Volver al ranking

DeimosC2/DeimosC2

Vue

DeimosC2 is a Golang command and control framework for post-exploitation.

security-toolsgolangc2red-teamquichttpsdohinfosechacktoberfest
Crecimiento de estrellas
Estrellas
1.2k
Forks
167
Crecimiento semanal
Issues
18
5001k
jul 2020jul 2022jul 2024jul 2026
README

License: MIT

DeimosC2

Deimos is in: DEPRECATED

DeimosC2 is no longer maintained and has a known XSS vulnerability (CVE-2025-26244).

Thanks to JaRm222 for identifying the vuln and notifying us. His writeup of the vuln can be found here.

DeimosC2 is a post-exploitation Command & Control (C2) tool that leverages multiple communication methods in order to control machines that have been compromised. DeimosC2 server and agents works on, and has been tested on, Windows, Darwin, and Linux. It is entirely written in Golang with a front end written in Vue.js.

Listener Features

  • Each listener has it's own RSA Pub and Private key that is leveraged to wrap encrypted agent communications.
  • Dynamically generate agents on the fly
  • Graphical map of listener and agents that are tied to it

Agent Features

  • Agent list page to give high level overview
  • Agent interaction page containing info of agent, ability to run jobs against agent, filebrowser, loot data, and ability to add comments

Supported Agents

  • TCP
  • HTTPS
  • DoH (DNS over HTTPS)
  • QUIC
  • Pivot over TCP

Frontend Features

  • Multi-User support with roles of admin and user
  • Graphs and visual interaction with listeners and agents
  • Password length requirements
  • 2FA Authentication using Google MFA
  • Websocket API Calls

Getting Started and Help

You can download the latest release and view the wiki for any assistance getting started or running the C2.

Submitting Issues

We welcome issues to be opened to help improve this project and keep it going. For bugs please use the template.

Authors

Credits

In order to develop this we used some of the awesome work of others. Below is a list of those we either used their code or were inspired by. If we missed you please let us know so we can add your name!

Disclaimer

This program should only be used on environments that you own or have explicit permission to do so. Neither the authors, nor Critical Start, Inc., will be held liable for any illegal use of this program.

Repositorios relacionados
x64dbg/x64dbg

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

C++Otherdebuggerwindows
x64dbg.com
49k2.8k
KeygraphHQ/shannon

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

TypeScriptnpmGNU Affero General Public License v3.0penetration-testingpentesting
keygraph.io
46k5.3k
aquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

GoGo ModulesApache License 2.0securitysecurity-tools
trivy.dev
37k547
lissy93/web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

TypeScriptnpmMIT Licenseosintprivacy
web-check.xyz
34.2k2.8k
Infisical/infisical

Infisical is the open-source platform for secrets, certificates, and privileged access management.

TypeScriptnpmOtherclienvironment-variables
infisical.com
28.3k2.1k
gitleaks/gitleaks

Find secrets with Gitleaks 🔑

GoGo ModulesMIT Licensesecuritysecurity-tools
gitleaks.io
28.2k2.2k
trufflesecurity/trufflehog

Find, verify, and analyze leaked credentials

GoGo ModulesGNU Affero General Public License v3.0secrettrufflehog
trufflesecurity.com
27.1k2.5k
Lissy93/web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

TypeScriptnpmMIT Licenseosintprivacy
web-check.xyz
24.3k1.9k
qeeqbox/social-analyzer

API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

JavaScriptnpmGNU Affero General Public License v3.0osintsocial-media
23.5k2.3k
lissy93/personal-security-checklist

🔒 A compiled checklist of 300+ tips for protecting digital security and privacy in 2026

TypeScriptnpmOtherprivacysecurity
digital-defense.io
21.9k1.5k
vxcontrol/pentagi

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

GoGo ModulesMIT Licenseai-agentsai-security-tool
pentagi.com
21.1k2.8k
motdotla/dotenv

Loads environment variables from .env for nodejs projects.

JavaScriptnpmBSD 2-Clause "Simplified" Licensedotenvenvironment-variables
dotenv.org
20.5k954