Skip to main content

Technical Architecture & Overview

Ligolo-ng sets up a TUN interface on the operator side and a lightweight agent on the pivot host, giving direct layer-3 access to internal networks over a reverse TCP or TLS connection. Standard tools such as nmap and browsers work through it without proxy configuration, and multi-hop pivots chain agents. It has largely displaced SOCKS-based pivoting in current penetration testing workflows.

Targeted Technical Use Cases

Pivoting into internal network segments during authorized engagements with full tool compatibility.

Evaluation & Trade-offs

Core Strengths

  • +Layer-3 tunneling avoids SOCKS quirks per tool.
  • +Single binary agent with reverse connection.
  • +Multi-hop pivots are straightforward.

Trade-Offs & Limitations

  • -TUN setup needs privileges on the operator machine.
  • -Engagement use requires written authorization; treat like other C2-adjacent tooling.

Defensive Security Application

Red team exercises that test network segmentation and egress filtering effectiveness.

Frequently Asked Questions

What is Ligolo-ng?

Ligolo-ng sets up a TUN interface on the operator side and a lightweight agent on the pivot host, giving direct layer-3 access to internal networks over a reverse TCP or TLS connection. Standard tools such as nmap and browsers work through it without proxy configuration, and multi-hop pivots chain agents. It has largely displaced SOCKS-based pivoting in current penetration testing workflows.

What is Ligolo-ng used for?

Pivoting into internal network segments during authorized engagements with full tool compatibility.

What are the strengths of Ligolo-ng?
  • +Layer-3 tunneling avoids SOCKS quirks per tool.
  • +Single binary agent with reverse connection.
  • +Multi-hop pivots are straightforward.
What are the limitations of Ligolo-ng?
  • +TUN setup needs privileges on the operator machine.
  • +Engagement use requires written authorization; treat like other C2-adjacent tooling.
How is Ligolo-ng used defensively?

Red team exercises that test network segmentation and egress filtering effectiveness.