Authorized Adversary Emulation

Adversary Emulation.
Red Team Operations.
Under Your Control.

Kogeki is a multi-operator post-exploitation framework built for authorized red teams, penetration testers, and adversary simulation programs. Deploy realistic operators, manage resilient agents, and validate defenses — all through encrypted command and control.

  • Multi-operator server/client architecture
  • Windows, Linux & macOS agent support
  • Fully encrypted C2 communications
kogeki-operator@team-1
$ kogeki-server --config prod.yaml
[+] Server listening on 0.0.0.0:443 (mTLS)
[+] Operator session authenticated: redteam-alpha
[*] Agent beacon received: DESKTOP-7X2A-42
[+] Agent linked via SMB pivot
[*] Task queued: socks5 --local 1080
[+] Tunnel established
... awaiting operator command
$ _
5+ Listener Types
3 Operating Systems
mTLS Encrypted Channels
Concurrent Operators

Built for Realistic Adversary Operations

Kogeki combines a modular server, cross-platform GUI client, and extensible agent plugins into one platform for controlled red-team engagements and security validation.

Post-Exploitation Framework

Extensible server

/client architecture with cross-platform GUI support for Linux, Windows, and macOS operators.

  • Multi
  • -Operator
  • Cross-Platform
  • <li>Go Server

Encrypted Command

& Control

Fully encrypted C2 channels with multiple listener profiles to adapt to different network environments.

  • mTLS
  • HTTPS
  • <li>Encrypted Beacons

Listener &

amp; Agent Plugins

Plugin-based

listeners and agents. Switch protocols without rebuilding the core framework.

  • HTTP/S
  • S
  • MB
  • TCP
  • DNS/Do
  • H

Session &

amp; Job Management

Track tasks, jobs, files

, processes, credentials, targets, and screenshots across every engagement.

  • Task Queue
  • Credentials
  • Screens
  • hots

Pivot & Tunneling

Socks4, Socks5, authenticated Socks5, plus local and reverse port forwarding for complex network paths.

  • Socks4/5
  • Port Forward
  • Agent Linking

Kogeki Scripting Engine

Automate operator

workflows with the built-in scripting engine. Run BOFs, custom tasks, and extension kits.

  • BOF Support
  • Extensions
  • Automationli>

From Server to Agent in Four Steps

Every Kogeki engagement follows a controlled workflow — deploy, listen, beacon, operate.

01

Deploy Server

Install the

Kogeki server on your infrastructure. Configure SSL, operators, and authentication.

02

Configure Listener

Choose a

listener profile — HTTP/S, SMB, TCP, DNS/DoH, or TCP/mTLS — matched to the engagement scenario.

03

Deploy Agent

Generate and

deploy a BUHUL or Halimun agent for Windows, Linux, or macOS targets.

04

Operate &

amp; Emulate

Run tasks, manage sessions, pivot through the network, and collect evidence for the resilience report.

Who Uses Kogeki

Kogeki is designed for authorized security professionals who need realistic, controlled adversary simulation.

Red Team

Exercises

Simulate advanced

adversaries to test detection, response, and resilience capabilities of blue teams.

Penetration Testing

Manage post

-exploitation phases across complex environments with reliable agents and operator collaboration.

Adversary Simulation

Emulate real

-world TTPs to validate defensive controls and improve incident response playbooks.

Security Validation

Provide documented evidence of control effectiveness and

gaps for compliance and assurance programs.

Engineered for Stealth & Scale

A Golang server for performance and stability, a C++ Qt client for cross-platform operators, and plugin-based agents that adapt to the target environment — all communicating through encrypted channels with full audit trails.

Go Server Runtime
C++ Qt Cross-Platform Client
mTLS Channel Security

Controlled Operations, By Design

Kogeki is built for authorized use. Built-in safeguards keep every engagement scoped, verifiable, and reversible.

Authorization Required

Every deployment

requires explicit authorization and proof of ownership for the target environment.

Kill Date & Working Time

Define exactly when agents are allowed to

run. Automatic expiration prevents lingering access.

Encrypted Channels

All operator

, listener, and agent traffic is encrypted to protect operational integrity.

Emergency Stop

Ongoing operations can be halted instantly from the server or client, with full session cleanup.

Common Questions

What is Kogeki?

Kogeki is an adversary emulation and post-exploitation framework for authorized red teams and penetration testers. It provides a multi-operator server, cross-platform GUI client, and extensible agents.

Is Kogeki legal to use?

Kogeki is intended exclusively for authorized security testing and adversary simulation. You must have explicit written permission before testing any system you do not own.

<span>Which platforms are supported?

The Kogeki server runs on Linux. The operator client runs on Linux, Windows, and macOS. Agents are available for Windows, Linux, and macOS targets.

What listener types are available?

Kogeki supports HTTP/S, SMB, TCP, DNS/DoH, and TCP/mTLS listeners. Additional listener profiles can be added through the plugin architecture.

How do I request access?

Contact the team through the request form below. Access is granted after verification of identity and intended use case.

Ready to Validate Your Defenses?

Request a demo or evaluation access for your authorized red-team program.