Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
bothan — ¿Es esta IP un servidor C2? | Kitploit
Herramientas/GitHubGitHub/audibleblink/bothan
Herramientas DefensivasReconocimientoRecopilación de InformaciónSeguridad de RedesComando y ControlInteligencia de Amenazas
GitHubaudibleblink/bothan

bothan

¿Es esta IP un servidor C2?

Ver Repositorio
2739hace 6 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

bothan

Confirma que una ip:port está alojando Empire. Soporte futuro para otros C2s.

Uso

# Direct single query
❯❯ bothan -v localhost:8080
DEBU[2020-01-19T20:25:02-05:00] Requesting...                                 host="localhost:8080"
INFO[2020-01-19T20:25:02-05:00] SUCCESS                                       host="http://localhost:8080" tool=empire

# Take a pre-existing list of host:port lines
❯❯ bothan -v -f hostslist.txt
DEBU[2020-01-19T20:25:10-05:00] Requesting...                                 host="localhost:8080"
INFO[2020-01-19T20:25:10-05:00] SUCCESS                                       host="http://localhost:8080" tool=empire

# Take Stdin
❯❯ cat masscan.oD.txt | jq -r '. | "\(.ip):\(.port)"' | bothan -f -
ERRO[2020-01-19T20:25:25-05:00] Get https://1.1.1.1:53: EOF                   host="1.1.1.1:53"
INFO[2020-01-19T20:25:25-05:00] SUCCESS                                       host="http://192.168.1.199:8080" tool=empire

# For masscan specifically, there's an option to parse its -oD json output format
❯❯ masscan 192.168.1.0/24 -p 8080 -oD - | bothan --masscan -f -
INFO[2020-01-19T20:25:31-05:00] SUCCESS                                       host="http://192.168.1.199:8080" tool=empire

Los éxitos se escriben en Stdout; el resto de los registros, en Stderr.

Instalación

go get github.com/audibleblink/bothan

Compilación

  1. Ten go
  2. Ten make
  3. Escribe make
bin
├── 386
│   ├── bothan.darwin
│   ├── bothan.linux
│   └── bothan.windows.exe
├── amd64
│   ├── bothan.darwin
│   ├── bothan.linux
│   └── bothan.windows.exe
├── arm
│   └── bothan.linux
└── arm64
    └── bothan.linux

4 directories, 8 files

Falsos Positivos

Para probar esto durante el desarrollo, inicialmente ejecuté Empire en su estado predeterminado y luego lo personalicé. Después, me basé en servidores listados en fuentes públicas de inteligencia de amenazas para probar; alrededor de 100.

98 fueron identificados como Empire. Uno simplemente agotó el tiempo de espera y el otro parecía muy modificado.

Es decir, no contaba con lo que consideraría un conjunto de muestras estadísticamente relevante para probar, así que por favor reporta cualquier falso {positivo,negativo} que encuentres.

Descargar herramienta