Xpanda is a cyber security software developed by ACCURATE Cyber Defense, designed to serve as a comprehensive platform for cyber drills, cybersecurity simulations, and advanced adversarial training. In an era where cyber threats grow more sophisticated by the day, Xpanda provides organizations, military cyber units, and security professionals with a controlled environment to simulate realistic attack scenarios and test their defensive capabilities. The tool is built with a modular architecture that covers a wide range of advanced features, making it one of the most versatile cybersecurity simulation frameworks available today.
One of Xpanda's most powerful and distinguishing capabilities is its multi-channel Command and Control (C2) functionality. The tool allows users to fire commands through a variety of popular communication and social media platforms, including Discord, Telegram, Slack, Google Chat, WhatsApp, and other social media channels. This feature is critical because real-world attackers frequently leverage legitimate collaboration and messaging platforms to maintain persistence, issue commands, and exfiltrate data, as this traffic often blends seamlessly with normal corporate communications. By replicating this behavior, Xpanda enables defenders to practice monitoring non-traditional communication channels for malicious activity and to detect anomalous traffic patterns on platforms that are typically whitelisted by corporate firewalls.
Xpanda also includes a suite of advanced modules that simulate the full spectrum of modern cyber attack techniques. The social engineering module allows facilitators to simulate sophisticated phishing campaigns, spear-phishing, and pretexting attacks, helping organizations test their human firewalls and employee awareness without exposing the organization to actual risk. The keylogger simulation module mimics the behavior of credential-harvesting malware, enabling security teams to test their Endpoint Detection and Response (EDR) systems' ability to detect input capture attempts and unauthorized process hooking. The network penetration testing module goes beyond simple scanning by simulating active exploitation, lateral movement, privilege escalation, and data exfiltration within a sandboxed environment, testing the resilience of network segmentation and intrusion detection systems.
The primary use of Xpanda lies in cyber drills and cybersecurity simulations. In an era where ransomware and state-sponsored attacks are prevalent, regular drills are essential for maintaining readiness. Xpanda enables Red Team exercises, where security professionals can emulate full-scale attacks on simulated infrastructure to test offensive capabilities in a legal and safe environment. It also supports Blue Team defense training, where defenders sharpen their incident response skills by detecting social engineering attempts, identifying keylogger traffic, and stopping network penetration in real time. Additionally, organizations can use Xpanda for tool validation, testing their existing security stack, including SIEM, SOAR, and firewalls, against the advanced vectors generated by the platform to ensure their tools are correctly tuned.
Developed by ACCURATE Cyber Defense, Xpanda represents the pinnacle of simulation technology. It bridges the gap between static training and chaotic real-world incidents, providing a safe, controlled, and deeply detailed environment where failure becomes a learning opportunity rather than a catastrophe. By incorporating Xpanda into your security posture, you are not just acquiring software; you are investing in the readiness of your human capital and preparing your team for the worst-case scenario by simulating it today.
ACCURATE Cyber Defense: Empowering Defenders Through Realistic Simulation.
