ssh-mitm is a free, open source threat detection & response project written in Python and released under GPL-3.0. It has 1,472 GitHub stars, 157 forks and 2 open issues, and was last pushed 18 days ago. On this registry it ranks #39 of 46 tracked projects in Threat Detection & Response, with 5 head-to-head comparisons available.

What is ssh-mitm?

SSH-MITM is a Python-based interactive SSH interception proxy for authorized security auditors, penetration testers, and researchers who need visibility and control over SSH sessions.

What it is

SSH-MITM places itself between an SSH client and its server, terminating each side of the connection independently while forwarding all traffic between them. The auditor gains full visibility of the session as it happens: credentials are logged as soon as authentication succeeds, and every intercepted connection also opens a mirror shell on a local port that can be attached to from a separate terminal. It lives in the Python ecosystem and is distributed under the GPL-3.0 licence.

The problem it addresses is that SSH traffic is otherwise opaque during an engagement — an auditor can see that a connection happened but not what the user typed, what they transferred, or how they authenticated. SSH-MITM removes that blind spot by turning the connection point into an observation and intervention point, replacing what would otherwise require ad-hoc shell logging or host-side instrumentation on a target the auditor may not be able to reconfigure. It is documented as an authorized-auditing tool and carries an explicit legal notice restricting it to systems the operator owns or has written permission to test.

Key capabilities

  • Opens a mirror shell for every intercepted connection (for example on a local port such as 34463), letting the auditor observe user activity in real time and inject commands independently without disturbing the original session.
  • Intercepts and manipulates SCP and SFTP file transfers, storing copies of transferred files or replacing files on the fly.
  • Intercepts TCP port forwarding tunnels and dynamic SOCKS 4/5 forwarding.
  • Performs the trivial auth attack to phish FIDO2 hardware token authentication.
  • Runs an interactive, browser-based tutorial via ssh-mitm tutorial, with five chapters covering password interception, public-key authentication, SFTP transfers, command execution, and live session mirroring against a sample target.
  • Supports the authentication paths an engagement is likely to encounter, logging remote address, username, password, and agent presence when a session authenticates.
  • Is tracked against relevant vulnerabilities in its topic list, including CVE-2021-36367 and CVE-2021-36368.

Who uses it and how

  • Penetration testers who have been granted a network position between a client and a server, routing clients through the proxy port (10022) while the target remains reachable as the remote host.
  • Auditors conducting authorized password and public-key authentication assessments who need credentials recorded during the engagement.
  • Security researchers reproducing FIDO2 and SSH authentication attacks in a lab setting, guided by the built-in tutorial rather than a live target.
  • Engagement teams that need to demonstrate real-time session awareness, attaching to mirror shells from separate terminals to watch and influence activity as it occurs.
  • Practitioners working from a single machine, since the tool requires no server installation and runs as a standalone executable.

Getting started

Download the AppImage from the GitHub releases page, make it executable, and run ssh-mitm server --remote-host, or install from source with pip install git+https://github.com/ssh-mitm/ssh-mitm.git; pip, Flatpak, and Snap options are described in the installation guide at https://docs.ssh-mim.at.

How it compares

The registry names no comparable or superseded tools for this entry, so SSH-MITM stands alone here.

When to use it — and when not to

Use it only when you can legitimately sit between a client and its server, because the tool's entire value depends on that network position and on written authorization; it will not help an auditor who only has a shell on the target host. The project itself warns that unauthorized interception of SSH traffic may be illegal in your jurisdiction. The main practical weakness in the facts provided is distribution consistency: the README notes that the PyPI release may lag behind, so users wanting the tutorial and recent improvements must install directly from GitHub rather than the packaged release.

project readme (upstream, from github) — read inline

SSH-MITM - ssh audits made simple

SSH-MITM intercepting password login

An interactive SSH interception tool for authorized security audits.
Intercept sessions, monitor live traffic, inject commands, and manipulate file transfers — all in real time.

Download as an AppImage     Download on Flathub     Get it from the Snap Store

OpenSSF Best Practices Code style: black CodeFactor Documentation Status PRs Welcome GitHub Follow me on GitHub

Legal notice: SSH-MITM is intended for authorized security audits, penetration testing, and research only. Do not use it against systems you do not own or have explicit written permission to test. Unauthorized interception of SSH traffic may be illegal in your jurisdiction.


🎓 New to SSH-MITM? Start with the interactive tutorial

ssh-mitm tutorial

Opens a browser-based, step-by-step guide — no target server needed. Five chapters follow an authorized assessment of Logfile Inc., covering password interception, public-key auth, SFTP transfers, command execution, and live session mirroring.

