GTFOBins
Star

GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems.

The project collects legitimate functions of Unix binaries that can be abused to get the f**k break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate the other post-exploitation tasks.

It is important to note that this is not a list of exploits, and the programs listed here are not vulnerable per se, rather, GTFOBins is a compendium about how to live off the land when you only have certain binaries available.

GTFOBins is a collaborative project created by Emilio Pinna and Andrea Cardaci where everyone can contribute with additional binaries and techniques.

If you are looking for Windows binaries you should visit LOLBAS.

Binary Functions
ansible-playbook
apt-get
apt
ar
aria2c
arj
arp
ash
at
atobm
awk
base32
base64
basenc
bash
bpftrace
bridge
bundler
busctl
busybox
byebug
c89
c99
cancel
capsh
cat
certbot
check_by_ssh
check_cups
check_log
check_memory
check_raid
check_ssl_cert
check_statusfile
chmod
chown
chroot
cmp
cobc
column
comm
composer
cowsay
cowthink
cp
cpan
cpio
cpulimit
crash
crontab
csh
csplit
csvtool
cupsfilter
curl
cut
dash
date
dd
dialog
diff
dig
dmesg
dmidecode
dmsetup
dnf
docker
dpkg
dvips
easy_install
eb
ed
emacs
env
eqn
ex
exiftool
expand
expect
facter
file
find
finger
flock
fmt
fold
ftp
gawk
gcc
gdb
gem
genisoimage
ghc
ghci
gimp
git
grep
gtester
gzip
hd
head
hexdump
highlight
hping3
iconv
iftop
install
ionice
ip
irb
jjs
join
journalctl
jq
jrunscript
knife
ksh
ksshell
latex
ld.so
ldconfig
less
ln
loginctl
logsave
look
ltrace
lua
lualatex
luatex
lwp-download
lwp-request
mail
make
man
mawk
more
mount
msgattrib
msgcat
msgconv
msgfilter
msgmerge
msguniq
mtr
mv
mysql
nano
nawk
nc
nice
nl
nmap
node
nohup
npm
nroff
nsenter
octave
od
openssl
openvpn
openvt
paste
pdb
pdflatex
pdftex
perl
pg
php
pic
pico
pip
pkexec
pkg
pr
pry
psql
puppet
python
rake
readelf
red
redcarpet
restic
rev
rlogin
rlwrap
rpm
rpmquery
rsync
ruby
run-mailcap
run-parts
rview
rvim
scp
screen
script
sed
service
setarch
sftp
sg
shuf
slsh
smbclient
snap
socat
soelim
sort
split
sqlite3
ss
ssh-keygen
ssh-keyscan
ssh
start-stop-daemon
stdbuf
strace
strings
su
sysctl
systemctl
tac
tail
tar
taskset
tbl
tclsh
tcpdump
tee
telnet
tex
tftp
time
timedatectl
timeout
tmux
top
troff
tshark
ul
unexpand
uniq
unshare
update-alternatives
uudecode
uuencode
valgrind
vi
view
vigr
vim
vimdiff
vipw
virsh
watch
wc
wget
whois
wish
xargs
xelatex
xetex
xmodmap
xmore
xxd
xz
yarn
yelp
yum
zip
zsh
zsoelim
zypper
No binary matches...