GoSecure/pyrdp
RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact observed · 2026-08-28
Health v2 · maintenance only
60/100
- Activity 82
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2917
- days_rel: n/a
- days_push: 112
- n_releases_24m: 0
Adoption not part of the score
1780 stars · 273 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library. It intercepts RDP connections to capture credentials, clipboard data, and files, and includes a player for watching sessions live or replaying them later.
Use cases
- intercept and monitor RDP connections as a man-in-the-middle
- capture plaintext credentials or NetNTLM hashes from RDP logins
- replay recorded RDP sessions or convert them to video
- record and exfiltrate files transferred over RDP or from shared drives
- analyze RDP malware activity in a honeypot
- take covert control of an active RDP session during a pentest
- convert RDP PCAPs into replays or JSON event streams
When to choose
- you need to inspect, record, or manipulate RDP traffic during a penetration test
- you are building an RDP honeypot to observe threat actors
- you want to replay or convert captured RDP sessions for analysis or evidence
When to avoid
- you need a general-purpose network proxy or MITM for protocols other than RDP
- you want a defensive RDP gateway rather than an offensive/analysis tool
- you need a polished commercial remote-desktop solution for end users
Facets
cli-tool · maturity active
security penetration-testing networking parser security penetration-testing networking python cli rdp mitm honeypot pentest session-replay remote-desktop linux docker
2 sources
- readme: https://github.com/GoSecure/pyrdp · fetched 2026-08-28 · ef6ee7bc8b9e
- homepage: https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/ · fetched 2026-08-29 · f1f534e05153
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| GoSecure/pyrdp | main | 60 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem