Maintaining Access
WireGuard is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. In penetration testing, it is used to create secure, persistent tunnels for maintaining access to compromised networks.
sudo apt install wireguard
wg-quick up <interface>
WireGuard is a modern VPN protocol that uses state-of-the-art cryptography to create secure network tunnels. In penetration testing, it enables persistent, encrypted access to compromised networks with minimal latency.
Unlike traditional VPNs, WireGuard integrates directly into the Linux kernel, provides seamless roaming, and requires minimal configuration — making it the go-to choice for red teams requiring reliable covert channels.
wg genkey > privatekeyGenerate a new private key and save it to a filewg pubkey < privatekey > publickeyDerive the public key from an existing private keywg genkey | tee privatekey | wg pubkey > publickeyGenerate a private key and its matching public key in one pipelinewg genpsk > presharedkeyGenerate a preshared key for extra symmetric protectionwg showShow status of all active WireGuard interfaceswg show allExplicitly show every interface's peers and statswg show wg0Show status, peers and handshakes for interface wg0wg show wg0 dumpPrint a tab-separated machine-readable dump of wg0wg show interfacesList the names of all WireGuard interfaceswg show wg0 public-keyPrint only the public key of interface wg0wg showconf wg0Print the current configuration of wg0 in config-file formatwg-quick up wg0Bring up the interface defined in /etc/wireguard/wg0.confwg-quick down wg0Tear down the wg0 interface and restore routingwg-quick save wg0Save the running config of wg0 back to its .conf filewg-quick strip wg0Print the config with wg-quick-only keys removed (for wg setconf)Maintain long-term encrypted access to compromised networks.
Route C2 traffic through encrypted WireGuard tunnels.
Access internal subnets via encrypted tunnel.
Hide C2 traffic within legitimate VPN connections.
Generate a private key with wg genkey > privatekey, then derive the public key with wg pubkey < privatekey > publickey. For a one-line pipeline: wg genkey | tee privatekey | wg pubkey > publickey. Each peer needs its own unique key pair for the tunnel to establish.
WireGuard uses UDP port 51820 by default. You can change it in the configuration file with ListenPort = 51820 under the [Interface] section, or at runtime with wg set wg0 listen-port 51820. Both peers must know each other's listening port.
Yes, WireGuard traverses NAT naturally since it uses UDP. For peers behind NAT, set PersistentKeepalive = 25 to maintain the NAT mapping. The endpoint of the public peer is automatically updated when the NATed peer sends its first packet.
Add a [Peer] section to the config file with the peer's PublicKey, AllowedIPs (the subnets routed through this peer), and optionally Endpoint (the peer's public IP:port). For example: AllowedIPs = 192.168.1.0/24 routes traffic for that subnet through the peer.
Yes, WireGuard is significantly faster due to its kernel-level integration and minimal codebase. WireGuard processes packets in the kernel space, while OpenVPN operates in user space. Benchmarks typically show WireGuard achieving near line-speed throughput with lower latency than OpenVPN.
Configure each site's router with a WireGuard interface. Each site gets a unique tunnel IP (e.g., 10.0.0.1/24 and 10.0.0.2/24). Set AllowedIPs to the remote site's LAN subnet (e.g., 192.168.2.0/24) and enable IP forwarding on both routers with sysctl net.ipv4.ip_forward=1.
This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.