Skip to content
@Whispergate

Whispergate

01110000 01110011 01110011 01110100 00100001

Whispergate

A small collective of security researchers focused on Offensive Research & Development.

GitHub Blog Contact


What We Do

Whispergate builds open-source tooling for offensive security professionals. Our work covers the full red team lifecycle, from initial access and payload development through command & control infrastructure, all the way to ICS/OT security research and training range automation.

Mythic C2 Ecosystem

A significant portion of our work extends the Mythic command and control framework. We develop and maintain custom agents, an alternative web UI, initial access wrappers, malleable profile generators, and integration tooling, giving operators a more complete and flexible Mythic experience out of the box.

Offensive Tooling

We research and release tools across the offensive development space: PIC shellcode agents, VM-based loaders, exfiltration frameworks, kernel exploitation plugins, and evasion utilities. Everything is built with real-world operator workflows in mind.

Red Team Infrastructure

We build and maintain tooling focused on protecting and managing red team infrastructure. This includes C2 redirection proxies, traffic filtering, redirector deployment automation, domain and email warming utilities, and payload hosting. Keeping operator infrastructure resilient and attribution-resistant is a core focus.

ICS / OT Security

Our ICS work centers on multi-protocol OT security frameworks and training content for industrial control system environments. We build tooling that lets security teams safely discover, enumerate, and validate OT assets in authorized lab settings.

Training Ranges & Infrastructure

We maintain a growing library of Ludus Ansible roles that let teams spin up full red/blue training environments in minutes, covering everything from C2 teamservers and redirectors to SIEM stacks, incident response platforms, and vulnerable Active Directory configurations.


Connect

Pinned Loading

  1. InfraGuard InfraGuard Public

    InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

    Python 322 25

  2. Erebus Erebus Public

    Erebus is an Initial Access wrapper for the Mythic Command & Control Server. It converts shellcode into payloads specifically used for phishing and IA operations.

    Python 229 20

  3. SCADAVER SCADAVER Public

    SCADAver: a Rust-powered, multi-protocol OT/ICS security framework for authorized labs featuring asset discovery, enumeration, controlled validation, simulators, and CLI, TUI, and web interfaces. D…

    Rust 88 7

  4. Hecate Hecate Public

    A modern alternative Web-UI for the Mythic Command and Control Server

    TypeScript 82 6

  5. Starburst Starburst Public

    PIC shellcode agent based on Stardust framework and Crystal Palace

    C++ 52 4

  6. JanusLoader JanusLoader Public

    RISC-V VM based shellcode loader PoC - Still WIP

    C++ 36

Repositories

Showing 10 of 72 repositories
  • Starburst Public

    PIC shellcode agent based on Stardust framework and Crystal Palace

    Whispergate/Starburst's past year of commit activity
    C++ 52 BSD-2-Clause 4 0 0 Updated Sep 29, 2026
  • Starburst.ArsenalKit Public

    Arsenal Kit like toolkit for Mythic's Starburst Agent

    Whispergate/Starburst.ArsenalKit's past year of commit activity
    C 10 BSD-2-Clause 1 0 0 Updated Sep 29, 2026
  • Starburst.UDRL-VS Public

    User-Defined Reflective Loader Project for Visual Studio 2026 - Made for Starburst

    Whispergate/Starburst.UDRL-VS's past year of commit activity
    C 2 BSD-2-Clause 0 0 0 Updated Sep 29, 2026
  • Athena Public

    Passive external attack-surface diff engine — the recon stage of the red team lifecycle

    Whispergate/Athena's past year of commit activity
    Python 0 BSD-2-Clause 0 0 0 Updated Sep 29, 2026
  • sleepmask-vs Public Forked from Cobalt-Strike/sleepmask-vs

    A simple Sleepmask BOF example

    Whispergate/sleepmask-vs's past year of commit activity
    C++ 1 Apache-2.0 34 0 0 Updated Sep 27, 2026
  • bof-vs Public Forked from Cobalt-Strike/bof-vs

    A Beacon Object File (BOF) template for Visual Studio

    Whispergate/bof-vs's past year of commit activity
    C++ 1 Apache-2.0 42 0 0 Updated Sep 27, 2026
  • InfraGuard Public

    InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

    Whispergate/InfraGuard's past year of commit activity
    Python 322 BSD-2-Clause 24 0 0 Updated Sep 27, 2026
  • Calypso Public

    C++ Based Syscall Packer

    Whispergate/Calypso's past year of commit activity
    C++ 1 BSD-2-Clause 0 0 0 Updated Sep 24, 2026
  • Daedalus Public

    Mythic Eventing Container to interact with CI/CD servers

    Whispergate/Daedalus's past year of commit activity
    Python 3 BSD-2-Clause 0 0 0 Updated Sep 23, 2026
  • ludus_maas_builders Public

    Ludus Malware as a Service Builders

    Whispergate/ludus_maas_builders's past year of commit activity
    Jinja 1 BSD-2-Clause 0 0 0 Updated Sep 21, 2026