Skip to main content

Overview

The checkin command requests the Demon agent to send a fresh checkin packet containing comprehensive metadata about the agent’s configuration, host system, process information, and operating system details.

Syntax

Parameters

This command takes no parameters.

Return Values

The checkin command returns detailed information organized into several categories:
object
string
Path where agent session data is stored on the teamserver
object
string
Unique identifier for the agent session (hex format)
hex
Magic value used for validation (0xDEADBEEF)
timestamp
Timestamp of the agent’s initial callback
timestamp
Timestamp of the agent’s most recent callback
string
32-byte AES encryption key (hex encoded)
string
16-byte AES initialization vector (hex encoded)
integer
Current sleep interval in seconds
integer
Jitter percentage applied to sleep delay
object
string
Computer hostname
string
Current user context
string
Domain or workgroup name
string
Internal IP address(es)
object
string
Name of the process hosting the agent
string
Process architecture (x86, x64, IA64, or Unknown)
integer
Process identifier (PID)
integer
Thread identifier (TID)
string
Full path to the process executable
boolean
Whether the process has elevated privileges
hex
Base address of the agent in memory
object
string
Windows version string
string
OS build number
string
OS architecture (x86, x64/AMD64, ARM, ARM64, Itanium-based)

Examples

Basic Usage

Example Output

Use Cases

  • Session Verification: Confirm the agent is still active and responsive
  • Configuration Review: Check current sleep settings and encryption parameters
  • Context Awareness: Verify user context and privilege level before running commands
  • Troubleshooting: Gather diagnostic information when investigating agent behavior
  • Reconnaissance: Collect host and process information for situational awareness

Notes

  • The checkin command does not modify any agent configuration
  • Encryption keys are regenerated during each checkin and automatically synchronized with the teamserver
  • This command is useful after modifying agent configuration to verify changes took effect
  • Agent ID is derived from session initialization and remains constant throughout the session