
A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a fully‑featured post‑exploitation agent with 150+ commands (v3.5). Includes C2 listeners, detailed technical documentation, and a universal cleaner tool for incident response training.
██▀███ ▓█████ ██▒ █▓ ██████ ██░ ██ ▓█████ ██▓ ██▓
▓██ ▒ ██▒▓█ ▀ ▓██░ █▒ ▒██ ▒ ▓██░ ██▒ ▓█ ▀ ▓██▒ ▓██▒
▓██ ░▄█ ▒▒███ ▓██ █▒░ ░ ▓██▄ ▒██▀▀██░ ▒███ ▒██░ ▒██░
▒██▀▀█▄ ▒▓█ ▄ ▒██ █░░ ▒ ██▒░▓█ ░██ ▒▓█ ▄ ▒██░ ▒██░
░██▓ ▒██▒░▒████▒ ▒▀█░ ▒██████▒▒░▓█▒░██▓ ░▒████▒░██████▒░██████▒
░ ▒▓ ░▒▓░░░ ▒░ ░ ░ ▐░ ▒ ▒▓▒ ▒ ░ ▒ ░░▒░▒ ░░ ▒░ ░░ ▒░▓ ░░ ▒░▓ ░
░▒ ░ ▒░ ░ ░ ░ ░ ░░ ░ ░▒ ░ ░ ▒ ░▒░ ░ ░ ░ ░░ ░ ▒ ░░ ░ ▒ ░
░░ ░ ░ ░░ ░ ░ ░ ░ ░░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
░
RevShell is a comprehensive educational project that demonstrates the evolution of a Windows reverse shell from a simple proof‑of‑concept to a fully‑featured post‑exploitation agent. The project is structured into three major versions, each building upon the previous one with increased capabilities, better stealth, and more advanced techniques.
This repository is intended exclusively for cybersecurity education, authorized penetration testing, and defensive research. All code is provided as‑is for learning purposes.
.
├── v1.0/
│ ├── README.md # User guide for v1.0
│ ├── TECHNICAL.md # Technical deep‑dive for v1.0
│ ├── listener.py # C2 listener (attacker side)
│ └── victim_win.py # Implant (victim side)
│
├── v2.0/
│ ├── README.md # User guide for v2.0
│ ├── TECHNICAL.md # Technical deep‑dive for v2.0
│ ├── listener.py # Enhanced C2 listener
│ ├── victim_win.py # Implant with 40+ commands
│ └── victim_win_ADMIN.py # Same as above + auto‑elevation
│
└── v3.5/
├── README.md # User guide for v3.5 (in progress)
├── TECHNICAL.md # Technical deep‑dive for v3.5 (in progress)
├── listener.py # Advanced listener (RC4 encryption)
├── victim_win.py # Full implant with 150+ commands
└── victim_win_ADMIN.py # Full implant + admin capabilities
| Feature | v1.0 | v2.0 | v3.5 |
|---|---|---|---|
| Encryption | XOR (single byte) | XOR (single byte) | RC4 + nonce + SHA‑256 |
| Persistence | Registry only | Registry + Task + Startup | Registry + Task + Startup + WMI + SYSTEM |
| Commands | 8 | 40+ | 150+ |
| File Transfer | ✅ | ✅ | ✅ + directory download |
| Keylogger | ❌ | ✅ | ✅ |
| Screenshot | ❌ | ✅ | ✅ + screen recording |
| Browser Stealer | ❌ | ✅ | ✅ |
| WiFi Passwords | ❌ | ✅ | ✅ |
| Privilege Escalation Checks | ❌ | ✅ | ✅ |
| Admin Commands | ❌ | disable_defender, dump_hashes | +20 admin commands (RDP, UAC, firewall, BSOD, etc.) |
| Anti‑VM / Sandbox | ❌ | ❌ | ✅ |
| Decoy GUI | ❌ | ❌ | ✅ |
| Beacon Jitter | ❌ | ❌ | ✅ |
| Port Forwarding | ❌ | ❌ | ✅ |
| Self‑Destruction | ❌ | ❌ | ✅ (autodestroy) |
| Auto‑Elevation (Admin) | ❌ | ❌ (separate version) | ✅ (integrated) |
This project is designed for:
This software is provided for educational and research purposes only.
Using this software to access, monitor, or control any computer system, network, or device without explicit, written permission from the owner is a violation of:
Penalties may include:
You may only use this software in the following scenarios:
THIS SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES, OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT, OR OTHERWISE, ARISING FROM, OUT OF, OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
By downloading, copying, installing, or using this software, you agree that you are solely responsible for your actions. The authors and contributors assume zero liability for any misuse, damage, or legal consequences resulting from the use of this software.
If you are unsure whether your intended use is legal, consult a qualified attorney before proceeding.
The techniques demonstrated in this project (reverse shells, persistence, credential harvesting, privilege escalation) are common knowledge in the cybersecurity field and are documented here to:
Understanding how attacks work is essential for building effective defenses. This project contributes to that goal by providing transparent, well‑commented code that can be studied and analyzed.
steal command, registry persistence.v1.0/v2.0/victim_win_ADMIN.py — same features + automatic UAC bypass (requests elevation on startup).v3.5/victim_win_ADMIN.py — full implant with integrated auto‑elevation and 20+ admin‑only commands.