Security tool · pivot
ligolo-ng
Modern pivoting via a userland TUN interface - no SOCKS proxychains gymnastics. Cleaner and faster than legacy tunneling for reaching internal subnets.
Overview
Where ligolo-ng fits
Modern pivoting via a userland TUN interface - no SOCKS proxychains gymnastics. Cleaner and faster than legacy tunneling for reaching internal subnets.
Detection-first use
Start with the least intrusive template that can distinguish your hypothesis from a normal response. Preserve raw output and a negative control.
Install
Installation references
Install with releaseAuthorization required
wget https://github.com/nicocha30/ligolo-ng/releases/latest/download/ligolo-ng_agent_linux_amd64.tar.gz- Positive signal
- Tool-specific output that supports the stated hypothesis.
- Negative control
- No result, or identical behavior against a known-safe control.
- Intrusiveness
- Review flags and target scope before execution.
Test safely
Command templates
Proxy (your box)Authorization required
Populate placeholders only with assets that are explicitly in scope.
./proxy -selfcert -laddr 0.0.0.0:{port}- Positive signal
- Tool-specific output that supports the stated hypothesis.
- Negative control
- No result, or identical behavior against a known-safe control.
- Intrusiveness
- Review flags and target scope before execution.
Agent (foothold)Authorization required
Populate placeholders only with assets that are explicitly in scope.
./agent -connect {server}:{port} -ignore-cert- Positive signal
- Tool-specific output that supports the stated hypothesis.
- Negative control
- No result, or identical behavior against a known-safe control.
- Intrusiveness
- Review flags and target scope before execution.
Related
Continue the workflow
Sources
Attribution and verification
Version history: normalized permanent page created 2026-08-20. Upstream activity and popularity are separate signals and do not establish tool safety.