BeEF
A penetration testing tool for assessing browser security by hooking web browsers and launching client-side attack modules
It takes care to curate a safe software space. Help us do more.
&
| + | Browser Hooking | Injects a JavaScript hook into a target browser so testers can control it remotely as a foothold for further attacks. |
|---|---|---|
| + | Command Module Library | Provides categorized Ruby and JavaScript modules for reconnaissance, persistence, and browser exploitation against a hooked session. |
| + | Web-Based Control Panel | Offers an administrative interface for viewing hooked browsers and launching modules against them in real time. |
| + | Network Discovery Modules | Scans internal network hosts and ports from within a hooked browser to pivot past perimeter defenses. |
| + | Extensible Module API | Lets developers write custom command modules and autorun rules through a documented development API. |
| - | No Windows Server Support | Prevents testers from running the controlling server itself on a Windows host. |
| - | Detectable Hooking Behavior | Leaves recognizable JavaScript and network patterns that let defenders fingerprint and block a hooked session. |
| - | Requires a Separate Delivery Vector | Depends on an existing vulnerability, such as XSS or social engineering, to get the hook script loaded into a target browser. |
...-1 more features/limitations. Contact us to get a complete list of features and system requirements.
System Requirements
| # | Minimum |
|---|---|
| 1 |
|
| 2 |
|
Want to get access to entire data for training LLM or studying software or may be something else? Contact us at contact [at] softorage [dot] com
Want to get access to entire data for training LLM or studying software or may be something else? Contact us at contact [at] softorage [dot] com
Ratings
Not available, but we appreciate help! You can help us improve this page by contacting us.