GTFOBins
Star

GTFOBins is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions.

The project collects legitimate functions of Unix binaries that can be abused to get the f**k break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate the other post-exploitation tasks. See the full list of functions.

This was inspired by the LOLBins project for Windows.

GTFOBins is a collaborative project created by norbemi and cyrus_and where everyone can contribute with additional binaries and techniques.

Binary Functions
apt-get
apt
aria2c
arp
ash
awk
base64
bash
busybox
cancel
cat
chmod
chown
cp
cpan
cpulimit
crontab
csh
curl
cut
dash
date
dd
diff
dmesg
dmsetup
dnf
docker
dpkg
easy_install
ed
emacs
env
expand
expect
facter
file
find
finger
flock
fmt
fold
ftp
gdb
gimp
git
grep
head
ionice
ip
irb
jjs
journalctl
jq
jrunscript
ksh
ld.so
less
logsave
ltrace
lua
mail
make
man
more
mount
mtr
mv
mysql
nano
nc
nice
nl
nmap
node
od
openssl
perl
pg
php
pic
pico
pip
puppet
python
readelf
red
rlogin
rlwrap
rpm
rpmquery
rsync
ruby
run-mailcap
run-parts
rvim
scp
screen
script
sed
setarch
sftp
shuf
smbclient
socat
sort
sqlite3
ssh
start-stop-daemon
stdbuf
strace
systemctl
tail
tar
taskset
tclsh
tcpdump
tee
telnet
tftp
time
timeout
ul
unexpand
uniq
unshare
vi
vim
watch
wget
whois
wish
xargs
xxd
yum
zip
zsh
zypper
No binary matches...