# tdragon6/Supershell

Supershell C2 远控平台，基于反向SSH隧道获取完全交互式Shell

Repository: https://github.com/tdragon6/Supershell
Canonical: https://ross.abutalabs.com/products/supershell
Homepage: https://github.com/tdragon6/Supershell/wiki
License: MIT
License Family: permissive
Last push: 2026-04-03T15:40:24+00:00

## Health v2 (maintenance only)
Score: 54/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 75, release rhythm 8, longevity 89
- inputs: {"age_days": 1257, "days_push": 152, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1810, forks 233 (observed 2026-08-28T04:05:39.499551+00:00)

## What it is
Supershell is a web-accessible C2 remote control platform that establishes reverse SSH tunnels to targets, yielding fully interactive shells with TAB completion, history, and interactive program support. It integrates payload generation for many OS architectures, client management, file management, memory injection, SFTP transfer, port forwarding, and team shell sharing, deployable with docker-compose.

## Use cases
- manage reverse shells from a web platform during penetration tests
- get fully interactive shells instead of basic reverse shells
- generate cross-platform C2 client payloads
- share shells with teammates without sharing credentials
- transfer files to compromised hosts via SFTP
- perform fileless execution via memory injection
- pivot inside internal networks with client listeners

## When to choose
- you need fully interactive reverse shells with team collaboration in authorized red-team or CTF work
- you want a self-hosted C2 with docker-compose one-click deployment
- you need multi-architecture payload generation and shell sharing

## When to avoid
- you need a stealthy production-grade C2 for real adversary emulation with advanced evasion
- you want a lightweight single reverse-shell tool without a web platform
- you lack authorization to test systems you do not own

## Facets
- artifact type: application
- maturity: active
- function: security, cli, gui, file-upload, web-framework
- domain: security, penetration-testing, developer-tools
- platform: self-hosted, windows, cross-platform
- tags: c2, reverse-shell, reverse-ssh-tunnel, red-team, post-exploitation, remote-access, payload-generation, team-collaboration, memory-injection, sftp, docker, web-server, linux

## Member repositories
- tdragon6/Supershell (main) score 54

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:39.499551+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:21:18.293371+00:00, confidence not recorded.
  - readme: https://github.com/tdragon6/Supershell (fetched 2026-08-28T04:05:39.499551+00:00, sha 1e8a0aad0647)
  - homepage: https://github.com/tdragon6/Supershell/wiki (fetched 2026-08-29T11:00:18.543032+00:00, sha 51f92842cb0e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
