t--p2p --direct-c2 --p2p-transport mtls\n```\n\nAn intermediate peer:\n\n```bash\n# 1.2.3.4 is the pre-existing agent node that you want to use as bootstrap peer\ngenerate --type linux_executable --arch amd64 --cc your.domain.com \\\n\t--p2p --p2p-transport mtls --peers 1.2.3.4\n```\n\n---\n\n## Additional Capabilities\n\n### Stealth \u0026 Evasion\n\n- **sRDI-like Shellcode Stager**: Load ELF binaries from memory without touching disk, similar to sRDI for Windows.\n- **Self-suspension \u0026 Resumption**: Agents can suspend themselves and let the stager manage their memory; the stager rotates XOR-based obfuscation while the agent is idle.\n- **Module Stomping**: Disguise malicious modules by loading them into the memory space of legitimate system libraries.\n- **OPSEC Warnings**: Real-time warnings for operations that pose operational security risks (e.g., \"fork and run\" patterns, unencrypted disk activity).\n- **Anti-debug/analysis** measures to make inspection harder.\n\n### Operator Experience\n\n- **Adaptive tmux UI**: Native integration with dynamic status bars, adaptive layouts, and real-time agent/C2 status monitoring.\n- **Intelligent auto-completion** with syntax highlighting.\n- **Pluggable Frontend**: Develop your own frontend by replicating `operator` package features.\n\n### File Transfer System\n\n- **Smart Transfer Strategy**: Agents can fetch files from peer agents via encrypted KCP tunnels before falling back to C2, improving speed and stealth.\n- **Integrity \u0026 Reliability**: SHA256 verification plus **resumable uploads/downloads** so interrupted transfers continue from the last offset.\n- **Compression**: Zstandard compression reduces bandwidth usage and accelerates transfers.\n- **FileServer Module**: Agents can host an encrypted HTTP server to share files with other agents, enabling peer-to-peer distribution.\n\n### Network Pivoting\n\n- **Flexible Pivoting**: Gossip mesh relay plus reverse-tunnel workflows for segmented networks.\n- **KCP-based UDP tunneling** for speed and resilience in high-latency environments.\n- **TOR/CDN** support for additional operational cover.\n\n### Payload Delivery\n\n- **Advanced Linux Stager**: 1.5K self-contained stage0 downloader; opsec focused; keeps the agent payload encrypted until execution; auto-restarts with jitter when connectivity requires.\n- **Agent-Side Listener**: Deploy listeners on compromised hosts to serve payloads internally, bypassing slow C2 connections.\n- **Multi-stage delivery** for Linux and Windows with ELF/DLL/shellcode options.\n\n### Post-Exploitation Arsenal\n\n- **OpenSSH credential harvesting** with real-time monitoring (`ssh_harvester`).\n- **Cross-platform memory dumping** capabilities (`mem_dump`).\n- **LPE**: Privilege escalation tools with automated suggestions (`lpe_suggest`).\n- **Log Sanitization**: `clean_log` module for anti-forensics.\n\n---\n\n## Documentation \u0026 Support\n\n### Community\n\nJoin our [Discord server](https://discord.gg/vU98aQtk9f) for real-time discussions, technical support, and the latest updates on emp3r0r development.\n\n### Resources\n\n- 📝 [Security Policy](./SECURITY.md)\n- 📜 [Changelog](./CHANGELOG.md)\n- 📦 [Module Development (including COFF/BOF)](https://github.com/jm33-m0/emp3r0r/wiki/Modules)\n\n### Troubleshooting\n\n- **Connection stalls**: Verify C2 host/WireGuard settings.\n- **Compatibility**: Remove `~/.emp3r0r` for a clean install; make sure to use the same build.\n- **Support**: Always use the latest release to get support.\n\n---\n\n## Support Development\n\nIf emp3r0r has proven valuable in your security research and testing, consider supporting its continued development via [GitHub Sponsors](https://github.com/sponsors/jm33-m0).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjm33-m0%2Femp3r0r","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjm33-m0%2Femp3r0r","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjm33-m0%2Femp3r0r/lists"}