Ross ROSS = Recommend OSS · open-source software intelligence for agents

ph4ntonn/Stowaway

👻Stowaway -- Multi-hop Proxy Tool for pentesters observed · 2026-08-28

github.com/ph4ntonn/Stowaway · Go · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

54/100

  • Activity 70
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2483
  • days_rel: n/a
  • days_push: 183
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

3411 stars · 441 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Stowaway is a multi-hop proxy tool written in Go, designed for penetration testers to route external traffic through chains of nodes into restricted internal networks. It builds a tree of admin/agent nodes with encrypted communication, SOCKS5 proxying, port forwarding, remote shells, and file transfer.

Use cases

  • proxy traffic through multiple compromised hosts into an internal network
  • set up a multi-level SOCKS5 proxy chain during a pentest
  • forward local and remote ports across a node chain
  • get a remote shell on an agent behind a firewall
  • tunnel node-to-node traffic over SSH or through SOCKS5/HTTP proxies
  • transfer files to and from machines inside a segmented network
  • reuse an existing open port to covertly accept agent connections

When to choose

  • you need multi-hop pivoting with a tree of nodes during an authorized red-team engagement
  • you want encrypted (TLS/AES-256-GCM) node-to-node traffic with forward and reverse connections
  • you need cross-platform agents including MIPS/ARM embedded devices
  • you want an interactive admin console with node tree management, shell, and file upload/download

When to avoid

  • you need a general-purpose VPN or full network-layer tunnel rather than proxy-style pivoting
  • your use case is not an authorized security assessment - unauthorized use is illegal
  • you need a GUI-managed enterprise proxy solution
  • you only need simple single-hop port forwarding, where ssh -L or socat suffices

Facets

cli-tool · maturity active

proxy networking security cryptography ssh security penetration-testing networking windows cross-platform cli multi-hop-proxy socks5 port-forwarding red-team tunneling pentesting reverse-connection traffic-encryption command-line linux macos

1 source

Member repositories

RepositoryRoleHealth v2
ph4ntonn/Stowawaymain54

For agents

markdown · JSON · MCP: product_card(name="ph4ntonn/Stowaway")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem