Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
endgame — ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations | Kitploit
Tools/GitHubGitHub/endgamec2framework/endgame
Privilege EscalationReconnaissanceExploit FrameworksPayload GenerationLateral MovementPost-ExploitationPenetration TestingCommand and ControlLearning & EducationRed TeamingAI Security
285217 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
endgamec2framework/endgame

endgame

ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations

View RepositoryWebsite

ENDGAME C2 FRAMEWORK


ENDGAME is a professional command and control framework built for authorized red team engagements, penetration testing, and educational security research. Designed to simulate realistic adversary techniques, assess detection coverage, and help security teams understand their defensive gaps — with a built-in AI Console that turns natural language into executed commands and automatically analyzes every result.

Hecho con IA, pensado y dirigido por un humano.

🌐 endgamec2framework.com  ·  📄 Documentation








Quick Start

git clone https://github.com/endgamec2framework/endgame
cd endgame
./install.sh

Re-run ./install.sh to update — it will pull the latest code and rebuild while preserving certificates and operator profiles.

Full setup guide: Documentation → Installation


🤖 AI Console — Natural Language Red Teaming

ENDGAME's AI Console is a first-class feature that brings an AI co-pilot directly into the operator workflow. It's not a chatbot tacked on the side — it lives in the same panel as your agent terminals, knows the full C2 command set, and has real-time context about the target: hostname, OS, user, privileges, and transport.

How it works

  1. Right-click any agent in the Agents table → Open AI Console
  2. An 🤖 tab opens in the bottom console pane — side by side with your regular terminal tabs
  3. Describe your objective in natural language (in any language)
  4. The AI suggests one or more C2 commands, each wrapped in a ▶ Ejecutar execute card
  5. Confirm execution — the task is dispatched to the real agent
  6. The output comes back and the AI automatically analyzes the result and proposes the next step
 
Left: right-click menu · Right: AI Console tab open in the console pane (qwen3.6)


Command executed on a real mTLS agent · AI analyzes output and suggests SHELL tasklist /v for SYSTEM-privilege process enumeration

Key capabilities

CapabilityDetail
Integrated into console paneOpens as a tab — no floating modal, no context switch
Full C2 command awarenessSystem prompt includes every available command, the agent's OS/arch/privileges, transport, and current task queue
Streaming responsesTokens stream in real time as the model generates them
Auto-analysis loopAfter every command execution the output is automatically sent back to the AI for interpretation and next-step recommendation
Multi-sessionOpen AI Console for multiple agents simultaneously — each tab maintains independent chat history
Provider agnosticWorks with Ollama (local, offline) or Anthropic Claude API — whichever is configured in the AI tab
Confirm before executeEvery suggested command requires an explicit click — the AI never sends tasks autonomously

Supported models (Ollama)

Any model available in your Ollama instance works. Recommended for red team context:

  • qwen3.6:latest — default · fast · good instruction following
  • qwen3.6:35b-a3b-coding-mxfp8 — larger · stronger code/command reasoning
  • deepseek-r1:8b / deepseek-r1:32b — reasoning models · good at multi-step attack chains
  • Any Anthropic Claude model via the Claude API

What's inside

ComponentSummary
ServerGo binary · multi-operator teamserver · SQLite op-log · mTLS API :31337 · DNS canary burn alerts
Web GUIKill-chain graph (auto-refresh) · agent console · AI Console · loot manager · AI assistant · multi-operator
Agent (Go)Windows · Linux · macOS · 7 transports · full evasion suite · API hashing (PEB walk, 22 fns off IAT) · Kerberos ops · inline PE loader · CONFIG runtime · ~13 MB
Agent (Nim)Windows · Linux · 7 transports incl. SMB pipe · indirect syscalls (Hell's Gate) · stack spoofing · NTDLL unhook · API hashing (PEB walk, 22 fns off IAT) · inline PE loader · BOF + .NET CLR · keylogger · SOCKS5 · ISHELL · browser creds · lateral movement · anti-sandbox · ~1 MB
Agent (Rust)Windows · Linux (x64) · 7 transports · indirect syscalls (Hell's Gate) · AMSI patch · sleep masking · API hashing · stack spoofing · NTDLL unhook · anti-sandbox · working hours · DNS canary · Kerberos ops · inline PE loader · BOF + .NET CLR · ISHELL · screenwatch · full injection suite · BLOCKDLLS · PEB spoof · ETW patch · browser creds · keylogger · SOCKS5 · lateral movement (8 methods) · ~507 KB
Agent (C)Windows · Linux (x64) · 7 transports · EXE + DLL format · API hashing (PEB walk, 35 fns off IAT) · PPID spoof · anti-sandbox · Kerberos ops · inline PE loader · NTDLL unhook · keylogger · SOCKS5 · ISHELL · browser creds · .NET CLR · BOF · lateral movement · ~130 KB
LoadersC / Go / Nim / shellcode stubs
ReportsHTML · JSON · CSV · MITRE ATT&CK Navigator layer · AI executive summary

Agent capabilities

Download Tool