
ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations
ENDGAME is a professional command and control framework built for authorized red team engagements, penetration testing, and educational security research. Designed to simulate realistic adversary techniques, assess detection coverage, and help security teams understand their defensive gaps — with a built-in AI Console that turns natural language into executed commands and automatically analyzes every result.
Hecho con IA, pensado y dirigido por un humano.
🌐 endgamec2framework.com · 📄 Documentation



git clone https://github.com/endgamec2framework/endgame
cd endgame
./install.sh
Re-run ./install.sh to update — it will pull the latest code and rebuild while preserving certificates and operator profiles.
Full setup guide: Documentation → Installation
ENDGAME's AI Console is a first-class feature that brings an AI co-pilot directly into the operator workflow. It's not a chatbot tacked on the side — it lives in the same panel as your agent terminals, knows the full C2 command set, and has real-time context about the target: hostname, OS, user, privileges, and transport.
🤖 tab opens in the bottom console pane — side by side with your regular terminal tabs


| Capability | Detail |
|---|---|
| Integrated into console pane | Opens as a tab — no floating modal, no context switch |
| Full C2 command awareness | System prompt includes every available command, the agent's OS/arch/privileges, transport, and current task queue |
| Streaming responses | Tokens stream in real time as the model generates them |
| Auto-analysis loop | After every command execution the output is automatically sent back to the AI for interpretation and next-step recommendation |
| Multi-session | Open AI Console for multiple agents simultaneously — each tab maintains independent chat history |
| Provider agnostic | Works with Ollama (local, offline) or Anthropic Claude API — whichever is configured in the AI tab |
| Confirm before execute | Every suggested command requires an explicit click — the AI never sends tasks autonomously |
Any model available in your Ollama instance works. Recommended for red team context:
qwen3.6:latest — default · fast · good instruction followingqwen3.6:35b-a3b-coding-mxfp8 — larger · stronger code/command reasoningdeepseek-r1:8b / deepseek-r1:32b — reasoning models · good at multi-step attack chains| Component | Summary |
|---|---|
| Server | Go binary · multi-operator teamserver · SQLite op-log · mTLS API :31337 · DNS canary burn alerts |
| Web GUI | Kill-chain graph (auto-refresh) · agent console · AI Console · loot manager · AI assistant · multi-operator |
| Agent (Go) | Windows · Linux · macOS · 7 transports · full evasion suite · API hashing (PEB walk, 22 fns off IAT) · Kerberos ops · inline PE loader · CONFIG runtime · ~13 MB |
| Agent (Nim) | Windows · Linux · 7 transports incl. SMB pipe · indirect syscalls (Hell's Gate) · stack spoofing · NTDLL unhook · API hashing (PEB walk, 22 fns off IAT) · inline PE loader · BOF + .NET CLR · keylogger · SOCKS5 · ISHELL · browser creds · lateral movement · anti-sandbox · ~1 MB |
| Agent (Rust) | Windows · Linux (x64) · 7 transports · indirect syscalls (Hell's Gate) · AMSI patch · sleep masking · API hashing · stack spoofing · NTDLL unhook · anti-sandbox · working hours · DNS canary · Kerberos ops · inline PE loader · BOF + .NET CLR · ISHELL · screenwatch · full injection suite · BLOCKDLLS · PEB spoof · ETW patch · browser creds · keylogger · SOCKS5 · lateral movement (8 methods) · ~507 KB |
| Agent (C) | Windows · Linux (x64) · 7 transports · EXE + DLL format · API hashing (PEB walk, 35 fns off IAT) · PPID spoof · anti-sandbox · Kerberos ops · inline PE loader · NTDLL unhook · keylogger · SOCKS5 · ISHELL · browser creds · .NET CLR · BOF · lateral movement · ~130 KB |
| Loaders | C / Go / Nim / shellcode stubs |
| Reports | HTML · JSON · CSV · MITRE ATT&CK Navigator layer · AI executive summary |