Post-Exploitation Framework
Extensible server
/client architecture with cross-platform GUI support for Linux, Windows, and macOS operators.Kogeki is a multi-operator post-exploitation framework built for authorized red teams, penetration testers, and adversary simulation programs. Deploy realistic operators, manage resilient agents, and validate defenses — all through encrypted command and control.
Kogeki combines a modular server, cross-platform GUI client, and extensible agent plugins into one platform for controlled red-team engagements and security validation.
Extensible server
/client architecture with cross-platform GUI support for Linux, Windows, and macOS operators.Fully encrypted C2 channels with multiple listener profiles to adapt to different network environments.
Plugin-based
listeners and agents. Switch protocols without rebuilding the core framework.Track tasks, jobs, files
, processes, credentials, targets, and screenshots across every engagement.Socks4, Socks5, authenticated Socks5, plus local and reverse port forwarding for complex network paths.
Automate operator
workflows with the built-in scripting engine. Run BOFs, custom tasks, and extension kits.Every Kogeki engagement follows a controlled workflow — deploy, listen, beacon, operate.
Install the
Kogeki server on your infrastructure. Configure SSL, operators, and authentication.Choose a
listener profile — HTTP/S, SMB, TCP, DNS/DoH, or TCP/mTLS — matched to the engagement scenario.Generate and
deploy a BUHUL or Halimun agent for Windows, Linux, or macOS targets.Kogeki is designed for authorized security professionals who need realistic, controlled adversary simulation.
Simulate advanced
adversaries to test detection, response, and resilience capabilities of blue teams.Manage post
-exploitation phases across complex environments with reliable agents and operator collaboration.Emulate real
-world TTPs to validate defensive controls and improve incident response playbooks.Provide documented evidence of control effectiveness and
gaps for compliance and assurance programs.A Golang server for performance and stability, a C++ Qt client for cross-platform operators, and plugin-based agents that adapt to the target environment — all communicating through encrypted channels with full audit trails.
Kogeki is built for authorized use. Built-in safeguards keep every engagement scoped, verifiable, and reversible.
Every deployment
requires explicit authorization and proof of ownership for the target environment.Define exactly when agents are allowed to
run. Automatic expiration prevents lingering access.All operator
, listener, and agent traffic is encrypted to protect operational integrity.Ongoing operations can be halted instantly from the server or client, with full session cleanup.
Kogeki is an adversary emulation and post-exploitation framework for authorized red teams and penetration testers. It provides a multi-operator server, cross-platform GUI client, and extensible agents.
Kogeki is intended exclusively for authorized security testing and adversary simulation. You must have explicit written permission before testing any system you do not own.
The Kogeki server runs on Linux. The operator client runs on Linux, Windows, and macOS. Agents are available for Windows, Linux, and macOS targets.
Kogeki supports HTTP/S, SMB, TCP, DNS/DoH, and TCP/mTLS listeners. Additional listener profiles can be added through the plugin architecture.
Contact the team through the request form below. Access is granted after verification of identity and intended use case.
Request a demo or evaluation access for your authorized red-team program.