Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
LSTAR — LSTAR - CobaltStrike 综合后渗透插件 | Kitploit
Tools/GitHubGitHub/lintstar/lstar
Penetration Testing FrameworksPrivilege EscalationPersistence MechanismsExploitationLateral MovementInformation GatheringPost-ExploitationCommand and ControlRed TeamingPayload Development
GitHublintstar/lstar
1.3k16894 years agoReviewed by Kitploit

LSTAR

LSTAR - CobaltStrike 综合后渗透插件

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

LSTAR - Aggressor

A plugin from initial access to domain takeover, enabling intranet traversal

With the goal of simplifying CS right-click operations and facilitating integration, referencing a large number of post-exploitation plugins

Restructured and enriched host credential acquisition, multi-level intranet penetration, hidden scheduled tasks, bypass-enabled Mimikatz, clone and add user functions, etc.

Features:

  • Cooperate with CobaltStrike's TCP, SMB, Proxy and other methods for internet-restricted hosts to penetrate complex network environments
  • Provide multiple bypass execution methods for RDP related, AddUser, LsassDump and other functions to handle unusual environments
  • Integrate multiple shadow user and hidden scheduled task functions running with WinAPI or Assembly memory loading for bypass

Main modules include:

image-20220115184528161

Each module adds a green separator line before execution, making it easy to locate echoed information and improve collaboration efficiency

image-20211016170807973

CobaltStrike host online WeChat notification plugin:

  • If you want to use the free WeChat template message push, please visit: https://github.com/lintstar/CS-PushPlus
  • If you have an enterprise WeChat push channel subscribed via ServerChan, please visit: https://github.com/lintstar/CS-ServerChan

Disclaimer

Download Tool

This project is only for security research and legitimate enterprise security construction. All consequences and responsibilities are borne by the user.

Update 2022.1.15

  • Added bypass-enabled clone user, add user, and scheduled task functions
  • Retrieve the latest version of Sunflower identification code and verification code
  • Integrated Ladon 9.1.1 multi-protocol alive detection and other functions
  • Categorized functions, simplified plugin secondary menus

InfoCollect

Common commands are categorized by scenario

image-20220114101130300

SharpGetInfo

Integrated the latest public version 9.1.1 of Ladon

image-20211229102143317

AntiVirusCheck

Antivirus information displayed locally on Beacon status bar

Implementation principle: https://blog.csdn.net/weixin_42282189/article/details/121090055

image-20220112150926351

IntrScan

Added Ladon multi-protocol alive detection (SMB, WMI, SNMP, HTTP, DNS, MAC, MSSQL)

To a certain extent, can detect intranet assets behind firewalls: Using MAC to bypass firewall and detect alive hosts

image-20211229171305053

Alive IP detection

image-20211229171224738

AuthPromote

BadPotato (BeichenDream)

Fixed the bug that only whoami could be executed; now you can run with System privileges via parameters

image-20220113165021408

image-20220113165229359

Badpotato (Ladon)

Added Ladon's Badpotato

image-20211229104134559

SweetPatato (Ladon)

image-20211229104432695

Note: Tests show that the above two privilege escalation behaviors are intercepted and killed by digital antivirus software

image-20211229103727123

AuthMaintain

SharpSchTask

【Use with caution】Utilizing Windows API, tooled to create hidden scheduled tasks while bypassing security software blocks for persistent control.

Project address: https://github.com/0x727/SchTask_0x727

image-20220114100528645

SharpShadowUser

【Use with caution】Bypass remote memory loading, clone hidden shadow user

Project address: https://github.com/An0nySec/ShadowUser

image-20220115175808998

EasyPersistent

Fixed PE file path issue; can now use API method to delete and add users properly

image-20220115182612757

PassCapture

Functions categorized by scenario

image-20220115172016468

SunFlower

Retrieve the latest version of Sunflower identification code and verification code

The latest Sunflower's base_encry_pwd parameter has been moved from config.ini to the registry

image-20220115173453909

RemoteLogin

Simplified secondary menu

image-20220115183414339

BypassCXK

SharpAddUser

Bypass AV: Use the DirectoryService namespace to add users to the Administrators and Remote Desktop groups

Project address: https://github.com/An0nySec/UserAdd

image-20220113152442668

CloneX

Security detection tool for adding and cloning users from the command line

Project address: https://github.com/0x727/CloneX_0x727

image-20220113155017688

Update 2021.10.18

  • Reintegrated and optimized the overall functional modules
  • Added BOF implementation for ZeroLogon vulnerability in Lateral Movement module
  • Added some functions that run via Assembly without dropping files

InfoCollect

SharpGetInfo (One-click host information collection)

Use Ladon to collect host basic information, network information, user information, process information, whether in domain, etc.

image-20211018111745511

SharpListRDP (RDP record query)

Collect RDP inbound and outbound connection records for easy identification of operation and maintenance hosts and lateral movement

image-20211016174456005

IntrScan

Cube (Modular detection)

Added Cube to replace the old version of brute force; also supports intranet info collection and MSSQL command execution. See the run instructions for details.

image-20211015174007171

Allin (Flexible auxiliary scanning)