- 100+ Security Commands
- Multi-Platform Bot Integration (Discord, Telegram, Slack, Signal, WhatsApp, Google Chat, iMessage)
- Web Interface with Cyberpunk Terminal UI
- Advanced Phishing Suite with 100+ Templates
- SSH Remote Access via All Platforms
- REAL Traffic Generation (ICMP/TCP/UDP/HTTP/DNS/ARP)
- Nikto Web Vulnerability Scanner
- Advanced Keylogger with PDF/Email/HTML Exfiltration
- Password Cracking Engine (Hashcat Integration)
- Social Engineering Suite with 100+ Phishing Templates
- IP Management & Threat Detection
- ARP Spoofing & Network Manipulation
- MAC Address Management
- NAT Information
- AI Transformer Engine
- Terminal Animations
- Multi-Platform Command Execution
- Email Composition & Sending
- PDF Report Generation
- Docker Security Scanning
curl -fsSL https://raw.githubusercontent.com/iankulani/xpanda_v2/main/install.sh | bashLinux/macOS
git clone https://github.com/iankulani/xpanda_v2.git
cd xpanda_v2chmod +x install.sh
./install.shpython3 -m venv venv
source venv/bin/activate
pip install -r requirements.txtpython3 xpanda_v2.pyWindows
git clone https://github.com/iankulani/xpanda_v2.git
cd xpanda-v2install.batpython -m venv venv
venv\Scripts\activate
pip install -r requirements.txtpython xpanda_v2.pydocker build -t xpanda-v2:2.0.0 .docker run -it --rm \
--name xpanda-v2 \
--network host \
--cap-add NET_ADMIN \
--cap-add NET_RAW \
--cap-add SYS_ADMIN \
-v xpanda_data:/home/xpanda/.xpanda \
xpanda-v2:2.0.0docker-compose up -ddocker-compose logs -f
docker-compose down
./xpanda
python3 xpanda_v2.py
πΌ> help
πΌ> ping 127.0.0.1
πΌ> nmap_quick 192.168.1.1
πΌ> traffic icmp 192.168.1.1 10
πΌ> keylogger_start
Network Commands
Command Description ping Ping a target nmap_quick Quick port scan nmap_full Full port scan traceroute Trace network path whois WHOIS lookup dns DNS lookup location IP geolocation Security Commands Command Description nikto Web vulnerability scan dos_syn SYN flood attack crack Password cracking arp_spoof ARP spoofing mac_info MAC address info nat_info NAT information Social Engineering Command Description phish_facebook Facebook phishing page phish_gmail Gmail phishing page phish_start Start phishing server phish_creds View captured credentials Platform Commands Command Description platform_send Send command to platform platform_status Show platform status agent_register Register agent System Commands Command Description status System status history Command history system System information threats Recent threats report Security report help Help menu
βοΈ Configuration Configuration is stored in ~/.xpanda/config.json:
json { "version": "2.0.0", "auto_start": false, "web": { "enabled": true, "port": 5000, "host": "0.0.0.0" }, "keylogger": { "enabled": false, "hotkey": "f10", "upload_interval": 30 }, "discord": { "enabled": false, "token": "", "prefix": "!" }, "telegram": { "enabled": false, "bot_token": "", "prefix": "/" } } π€ Platform Integrations Discord Create a bot at https://discord.com/developers
Get your bot token
Configure in xPanda-V2:
text πΌ> platform_send discord "ping 8.8.8.8" Telegram Talk to @BotFather on Telegram
Create a new bot and get the token
Configure in xPanda-V2
Slack Create a Slack app at https://api.slack.com/apps
Get your bot token
Configure in xPanda-V2
π³ Docker Deployment Production Deployment yaml
version: '3.8' services: xpanda: image: xpanda-v2:2.0.0 network_mode: host cap_add: - NET_ADMIN - NET_RAW - SYS_ADMIN volumes: - xpanda_data:/home/xpanda/.xpanda restart: always volumes: xpanda_data: bash docker-compose -f docker-compose.prod.yml up -d π CI/CD The project uses GitLab CI/CD with the following stages:
Validate - Lint Python, YAML, Dockerfile
Test - Unit tests, dependency checks, security scans
Build - Docker image build
Security - Trivy, Grype vulnerability scans
Deploy - Staging and production deployment
Environment Variables Variable Description CI_REGISTRY_USER Docker registry username CI_REGISTRY_PASSWORD Docker registry password SSH_PRIVATE_KEY SSH private key for deployment STAGING_HOST Staging server hostname PRODUCTION_HOST Production server hostname π§ Troubleshooting Common Issues
- Permission denied on raw sockets
bash
sudo python3 xpanda_v2.py 2. Missing system tools
bash
sudo apt-get install nmap curl wget netcat-openbsd dnsutils traceroute openssh-client docker.io git nikto hashcat iptables macchanger hping3 tcpdump openssl
brew install nmap curl wget netcat bind traceroute openssh docker git nikto hashcat tcpdump openssl 3. Python package errors
bash
pip install --force-reinstall -r requirements.txt 4. Docker permission issues
bash
sudo usermod -aG docker $USER newgrp docker 5. Web dashboard not accessible
bash
sudo ufw allow 5000
sudo iptables -A INPUT -p tcp --dport 5000 -j ACCEPT Getting Help bash
python3 requirements-check.py
tail -f ~/.xpanda/xpanda.log
XPANDA_DEBUG=1 python3 xpanda_v2.py
