trustedsec/trevorc2
TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution. observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3232
- days_rel: n/a
- days_push: 1675
- n_releases_24m: 0
Adoption not part of the score
1344 stars · 281 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
TrevorC2 is a client/server command-and-control framework that tunnels communications through a browsable, legitimate-looking website to evade detection. It hides commands in website content (e.g., before the </body> tag) and exfiltrates data without POST requests, using configurable timing intervals.
Use cases
- set up a covert c2 channel that blends into normal web traffic
- red team command and control over http
- test detection of c2 traffic masquerading as legitimate browsing
- exfiltrate data without post requests
- clone a website as a cover for c2 server
- run implant communications over get requests only
When to choose
- you need a lightweight, customizable c2 for authorized red team engagements
- you want c2 traffic that looks like normal HTTP GET browsing
- you need a portable client supporting Windows, macOS, and Linux
When to avoid
- you need a full-featured production c2 framework with encryption and heavy randomization
- you want actively developed tooling with recent updates
- you need a supported, licensed enterprise product
Facets
application · maturity maintenance
security http-client http-server cryptography security penetration-testing windows python cli command-and-control c2 red-team covert-channel traffic-masquerading offensive-security command-line linux macos
1 source
- readme: https://github.com/trustedsec/trevorc2 · fetched 2026-08-28 · 5d824ca1c931
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| trustedsec/trevorc2 | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="trustedsec/trevorc2")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem