A C2 post-exploitation framework
Alan Framework is a post-exploitation framework useful during red-team activities.
If you find my tool useful, please consider to sponsor me.
The creation of this kind of software has always caused controversies. If you're wondering why I decided to create this tool, it's because I'm convinced that the ultimate learning experience is implementing what you learned. During the reverse engineering process, many small details are overlooked. Little by little, these details prevent the researcher from having a complete picture of what is going on. Finally, I'm a programmer first, and I love to develop this kind of program 😄
Blog posts
For more information on its usage please read the documentation.
To compile Alan the following actions must be performed:
Demo videos
proxy command for pivotinginfo and info++ commands display if the agent is using a proxyrun command that cause the & option to not workalan.logevidences folderinfo commandVanilla package type for agent creation. This allows a better integration of custom packer.run was extended to support the execution of Javascript files.info++ command now shows the Volume label and the FS type.run commandkill commandexec commandinject message since it can be achieved with the run command in backgroundupload and download commandsinfo commandshell command to execute a single commandinject command. This command allows the operator to inject code into a remote processsleep command performed in short sleep of 400 msec each.sleeplisteners since superfluousinfo command with more informationquit command to exitmigrate commandps command to list the currently running processesdownload command to locally download a file or an entire directoryupload command to upload files to the compromised hostSuccessRequest as HTTP server response option to customize the http/s listener responseErrorRequest to customize the http/s listener response for bad requestsprepend and append as HTTP server request option to specify in the agent profdetach command to temporary exit from a joined agentdetach command to temporary exit from a command shelllisteners command to list the available listenersget-config command to download the current agent configurationupdate command to update the agent configuration