# DeEpinGh0st/Erebus

CobaltStrike后渗透测试插件

Repository: https://github.com/DeEpinGh0st/Erebus
Canonical: https://ross.abutalabs.com/products/erebus
Language: PowerShell
License: GPL-3.0
License Family: copyleft
Topics: cobaltstrike
Last push: 2021-10-28T06:20:51+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2533, "days_push": 1770, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1568, forks 219 (observed 2026-08-28T04:05:05.162310+00:00)

## What it is
Erebus is a post-exploitation plugin for Cobalt Strike written in PowerShell and Sleep (Aggressor Script). It bundles information gathering, privilege escalation exploits, credential theft, browser cookie stealing, and various post-exploitation utilities into the Cobalt Strike beacon menu.

## Use cases
- enumerate local privilege escalation vulnerabilities on a Windows target
- run Potato-family UAC bypass and elevation exploits from Cobalt Strike
- steal browser cookies from common Chinese and mainstream browsers
- dump Windows credentials with an AV-evading mimikatz variant
- clear RDP login traces on a compromised host
- enable RDP or turn off the firewall on a target machine
- collect system and user information with Seatbelt-style gathering

## When to choose
- you run Cobalt Strike 4.x and want an integrated post-exploitation toolkit
- you need quick Windows privilege escalation and credential access during authorized red-team engagements
- you want browser cookie theft and log-clearing utilities accessible from the beacon right-click menu

## When to avoid
- you do not use Cobalt Strike as your C2 framework
- you need a maintained tool - the last release was October 2021 and some async features are known to be buggy
- you require support for non-Windows targets, since most modules are Windows-specific

## Facets
- artifact type: plugin
- maturity: maintenance
- function: penetration-testing, security, developer-tools
- domain: security, penetration-testing, windows
- platform: windows, cross-platform
- tags: cobalt-strike, post-exploitation, privilege-escalation, red-team, c2-plugin, powershell, offensive-security

## Member repositories
- DeEpinGh0st/Erebus (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:05.162310+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:58:55.830067+00:00, confidence not recorded.
  - readme: https://github.com/DeEpinGh0st/Erebus (fetched 2026-08-28T04:05:05.162310+00:00, sha 5d31916c3139)
- Data as of 2026-08-30T08:39:29.467469+00:00.
