Ross ROSS = Recommend OSS · open-source software intelligence for agents

D00Movenok/BounceBack

↕️🤫 Stealth redirector for your red team operation security observed · 2026-08-28

github.com/D00Movenok/BounceBack · Go · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

73/100

  • Activity 93
  • Release rhythm 40
  • Longevity 86
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 238
  • age_days: 1206
  • days_rel: 185
  • days_push: 44
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

1103 stars · 106 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

BounceBack is a stealth reverse proxy with WAF-like filtering designed to hide red team C2 and phishing infrastructure from blue teams, sandboxes, and scanners. It applies configurable boolean rule pipelines (IP blacklists, geolocation, reverse lookup, Malleable C2 profile validation, time windows) to real-time traffic to block illegitimate visitors.

Use cases

  • hide c2 server infrastructure from scanners and sandboxes
  • filter out security vendor ips from my red team redirector
  • validate inbound traffic against a cobalt strike malleable c2 profile
  • set up a stealth redirector for phishing infrastructure
  • block automated scanners and blue team reconnaissance from reaching my proxy
  • restrict proxy access to specific countries or work hours

When to choose

  • you run red team operations and need an opsec-hardened redirector in front of C2 or phishing servers
  • you want configurable boolean rule pipelines combining IP, geolocation, reverse DNS, and packet regex filtering
  • you use Cobalt Strike and want automatic Malleable C2 profile traffic validation
  • you need multiple proxies with different filter pipelines in a single instance

When to avoid

  • you need a general-purpose production reverse proxy or WAF for legitimate web applications
  • you want a managed cloud service rather than a self-hosted Go binary
  • your use case has no relation to offensive security or infrastructure hiding
  • you need a GUI-managed proxy rather than configuration-file-driven setup

Facets

cli-tool · maturity active

proxy security http-server middleware logging security penetration-testing networking backend windows go cli self-hosted red-team c2 redirector reverse-proxy waf opsec cobalt-strike traffic-filtering domain-fronting phishing-infrastructure linux macos

1 source

Member repositories

RepositoryRoleHealth v2
D00Movenok/BounceBackmain73

For agents

markdown · JSON · MCP: product_card(name="D00Movenok/BounceBack")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem