Ghost of Death is an app to spoof your OS.
It's meant to spoof scanning apps, like nmap or Metasploit.
You must be admin/root.
2-28-26: Addressed a couple of bugs. Totally reworked Linux version.
This app won't get a perfect match in the spoof, but it won't let them know your OS.
3-1-26: Tweaked on the Linux version some more.
3-2-26: That last Linux version was messed up, new one works, theoretically.
Features
- 12 OS profile presets (Windows, Linux, macOS, FreeBSD, OpenBSD, Cisco, Android) with one-click apply
- TTL spoofing — registry write (Windows) / sysctl (Linux)
- TCP Window Size spoofing (Linux)
- MSS (Maximum Segment Size) spoofing (Linux)
- Manual TTL override (1-255)
- One-click restore to OS defaults
- Live TTL check via loopback ping — ground truth, confirms reboot status
- Live TTL config check — reads registry (Windows) / sysctl (Linux)
- Hostname plausibility check — flags hostnames that contradict claimed OS
- Betrayal port scanner — checks localhost for ports that expose real OS: 135 MS RPC, 139 NetBIOS, 445 SMB, 3389 RDP, 5985 WinRM (Windows) 111 rpcbind (Linux)
- Recommended nmap command reference (per selected profile)
- Metasploit auxiliary module reference table — the 6 modules most likely to expose your real OS with quick-use commands
- A lot of talk, it may not spoof your OS, but it will keep a secret...
Categories
Penetration TestingFollow Ghost of Death
Other Useful Business Software
Our Free Plans just got better! | Auth0
You asked, we delivered! Auth0 is excited to expand our Free and Paid plans to include more options so you can focus on building, deploying, and scaling applications without having to worry about your security. Auth0 now, thank yourself later.
Rate This Project
Login To Rate This Project
User Reviews
Be the first to post a review of Ghost of Death!