SkillAgentSearch skills...

CACM

Linux权限维持

Install / Use

/learn @RuoJi6/CACM
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

<br/> <p align="center"> <img alt="GitHub Contributors" src="https://img.shields.io/badge/%E4%BD%9C%E8%80%85-%E5%BC%B1%E9%B8%A1-red" /> <img alt="GitHub Contributors" src="https://img.shields.io/badge/%E5%8D%9A%E5%AE%A2-www.ruoji6.github.io-blue" /> <img alt="GitHub Contributors" src="https://img.shields.io/badge/%E5%AE%89%E5%85%A8%E5%9B%A2%E9%98%9F-One--fox-pink" /> <img src="https://badgen.net/github/stars/RuoJi6/HackerPermKeeper/?icon=github&color=black"> <a href="https://github.com/RuoJi6/HackerPermKeeper/releases"><img src="https://img.shields.io/github/downloads/RuoJi6/HackerPermKeeper/total?color=blueviolet"></a> <img src="https://badgen.net/github/issues/RuoJi6/HackerPermKeeper"> </p> <br/> <br/>

中文手册English manual

项目介绍

一款Linux权限维持+后渗透的工具,功能:端口扫描,敏感信息,指纹识别,IP伪装,键盘监控,进程隐藏,内容搜索,文件搜索,下载工具,edr/av识别,权限维持,docker敏感信息扫描,ssh连接伪装等多个功能。

在针对文件操作的时候,操作之前会copy文件的时间戳,操作完成会恢复到修改之前状态。

演示截图:

端口扫描

<img width="3134" height="970" alt="image" src="https://github.com/user-attachments/assets/8bec3eac-e819-44d4-81aa-cf6d2f9f9853" />

docker敏感信息

<img width="1974" height="1960" alt="image" src="https://github.com/user-attachments/assets/c52ce60d-68b0-4ddf-9ef4-68b316f2a9ff" />

端口复用

<img width="1721" height="936" alt="image" src="https://github.com/user-attachments/assets/2002a51e-ebf6-47c9-90a7-77aec9236907" />

suid权限维持

<img width="1701" height="345" alt="image" src="https://github.com/user-attachments/assets/433741ee-45e4-445a-9180-de5ce3533e78" />

覆盖删除遗留文件

<img width="682" height="270" alt="image" src="https://github.com/user-attachments/assets/c697c4f3-da5d-47ae-87bc-ae80b833a52d" />

国内环境下载fscan

<img width="658" height="355" alt="image" src="https://github.com/user-attachments/assets/d6b66387-8fa5-4d4b-9a32-40643e3b4e2d" />

ssh权限维持

<img width="853" height="478" alt="image" src="https://github.com/user-attachments/assets/adbf0c09-20f4-4454-b7f3-b03228261584" />

删除历史命令

<img width="684" height="242" alt="image" src="https://github.com/user-attachments/assets/53c2ffb3-7625-4512-b45f-cd0d47811ec4" />

内部计划

目前放出的版本会带有upx特征,但是内部已去upx特征: <img width="992" height="219" alt="image" src="https://github.com/user-attachments/assets/2ff3ac98-0ecf-42e9-8650-8b7698057c7d" /> <img width="1656" height="932" alt="image" src="https://github.com/user-attachments/assets/adb5e452-d563-41e6-b873-1bf99ee20945" />

加入内部:

  • 提交edr/dv进程名以及文件位置
  • 提交Linux权限维持技巧
  • 提供edr/av测试环境
  • 提交重大bug

感谢

| 感谢者名单: | | ------------- | | hackerschoice | | shadow1ng | | chainreactors | | 棉花糖 | | 蜉蝣信安 | | 知攻善防实验室 |

赞助

感谢下面师傅的赞助!!!!!! | 赞助者名单: | | ------------- | | Rebel | | To1y5 | | 无末 |

Stargazers over time

Stargazers over time

交流群

image

Related Skills

View on GitHub
GitHub Stars992
CategoryDevelopment
Updated5d ago
Forks113

Security Score

95/100

Audited on Mar 27, 2026

No findings