xiaogang000/XG_NTAI
用于Webshell木马免杀、流量加密传输,多多支持star observed · 2026-08-28
Health v2 · maintenance only
37/100
- Activity 28
- Release rhythm 28
- Longevity 74
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 83
- age_days: 1047
- days_rel: 432
- days_push: 432
- n_releases_24m: 2
Adoption not part of the score
1075 stars · 78 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A Java-based GUI tool for generating obfuscated webshell payloads (ASP, PHP, JSP, JSPX) that evade WAF and antivirus detection, compatible with Behinder and Godzilla webshell managers. It also generates encrypted traffic protocol configs to disguise webshell C2 traffic as normal business requests and can convert JSP code into Tomcat servlet memory shells.
Use cases
- generate undetectable webshell payloads for authorized pentests
- evade WAF detection for Behinder or Godzilla webshells
- encrypt and disguise webshell traffic as normal business requests
- create custom Behinder 4.0 traffic protocol config files
- convert JSP code into a Tomcat servlet memory shell
- add fake WAF pages to webshell responses
When to choose
- you are doing authorized red-team or penetration testing and need webshell evasion
- you need to disguise webshell C2 traffic to match a target site's normal traffic patterns
- you want a single tool covering ASP/PHP/JSP/JSPX payload obfuscation plus traffic encryption
When to avoid
- you need a general-purpose webshell manager itself (use Behinder or Godzilla directly)
- you are looking for a defensive detection tool rather than an offensive one
- you need support for non-Tomcat memory shells or non-Java environments
Facets
application · maturity active
penetration-testing security cryptography penetration-testing security cross-platform jvm webshell antivirus-evasion traffic-encryption behinder godzilla memory-webshell red-team waf-bypass desktop
1 source
- readme: https://github.com/xiaogang000/XG_NTAI · fetched 2026-08-28 · 31c6bf04045a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| xiaogang000/XG_NTAI | main | 37 |
For agents
markdown · JSON · MCP: product_card(name="xiaogang000/XG_NTAI")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem