jm33-m0/emp3r0r
Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents. observed · 2026-08-28
Health v2 · maintenance only
95/100
- Activity 99
- Release rhythm 87
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 0.0
- age_days: 2412
- days_rel: 7
- days_push: 7
- n_releases_24m: 177
Adoption not part of the score
1741 stars · 280 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
emp3r0r is an open-source post-exploitation framework and command-and-control (C2) system written in Go, targeting Linux and Windows hosts. It uses self-healing gossip mesh networking for agent communication, supports fileless in-memory execution, cross-platform BOF loading, and scriptable agents via an embedded Starlark engine.
Use cases
- maintain persistent C2 access to compromised Linux and Windows hosts
- run post-exploitation modules filelessly in memory without spawning shells
- execute BOFs (Beacon Object Files) cross-platform on Linux and Windows
- build resilient mesh networks of agents with peer discovery
- run Starlark scripts on targets without Python or PowerShell installed
- proxy Win32 API calls from scripts on Windows targets
- transfer files between agents in the mesh
- perform red team operations with stealthy, OPSEC-focused tooling
When to choose
- you need a free, open-source C2 framework for authorized red team engagements
- your targets are primarily Linux and you need modern, stealthy Linux tradecraft
- you want mesh-based agent communication that self-heals without a single point of failure
- you need fileless, in-memory execution to avoid disk-based detection
- you want scriptable agents without requiring interpreters on the target host
When to avoid
- you need a commercially supported C2 with vendor SLAs and support
- you are looking for a vulnerability scanner or general penetration testing suite rather than a post-exploitation C2
- your engagement requires a simple, well-documented beginner-friendly framework
- you cannot legally possess or use offensive security tooling in your jurisdiction
Facets
application · maturity active
security penetration-testing networking rpc cryptography security penetration-testing networking operating-systems windows cross-platform go c2 post-exploitation red-team rat gossip-mesh bof starlark stealth rootkit privilege-escalation linux
3 sources
- readme: https://github.com/jm33-m0/emp3r0r · fetched 2026-08-28 · 156d0b29c5be
- homepage: https://jm33.me · fetched 2026-08-29 · 0227474678c3
- site_page: https://jm33.me/pages/about.html · fetched 2026-08-29 · cd3dd6aa6005
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| jm33-m0/emp3r0r | main | 95 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem