Ross ROSS = Recommend OSS · open-source software intelligence for agents

jm33-m0/emp3r0r

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents. observed · 2026-08-28

github.com/jm33-m0/emp3r0r · homepage · Go · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 0.0
  • age_days: 2412
  • days_rel: 7
  • days_push: 7
  • n_releases_24m: 177

Full methodology

Adoption not part of the score

1741 stars · 280 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

emp3r0r is an open-source post-exploitation framework and command-and-control (C2) system written in Go, targeting Linux and Windows hosts. It uses self-healing gossip mesh networking for agent communication, supports fileless in-memory execution, cross-platform BOF loading, and scriptable agents via an embedded Starlark engine.

Use cases

  • maintain persistent C2 access to compromised Linux and Windows hosts
  • run post-exploitation modules filelessly in memory without spawning shells
  • execute BOFs (Beacon Object Files) cross-platform on Linux and Windows
  • build resilient mesh networks of agents with peer discovery
  • run Starlark scripts on targets without Python or PowerShell installed
  • proxy Win32 API calls from scripts on Windows targets
  • transfer files between agents in the mesh
  • perform red team operations with stealthy, OPSEC-focused tooling

When to choose

  • you need a free, open-source C2 framework for authorized red team engagements
  • your targets are primarily Linux and you need modern, stealthy Linux tradecraft
  • you want mesh-based agent communication that self-heals without a single point of failure
  • you need fileless, in-memory execution to avoid disk-based detection
  • you want scriptable agents without requiring interpreters on the target host

When to avoid

  • you need a commercially supported C2 with vendor SLAs and support
  • you are looking for a vulnerability scanner or general penetration testing suite rather than a post-exploitation C2
  • your engagement requires a simple, well-documented beginner-friendly framework
  • you cannot legally possess or use offensive security tooling in your jurisdiction

Facets

application · maturity active

security penetration-testing networking rpc cryptography security penetration-testing networking operating-systems windows cross-platform go c2 post-exploitation red-team rat gossip-mesh bof starlark stealth rootkit privilege-escalation linux

3 sources

Member repositories

RepositoryRoleHealth v2
jm33-m0/emp3r0rmain95

For agents

markdown · JSON · MCP: product_card(name="jm33-m0/emp3r0r")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem