goshs is a free, open source networking & connectivity project written in Go and released under MIT. It has 987 GitHub stars, 58 forks and 0 open issues, and was last pushed 3 days ago. On this registry it ranks #43 of 45 tracked projects in Networking & Connectivity, with 5 head-to-head comparisons available.

What is goshs?

goshs is a single-binary file server written in Go for red teamers, CTF players, and developers who need more capability than python3 -m http.server without configuring Apache.

What it is

goshs is an MIT-licensed Go project that bundles many network services into one executable: HTTP/S, WebDAV, FTP/SFTP, SMB, LDAP/S, plus a DNS server, an SMTP server, basic auth, share links, and NTLM hash capture with cracking. It lives in the Infrastructure & Operations / Networking & Connectivity space and is positioned as a replacement for Python's SimpleHTTPServer — the README opens on the scenario of being mid-engagement and needing to transfer a file, catch an SMB hash, or stand up a quick HTTPS server when python3 -m http.server will not do.

The concrete problem it solves is tool sprawl during an engagement or a quick dev workflow: instead of configuring Apache for HTTPS, running a separate SMB listener for hash capture, and juggling another chat tool for team coordination, goshs serves files and runs the auxiliary services from one command. File operations include resumable and seekable downloads via HTTP Range, drag-and-drop upload through POST/PUT, deletion, bulk ZIP, and QR codes.

Key capabilities

  • Serve files over HTTP/S, WebDAV, FTP/SFTP, SMB, and LDAP/S from one binary, with TLS from a self-signed certificate, Let's Encrypt, or a custom certificate.
  • Capture SMB NTLM hashes with -smb -smb-domain CORP, and capture LDAP credentials with NTLM cracking against a wordlist such as /usr/share/wordlists/rockyou.txt, including JNDI mode for Log4Shell.
  • Catch DNS callbacks and receive emails via goshs -dns -dns-ip 1.2.3.4 -smtp -smtp-domain your-domain.com.
  • Render payload templates on demand, substituting {{.LHOST}} and {{.LPORT}} plus custom --tpl-var values when a file is fetched with ?tpl.
  • Run server modes including read-only, upload-only, no-delete, silent, invisible, CLI command execution, and TTL self-destruct (--ttl 2h).
  • Share files through token-based links with download and time limits, protected by basic auth, certificate auth, IP whitelists, and file-based ACLs.
  • Use the interactive terminal dashboard (--tui) with live panes for HTTP, DNS, SMB, LDAP, SMTP, reverse shells, and team chat, with shell attach and upgrade.

Who uses it and how

  • Red teamers mid-engagement who need to stand up HTTPS with basic auth (goshs -s -ss -b user:password) or serve payloads that auto-fill the callback host and port at download time (goshs -i 10.10.14.7 --template).
  • CTF and capture-the-flag teams using the live team chat — shared between web and TUI — with markdown, emoji shortcodes, image paste, file upload, and optional disk persistence.
  • Operators running headless SSH sessions who use --tui for an interactive full-screen dashboard and monitor reverse shells as they arrive.
  • Users who want a short-lived listener that self-destructs after a set period, such as goshs --ttl 2h.
  • Developers and pentesters who hook up webhooks, a JSON API, mDNS, or a tunnel via localhost.run.

Getting started

The README's quick start runs the binary directly — goshs serves the current directory on port 8000 — and releases are published via goreleaser on GitHub, with documentation at docs.goshs.de and a live demo at demo.goshs.de.

How it compares

It stands alongside python3 -m http.server, which it is explicitly designed to replace: where Python's SimpleHTTPServer offers only plain HTTP file listing, goshs adds TLS, authentication, multiple transfer protocols, hash capture, and collaboration features in one binary. Beyond Python's standard library, this registry names no comparable tool among the facts provided.

When to use it — and when not

Because it is a single binary, there is no database, storage layer, or SMTP infrastructure to operate separately — the SMTP and DNS servers are built in — but a self-hoster must still manage TLS certificates, ACL files, and wordlists for cracking. It is a poor fit for anyone who needs a hardened production web server with long-lived multi-user content, and the security-sensitive modes (NTLM capture, credential capture, reverse shell catching) are appropriate only for authorized testing. The project ships under the MIT licence with zero open issues and a recent push, though the full documentation lives off-repo at docs.goshs.de rather than in the README itself.

project readme (upstream, from github) — read inline

Version GitHub License GitHub go.mod Go version GitHub issues Downloads Stars goreleaser codecov OpenSSF Scorecard OpenSSF Best Practices

goshs-logo

You're mid-engagement. You need to transfer a file, catch an SMB hash, or stand up a quick HTTPS server — and python3 -m http.server won't cut it.

goshs is a single-binary file server built for the moments when you need more than Python's SimpleHTTPServer but don't want to configure Apache. HTTP/S, WebDAV, FTP/SFTP, SMB, LDAP/S, basic auth, share links, DNS/SMTP callbacks, NTLM hash capture + cracking — all from one command.

intro

goshs-screenshot-light goshs-screenshot-dark

Demo

Try it out yourself: demo.goshs.de

goshs-demo

Quick Start

# Serve the current directory on port 8000
goshs

# Serve with HTTPS (self-signed) and basic auth
goshs -s -ss -b user:password

# Capture SMB hashes
goshs -smb -smb-domain CORP

# Capture LDAP credentials and NTLM hashes (with optional wordlist cracking)
goshs -ldap
goshs -ldap -ldap-wordlist /usr/share/wordlists/rockyou.txt

# Catch DNS callbacks and receive emails
goshs -dns -dns-ip 1.2.3.4 -smtp -smtp-domain your-domain.com

# Self-destruct after 2 hours
goshs --ttl 2h

# Run with the interactive terminal dashboard (great for headless SSH sessions)
goshs --tui

# Serve payloads that auto-fill your callback host/port at download time
goshs -i 10.10.14.7 --template --tpl-var LPORT=4444
# fetch rendered: curl 'http://10.10.14.7:8000/rev.ps1?tpl'

Documentation

For a detailed documentation go to docs.goshs.de

Features

📁 File Operations Download (resumable & seekable via HTTP Range), upload (drag & drop, POST/PUT), delete, bulk ZIP, QR codes
🔌 Protocols HTTP/S, WebDAV, FTP/SFTP, SMB, LDAP/S
🔒 Auth & Security Basic auth, certificate auth, TLS (self-signed, Let's Encrypt, custom cert), IP whitelist, file-based ACLs
⚙️ Server Modes Read-only, upload-only, no-delete, silent, invisible, CLI command execution, TTL self-destruct
🔗 Share Links Token-based sharing, download limit, time limit
🎯 Collaboration / CTF Live team chat (markdown, emoji + :shortcodes: autosuggest, image paste, file upload, reactions, message edit, optional disk persistence — shared web ↔ TUI), DNS server, SMTP server, SMB NTLM hash capture + cracking, LDAP credential capture + NTLM hash cracking (JNDI mode for Log4Shell), redirect endpoint, Rev Shell Catcher + Payload generator
🧩 Payload Templating Render {{.LHOST}}/{{.LPORT}} + custom --tpl-var values into served files on demand (?tpl)
🔔 Integration Webhooks, tunnel via localhost.run, config file, JSON API, mDNS
🖥️ TUI Dashboard Interactive full-screen terminal dashboard; live panes for HTTP, DNS, SMB, LDAP, SMTP, reverse shells and team chat; attach and upgrade shells from the terminal
🛠️ Misc Dark/light themes, team chat, self-update, log output, embed files, drop privileges

Installation

Method
🐧 curl | sh curl -sSfL https://goshs.de/install.sh | sh
🦫 Go go install goshs.de/goshs/v2@latest
🐉 Kali & Parrot OS sudo apt install goshs
🎗️ Arch Linux (AUR) yay -S goshs-bin
🖤 BlackArch pacman -S goshs
🏔️ Alpine Linux (edge) apk add goshs
🫙 Snap snap install goshs
🎩 Fedora / RHEL (COPR) dnf copr enable goshs-labs/goshs && dnf install goshs
🦎 openSUSE sudo zypper install goshs
❄️ Nix / NixOS nix-env -iA nixpkgs.goshs
🍺 Homebrew brew install goshs
🪟 Scoop scoop bucket add extras && scoop install extras/goshs
🪟 winget winget install GoshsLabs.Goshs
🍫 Chocolatey choco install goshs
🐳 Docker docker run --rm -it -p 8000:8000 -v "$PWD:/pwd" goshs-labs/goshs:latest -d /pwd
📦 Release Download from GitHub Releases
🐚 Shell completion

goshs can install tab completion for bash, fish, and zsh:

goshs --completion bash
goshs --completion fish
goshs --completion zsh

On macOS with Homebrew the correct Homebrew path is used automatically. After installation the command prints an exact activation instruction, e.g.:

source ~/.local/share/bash-completion/completions/goshs
🔧 Build yourself

The bundled web assets are committed, so a plain build just works:

git clone https://github.com/goshs-labs/goshs.git
cd goshs
go build -o goshs .

If you change the JavaScript or SCSS sources, rebuild the assets first with esbuild and sass installed:

make generate
go build -o goshs .

Code Contributors

Contributors

Security Contributors

These are the awesome contributors that made goshs even more secure :heart:

Community

Join the Discord Community and start connecting.

Join Discord

Star History

Star History Chart

Credits

A special thank you goes to sc0tfree for inspiring this project with his project updog written in Python.

Frequently asked questions

Is goshs free to use?

goshs is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does goshs do?

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TL

What is goshs written in?

goshs is primarily written in Go. Its source is publicly available at https://github.com/goshs-labs/goshs, and it has 987 GitHub stars.