Overview
Thecheckin command requests the Demon agent to send a fresh checkin packet containing comprehensive metadata about the agent’s configuration, host system, process information, and operating system details.
Syntax
Parameters
This command takes no parameters.Return Values
Thecheckin command returns detailed information organized into several categories:
object
string
Unique identifier for the agent session (hex format)
hex
Magic value used for validation (0xDEADBEEF)
timestamp
Timestamp of the agent’s initial callback
timestamp
Timestamp of the agent’s most recent callback
string
32-byte AES encryption key (hex encoded)
string
16-byte AES initialization vector (hex encoded)
integer
Current sleep interval in seconds
integer
Jitter percentage applied to sleep delay
object
object
object
Examples
Basic Usage
Example Output
Use Cases
- Session Verification: Confirm the agent is still active and responsive
- Configuration Review: Check current sleep settings and encryption parameters
- Context Awareness: Verify user context and privilege level before running commands
- Troubleshooting: Gather diagnostic information when investigating agent behavior
- Reconnaissance: Collect host and process information for situational awareness
Notes
- The
checkincommand does not modify any agent configuration - Encryption keys are regenerated during each checkin and automatically synchronized with the teamserver
- This command is useful after modifying agent configuration to verify changes took effect
- Agent ID is derived from session initialization and remains constant throughout the session
