Skip to main content

Overview

The config command allows operators to modify the Demon agent’s configuration settings at runtime without regenerating payloads. This enables dynamic adaptation to operational requirements and defensive posture.

Syntax

Configuration Categories

Implant Settings

boolean
Enable or disable verbose output from the agent.
  • true - Enable detailed logging and output
  • false - Minimal output (default)
integer
Set the sleep obfuscation technique.
  • 0 - WaitForSingleObjectEx (no obfuscation)
  • 1 - FOLIAGE
  • 2 - Ekko
string
Configure the return address for stack spoofing during sleep.
Format: library!function+0xoffsetExample: ntdll!NtAddBootEntry+0x14
boolean
Enable or disable Vectored Exception Handler for BOF execution.
  • true - Use VEH for exception handling
  • false - Standard exception handling
boolean
Enable or disable threaded BOF execution.
  • true - Execute BOFs in separate threads
  • false - Execute BOFs in main thread

Memory Management

integer
Set the memory allocation technique.
  • 0 - VirtualAllocEx (Win32 API)
  • 1 - NtAllocateVirtualMemory (Indirect syscall)
integer
Set the memory protection technique.
  • 0 - VirtualProtectEx (Win32 API)
  • 1 - NtProtectVirtualMemory (Indirect syscall)

Injection Settings

integer
Set the thread creation technique for injection.
  • 0 - Default (configured in profile)
  • 1 - CreateRemoteThread
  • 2 - NtCreateThreadEx (syscall)
  • 3 - NtQueueApcThread (syscall)
string
Configure return address spoofing for injection.
Format: library!function+0xoffset
string
Set the 64-bit process to spawn for fork & run operations.
Common options:
  • C:\Windows\System32\werfault.exe
  • C:\Windows\System32\dllhost.exe
  • C:\Windows\System32\RuntimeBroker.exe
  • C:\Windows\System32\svchost.exe
string
Set the 32-bit process to spawn for fork & run operations.
Common options:
  • C:\Windows\SysWOW64\werfault.exe
  • C:\Windows\SysWOW64\dllhost.exe
  • C:\Windows\SysWOW64\rundll32.exe

Operational Security

string
Set or update the agent’s self-destruct date (UTC).
Format: YYYY-MM-DD HH:MM:SS (UTC)When the kill date is reached, the agent will:
  • Clean up artifacts
  • Exit the thread/process
  • Stop communicating with teamserver
string
Set the hours during which the agent will callback.
Format: HH:MM-HH:MM (24-hour format)Outside working hours, the agent will not check in to the teamserver.

Examples

Configure Maximum OPSEC

Configure for Speed (Less OPSEC)

Set Operational Timeframe

Configure BOF Execution

Modify Sleep Obfuscation

Configuration IDs (Internal)

These are the internal command IDs used by the agent (from commands.go:80-98):

OPSEC Impact

Recommended settings for evasion:
Impact:
  • Uses indirect syscalls to bypass usermode hooks
  • Advanced sleep obfuscation (Ekko)
  • APC-based injection
  • Legitimate spawn process

Return Values

string
Configuration update status: Success or Error
string
The configuration key that was modified
string
The new value that was set

Verification

After changing configuration, use checkin to verify settings:
The checkin output will reflect updated configuration values.

Use Cases

Adapt to Detection

Operational Constraints

Performance Tuning

Debugging

Notes

  • Configuration changes take effect immediately
  • Settings do not persist across agent restarts
  • Some settings only apply to future operations (e.g., spawn process)
  • Kill date and working hours are checked during sleep cycles
  • Invalid values may cause errors or be silently ignored
  • Use checkin to verify configuration changes
  • Profile defaults are used until explicitly changed with config