awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
t3l3machus avatar

t3l3machus/hoaxshell

0
View on GitHub↗
3,421 星标·524 分支·Python·bsd-2-clause·9 次浏览

Hoaxshell

Hoaxshell is a command and control system for Windows remote command execution. It provides a framework for generating and managing reverse shell payloads that utilize an HTTP beaconing protocol, where victim clients periodically poll a handler to receive and execute instructions.

The project distinguishes itself through its ability to bypass PowerShell Constrained Language Mode using specialized payload generation. It supports encrypted command and control via TLS certificate injection and provides mechanisms for remote session recovery, allowing a handler to reestablish control over active payloads after a disconnection or system crash.

The system covers a broad range of capabilities including the generation of both PowerShell and cURL-based payloads, the use of custom HTTP headers to obfuscate traffic, and the integration of public tunnel routing to bypass NAT and firewall restrictions.

The tool is implemented in Python.

Features

  • C2 Beaconing Protocols - Implements an HTTP beaconing protocol where victim clients periodically poll a handler to receive and execute instructions.
  • PowerShell Language Mode Bypasses - Implements specialized PowerShell payload construction to bypass Constrained Language Mode restrictions on hardened Windows systems.
  • HTTP Beaconing C2 Systems - Provides a command and control system where victims periodically poll a handler over HTTP to receive instructions.
  • Constrained Language Mode Payloads - Constructs PowerShell commands using specific syntax and alternative cmdlets to execute in restricted language mode environments.
  • Constrained Mode Payloads - Generates specific payload variants that remain functional even when PowerShell is in constrained language mode.
  • PowerShell Payloads - Generates encoded single-line PowerShell payloads for remote command execution.
  • C2 Beacon Generators - Provides the core capability to generate PowerShell payloads that establish HTTP beaconing sessions with a C2 handler.
  • C2 HTTPS Listeners - Ships a secure listener that uses TLS certificates to encrypt shell traffic and supports routing through public tunnels.
  • HTTP Beaconing Protocols - Implements an HTTP beaconing protocol for persistent remote command execution and control.
  • C2 Session Identifiers - Uses unique identifiers embedded in HTTP headers to associate incoming requests with specific persistent shell sessions.
  • Shell Session Persistence - Maintains session metadata allowing disconnected victims to reattach to their existing shell upon reconnection.
  • Remote Command Execution Tools - Establishes persistent remote access to Windows systems using encoded PowerShell or cURL payloads.
  • Reverse Shell Listeners - Provides a standalone HTTP/HTTPS listener to manage multiple incoming reverse shell connections via session IDs.
  • Reverse Shells - Generates and manages PowerShell or CMD payloads that establish remote command execution over HTTP or HTTPS.
  • PowerShell Reverse Shell Frameworks - Generates and manages Windows reverse shell payloads that communicate over HTTP or HTTPS for remote command execution.
  • Reverse Shell Payloads - Creates operational reverse shell command strings that connect the target system to a remote handler.
  • Payload Traffic Encryptions - Secures remote shell traffic using SSL certificates and custom HTTP headers to evade network detection.
  • Session Identifiers - Uses unique session identifiers in HTTP headers to associate incoming requests with specific shell sessions.
  • C2 Session Recovery - Reestablishes control over active remote payloads after a handler crash or network disconnection using session identifiers.
  • Network Tunneling - Routes reverse shell traffic through services like Ngrok or LocalTunnel to bypass firewalls and NAT restrictions.
  • Encrypted Shells - Secures C2 traffic using TLS certificates to create encrypted HTTPS shells and evade network detection.
  • Session Restoration - Re-establishes connectivity to a running remote payload following a handler disconnection or system crash.
  • Header Obfuscation - Disguises session traffic by using custom HTTP header names to bypass antivirus traffic analysis.
  • NAT Traversal Routings - Routes reverse shell connections through public tunnel services to reach targets located behind NAT.
  • Traffic Tunneling - Directs reverse shell traffic through public tunnel services to operate without a static IP address.
  • Tunnel-Agnostic Listeners - Binds the local listener to a port that accepts forwarded traffic from external tunneling services like Ngrok.
  • C2 Session Recovery - Enables recovery of control over active remote payloads by starting a new handler instance.
  • Listener Certificate Injection - Embeds custom SSL certificates and private keys into the listener to encrypt traffic and evade network detection.
  • cURL-Based Shell Payloads - Provides reverse shell capabilities using Windows Command Prompt and cURL to bypass PowerShell-specific security restrictions.
  • cURL Reverse Shells - Provides an alternative delivery mechanism using Windows CMD and cURL for environments where PowerShell is restricted.
  • Session ID Capturers - Provides a session grab mode to reconnect to running payloads by capturing existing session IDs after a restart.
  • Stateful Session Persistence - Maintains session state on the handler to allow disconnected victims to reattach using their session ID.
  • Payload Obfuscators - Randomizes session IDs, URLs, and headers to obfuscate payload signatures and evade antivirus detection.
  • C2 Frameworks - PowerShell-based C2 framework with SSL encryption support.
  • Command and Control - Generates and handles Windows reverse shell payloads over HTTP.
  • Defense Evasion Tools - Tool for creating reverse shells that evade detection.

Star 历史

t3l3machus/hoaxshell 的 Star 历史图表t3l3machus/hoaxshell 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

常见问题解答

t3l3machus/hoaxshell 是做什么的?

Hoaxshell is a command and control system for Windows remote command execution. It provides a framework for generating and managing reverse shell payloads that utilize an HTTP beaconing protocol, where victim clients periodically poll a handler to receive and execute instructions.

t3l3machus/hoaxshell 的主要功能有哪些?

t3l3machus/hoaxshell 的主要功能包括:C2 Beaconing Protocols, PowerShell Language Mode Bypasses, HTTP Beaconing C2 Systems, Constrained Language Mode Payloads, Constrained Mode Payloads, PowerShell Payloads, C2 Beacon Generators, C2 HTTPS Listeners。

t3l3machus/hoaxshell 有哪些开源替代品?

t3l3machus/hoaxshell 的开源替代品包括: malwaredllc/byob — This project is a post-exploitation framework and command and control platform designed for security research and… samratashok/nishang — Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows… hackerschoice/thc-tips-tricks-hacks-cheat-sheet — This project is a comprehensive command-line reference and toolkit designed for Linux system administration and… k8gege/ladon — Ladon is an internal network penetration scanner and vulnerability assessment tool designed to identify high-risk… pentestmonkey/php-reverse-shell — This project consists of PHP-based payloads and scripts designed to establish reverse network connections for remote… joaomatosf/jexboss — jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit…

Hoaxshell 的开源替代方案

相似的开源项目,按与 Hoaxshell 的功能重合度排序。
  • malwaredllc/byobmalwaredllc 的头像

    malwaredllc/byob

    9,478在 GitHub 上查看↗

    This project is a post-exploitation framework and command and control platform designed for security research and penetration testing. It functions as a remote access tool consisting of a central command server and encrypted executable payloads that establish reverse shell connections. The system utilizes a web-based dashboard for multi-client administration, allowing for remote host monitoring and direct shell access through an in-browser terminal. It generates cross-platform, encrypted binaries that employ a multi-stage delivery chain and a key exchange mechanism to secure communications.

    Python
    在 GitHub 上查看↗9,478
  • samratashok/nishangsamratashok 的头像

    samratashok/nishang

    9,951在 GitHub 上查看↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    在 GitHub 上查看↗9,951
  • hackerschoice/thc-tips-tricks-hacks-cheat-sheethackerschoice 的头像

    hackerschoice/thc-tips-tricks-hacks-cheat-sheet

    3,853在 GitHub 上查看↗

    This project is a comprehensive command-line reference and toolkit designed for Linux system administration and network security assessment. It provides a collection of technical snippets and operational guides focused on managing remote environments, orchestrating shell sessions, and executing administrative tasks through native terminal utilities. The repository distinguishes itself by offering specialized techniques for stealthy operations and infrastructure manipulation. It covers methods for establishing encrypted tunnels to bypass firewalls, obfuscating process identities and command hi

    Shell
    在 GitHub 上查看↗3,853
  • k8gege/ladonk8gege 的头像

    k8gege/Ladon

    5,297在 GitHub 上查看↗

    Ladon is an internal network penetration scanner and vulnerability assessment tool designed to identify high-risk security flaws and assets across network segments. It operates as a fileless security scanner, executing its engine and modules directly in memory to avoid leaving a disk footprint on target systems. The project is distinguished by its integration as a plugin for command beacons, specifically within the Cobalt Strike framework. This allows for memory-resident network discovery and vulnerability detection. It further supports stealth operations through payload and script obfuscatio

    C#brute-forceexpexploit
    在 GitHub 上查看↗5,297
  • 查看 Hoaxshell 的所有 30 个替代方案→