⌁ Ghostline Field Manual
Loading...

Operator handbook

How Ghostline works

Ghostline is a contained game/range experience. The language is immersive, but all target routes, mail interactions, loot, files and callbacks are in-game only.

Contract types

  • Recon: map hosts, services, target people and clues.
  • CVE research: inspect NVD/MITRE/Exploit-DB references, stage a safe PoC stub, and prove posture.
  • GhostMail route: identify a trusted sender, template, reply-to and optional link.
  • Callback/credential: generate a contract-bound link, host it, mail it, and read the returned proof file.
  • Web/API: use whatweb, gobuster, ffuf, curl and evidence commands.
  • Team campaign: split route tasks with a crew and share payout/rep.

Contract rhythm

  1. Complete or opt out of Sandbox.
  2. Accept a contract to unlock Console, Target Site, Hint, Research and PoC controls.
  3. Research the reference if provided.
  4. Use console commands and GhostMail/Market when required.
  5. Package evidence and submit the report flag.

Useful commands

cat briefing.txt
ip addr show tun0
sudo nmap -Pn -sS -sV -sC -O -p- TARGET_IP
whatweb http://TARGET_HOST
gobuster dir -u http://TARGET_HOST -w /usr/share/wordlists/dirb/common.txt
searchsploit CVE-YYYY-NNNN
ghostline payload generate --type credential --scenario OP-CODE --port 8000
python3 -m http.server 8000 --directory ~/files/payloads
ghostline links
ghostline creds
hackops evidence add --scenario OP-CODE --notes "proof captured"
hackops-report --scenario OP-CODE --submit

Ranks

RepRank
0Script Kiddie
250Packet Rat
750Shell Scout
1,500Exploit Analyst
2,800Red Cell Operator
4,500Ghost Strategist
7,000Elite Operator
11,000OffSec Legend
17,000Ghostline Architect

Rep is awarded for completions, clean routes, achievements and team contributions. Expired/dropped contracts can reduce rep.

Heat logic

Heat rises when you play noisy: repeated wrong commands, target-mail bounces, obvious sender mistakes, excessive scans and missed deadlines. Heat drops when you close contracts cleanly, complete Sandbox, buy clean-route training, or use heat-reduction items.

  • 0-39: cool.
  • 40-69: watched; some higher-tier brokers hesitate.
  • 70-99: hot; payouts may be less forgiving.
  • 100+: caught/locked. Pay a fictional fine/bribe or use a Get Out of Jail Free Card from inventory/market to continue.

The heat system is purely in-game. It teaches OPSEC discipline and route quality.

GhostMail rules

Email another player uses normal subject/body only. Templates, sender spoofing and lure links appear only when the selected target contract actually supports them. Target mail requires a valid target address, trusted sender route, correct template, optional hosted link, and a reply-to address where the game can deliver the result.

Interactive Sandbox Range

The Sandbox is a guided mini-contract. Complete each task in order: read the broker drop, accept SBX-001, inspect the synthetic target site, run the nmap practice command, research the public CVE trail, stage the safe file/link, send GhostMail with the trusted sender route and your Reply-To, read the callback file, then submit hackops-report --sandbox --submit.

Paid contracts use the same rhythm but with different objectives, routes, hints, target profiles and proof requirements.