Advanced Command & Control Framework

A professional-grade solution for security teams and red teaming operations and large scale cyber defence exercises

Key Features

Modular Plugin Architecture

Listeners, commands and payload builders are all just plugins. The official SDK lets you craft new server-side or client-side modules, and almost every "built-in" feature you see is itself a plugin, proof that your own extensions can live first-class inside the UI and API.

Versatile Listener Suite

Need a classic reverse HTTP beacon, an internal relay for lateral movement, or a quick reverse-shell catch-all? Tuoni ships multiple listener types: Reverse HTTP/TCP, Bind TCP/SMB, Relay listeners and an External listener to fit almost any network layout or EDR evasion plan.

Rich Command Library

Out-of-the-box native commands live inside the agent process for maximal stealth, while plugin commands can inject into an existing PID or spin up a sacrificial process under alternate creds, giving you surgical control over how and where shell-code runs.

Cross-Platform Payload Generation

Generate Windows (x86/x64), Linux and BSD agents, or switch to the Commercial Payload template for an ultra-configurable build with AMSI/ETW bypass options, delayed execution, obfuscated sleeps and more. All payloads are produced straight from the GUI or API in seconds.

REST API & Python Library

Anything you can click you can script. A fully documented OpenAPI/Swagger endpoint plus a thin Python helper library let you spin up listeners, push commands or harvest results from your own tooling or CI pipeline.

Offline / Air-Gapped Mode

Export the entire Git repo and Docker images to a single archive, rsync it into a dark-site and run tuoni import-tuoni-package Perfect for ranges, classified networks or competition environments where Internet access is a no-go.

Commercial Add-Ons

Commercial licence holders unlock extra native + plugin commands and a payload family that layers heavy obfuscation, per-build randomness and multi-architecture support. Ideal for red-teamers facing modern EDR.

Integrated Discovery & File Hosting

Hosts, services and credentials discovered during operations are auto-catalogued and editable in the "Discovery" views, while the built-in file server lets you stage binaries or scripts on every HTTP/HTTPS listener with ease.

About Tuoni

Tuoni is an advanced Command & Control framework designed for security professionals. It provides a robust platform for managing penetration testing operations, red team engagements, and security assessments.

With continuous improvements in stability, performance, and features, Tuoni empowers security teams to work efficiently and effectively in complex security environments.

Latest Release

Tuoni 0.10.3

Maintenance and Stability Improvements

  • Resolved terminal file caching issue that impacted resource utilization
  • Fixed terminal autocomplete functionality to ensure consistent command completion
  • Implemented graceful error handling in Server-Side Script engine
View Release Notes

Licensing Options

Select the Tuoni edition that suits your operational requirements. Contact us for detailed pricing information.

Free

Community Edition

  • Basic command & control framework
  • Wide range of free plugins
  • Open source examples
  • Community support
  • Regular software updates
  • Standard documentation

Commercial

Professional Edition

  • All Community Edition features
  • Commercial Windows Agent
  • Linux & BSD Agents
  • Extended commercial command set
  • Access to private launchers
  • Secondary support channel

Unlimited

Enterprise Solution

  • Unlimited organizational deployment
  • Early access to experimental features
  • On-demand custom development
  • Support on agent configurations
  • Training sessions (remote/on-site)
  • Dedicated support with SLA

Already have a license key? Visit our commercial page to verify and download assets for your license.

Get in Touch

Contact our sales team to discuss pricing options, request a personalized demo, or inquire about custom development services for your organization's specific needs. We offer flexible licensing models tailored to your requirements.

Documentation

docs.shelldot.com

Community

Join our Discord