NexShell v2.2
Unified Pentest Operations Platform · 58 Professional Plugins · stdlib zero-deps
A professional-grade Unified Pentest Operations Platform managing sessions, assets, findings, evidence, transport channels, operation scope, credential inventory, timelines, real-time web dashboards, and a 58-plugin attack suite covering modern 2025/2026 attack vectors — all from a single REPL interface with zero external dependencies.
Overview
NexShell v2.2 is a complete evolution beyond standard reverse shell handlers. It combines session management, host asset inventory, vulnerability findings, chain of custody evidence collection, transport channels (TCP, TLS, HTTP, WebSocket, DoH), engagement timelines, and an interactive Metasploit-style REPL with a real-time web dashboard.
Real Platform Statistics (v2.2)
| Metric | Value |
|---|---|
| Python Source Files | 112+ modular files |
| Lines of Code | 69,000+ lines |
| CLI Commands | 58 built-in commands |
| Loaded Plugins | 58 auto-discovered plugins |
| MITRE ATT&CK Mapped | 30+ techniques |
| External Dependencies | 0 (Standard Library only) |
| Persistence | SQLite engine (NexDB) |
| Dashboard | Real-Time WebSocket Web UI |
Key Features & Architecture
nexshell/
├── nexshell.py # Main REPL interface (58 CLI commands)
├── core/ # Kernel: EventBus, Plugin registry, Rule Engine, Workflows
├── db/ # SQLite persistence (NexDB schema v2)
├── modules/ # Transport layer (TCP/TLS/HTTP/WebSocket/DoH)
├── web/ # Real-time WebSocket + REST Web Dashboard (Port :8888)
├── inventory/ # Asset management (Hosts, Services, Credential Store)
├── operations/ # Engagement workspace (Scope manager, Timeline, Checklist)
├── plugins/ # 58 auto-discovered plugins (Waves 1, 2 & 3)
└── tools/ # Pre-bundled binaries (Linux & Windows tools)
58 Professional Plugins Suite
NexShell includes 58 professional-grade plugins organized into three execution waves:
Wave 1 — Core Recon & Post-Exploitation
auto-enum-linux: Full Linux post-exploitation (Sudo CVE-2023-22809, PwnKit, eBPF, SELinux).auto-enum-windows: Windows enumeration (Entra ID/PRT tokens, Defender exclusions, LAPS, WSUS MitM).privesc-scanner: GTFOBins SUID/SGID audit & kernel exploit suggester (CVE-2025-32462, CVE-2026-3888).cred-hunter: Multi-source credential hunter (SaaS tokens, AWS/GCP/Azure keys, .env, browser DBs).network-scout: Subnet discovery, banner grabbing, and K8s/DevOps port identification.persistence-check: Systemd, cron, Registry Run keys, WMI subscriptions, and udev rule auditing.
Wave 2 — Advanced Attack Modules
cloud-recon: AWS IMDSv1/v2, GCP ADC, Azure Managed Identity, and Kubernetes RBAC checks.ad-attack: Kerberoasting, AS-REP Roasting, AD CS ESC1-ESC11 templates, and Shadow Credentials.container-escape: Docker/runc escape checks (CVE-2024-21626 Leaky Vessels, runc exec overwrite).lateral-mover: Automated lateral movement path analysis across SMB, WinRM, WMI, and SSH.amsi-bypass&etw-patcher: In-memory security control bypass modules.
Wave 3 — Post-Exploitation Engine
smart-tty-upgrade: 7-stage interactive TTY shell upgrade engine.file-transfer-engine: 12-method fallback file transfer (certutil, bitsadmin, curl, wget, etc.).persistence-engine: 16-mechanism automated persistence installer.reverse-shell-gen: 20+ payload generator with AMSI bypass wrappers & Base64 obfuscation.
Real-Time Web Dashboard
The web dashboard is served at http://localhost:8888 directly from the standard library without external frameworks:
- Live Session Telemetry: Real-time status of active shells and transport channels.
- Host & Service Graph: Interactive visualization of discovered assets and port maps.
- MITRE ATT&CK Heatmap: Auto-populated heatmap of observed techniques during the operation.
- Loot & Evidence Inventory: Centralized view of extracted hashes, files, and credentials.
Installation & Execution
# Clone the repository
git clone https://github.com/vulnquest58/nexshell.git
cd nexshell
# Launch interactive REPL
python nexshell.py
(NexShell)> help # List all 58 commands
(NexShell)> web start # Launch Web Dashboard at http://localhost:8888
(NexShell)> plugins list # List all 58 loaded plugins
(NexShell)> health # Run system health checks