Added Allin for flexible scanning. Example: remotely obtain NIC IP:

image-20211015173332706

SharpOXID-Find (OXID detection)

If you don't want to drop an EXE, you can use Assembly mode for quick OXID detection

image-20211018112045735

IntrAgent

Stowaway (Penetrate multi-level intranet)

Run after uploading agent

image-20211012100041529

Admin side receives the connection and can build a Socks5 tunnel

image-20211011203216542

Delete agent

image-20211012094116014

PassCapture

LsassDump (WinAPI)

Modified the execution method of LsassDump; when deleting LsassDump, the dumped C:\Windows\Temp\1.dmp is also deleted

image-20211016174730994

Mimidump (Remotely read .dmp)

Added support for LsassDump (WinAPI) function, remotely read the dumped C:\Windows\Temp\1.tmp from the target machine (.net 4.5)

image-20211015094927257

RemoteLogin

Added methods to enable, disable, and query RDP related information using PowerShell

image-20211018113058495

PS scripts are sourced from the RDP module of the Black Devil plugin in References

Query RDP status

image-20211015150247382

Enable RDP service

image-20211015150320880

Get RDP port

image-20211015150713858

View RDP historical login credentials

image-20211015150429336

Retrieve RDP historical login credentials

image-20211015150502487

LateMovement

IPC connection

image-20211018105021131

Ticket passing

image-20211016173510988

ZeroLogonBOF

Added BOF implementation for ZeroLogon vulnerability

Reference: https://github.com/rsmudge/ZeroLogon-BOF

image-20211014143141276

Update 2021.09.05

  • Adapted some functions for x86 architecture machines
  • Added some bypass small tools using Windows API
  • Intranet scanning module added parameter hints when running corresponding functions

IntrScan

Fscan

Added upload of corresponding EXE file based on target machine architecture

image-20210905154601537

Added parameter hints output for targeted execution of individual modules

image-20210905161338995

Crack

Added Crack intranet brute force tool

image-20210905161656828

TailorScan

Added upload of corresponding EXE file based on target machine architecture

image-20210905160326319

PassCapture

LaZagne

Fixed a BUG in version V1.2 where LaZagne was killed and its dropped file deleted before it finished running due to network issues. Changed to manual execution mode.

image-20210904175955070

LsassDump

Added LsassDump using Windows API for memory dumping, supports both x86 and x64 machines

image-20210904180546301

After successful dump, the generated 1.dmp is saved in C:\Windows\Temp\ directory

image-20211015093809697

Directly read it locally:

image-20210904183721654

LateMovement

Added RDP related functions:

image-20210905215527815

Use Windows API to enable RDP service

image-20210905215709267

Update 2021.08.12

InfoCollect

Added CheckVM to detect if the target is a virtual machine

20210808_2213

AVSearch

The previous script had a certain probability of failure:

image-20210808222325403

Updated with a new antivirus detection method

image-20210808221945724

AuthPromote

Fixed BUG in the previous privilege escalation module

image-20210811105401723

AuthMaintain

EasyPersistent: https://github.com/yanghaoi/CobaltStrike_CNA

Added a Cobalt Strike CNA script for Windows system privilege persistence

Uses reflective DLL module via API to visually operate on common privilege persistence methods like system services and scheduled tasks. Very useful. (Author's words)

image-20210812170907609

Documentation: https://github.com/yanghaoi/CobaltStrike_CNA/blob/main/EasyCNA/README.md

image-20210812170946202

PassCapture

Mimikatz Related

image-20210811104834675

Lazagne

A useful tool for retrieving host passwords in real-world tests (uploaded and runs, then automatically deletes the exe file)

image-20210811102145547

Browser Passwords

image-20210811105159479

Local Software (Navicat, Xshell, etc.)

image-20210811105105056

FakeTheScreen

Optimized phishing password stealing for Windows 10 and Windows 7

image-20210811095234252

Since the fake page effect is not great, it is only recommended for desperate situations:

image-20210811094621414

Reference

梼杌 - taowu-cobalt-strike

Z1-AggressorScripts

九世自开-csplugin

EasyPersistent Windows Privilege Persistence

黑魔鬼-CSplugins

InfoCollect

Added Netview and Powerview functions

image-20210707112534352

AvSearch

Process query via Wmic

image-20210707114047098

image-20210706105117525

IntrScan

Contains various intranet scanning tools

image-20210707112718120

Custom command execution

image-20210706110153336

fscan defaults to upload to C:\\Windows\\Temp\\

image-20210706110110475

Console output

image-20210706110008931

Delete fscan and result text

image-20210706110809988

IntrAgent

Useful intranet penetration tools, all without dropping config files, reducing traceability risk

image-20210707112750687

AuthMaintain

Added Silver Ticket and Golden Ticket based on Taowu

image-20210707112856320

LateMovement

Includes lateral movement tools like sharpwmi based on port 135

image-20210707113642982

TraceClean

Stitched from Jiushi's trace cleaning, to be improved

image-20210707113717904

BypassCxk

cxk's time-limited bypass version of adduser and mimikatz

image-20210707113737475

HavingFun

Just for fun when hacking websites

image-20210707113749756