# xiaogang000/XG_NTAI

用于Webshell木马免杀、流量加密传输，多多支持star

Repository: https://github.com/xiaogang000/XG_NTAI
Canonical: https://ross.abutalabs.com/products/xg_ntai
License Family: other
Last push: 2025-06-27T05:47:22+00:00

## Health v2 (maintenance only)
Score: 37/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 28, release rhythm 28, longevity 74
- inputs: {"age_days": 1047, "days_push": 432, "days_rel": 432, "gap_med": 83, "n_releases_24m": 2}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1075, forks 78 (observed 2026-08-28T04:03:29.135960+00:00)

## What it is
A Java-based GUI tool for generating obfuscated webshell payloads (ASP, PHP, JSP, JSPX) that evade WAF and antivirus detection, compatible with Behinder and Godzilla webshell managers. It also generates encrypted traffic protocol configs to disguise webshell C2 traffic as normal business requests and can convert JSP code into Tomcat servlet memory shells.

## Use cases
- generate undetectable webshell payloads for authorized pentests
- evade WAF detection for Behinder or Godzilla webshells
- encrypt and disguise webshell traffic as normal business requests
- create custom Behinder 4.0 traffic protocol config files
- convert JSP code into a Tomcat servlet memory shell
- add fake WAF pages to webshell responses

## When to choose
- you are doing authorized red-team or penetration testing and need webshell evasion
- you need to disguise webshell C2 traffic to match a target site's normal traffic patterns
- you want a single tool covering ASP/PHP/JSP/JSPX payload obfuscation plus traffic encryption

## When to avoid
- you need a general-purpose webshell manager itself (use Behinder or Godzilla directly)
- you are looking for a defensive detection tool rather than an offensive one
- you need support for non-Tomcat memory shells or non-Java environments

## Facets
- artifact type: application
- maturity: active
- function: penetration-testing, security, cryptography
- domain: penetration-testing, security
- platform: cross-platform, jvm
- tags: webshell, antivirus-evasion, traffic-encryption, behinder, godzilla, memory-webshell, red-team, waf-bypass, desktop

## Member repositories
- xiaogang000/XG_NTAI (main) score 37

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:29.135960+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:53:29.021613+00:00, confidence not recorded.
  - readme: https://github.com/xiaogang000/XG_NTAI (fetched 2026-08-28T04:03:29.135960+00:00, sha 31c6bf04045a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
