Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
notRDP — Havoc C2 plugin that creates a hidden Windows desktop, streams it to a browser viewer, and injects mouse/keyboard input for covert remote control. | Kitploit
Tools/GitHubGitHub/dagowda/notrdp
Persistence MechanismsImpersonation ToolsData ExfiltrationPost-ExploitationPenetration TestingCommand and ControlRed TeamingRemote Access ToolPayload Development
GitHubdagowda/notrdp

notRDP

Havoc C2 plugin that creates a hidden Windows desktop, streams it to a browser viewer, and injects mouse/keyboard input for covert remote control.

20425152 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

notRDP

A Havoc C2 plugin that creates an invisible alternate Windows desktop, streams it to a browser-based viewer, and supports full mouse/keyboard interaction like RDP, but invisible to the target user.

image_alt

How It Works

  1. Creates a hidden desktop via CreateDesktopW and launches explorer.exe on it
  2. Captures the hidden desktop using PrintWindow compositing and streams JPEG frames
  3. Injects mouse/keyboard input via PostMessage directly to hidden desktop windows
  4. Renders the stream in a browser viewer with full input capture

Prerequisites

Cross-compiler: x86_64-w64-mingw32-gcc (and optionally i686-w64-mingw32-gcc for x86)

Install on Ubuntu / Debian / Kali

sudo apt update && sudo apt install gcc-mingw-w64-x86-64 gcc-mingw-w64-i686

Install on Arch

sudo pacman -S mingw-w64-gcc

Install on Fedora

sudo dnf install mingw64-gcc mingw32-gcc

Compiling

make        # x64 only
make both   # x64 + x86
make clean  # remove .o files

Manual (without Make)

x86_64-w64-mingw32-gcc -c -Wall -Wno-unused-variable -o screenshot.x64.o screenshot.c
x86_64-w64-mingw32-gcc -c -Wall -Wno-unused-variable -o screeninput.x64.o screeninput.c
x86_64-w64-mingw32-gcc -c -Wall -Wno-unused-variable -o notrdp_mgr.x64.o notrdp_mgr.c

Installation

  1. Compile the BOFs
  2. In the Havoc Client: Scripts Manager > Load Script > notrdp.py

Usage

notrdp [port] [quality]   # Start hidden desktop session
notrdp-close              # Close session

notrdpuser Plugin

A variant plugin that captures the user's real desktop session instead of creating a hidden one. Includes opsec-friendly keystroke capture via GetAsyncKeyState polling embedded in the screenshot BOF. Packaged as notrdpuser.zip in the same repo extract and load notrdpuser.py the same way.

notrdpuser [port] [quality]   # Start user desktop streaming + keystroke capture
notrdpuser-close              # Close session
Download Tool