CACM
Linux权限维持
Install / Use
/learn @RuoJi6/CACMREADME
项目介绍
一款Linux权限维持+后渗透的工具,功能:端口扫描,敏感信息,指纹识别,IP伪装,键盘监控,进程隐藏,内容搜索,文件搜索,下载工具,edr/av识别,权限维持,docker敏感信息扫描,ssh连接伪装等多个功能。
在针对文件操作的时候,操作之前会copy文件的时间戳,操作完成会恢复到修改之前状态。
演示截图:
端口扫描
<img width="3134" height="970" alt="image" src="https://github.com/user-attachments/assets/8bec3eac-e819-44d4-81aa-cf6d2f9f9853" />docker敏感信息
<img width="1974" height="1960" alt="image" src="https://github.com/user-attachments/assets/c52ce60d-68b0-4ddf-9ef4-68b316f2a9ff" />端口复用
<img width="1721" height="936" alt="image" src="https://github.com/user-attachments/assets/2002a51e-ebf6-47c9-90a7-77aec9236907" />suid权限维持
<img width="1701" height="345" alt="image" src="https://github.com/user-attachments/assets/433741ee-45e4-445a-9180-de5ce3533e78" />覆盖删除遗留文件
<img width="682" height="270" alt="image" src="https://github.com/user-attachments/assets/c697c4f3-da5d-47ae-87bc-ae80b833a52d" />国内环境下载fscan
<img width="658" height="355" alt="image" src="https://github.com/user-attachments/assets/d6b66387-8fa5-4d4b-9a32-40643e3b4e2d" />ssh权限维持
<img width="853" height="478" alt="image" src="https://github.com/user-attachments/assets/adbf0c09-20f4-4454-b7f3-b03228261584" />删除历史命令
<img width="684" height="242" alt="image" src="https://github.com/user-attachments/assets/53c2ffb3-7625-4512-b45f-cd0d47811ec4" />内部计划
目前放出的版本会带有upx特征,但是内部已去upx特征: <img width="992" height="219" alt="image" src="https://github.com/user-attachments/assets/2ff3ac98-0ecf-42e9-8650-8b7698057c7d" /> <img width="1656" height="932" alt="image" src="https://github.com/user-attachments/assets/adb5e452-d563-41e6-b873-1bf99ee20945" />
加入内部:
- 提交edr/dv进程名以及文件位置
- 提交Linux权限维持技巧
- 提供edr/av测试环境
- 提交重大bug
感谢
| 感谢者名单: | | ------------- | | hackerschoice | | shadow1ng | | chainreactors | | 棉花糖 | | 蜉蝣信安 | | 知攻善防实验室 |
赞助
感谢下面师傅的赞助!!!!!! | 赞助者名单: | | ------------- | | Rebel | | To1y5 | | 无末 |
Stargazers over time
交流群
Related Skills
node-connect
344.4kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
frontend-design
99.2kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
openai-whisper-api
344.4kTranscribe audio via OpenAI Audio Transcriptions API (Whisper).
qqbot-media
344.4kQQBot 富媒体收发能力。使用 <qqmedia> 标签,系统根据文件扩展名自动识别类型(图片/语音/视频/文件)。
Security Score
Audited on Mar 27, 2026
