Ghost of Death is an app to spoof your OS.
It's meant to spoof scanning apps, like nmap or Metasploit.
You must be admin/root.
2-28-26: Addressed a couple of bugs. Totally reworked Linux version.
This app won't get a perfect match in the spoof, but it won't let them know your OS.
3-1-26: Tweaked on the Linux version some more.
3-2-26: That last Linux version was messed up, new one works, theoretically.
3-3-26: After much labor it's done. It has Windows, Mac and Android now. Windows comes closest for the spoof, but none of the profiles will let them know your running Kali.
Features
- 4 OS profile presets (Windows, 2 macOS, Android) with one-click apply
- TTL spoofing — sysctl (Linux)
- TCP Window Size spoofing
- MSS (Maximum Segment Size) spoofing
- Manual TTL override (1-255)
- One-click restore to OS defaults
- Live TTL check via loopback ping — ground truth, confirms reboot status
- Live TTL config check — sysctl
- Hostname plausibility check — flags hostnames that contradict claimed OS
- Betrayal port scanner — checks localhost for ports that expose real OS: 135 MS RPC, 139 NetBIOS, 445 SMB, 3389 RDP, 5985 WinRM (Windows) 111 rpcbind (Linux)
- Recommended nmap command reference (per selected profile)
- Metasploit auxiliary module reference table — the 6 modules most likely to expose your real OS with quick-use commands
- A lot of talk, it may not spoof your OS, but it will keep a secret...
Categories
Penetration TestingFollow Ghost of Death
Other Useful Business Software
Custom VMs From 1 to 96 vCPUs With 99.95% Uptime
Live migration and automatic failover keep workloads online through maintenance. One free e2-micro VM every month.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of Ghost of Death!