{"id":15505953,"url":"https://github.com/n00py/post-ex","last_synced_at":"2026-03-15T22:47:35.060Z","repository":{"id":41142658,"uuid":"67277539","full_name":"n00py/pOSt-eX","owner":"n00py","description":"Post-exploitation scripts for OS X persistence and privesc","archived":false,"fork":false,"pushed_at":"2017-04-12T19:46:03.000Z","size":26,"stargazers_count":73,"open_issues_count":0,"forks_count":25,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-10-11T08:14:26.305Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://www.n00py.io/2016/10/using-email-for-persistence-on-os-x/","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/n00py.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2016-09-03T07:33:41.000Z","updated_at":"2025-10-11T01:32:29.000Z","dependencies_parsed_at":"2022-09-09T21:20:56.988Z","dependency_job_id":null,"html_url":"https://github.com/n00py/pOSt-eX","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/n00py/pOSt-eX","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/n00py%2FpOSt-eX","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/n00py%2FpOSt-eX/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/n00py%2FpOSt-eX/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/n00py%2FpOSt-eX/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/n00py","download_url":"https://codeload.github.com/n00py/pOSt-eX/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/n00py%2FpOSt-eX/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30553575,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-15T15:03:43.933Z","status":"ssl_error","status_checked_at":"2026-03-15T15:03:37.630Z","response_time":61,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-10-02T09:25:01.943Z","updated_at":"2026-03-15T22:47:35.034Z","avatar_url":"https://github.com/n00py.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"### Now included in Empire 2.0 Beta\n- bashdoor.py - Empire module to backdoor the sudo command\n- mail.py - Empire Module to add mail rule persistence \n- piggyback.py - Empire Module for piggybacking off of sudo sessions\n-  ard.py - Enables ScreenSharing to allow you to connect to the host via VNC.\n\nIt's recommended just to use the Empire modules, but I've left the other scripts I created when initially developing this.  \n\nhttps://www.n00py.io/2016/10/using-email-for-persistence-on-os-x/\n\nhttps://www.n00py.io/2016/10/privilege-escalation-on-os-x-without-exploits/\n\n# pOSt-eX - OS X post-exploitation scripts\n- mail.py - Creates a an ApleScript payload with Empire and configures a mail rule to launch it\n- persist.py - EmPyre module implementation of mail.py\n- monitor.py - Piggybacks off a user's sudo session to spawn an agent with root privileges \n- piggyback.py - EmPye module of monitor.py\n\n## MailPersist - Post-exploitation script for OS X persistance \n\n## ABOUT:\nThis script creates a new rule in the OS X Mail application to automatically trigger an AppleScript payload when an email is recieved using a trigger word in the subject of the email.\n\nThe trigger email will be deleted before it is visible.  The Script Monitor will also be killed imediately after executing the python stager. There should not be any visual indicators. \n\n## INSTALL:\n\nAll dependancies are met on a default installation of OS X.  With that said, you will likely want to use EmPyre to create your AppleScript payload. \nhttps://github.com/adaptivethreat/EmPyre\n\n## USAGE:\nCreating an AppleScript payload with [Empyre](https://github.com/adaptivethreat/EmPyre):\n```\n(EmPyre) \u003e listeners\n(EmPyre: listeners) \u003e set Name mylistener\n(EmPyre: listeners) \u003e execute\n(EmPyre: listeners) \u003e usestager applescript mylistener\n(EmPyre: stager/applescript) \u003e execute\n```\nOpen mail.py and paste the output in the specified area.  Modify the trigger word as you see fit.  \n\nWhen pasting the AppleScript payload from Empire, you need to make two modifications:\n- Double up the backslash characters\n- Remove the final double quote \n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fn00py%2Fpost-ex","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fn00py%2Fpost-ex","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fn00py%2Fpost-ex/lists"}