# Install bounceback with Homebrew

Stealth redirector for red team operation security. Version 1.5.3 via Homebrew; verified 2026-07-26.

## Install

```sh
sudo av install brew:bounceback
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install bounceback
```

  Evidence: local Homebrew formula metadata

## Package facts

- **Package key:** brew:bounceback
- **Package manager:** Homebrew
- **Version:** 1.5.3
- **Source summary:** Stealth redirector for red team operation security
- **Homepage:** <https://github.com/D00Movenok/BounceBack>
- **Repository:** <https://github.com/D00Movenok/BounceBack>
- **Last updated:** 2026-07-26T10:56:35+02:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- bounceback (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 1.5.3
## Project history and usage

BounceBack is a Go-based red-team redirector and reverse proxy for hiding command-and-control, phishing, or other operation infrastructure from scanners and unwanted visitors.

### Project history

The public repository was created in May 2023. Its README describes BounceBack as a highly customizable reverse proxy with WAF-like filtering, real-time traffic analysis, IP and geolocation rules, domain fronting support, Malleable C2 profile validation, and multiple proxy protocols.

The first GitHub release line began with v1.0.0 in July 2023, followed by 1.4 and 1.5 releases through 2026.

### Adoption history

BounceBack appears to be a niche security-operations package rather than a broad platform dependency. Its Homebrew formula gives it a package-manager entry point, while the upstream README directs users to download release archives, edit `config.yml`, and run the `bounceback` binary.

Repository metadata shows meaningful interest for a specialized red-team tool, but its adoption story is still mostly upstream GitHub releases plus the Homebrew package.

### How it is used

Operators configure rules, proxies, and globals in `config.yml`, optionally refresh bundled banned-IP data, and run `bounceback` with a config and log path. The tool supports HTTP(S), DNS, raw TCP, TLS-wrapped TCP, and UDP proxying with rule pipelines.

The practical use case is traffic triage: allow expected operator or target traffic through while rejecting traffic from scanners, security vendors, sandboxes, or requests that fail a configured C2 profile.

### Why package nerds care

For package nerds, BounceBack is interesting as a security tradecraft tool packaged like an ordinary CLI. It shows how red-team infrastructure utilities increasingly ship as small Go binaries with YAML config, release archives, and Homebrew distribution.

### Timeline

- 2023: Public GitHub repository created.
- 2023: v1.0.0 published on GitHub Releases.
- 2024: v1.5.0 and v1.5.1 release line continued.
- 2026: v1.5.3 published.

### Related projects

- Cobalt Strike Malleable C2 profiles are directly relevant because BounceBack validates inbound traffic against Malleable profile rules.
- Generic reverse proxies and web application firewalls are adjacent infrastructure patterns, though BounceBack applies them to red-team OPSEC.

### Sources

- <https://api.github.com/repos/D00Movenok/BounceBack>
- <https://github.com/D00Movenok/BounceBack>
- <https://github.com/D00Movenok/BounceBack/releases>
- <https://github.com/D00Movenok/BounceBack/wiki>
- <https://raw.githubusercontent.com/D00Movenok/BounceBack/main/config.yml>


## Security Notes

formula declares a Homebrew service.

- **Geiger risk:** orange / medium
- formula declares a Homebrew service


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: config.yml

## Combined YAML source

View the package source record on GitHub. [combined/bounceback.yml](https://github.com/mxcl/pkgdb/blob/main/combined/bounceback.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- cross-ecosystem install command graph
