Skip to main content

Overview

Havoc includes a COFF (Common Object File Format) loader that executes Beacon Object Files (BOFs) in-memory. This allows operators to run small, position-independent code modules without spawning new processes or loading full executables.
The COFF loader provides Beacon API compatibility, allowing most Cobalt Strike BOFs to run unmodified in Havoc agents.

Architecture

COFF File Structure

BOFs are compiled as object files (not linked executables): Source: payloads/Demon/include/core/CoffeeLdr.h

Loader Context

Source: payloads/Demon/include/core/CoffeeLdr.h

Loading Process

1. COFF Parsing

Source: payloads/Demon/src/core/CoffeeLdr.c:672

2. Memory Allocation

Source: payloads/Demon/src/core/CoffeeLdr.c:728

3. Symbol Resolution

Source: payloads/Demon/src/core/CoffeeLdr.c:87

4. Relocation Processing

Source: payloads/Demon/src/core/CoffeeLdr.c:423

5. Memory Protection

Source: payloads/Demon/src/core/CoffeeLdr.c:276

6. Execution

Source: payloads/Demon/src/core/CoffeeLdr.c:241

Beacon API Compatibility

Havoc provides Beacon API functions for BOF compatibility: Source: payloads/Demon/src/core/ObjectApi.c

Exception Handling

Source: payloads/Demon/src/core/CoffeeLdr.c:32

Cleanup

Source: payloads/Demon/src/core/CoffeeLdr.c:394

OPSEC Considerations

Detection Vectors:
  1. Unusual Memory Allocations: RWX memory for BOF execution
  2. In-Memory Code: Executable code without backing file
  3. API Call Patterns: Beacon API usage from unexpected locations
  4. Exception Handlers: VEH registration for crash handling
  5. Memory Scanning: BOF signatures in process memory

Mitigation

  1. Memory Protection: Use RW then RX (not RWX)
  2. Code Obfuscation: Encrypt BOFs before loading
  3. Limited Execution: Run BOFs sparingly
  4. Clean Memory: Ensure proper cleanup after execution

Usage

Advantages Over .NET

  1. Smaller Footprint: No CLR loading required
  2. Faster Execution: Direct native code execution
  3. Less Suspicious: No .NET assemblies in memory
  4. Better OPSEC: Smaller attack surface
  5. Flexibility: Can use any Windows API directly

References

  • COFF loader: payloads/Demon/src/core/CoffeeLdr.c
  • Beacon API: payloads/Demon/src/core/ObjectApi.c
  • COFF structures: payloads/Demon/include/core/CoffeeLdr.h
  • Cobalt Strike BOF documentation
  • Microsoft PE/COFF specification