Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
RevShell — A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a fully‑featured post‑exploitation agent with 150+ commands (v3.5). Includes C2 listeners, detailed technical documentation, and a universal cleaner tool for incident response training. | Kitploit
Tools/GitHubGitHub/dragon56yt/revshell
Privilege EscalationPersistence MechanismsLateral MovementData ExfiltrationPost-ExploitationMalware AnalysisPenetration TestingCommand and ControlLearning & EducationRed TeamingPayload Development
2163 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a fully‑featured post‑exploitation agent with 150+ commands (v3.5). Includes C2 listeners, detailed technical documentation, and a universal cleaner tool for incident response training.

GitHub
dragon56yt/revshell

RevShell

View RepositoryWebsite
Share

🔥 RevShell Project — Advanced Windows Reverse Shell

██▀███   ▓█████  ██▒   █▓   ██████  ██░ ██  ▓█████  ██▓     ██▓    
▓██ ▒ ██▒▓█   ▀ ▓██░   █▒ ▒██    ▒ ▓██░ ██▒ ▓█   ▀ ▓██▒    ▓██▒    
▓██ ░▄█ ▒▒███   ▓██  █▒░  ░ ▓██▄   ▒██▀▀██░ ▒███   ▒██░    ▒██░    
▒██▀▀█▄  ▒▓█  ▄  ▒██ █░░    ▒   ██▒░▓█ ░██  ▒▓█  ▄ ▒██░    ▒██░    
░██▓ ▒██▒░▒████▒  ▒▀█░    ▒██████▒▒░▓█▒░██▓ ░▒████▒░██████▒░██████▒
░ ▒▓ ░▒▓░░░ ▒░ ░  ░ ▐░    ▒ ▒▓▒ ▒ ░ ▒ ░░▒░▒ ░░ ▒░ ░░ ▒░▓  ░░ ▒░▓  ░
  ░▒ ░ ▒░ ░ ░  ░  ░ ░░    ░ ░▒  ░ ░ ▒ ░▒░ ░  ░ ░  ░░ ░ ▒  ░░ ░ ▒  ░
  ░░   ░    ░       ░░    ░  ░  ░   ░  ░░ ░    ░     ░ ░     ░ ░   
   ░        ░  ░     ░          ░   ░  ░  ░    ░  ░    ░  ░    ░  ░
                    ░                                              

📖 Overview

RevShell is a comprehensive educational project that demonstrates the evolution of a Windows reverse shell from a simple proof‑of‑concept to a fully‑featured post‑exploitation agent. The project is structured into three major versions, each building upon the previous one with increased capabilities, better stealth, and more advanced techniques.

This repository is intended exclusively for cybersecurity education, authorized penetration testing, and defensive research. All code is provided as‑is for learning purposes.


📁 Repository Structure

.
├── v1.0/
│ ├── README.md # User guide for v1.0
│ ├── TECHNICAL.md # Technical deep‑dive for v1.0
│ ├── listener.py # C2 listener (attacker side)
│ └── victim_win.py # Implant (victim side)
│
├── v2.0/
│ ├── README.md # User guide for v2.0
│ ├── TECHNICAL.md # Technical deep‑dive for v2.0
│ ├── listener.py # Enhanced C2 listener
│ ├── victim_win.py # Implant with 40+ commands
│ └── victim_win_ADMIN.py # Same as above + auto‑elevation
│
└── v3.5/
├── README.md # User guide for v3.5 (in progress)
├── TECHNICAL.md # Technical deep‑dive for v3.5 (in progress)
├── listener.py # Advanced listener (RC4 encryption)
├── victim_win.py # Full implant with 150+ commands
└── victim_win_ADMIN.py # Full implant + admin capabilities


🔄 Version Evolution

Featurev1.0v2.0v3.5
EncryptionXOR (single byte)XOR (single byte)RC4 + nonce + SHA‑256
PersistenceRegistry onlyRegistry + Task + StartupRegistry + Task + Startup + WMI + SYSTEM
Commands840+150+
File Transfer✅✅✅ + directory download
Keylogger❌✅✅
Screenshot❌✅✅ + screen recording
Browser Stealer❌✅✅
WiFi Passwords❌✅✅
Privilege Escalation Checks❌✅✅
Admin Commands❌disable_defender, dump_hashes+20 admin commands (RDP, UAC, firewall, BSOD, etc.)
Anti‑VM / Sandbox❌❌✅
Decoy GUI❌❌✅
Beacon Jitter❌❌✅
Port Forwarding❌❌✅
Self‑Destruction❌❌✅ (autodestroy)
Auto‑Elevation (Admin)❌❌ (separate version)✅ (integrated)

🎯 Intended Use

This project is designed for:

  • Cybersecurity students learning about reverse shells, C2 communication, and post‑exploitation techniques.
  • Penetration testers who need a flexible, well‑documented implant for authorized engagements.
  • Blue teams / Defenders who want to understand attacker tools to build better detection rules.
  • CTF players looking for a customizable reverse shell for Windows challenges.

⚖️ Legal Disclaimer (IMPORTANT — READ CAREFULLY)

This software is provided for educational and research purposes only.

1. No Authorization = Illegal Use

Using this software to access, monitor, or control any computer system, network, or device without explicit, written permission from the owner is a violation of:

  • Computer Fraud and Abuse Act (CFAA) — 18 U.S.C. § 1030 (United States)
  • General Data Protection Regulation (GDPR) — EU Regulation 2016/679
  • Computer Misuse Act 1990 (United Kingdom)
  • Criminal Code of Canada — Section 342.1 / 430
  • Cybercrime Act 2001 (Australia)
  • Information Technology Act 2000 (India)
  • And similar laws in virtually every country around the world.

Penalties may include:

  • Heavy fines (up to hundreds of thousands of dollars/euros)
  • Imprisonment (up to 10‑20 years depending on jurisdiction)
  • Permanent criminal record
  • Civil lawsuits from affected parties

2. Authorized Use Only

You may only use this software in the following scenarios:

  • On your own personal systems that you own and control.
  • In isolated laboratory environments (virtual machines with no network access to production systems).
  • As part of an authorized penetration test where you have a signed legal contract and explicit scope of work.
  • For academic research within a controlled, supervised environment.

3. No Warranty

THIS SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES, OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT, OR OTHERWISE, ARISING FROM, OUT OF, OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

4. User Responsibility

By downloading, copying, installing, or using this software, you agree that you are solely responsible for your actions. The authors and contributors assume zero liability for any misuse, damage, or legal consequences resulting from the use of this software.

If you are unsure whether your intended use is legal, consult a qualified attorney before proceeding.

5. Educational Purpose Statement

The techniques demonstrated in this project (reverse shells, persistence, credential harvesting, privilege escalation) are common knowledge in the cybersecurity field and are documented here to:

  • Educate defenders on attacker methodologies.
  • Provide a reference implementation for students.
  • Enable controlled testing of detection and response capabilities.

Understanding how attacks work is essential for building effective defenses. This project contributes to that goal by providing transparent, well‑commented code that can be studied and analyzed.


🔗 Quick Links per Version

v1.0 — Basic Reverse Shell

  • Features: XOR encryption, file upload/download, steal command, registry persistence.
  • Files: v1.0/
  • Documentation: README (v1.0) | TECHNICAL (v1.0)

v2.0 — Expanded Post‑Exploitation

  • Features: +30 new commands, multi‑method persistence, keylogger, browser stealer, WiFi passwords, privesc checks.
  • Files: v2.0/
  • Documentation: README (v2.0) | TECHNICAL (v2.0)
  • Admin Variant: victim_win_ADMIN.py — same features + automatic UAC bypass (requests elevation on startup).

v3.5 — Advanced C2 Agent

  • Features: RC4 encryption with nonce, beacon jitter, anti‑VM, decoy GUI, 150+ commands, port forwarding, screen/mic recording, admin backdoors, self‑destruction.
  • Files: v3.5/
  • Documentation: README (v3.5) | TECHNICAL (v3.5)
  • Admin Variant: victim_win_ADMIN.py — full implant with integrated auto‑elevation and 20+ admin‑only commands.

🛠️ Basic Usage (All Versions)

Download Tool