Teamserver
The Havoc teamserver is the core backend component written in Go. It manages all agent sessions, handles client connections, spawns listeners, and generates payloads.Overview
The teamserver acts as the central hub between operator clients and deployed agents:- Multi-user: Supports multiple operators connecting simultaneously
- Persistent: Saves sessions to SQLite database
- Configurable: Driven by YAOTL profile files
- Cross-platform: Runs on Linux, macOS, and Docker
The teamserver requires Go 1.18+ and several build dependencies (MinGW, NASM) for payload compilation.
Core Responsibilities
1. Client Connection Management
The teamserver runs a WebSocket server for operator clients:- Client connects to
wss://teamserver:40056/havoc/ - Teamserver generates self-signed TLS certificate
- Client sends credentials with SHA3-256 hashed password
- Teamserver validates against YAOTL profile operators
- On success, sends all session state to client
Each client connection runs in its own goroutine for concurrent handling.
2. Listener Management
The teamserver spawns and manages multiple listener types: HTTP/HTTPS Listeners3. Agent Session Handling
The teamserver processes agent callbacks:- Each agent has unique AgentID, AES key, and IV
- Job queue stores pending commands
- Last callback time tracked for health monitoring
- Pivot relationships stored for linked agents
4. Payload Generation
The teamserver compiles Demon payloads on demand:- EXE: Standalone executable
- DLL: Dynamic library with exported functions
- Shellcode: Position-independent code for injection
Compilers must be specified in the YAOTL profile’s
Build block or auto-detected from PATH.5. Event Broadcasting
The teamserver maintains event synchronization across all clients:- New agent registration
- Agent output and command results
- Listener status changes
- Chat messages
- Loot and downloads
6. Database Persistence
All session data persists to SQLite:Starting the Teamserver
Basic Usage
Command Line Arguments
Startup Sequence
Data Storage Locations
Database
data/havoc.db - SQLite databaseLogs
data/loot/YYYY.MM.DD_HH:MM:SS/ - Session logsCertificates
data/server.cert, data/server.key - TLS certsProfiles
profiles/*.yaotl - Configuration filesService API (External C2)
The teamserver exposes an endpoint for custom agents:Webhook Integration
Optional Discord webhooks for notifications:Best Practices
Security
- Use strong operator passwords
- Restrict teamserver to trusted networks
- Enable TLS on HTTP listeners
- Rotate AES keys between operations
Performance
- Limit concurrent agent callbacks
- Use appropriate sleep/jitter values
- Monitor database size
- Archive old sessions
Reliability
- Backup database regularly
- Test profiles before deployment
- Monitor listener health
- Set appropriate kill dates
Operations
- Document operator credentials
- Coordinate listener ports
- Use unique listener names
- Review logs after sessions
