Skip to main content

Teamserver

The Havoc teamserver is the core backend component written in Go. It manages all agent sessions, handles client connections, spawns listeners, and generates payloads.

Overview

The teamserver acts as the central hub between operator clients and deployed agents:
  • Multi-user: Supports multiple operators connecting simultaneously
  • Persistent: Saves sessions to SQLite database
  • Configurable: Driven by YAOTL profile files
  • Cross-platform: Runs on Linux, macOS, and Docker
The teamserver requires Go 1.18+ and several build dependencies (MinGW, NASM) for payload compilation.

Core Responsibilities

1. Client Connection Management

The teamserver runs a WebSocket server for operator clients:
Authentication Flow:
  1. Client connects to wss://teamserver:40056/havoc/
  2. Teamserver generates self-signed TLS certificate
  3. Client sends credentials with SHA3-256 hashed password
  4. Teamserver validates against YAOTL profile operators
  5. On success, sends all session state to client
Each client connection runs in its own goroutine for concurrent handling.

2. Listener Management

The teamserver spawns and manages multiple listener types: HTTP/HTTPS Listeners
SMB Named Pipe Listeners
External C2 Listeners
Listeners are automatically restored from the database on teamserver restart.

3. Agent Session Handling

The teamserver processes agent callbacks:
Agent State Management:
  • Each agent has unique AgentID, AES key, and IV
  • Job queue stores pending commands
  • Last callback time tracked for health monitoring
  • Pivot relationships stored for linked agents

4. Payload Generation

The teamserver compiles Demon payloads on demand:
Supported Formats:
  • EXE: Standalone executable
  • DLL: Dynamic library with exported functions
  • Shellcode: Position-independent code for injection
Compilers must be specified in the YAOTL profile’s Build block or auto-detected from PATH.

5. Event Broadcasting

The teamserver maintains event synchronization across all clients:
Event Types:
  • New agent registration
  • Agent output and command results
  • Listener status changes
  • Chat messages
  • Loot and downloads

6. Database Persistence

All session data persists to SQLite:

Starting the Teamserver

Basic Usage

Root privileges are required to bind listeners on ports below 1024 (e.g., port 80/443).

Command Line Arguments

Startup Sequence

Data Storage Locations

Database

data/havoc.db - SQLite database

Logs

data/loot/YYYY.MM.DD_HH:MM:SS/ - Session logs

Certificates

data/server.cert, data/server.key - TLS certs

Profiles

profiles/*.yaotl - Configuration files

Service API (External C2)

The teamserver exposes an endpoint for custom agents:
Configuration (in YAOTL profile):
Custom agents can POST to this endpoint with their own magic values and protocols.

Webhook Integration

Optional Discord webhooks for notifications:

Best Practices

Security

  • Use strong operator passwords
  • Restrict teamserver to trusted networks
  • Enable TLS on HTTP listeners
  • Rotate AES keys between operations

Performance

  • Limit concurrent agent callbacks
  • Use appropriate sleep/jitter values
  • Monitor database size
  • Archive old sessions

Reliability

  • Backup database regularly
  • Test profiles before deployment
  • Monitor listener health
  • Set appropriate kill dates

Operations

  • Document operator credentials
  • Coordinate listener ports
  • Use unique listener names
  • Review logs after sessions