YAOTL Profiles
Havoc Framework uses YAOTL (Yet Another Operator Translation Language) files to configure the teamserver, operators, listeners, and agent behavior. These profiles define everything from network settings to agent sleep times.Overview
YAOTL is a custom configuration language similar to HCL (HashiCorp Configuration Language). It provides:- Block-based syntax: Hierarchical configuration structure
- Type safety: Validated configuration with clear error messages
- Comments: Document your profiles inline
- Profiles: Reusable configurations for different operations
YAOTL profile files use the
.yaotl extension and are typically stored in the profiles/ directory.Profile Structure
A complete YAOTL profile consists of five main blocks:Only
Teamserver, Operators, and Demon blocks are required. Listeners and Service are optional.Teamserver Block
Configures the teamserver host, port, and build tools.Basic Configuration
Parameters
Build Block
Specifies paths to compilation tools:Operators Block
Defines authorized users and their credentials.Configuration
Parameters
Eachuser block:
Passwords are stored in plain text in the profile but transmitted as SHA3-256 hashes during authentication.
Demon Block
Configures default agent behavior and injection settings.Basic Configuration
Parameters
Injection Block
Defines processes to spawn for injection:Binary Block (Advanced)
Customize compiled binary properties:Listeners Block
Defines HTTP, HTTPS, SMB, and External C2 listeners.HTTP/HTTPS Listener
HTTP Parameters
Teams Profile Example
Mimic Microsoft Teams traffic:This profile makes agent traffic resemble legitimate Microsoft Teams communications, helping evade detection.
Custom TLS Certificate
SMB Listener
For pivot/lateral movement via named pipes:SMB Parameters
SMB listeners are used for agent-to-agent communication in pivot scenarios, not for initial callbacks.
External C2 Listener
For custom agent integrations:Service Block
Enables the Service API for custom agents (External C2).Configuration
Parameters
Usage
Custom agents POST to:WebHook Block (Optional)
Send notifications to Discord:Complete Example
Here’s the defaulthavoc.yaotl profile:
Advanced Example: HTTP + SMB
Fromhttp_smb.yaotl:
Profile Validation
The teamserver validates profiles on startup:- Syntax errors: Missing quotes, brackets, or commas
- Type errors: Wrong data type (e.g., string instead of int)
- Required fields: Missing mandatory parameters
- Invalid values: Out-of-range values or unknown options
Best Practices
Security
- Use strong operator passwords
- Change default passwords
- Set appropriate kill dates
- Use HTTPS for listeners
- Rotate profiles between ops
Operational
- Document profile purpose
- Use descriptive listener names
- Set realistic sleep/jitter
- Configure working hours
- Test before deployment
Network
- Match legitimate traffic patterns
- Use credible User-Agent strings
- Customize HTTP headers
- Configure appropriate URIs
- Consider using redirectors
Evasion
- Vary injection targets
- Customize binary properties
- Use sleep obfuscation
- Enable indirect syscalls
- Mimic known services (Teams, etc.)
Profile Library
Havoc includes several example profiles:Create custom profiles for different operations, environments, or detection strategies. Store them in
profiles/ with descriptive names.