Skip to main content

YAOTL Profiles

Havoc Framework uses YAOTL (Yet Another Operator Translation Language) files to configure the teamserver, operators, listeners, and agent behavior. These profiles define everything from network settings to agent sleep times.

Overview

YAOTL is a custom configuration language similar to HCL (HashiCorp Configuration Language). It provides:
  • Block-based syntax: Hierarchical configuration structure
  • Type safety: Validated configuration with clear error messages
  • Comments: Document your profiles inline
  • Profiles: Reusable configurations for different operations
YAOTL profile files use the .yaotl extension and are typically stored in the profiles/ directory.

Profile Structure

A complete YAOTL profile consists of five main blocks:
Only Teamserver, Operators, and Demon blocks are required. Listeners and Service are optional.

Teamserver Block

Configures the teamserver host, port, and build tools.

Basic Configuration

Parameters

Build Block

Specifies paths to compilation tools:
If you omit the Build block, the teamserver will search for compilers in your PATH.

Operators Block

Defines authorized users and their credentials.

Configuration

Parameters

Each user block:
Passwords are stored in plain text in the profile but transmitted as SHA3-256 hashes during authentication.

Demon Block

Configures default agent behavior and injection settings.

Basic Configuration

Parameters

Injection Block

Defines processes to spawn for injection:
Choose inconspicuous processes like notepad.exe, Werfault.exe, or RuntimeBroker.exe for injection targets.

Binary Block (Advanced)

Customize compiled binary properties:

Listeners Block

Defines HTTP, HTTPS, SMB, and External C2 listeners.

HTTP/HTTPS Listener

HTTP Parameters

Teams Profile Example

Mimic Microsoft Teams traffic:
This profile makes agent traffic resemble legitimate Microsoft Teams communications, helping evade detection.

Custom TLS Certificate

SMB Listener

For pivot/lateral movement via named pipes:

SMB Parameters

SMB listeners are used for agent-to-agent communication in pivot scenarios, not for initial callbacks.

External C2 Listener

For custom agent integrations:

Service Block

Enables the Service API for custom agents (External C2).

Configuration

Parameters

Usage

Custom agents POST to:
With authentication:
Use the Service API to integrate custom implants like Talon or your own agents.

WebHook Block (Optional)

Send notifications to Discord:

Complete Example

Here’s the default havoc.yaotl profile:

Advanced Example: HTTP + SMB

From http_smb.yaotl:

Profile Validation

The teamserver validates profiles on startup:
Common Errors:
  • Syntax errors: Missing quotes, brackets, or commas
  • Type errors: Wrong data type (e.g., string instead of int)
  • Required fields: Missing mandatory parameters
  • Invalid values: Out-of-range values or unknown options
Test your profile with --debug flag to see detailed validation output.

Best Practices

Security

  • Use strong operator passwords
  • Change default passwords
  • Set appropriate kill dates
  • Use HTTPS for listeners
  • Rotate profiles between ops

Operational

  • Document profile purpose
  • Use descriptive listener names
  • Set realistic sleep/jitter
  • Configure working hours
  • Test before deployment

Network

  • Match legitimate traffic patterns
  • Use credible User-Agent strings
  • Customize HTTP headers
  • Configure appropriate URIs
  • Consider using redirectors

Evasion

  • Vary injection targets
  • Customize binary properties
  • Use sleep obfuscation
  • Enable indirect syscalls
  • Mimic known services (Teams, etc.)

Profile Library

Havoc includes several example profiles:
Create custom profiles for different operations, environments, or detection strategies. Store them in profiles/ with descriptive names.