# RuoJi6/CACM

Linux权限维持

Repository: https://github.com/RuoJi6/CACM
Canonical: https://ross.abutalabs.com/products/cacm
Homepage: https://ruoji6.github.io/
License: MIT
License Family: permissive
Topics: keep, linux, linux-shell, permissions, att, attck
Last push: 2026-06-10T09:52:12+00:00

## Health v2 (maintenance only)
Score: 85/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 86, release rhythm 87, longevity 81
- inputs: {"age_days": 1141, "days_push": 84, "days_rel": 84, "gap_med": 4, "n_releases_24m": 22}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1121, forks 123 (observed 2026-08-28T04:03:39.932202+00:00)

## What it is
CACM is a Linux post-exploitation and privilege persistence tool that bundles port scanning, sensitive information gathering, EDR/AV identification, process hiding, SSH connection spoofing, and multiple persistence techniques. It also preserves file timestamps during file operations to reduce forensic traces.

## Use cases
- maintain persistence on a compromised linux host
- scan ports and collect sensitive info during post-exploitation
- identify EDR/AV processes on a target machine
- hide processes and spoof ssh connections
- scan docker environments for sensitive data
- clean shell history and restore file timestamps to avoid detection
- download tools like fscan in restricted network environments

## When to choose
- you are doing authorized red team or penetration testing on linux targets
- you need an all-in-one post-exploitation toolkit with persistence techniques
- you want anti-forensic features like timestamp preservation and history cleanup

## When to avoid
- you need a defensive or hardening tool - this is offensive-oriented
- you are on windows or macos - it targets linux
- you cannot legally or ethically use offensive security tooling

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, penetration-testing, networking, search-engine, developer-tools
- domain: security, penetration-testing, operating-systems
- platform: cli
- tags: privilege-persistence, post-exploitation, red-team, edr-av-detection, process-hiding, ssh-persistence, anti-forensics, port-scanning, command-line, linux

## Member repositories
- RuoJi6/CACM (main) score 85

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:39.932202+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:40:58.712149+00:00, confidence not recorded.
  - readme: https://github.com/RuoJi6/CACM (fetched 2026-08-28T04:03:39.932202+00:00, sha 9ffb0088bbc5)
  - homepage: https://ruoji6.github.io/ (fetched 2026-08-29T12:44:54.053481+00:00, sha 277401d906d0)
- Data as of 2026-08-30T08:39:29.467469+00:00.
