This is a CTF management bot containing features I personally find necessary or useful. It was originally created for the CatN1p hacking team, but anyone can use it!
The project is split into two runtimes:
bot/: Discord bot that exposes slash commands, runs inside the provided container or any Node.js environment.revshell/: Reverse shell relay service (Express REST API + TCP bridge). It now runs alongside the bot through the rootdocker-compose.yml, assuming the reverse-shell TCP port (default3000) is reachable from your Tailscale network or other tunnel.
- Users run
/revshell createfrom Discord. - The bot calls the external revshell REST API (HTTP 8000) to create a pairing.
- Operators/targets connect to the revshell TCP listener (port 3000) to bridge shells.
- Additional
/revshell statusand/revshell closecommands use the same REST API.
- Copy
env.exampleto.envand populate the required secrets before runningdocker compose up. - Point
REVSHELL_ACCESS_HOSTNAMEat a dedicated reverse-shell domain (for examplerevshell.example.comor your Tailscale DNS name); the service shares this host in generated commands. REVSHELL_ACCESS_PORTis the port advertised to operators/targets (defaults to3000); keep it aligned with your public tunnel or Tailscale funnel configuration.REVSHELL_TCP_BIND_PORTsets the host port that Docker binds to the reverse-shell listener (defaults to3000); change it if another process already occupies that port and point your tunnel at the new value (e.g.tailscale funnel --tcp 3000 tcp://localhost:3300).REVSHELL_ACCESS_TLScontrols whether generated commands default to TLS (openssl s_client) or plain TCP (nc). Set it totruewhen your ingress (Cloudflare Tunnel, Tailscale Funnel with TLS, etc.) expects a TLS handshake.REVSHELL_AUTH_TIMEOUT_SECONDSadjusts how long the TCP listener waits for the initialAUTH <key> <role>line before closing a connection (defaults to 30 seconds). Increase it if operators/targets frequently connect manually and need more time before authenticating.REVSHELL_HANDSHAKE_MAX_BYTEScaps the size of the initial handshake buffer (defaults to2048bytes); tune it if your proxy inserts banners or metadata ahead of the auth line.REVSHELL_HTTP_PORTcontrols the host port used to reach the revshell REST API (defaults to8000).- Slash command output mirrors
REVSHELL_ACCESS_TLS: 버튼으로Plain/TLS모드를 전환해 필요한 명령만 볼 수 있습니다. - Adjust
REVSHELL_HTTP_BASE_URL/REVSHELL_TCP_HOSTif you deploy the revshell service somewhere other than the bundled container.
- Appendix CatN1p: https://ctftime.org/team/389809