Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
FFM — Freedom Fighting Mode: open source hacking harness | Kitploit
Tools/GitHubGitHub/justicerage/ffm
Privilege EscalationLateral MovementData ExfiltrationInformation GatheringPost-ExploitationPenetration TestingCommand and ControlUtilities & FrameworksRed Teaming
GitHubjusticerage/ffm

FFM

Freedom Fighting Mode: open source hacking harness

34947175 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

Freedom Fighting Mode (FFM)

FFM is a hacking harness that you can use during the post-exploitation phase of a red-teaming engagement. The idea of the tool was derived from a 2007 conference from @thegrugq.

It was presented at SSTIC 2018 (video) and the accompanying slide deck is available at this url. If you're not familiar with this class of tools, it is strongly advised to have a look at them to understand what a hacking harness' purpose is. All the comments are included in the slides.

This project is distributed under the terms of the GPL v3 License.

Documentation

The primary documentation lives in this README and the command modules under commands/. The SSTIC talk links above remain the best high-level background for how the harness is meant to be used. Additional walkthrough material is available at:

  • https://ice-wzl.gitbook.io/hacknetics/c2-frameworks/ffm-documentation

Contributors

  • ice-wzl contributed commands, documentation, and refactors during the project history.

Installation

Docker Install

  • With the diversity of modern terminal prompts, we highly recommend using docker with this tool.
  • Utilizing the Dockerfile in this repository will drastically cut down on potential errors encountered.
  • Utilizing a container to interact with remote hosts is also more secure. If you were to get exploited while interacting with a remote host, they would be sitting in your container vice your actual host. Lets still hope that does not happen.
  • Ensure you have Docker installed on your local system
git clone https://github.com/JusticeRage/FFM.git
cd /FFM

docker build Docker_Install/ -t ffm:ffm

docker image list 
REPOSITORY                TAG         IMAGE ID      CREATED        SIZE
localhost/ffm             ffm         fb6dd17e3b91  9 minutes ago  614 MB
docker.io/library/ubuntu  22.04       3b418d7b466a  2 weeks ago    80.3 MB

#run your new container and drop into a /bin/bash prompt as root
docker run -it --entrypoint /bin/bash -u 0 fb6dd17e3b91
  • Once in your container set the passwd for root and neo
  • su neo and now you are all set

Non Docker Install

  • Not recommended
 git clone https://github.com/JusticeRage/FFM.git
 cd /FFM
 pip install -r requirements.txt

Usage

The goal of a hacking harness is to act as a helper that automates common tasks during the post-exploitation phase, but also safeguards the user against mistakes they may make.

It is an instrumentation of the shell. Run ./ffm.py to activate it and you can start working immediately. Commands are split across the small modules under commands/, with commands/command_manager.py handling discovery and registration. The main groups are enumeration, help, stealth, transfer, and execution.

There are two commands you need to know about:

  • Type !list to display all the commands provided by the harness.
  • Type !list tags to see the different tags that commands can be binned under
!list tags
List of commands available:
	 enumeration
	 execution
	 help
	 stealth
	 transfer
  • You can now type !list enumeration (or one of the other tags) to see commands that fall into that category.
!list enumeration
List of commands available:
	!backup-hunter: Hunts for backup files
	!info: Returns CPU(s), Architecture, Memory, and Kernel Verison for the current machine.
	!log: Toggles logging the harness' input and output to a file.
	!mtime: Returns files modified in the last X minutes
	!os: Prints the distribution of the current machine.
	!db-hunter: Hunts for .sqlite, .sqlite3, and .db files
	!sshkeys: Hunts for Private and Public SSH keys on the current machine.
	!suid: Finds SUID, SGID binaries on the current machine.
	--snip--

  • Type SHIFT+TAB to perform tab completion on the local machine. This may be useful if you're ssh'd into a remote computer but need to reference a file that's located on your box.

List of features

This hacking harness provides a few features that are described below. As they are described, the design philosophy behind the tool will also be introduced. It is not expected that all the commands implemented in FFM will suit you. Everyone has their own way of doing things, and tuning the harness to your specific need is likely to require you to modify some of the code and/or write a few plugins. A lot of effort went into making sure this is a painless task.

Commands

Enumeration Commands

  • !os is an extremely simple command that just runs cat /etc/*release* to show what OS the current machine is running. It is probably most valuable as a demonstration that in the context of a hacking harness, you can define aliases that work across machine boundaries. SSH into any computer, type !os and the command will be run. The enumeration commands live in commands/enumeration_commands.py, the help commands in commands/help_commands.py, and the stealth-related commands are split across commands/stealth_commands.py, commands/notty_sudo.py, and commands/log_control.py.
  • !backup-hunter Hunts for backup files
  • !info Returns CPU(s), Architecture, Memory, and Kernel Verison for the current machine.
  • !log Toggles logging the harness' input and output to a file. Implemented in commands/log_control.py.
  • !mtime Returns files modified in the last X minutes. For example !mtime 5 will get all files on the local machine (that you have rights to see) that have been modified in the last 5 minutes.
  • !db-hunter Hunts for .sqlite, .sqlite3, and .db files and other database files
  • !sshkeys Hunts for Private and Public SSH keys on the current machine.
  • !suid Finds SUID, SGID binaries on the current machine.
  • !strange-dirs Checks device starting at user specified path for strange directories on a host
  • !sudo-version Checks for a vulnerable sudo version
  • !vm Checks if device is a Virtual Machine

Transfer Commands

  • Commands that help you pull and push files, pretty straight forward.
  • !download [remote file] [local path] gets a file from the remote machine and copies it locally through the terminal. This command is a little more complex because more stringent error checking is required but it's another command you can easily read to get started. It lives in commands/download_file.py. Note that it requires xxd or od on the remote machine to function properly.
  • !download-dir [remote directory] [local destination] streams a tar archive of a remote directory through the terminal and extracts it locally without touching the remote filesystem. It lives in commands/download_directory.py. It requires tar and base64 on the remote machine, and uses gzip as well when available.
  • !upload [local file] [remote path] works exactly the same as the previous command, except that a local file is put on the remote machine. It lives in commands/upload_file.py.

Execution Commands

Download Tool