GTFOBins

GTFOBins is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions.

The project collects legitimate Unix binaries that can be abused to get the f**k break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate the other post-exploitation tasks. See the full list of functions.

This was inspired by the LOLBins project for Windows.

GTFOBins aims to be a shared project where everyone can contribute with additional binaries and techniques.

List of GTFOBins

Binary Functions
ash
awk
bash
csh
curl
dash
ed
emacs
env
expect
find
ftp
gdb
ionice
ld.so
less
man
more
nc
node
perl
php
python2
python3
rpm
rpmquery
ruby
scp
setarch
sftp
socat
ssh
strace
tar
taskset
tclsh
telnet
tftp
vi
watch
wget
wish
zsh