emp3r0r vs Merlin
GitHub Stats
About emp3r0r
emp3r0r is a Linux-focused Command and Control framework featuring a mesh network architecture where agents can relay through each other. It supports multiple transport protocols including HTTP/2, TLS, and steganography-based communications hidden in images. The framework provides automated post-exploitation including privilege escalation, credential harvesting, keylogging, and file exfiltration. Agents feature self-healing capabilities, process injection, anti-debugging, and containerized execution to avoid detection. The operator interface provides module management, agent tasking, and real-time status monitoring. Designed specifically for Linux environments where other C2 frameworks have limited support.
About Merlin
Merlin is a cross-platform post-exploitation Command and Control (C2) server and agent written in Go. It communicates over HTTP/2 and HTTP/3 (QUIC), leveraging modern protocols that many security tools and network monitors do not inspect. The server provides an interactive CLI for managing multiple agents, executing commands, uploading/downloading files, and running post-exploitation modules. Agents compile to single static binaries for Windows, Linux, and macOS. Merlin supports encrypted JWE/JWT communications, domain fronting, and multiple listener types for operational flexibility.
Platform Support
Tags
Shared
emp3r0r only
Merlin only