Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0192
MITRE ATT&CK Tool

Pupy (S0192)

ShareXLinkedInRedditHN

[Pupy](https://attack.mitre.org/software/S0192) is an open source, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool. (Citation: GitHub Pupy) It is written in Python and can be generated as a payload in several different ways (Windows exe, Python file, PowerShell oneliner/file, Linux elf, APK, Rubber Ducky, etc.). (Citation: GitHub Pupy) [Pupy](https://attack.mitre.org/software/S0192) is publicly available on GitHub. (Citation: GitHub Pupy)

Platforms: Linux, Windows, macOS, Android

▪Techniques implemented (41)

T1569.002Service ExecutionT1046Network Service DiscoveryT1113Screen CaptureT1552.001Credentials In FilesT1105Ingress Tool TransferT1135Network Share DiscoveryT1573.002Asymmetric CryptographyT1548.002Bypass User Account ControlT1059.001PowerShellT1033System Owner/User DiscoveryT1136.002Domain AccountT1041Exfiltration Over C2 ChannelT1555.003Credentials from Web BrowsersT1123Audio CaptureT1055.001Dynamic-link Library InjectionT1016System Network Configuration DiscoveryT1114.001Local Email CollectionT1543.002Systemd ServiceT1136.001Local AccountT1547.013XDG Autostart EntriesT1083File and Directory DiscoveryT1082System Information DiscoveryT1003.001LSASS MemoryT1056.001KeyloggingT1071.001Web ProtocolsT1497.001System ChecksT1021.001Remote Desktop ProtocolT1550.003Pass the TicketT1557.001Name Resolution Poisoning and SMB RelayT1087.001Local AccountT1059.006PythonT1125Video CaptureT1685.005Clear Windows Event LogsT1134.001Token Impersonation/TheftT1560.001Archive via UtilityT1547.001Registry Run Keys / Startup FolderT1003.005Cached Domain CredentialsT1003.004LSA SecretsT1049System Network Connections DiscoveryT1555Credentials from Password StoresT1057Process Discovery

▪Used by groups (2)

G0059Magic HoundG0064APT33
S0192on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.