SSH-MITM interactive tutorial


Quick Start

Placed between a client and its SSH server, SSH-MITM intercepts the connection — terminating both sides independently and forwarding all traffic while giving the auditor full visibility and control:

SSH-MITM setup

1. Install

SSH-MITM requires no installation. Download the AppImage and you are ready to go:

wget -O ssh-mitm https://github.com/ssh-mitm/ssh-mitm/releases/latest/download/ssh-mitm-x86_64.AppImage
chmod +x ssh-mitm

Move it to a directory on your PATH (e.g. ~/.local/bin) to run it as ssh-mitm like below.

For other installation options (pip, Flatpak, Snap) see the installation guide.

⚡ Get the latest version

The PyPI release may lag behind. Install directly from GitHub to get the interactive tutorial and all recent improvements:

pip install git+https://github.com/ssh-mitm/ssh-mitm.git

2. Start SSH-MITM

Point SSH-MITM at your target host — use a system you are authorized to test:

ssh-mitm server --remote-host <target-host>

3. Route a client connection

Have the SSH client connect through SSH-MITM on port 10022:

ssh -p 10022 user@mitm-host

SSH-MITM intercepts the session and logs the credentials immediately:

INFO     Remote authentication succeeded
    Remote Address: <target-host>:22
    Username: alice
    Password: secret
    Agent: no agent

SSH-MITM intercepting credentials

4. Attach to the live session

For every intercepted connection, SSH-MITM opens a mirror shell on a local port:

INFO     ℹ created mirrorshell on port 34463. connect with: ssh -p 34463 127.0.0.1

Connect to it from a separate terminal:

ssh -p 34463 127.0.0.1

The mirror shell reflects the session in real time. The auditor can observe the user's activity and inject commands independently, without affecting the original connection.

What SSH-MITM can do

Feature Description
Interactive session monitoring Attach to any intercepted session via a mirror shell — observe and inject commands in real time
File transfer manipulation Intercept SCP/SFTP transfers, store copies, or replace files on the fly
Port forwarding interception Intercept TCP tunnels and dynamic SOCKS 4/5 forwarding
FIDO2 token phishing Intercept hardware token authentication via the trivial auth attack (OpenSSH info)
Authentication interception Capture passwords; accept the same public key as the target server and fall back to password auth automatically
MOSH session monitoring Intercept and decrypt MOSH (Mobile Shell) UDP sessions; view the live terminal via a built-in VT100/ANSI emulator
PowerShell remoting (PSRP) Intercept PowerShell remoting sessions over SSH; log commands, output, errors, and state transitions; write per-session transcripts
Client auditing Identify known vulnerabilities in connecting SSH clients from key negotiation behavior alone
Plugin support Extend and customize all interception behavior with plugins

Use Cases

  • Penetration testing — actively audit SSH clients and servers in authorized engagements; intercept, manipulate, and replay sessions
  • Security research — analyze SSH client behavior, authentication flows, and protocol-level weaknesses interactively
  • Training environments — demonstrate MITM techniques and session hijacking in controlled lab setups
  • Malware analysis — monitor and interact with SSH sessions from suspicious clients in isolated environments

Security Research

SSH-MITM was originally developed to investigate a fundamental weakness in how SSH clients handle hardware token authentication. The research uncovered that FIDO2 tokens — often used as a second factor — can be phished through a technique called trivial authentication.

The attack exploits the fact that SSH clients can be forced into a trivial authentication method — such as keyboard-interactive with no prompts — which effectively grants access without any real authentication. This completely bypasses hardware token protection, since the token is never challenged. SSH-MITM can simulate this against any client that does not explicitly reject it:

ssh-mitm server --enable-trivial-auth

Operating from the Man-in-the-Middle position makes it possible to observe SSH client behavior that is invisible from either endpoint. SSH-MITM has been used to discover 7 previously unknown vulnerabilities in widely-deployed SSH software:

CVE-2026-60000 CVE-2022-38337 CVE-2022-38336 CVE-2021-36370 CVE-2021-36369 CVE-2021-36368 CVE-2021-36367

Latest: CVE-2026-60000 — OpenSSH's GSSAPI authentication violated RFC 4462 in ways that let an attacker bypass MaxAuthTries entirely, causing a pre-authentication denial of service. The same root cause also produced a username validity oracle and a privileged-process crash, all fixed in OpenSSH 10.4.

Talk at DeepSec 2021 — full explanation of the attack:
Click to view on vimeo.com
Click to view video on vimeo.com

Download presentation slides

Not every result of this research is a vulnerability — see Upstream Contributions for hardening fixes contributed directly to OpenSSH.

(back to top)

Contributing

Contributions are welcome! Please read CONTRIBUTING.md for details on the development setup, code style, and how to submit a pull request.

(back to top)

Contact

(back to top)

Contributors

Frequently asked questions

Is ssh-mitm free to use?

ssh-mitm is open source under the GPL-3.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does ssh-mitm do?

SSH-MITM - ssh audits made simple

What is ssh-mitm written in?

ssh-mitm is primarily written in Python. Its source is publicly available at https://github.com/ssh-mitm/ssh-mitm, and it has 1,472 GitHub stars.