# infobyte/evilgrade

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.

Repository: https://github.com/infobyte/evilgrade
Canonical: https://ross.abutalabs.com/products/evilgrade
Homepage: https://www.faradaysec.com/
Language: Perl
License Family: other
Topics: security, update, evilgrade, fake, pentest, penetration, payload, mitm
Last push: 2021-09-01T17:08:27+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 4881, "days_push": 1827, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1326, forks 275 (observed 2026-08-28T04:04:22.841931+00:00)

## What it is
Evilgrade is a modular penetration testing framework that exploits poor software update implementations by injecting fake updates via DNS manipulation and man-in-the-middle scenarios. It ships with pre-made agent binaries, default configurations for fast pentests, and built-in web and DNS server modules covering dozens of popular applications.

## Use cases
- simulate fake update attacks during a pentest
- test whether software updaters validate signatures
- demonstrate ARP spoofing or DNS cache poisoning risks
- deliver a payload through a hijacked update channel
- train red teamers on MITM update exploitation

## When to choose
- you need to test update mechanisms against MITM attacks
- you want a ready-made framework with modules for many applications
- you are doing authorized red team or security research work

## When to avoid
- you need a general-purpose exploitation framework like Metasploit
- you want actively maintained tooling with recent updates
- you lack authorization to test target networks

## Facets
- artifact type: framework
- maturity: maintenance
- function: penetration-testing, security, http-server, web-scraping
- domain: security, penetration-testing, networking
- platform: windows, cross-platform, cli
- tags: fake-updates, mitm, dns-spoofing, payload-delivery, perl, update-hijacking, linux, macos

## Member repositories
- infobyte/evilgrade (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:22.841931+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:46:22.314830+00:00, confidence not recorded.
  - readme: https://github.com/infobyte/evilgrade (fetched 2026-08-28T04:04:22.841931+00:00, sha 66eb035767d4)
  - homepage: https://www.faradaysec.com/ (fetched 2026-08-29T12:05:32.291483+00:00, sha 3d723988fb85)
  - site_page: https://faradaysec.com/about-us (fetched 2026-08-29T12:05:32.304925+00:00, sha a3b9e91f7546)
  - site_page: https://docs.faradaysec.com/ (fetched 2026-08-29T12:05:32.307508+00:00, sha 774e758c744c)
  - site_page: https://faradaysec.com/platform/integrations (fetched 2026-08-29T12:05:32.300979+00:00, sha 3b8a56a82e46)
  - site_page: https://faradaysec.com/pricing (fetched 2026-08-29T12:05:32.303042+00:00, sha e2e03824be74)
  - site_page: https://faradaysec.com/platform-pricing (fetched 2026-08-29T12:05:32.309900+00:00, sha 783308084f96)
- Data as of 2026-08-30T08:39:29.467469+00:00.
