Skip to main content

Overview

The Command class allows you to define custom commands that operators can execute through your agent in the Havoc client. Each command specifies its parameters, permissions, and generates a task payload for the agent to execute.

Class Definition

Required Attributes

int
required
Unique identifier for the command. Should match the command ID in your agent implementation.Example: 0x101 or COMMAND_SHELL
string
required
Command name as typed by operators in the Havoc client console.Example: "shell", "upload", "screenshot"
string
required
Brief description of what the command does.
string
Detailed help text displayed when operators run help [command].
bool
required
Whether the command requires administrator/elevated privileges.
  • True: Command requires admin rights
  • False: Command works with normal privileges
list[CommandParam]
required
List of parameters the command accepts. Can be an empty list [] for commands with no parameters.
list[string]
List of MITRE ATT&CK technique IDs associated with this command.Example: ["T1059.003", "T1106"]

CommandParam

Defines a command parameter with validation rules.
string
required
Parameter name as used in the arguments dictionary.
bool
required
Whether the parameter expects a file path. When True, Havoc validates the file exists.
bool
required
Whether the parameter is optional. When False, the command requires this parameter.

Required Methods

job_generate()

Generates the task payload to send to the agent. This method is called when an operator executes the command. Parameters:
dict
required
Dictionary containing parameter values where keys match the parameter names defined in Params.
Returns: bytes - The packed task payload to send to the agent

Packer Utility

The Packer class builds binary task payloads for your agent.

Methods

function
Adds a 4-byte integer to the buffer.
function
Adds length-prefixed binary data or string to the buffer.
bytes
The final packed binary buffer to return from job_generate().

Command Examples

Registering Commands

Register commands with your agent in the __init__ method:

Command Workflow

  1. Operator Input: Operator types command in Havoc client
  2. Parameter Validation: Havoc validates parameters against Params definition
  3. Job Generation: job_generate() is called with parsed arguments
  4. Task Packing: Command packs task data using Packer
  5. Transmission: Packed task is sent to agent via Service API
  6. Agent Execution: Agent receives, unpacks, and executes the task
  7. Response: Agent sends results back through the response() handler

Best Practices

Ensure each command has a unique CommandId to avoid conflicts. Consider using a hex range:
Validate arguments in job_generate() before packing:
Set NeedAdmin = True for commands requiring elevated privileges:
Tag commands with relevant MITRE techniques for threat intelligence:
Provide clear help text with usage examples:

AgentType

Learn about agent implementation and response handling

HavocService

Connect your agent to the Teamserver