t3l3machus/Villain
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines). observed · 2026-08-28
Health v2 · maintenance only
40/100
- Activity 22
- Release rhythm 28
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 50
- age_days: 1408
- days_rel: 666
- days_push: 469
- n_releases_24m: 2
Adoption not part of the score
4439 stars · 695 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Villain is a high-level stage 0/1 command-and-control (C2) framework written in Python that handles multiple reverse TCP and HoaxShell-based shells. It enhances shell sessions with payload generation, file uploads, fileless script execution, and session sharing between sibling Villain instances.
Use cases
- generate reverse shell payloads for windows and linux targets
- manage multiple reverse tcp and hoaxshell sessions from one terminal
- share shell sessions between team members in a red team operation
- upload files to compromised hosts over http
- run fileless scripts against active shell sessions
- catch and handle shells during penetration tests
When to choose
- you need a lightweight stage 0/1 C2 for catching reverse shells during authorized pentests
- you want quick payload generation and multi-session handling in a terminal
- you need multiplayer session sharing across operator machines
When to avoid
- you need a full-featured long-term post-exploitation C2 like Metasploit or Sliver
- you are not conducting authorized security testing
- you need a tool that runs natively on windows or macos
Facets
cli-tool · maturity active
security penetration-testing cli http-server file-upload security penetration-testing developer-tools python cli c2 red-team reverse-shell hoaxshell offensive-security payload-generation multiplayer command-line linux
1 source
- readme: https://github.com/t3l3machus/Villain · fetched 2026-08-28 · 6f7bbc2c5284
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| t3l3machus/Villain | main | 40 |
For agents
markdown · JSON · MCP: product_card(name="t3l3machus/Villain")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem