Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
TornadoRevC2 — Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5 pivoting, and persistence. | Kitploit
도구/GitHubGitHub/kamalx06/tornadorevc2
Penetration Testing FrameworksPrivilege EscalationPersistence MechanismsLateral MovementScripting & AutomationInformation GatheringPost-ExploitationCommand and ControlRed TeamingRemote Access ToolPayload Development
347877일 전Kitploit 검토 완료
GitHubkamalx06/tornadorevc2

TornadoRevC2

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5 pivoting, and persistence.

저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

TornadoRevC2

A lightweight, modular post-exploitation framework for authorized security research, red-team operations, and penetration testing. TornadoRevC2 manages interactive reverse shell and bind shell sessions on Linux and Windows hosts through a unified operator console, across plain TCP, server-authenticated TLS, and mutually authenticated TLS transports. Core session handling is extended by a cross-platform plugin architecture for host enumeration, situational awareness, and operational tasks.

Important: TornadoRevC2 is a session handler and post-exploitation framework—not a beacon-style command-and-control platform. It prioritizes reliable interactive shells, structured operator workflows, and on-demand plugin execution over persistent agent infrastructure.


Legal Notice

Use this software only on systems you own or on systems where you have explicit written authorization. You are solely responsible for compliance with applicable laws and organizational policies. The authors and contributors accept no liability for misuse, data loss, or legal consequences arising from the use of this project.


Demo

TornadoRevC2 Demo

Quick demo: session management, plugin execution, SOCKS5 pivoting.


Table of Contents

  • Introduction
  • Key Features
  • Design Philosophy
  • Operational Security
  • Architecture
  • Requirements & Installation
  • Quick Start
  • Operator Reference
  • Built-in Plugins
  • Plugin Development
  • Session Logging
  • Project Structure
  • TLS & mTLS Configuration
  • License

Introduction

TornadoRevC2 is a modular post-exploitation framework that handles sessions over two transports: reverse shells (target dials the handler over plain TCP, server-authenticated TLS, or mutual TLS with client-certificate verification) and bind shells (the handler dials the target, over plain TCP or TLS). Both transports produce sessions that flow through the same probe, plugin, transfer, and reporting pipeline — there is no functional difference to the operator once a session is established. The framework provides a unified operator console for session management, host reconnaissance, chunked file transfer, in-memory payload execution, SOCKS5 pivoting, plugin-driven post-exploitation, structured reporting, and a built-in update command for automatic Git-based updates and seamless handler restarts. Originally developed as a lightweight reverse shell handler, the project has evolved into an extensible framework in which capabilities such as firewall enumeration, credential store metadata collection, network mapping, browser profiling, and additional post-exploitation functionality are implemented as independent, modular plugins. The framework also includes the make_token plugin for establishing new C2 sessions via remote protocols (SSH, WinRM, SMB, WMI, MSSQL, DCOM, and MySQL/MariaDB) using command-line tools from the operator side, and an upgrade_mtls plugin that migrates a live session onto the mutual-TLS listener by pushing the handler's client certificate bundle to the target.

Supported target platforms: Linux and Windows (primary), with compatibility for generic Unix and BSD environments where applicable.


Key Features

CategoryCapabilities
Session handlingMulti-client TCP / TLS / mTLS listeners with automatic PKI bootstrapping · On-demand mTLS upgrade for live sessions · Bind shell support — dial a target listening on TCP or TLS · Interactive PTY/TTY shells · Session fingerprinting and reconnect tracking
Operational securityShell history suppression on Linux and Windows · No pty.spawn or Invoke-Expression in command paths · Session-scoped probe markers · Jitter between automated commands · PTY upgrade verification (falls back to the original shell when bash handoff fails)
File transferChunked upload with resume · Chunked download with resume · SHA-256 integrity verification · Optional HTTPS transport for upload (--https) and push-style download (--https-push), with target-interface binding and callback address override
Payload executionIn-memory execution for py, ps, exe, elf, bat, and sh — with memfd-based ELF execution (modern and legacy fallbacks) and subsystem-aware PE loading
Pivoting & tunnelingSOCKS5 proxy through compromised sessions · Windows tunnel agent runs in-memory (C#, no disk artifact); Unix uses a Python agent under /tmp · socks test requires an already-running proxy and does not deploy the agent implicitly · Soft and hard tunnel reset (socks reset [--hard]) · Automatic remote agent cleanup on socks stop and session disconnect · Ligolo-NG and Chisel agent deployment with background persistence
Remote session establishmentmake_token — establish new sessions over SSH, WinRM, SMB, WMI, MSSQL, DCOM, or MySQL/MariaDB from the operator side, with password / NTLM-hash / SSH-key / WinRM-client-certificate authentication, MySQL UDF auto-loading, custom-command execution, and netexec integration
Impersonationrunas — execute commands or spawn a TLS-encrypted shell as another user, local or remote, with domain support and netexec integration · steal_token — list processes and owners, impersonate another process's token, or spawn a cmd / reverse shell running as the token owner
Token privilegesenablepriv — enable, disable, list, or toggle every privilege on the current Windows token via in-memory C# (AdjustTokenPrivileges), with --list / --list-all / --all modes
EnumerationCovering host triage, detection-environment preflight, network posture, credentials and browser metadata, Kerberos tickets, Linux internals (sudo configuration, writable filesystem targets, restricted-shell detection), Windows domain trusts, WMI persistence, loaded modules, and Windows domain and system configuration
Operational pluginsMulti-pass secure file wiping · Hybrid file encryption · Shell history clearing · Windows event log clearing · Cross-platform keystroke capture with window context
PersistenceCross-platform backdoor installation using TLS-encrypted payloads — cron @reboot on Linux/Unix, Run registry on Windows
ExtensibilityRuntime plugin load, reload, unload, and rescan (live discovery — no handler restart) · External plugins via TORNADOREVC2_PLUGIN_DIR · Documented SessionContext API
ReportingPer-session logging · Structured plugin output · HTML transcript export
Self-updateGit-based update command with repository verification, fast-forward pull, and automatic handler restart

Not supported: Task scheduling, or beacon-style callback infrastructure.


Design Philosophy

TornadoRevC2 is engineered for environments where deployment friction and operational footprint matter.

Dependency-light, native-command design

Plugins leverage native Windows and Linux utilities and built-in system commands already present on the target host—netsh, ss, iptables, ufw, firewall-cmd, nft, PowerShell cmdlets, nmcli, wevtutil, and others. Collectors invoke these tools through the reverse shell channel and parse output remotely, minimizing the need to upload additional binaries or install dependencies.

Enumeration without artifact drops

도구 다운로드