The Victim detail view exposes live browser controls only after an
authorized target has established a campaign session.
Video demo
The recording uses a synthetic, authorized target to show the operator-facing
session view and evidence panels.
Protocols
- VNC uses the VNC browser image and a proxied live view.
- Selkies (default) uses the Selkies image and exposes additional streaming-quality
settings in the campaign wizard.
Session behavior
Each victim session receives a dedicated browser container. The admin backend
validates campaign and victim ownership before returning stream access or
performing runtime actions.
If a stream does not become ready within the configured startup timeout, check
the campaign and target-session logs before recreating the session.
Screenshots
Screenshots are captured only when an authenticated operator requests one.
They are taken inside the browser container and stored in the standard
campaign storage, and then shown in the victim gallery.
Keylogger
Empty records are not intended to appear as copyable keylog blocks. Session
and timestamp markers provide context, while only actual key content is
copyable. Last modified on August 28, 2026