Ross ROSS = Recommend OSS · open-source software intelligence for agents

t3l3machus/Villain

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines). observed · 2026-08-28

github.com/t3l3machus/Villain · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

40/100

  • Activity 22
  • Release rhythm 28
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 50
  • age_days: 1408
  • days_rel: 666
  • days_push: 469
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

4439 stars · 695 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Villain is a high-level stage 0/1 command-and-control (C2) framework written in Python that handles multiple reverse TCP and HoaxShell-based shells. It enhances shell sessions with payload generation, file uploads, fileless script execution, and session sharing between sibling Villain instances.

Use cases

  • generate reverse shell payloads for windows and linux targets
  • manage multiple reverse tcp and hoaxshell sessions from one terminal
  • share shell sessions between team members in a red team operation
  • upload files to compromised hosts over http
  • run fileless scripts against active shell sessions
  • catch and handle shells during penetration tests

When to choose

  • you need a lightweight stage 0/1 C2 for catching reverse shells during authorized pentests
  • you want quick payload generation and multi-session handling in a terminal
  • you need multiplayer session sharing across operator machines

When to avoid

  • you need a full-featured long-term post-exploitation C2 like Metasploit or Sliver
  • you are not conducting authorized security testing
  • you need a tool that runs natively on windows or macos

Facets

cli-tool · maturity active

security penetration-testing cli http-server file-upload security penetration-testing developer-tools python cli c2 red-team reverse-shell hoaxshell offensive-security payload-generation multiplayer command-line linux

1 source

Member repositories

RepositoryRoleHealth v2
t3l3machus/Villainmain40

For agents

markdown · JSON · MCP: product_card(name="t3l3machus/Villain")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem