WKL-Sec/HiddenDesktop
HVNC for Cobalt Strike observed · 2026-08-28
Health v2 · maintenance only
20/100
- Activity 0
- Release rhythm 8
- Longevity 85
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1201
- days_rel: n/a
- days_push: 1000
- n_releases_24m: 0
Adoption not part of the score
1343 stars · 207 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Hidden Desktop is a Cobalt Strike BOF implementation of HVNC (Hidden Virtual Network Computing), letting red team operators interact with a remote Windows desktop session covertly. It is a C rewrite of TinyNuke's HVNC, consisting of a BOF initializer, position-independent shellcode, a server with operator UI, and application launcher BOFs.
Use cases
- covertly view and control a remote Windows desktop during a red team engagement
- run applications like browsers or cmd in a hidden desktop session on a compromised host
- replace TinyNuke-based HVNC tooling with a native Cobalt Strike BOF
- launch programs invisibly to the logged-in user via Beacon
- forward HVNC traffic through the team server with rportfwd
When to choose
- you operate Cobalt Strike and need hidden desktop/VNC-like capability
- you want a C-based, position-independent HVNC alternative to TinyNuke forks
- you need to launch and interact with applications on a hidden Windows desktop from a Beacon
When to avoid
- you need a general-purpose legitimate remote desktop tool
- you do not use Cobalt Strike or compatible Beacon environments
- you need cross-platform operator UI support beyond Windows
Facets
cli-tool · maturity active
security penetration-testing security penetration-testing developer-tools windows cli hvnc cobalt-strike bof red-team hidden-desktop remote-desktop offensive-security remote-control
1 source
- readme: https://github.com/WKL-Sec/HiddenDesktop · fetched 2026-08-28 · 7078a46df330
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| WKL-Sec/HiddenDesktop | main | 20 |
For agents
markdown · JSON · MCP: product_card(name="WKL-Sec/HiddenDesktop")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem