Skip to main content

Command Overview

Demon implements a comprehensive command set organized by functionality. All commands are dispatched through a central command dispatcher and executed based on the command ID.
Type help in the Demon interact window to see all available commands. Use help [command] for detailed information about a specific command.

Session Management

checkin

Request a full checkin from the Demon agent.
Output includes:
  • Magic values for verification
  • First and last call timestamps
  • AES encryption key and IV
  • Current sleep delay and jitter
  • Request ID tracking
  • Computer hostname
  • Current username and domain
  • Internal IP addresses
  • Network adapter information
  • Process name and path
  • Process architecture (x86/x64)
  • Process ID (PID)
  • Parent Process ID (PPID)
  • Elevated/Integrity level
  • Windows version
  • Build number
  • OS architecture

sleep

Modify the agent’s sleep interval and jitter.
Examples:
Behavior:
  • With jitter, actual sleep time varies: sleep ± (sleep * jitter / 100)
  • Sleep of 0 enables interactive mode for real-time operations
  • Sleep obfuscation only occurs when sleep > 0 and no jobs running
Working hours and kill date restrictions still apply even with modified sleep values.

exit

Terminate the Demon agent.
This command causes the agent to terminate immediately. There is no recovery once executed.
Cleanup actions:
  • Closes all handles
  • Frees allocated memory
  • Terminates all job threads
  • Exits process cleanly

Process Management

proc list

Enumerate running processes on the target system.
Output columns:
  • Process Name
  • PID (Process ID)
  • PPID (Parent Process ID)
  • Architecture (x86/x64)
  • Username (if accessible)
  • Session ID
Implementation: Uses CreateToolhelp32Snapshot and Process32FirstW/Process32NextW

proc kill

Terminate a process by PID.
Example:
Method: Opens process with PROCESS_TERMINATE access and calls NtTerminateProcess (via syscall if configured).

proc create

Spawn a new process in suspended or running state.
States:
  • suspended - Process created in suspended state
  • normal - Process starts immediately
Examples:
Use cases:
  • Suspended: For process injection targets
  • Normal: Execute commands and capture output

proc module

List loaded modules in a target process.
Output:
  • Module name
  • Base address
  • Module size
  • Full path
Use case: Identify loaded DLLs for injection or hijacking opportunities

proc grep

Search for processes by name.
Example:
Output: All processes matching the search term with full details

proc memory

Query memory regions in a target process.
Protection values:
  • PAGE_EXECUTE_READ (0x20)
  • PAGE_EXECUTE_READWRITE (0x40)
  • PAGE_READWRITE (0x04)
Example:
Output: Base address, size, and protection of matching memory regions

File System Operations

fs dir

List directory contents.
Example:
Output:
  • File/Directory name
  • Size
  • Last modified time
  • Attributes (Hidden, System, Archive, etc.)

fs cd

Change current working directory.
Example:

fs pwd

Print current working directory.

fs download

Download a file from the target to the teamserver.
Features:
  • Chunked transfer (configurable chunk size)
  • Progress tracking
  • Automatic resumption on failure
Example:
Large files are automatically split into chunks. Check download progress with the transfer command.

fs upload

Upload a file from the teamserver to the target.
Example:

fs cat

Read and display file contents.
Example:
Large files will be truncated in output. Use fs download for large files.

fs remove

Delete a file.
Example:

fs mkdir

Create a directory.

fs copy

Copy a file or directory.

fs move

Move or rename a file.

Token Management

token getuid

Display current user context.
Output:
  • Username
  • Domain
  • SID
  • Integrity level
  • Token type

token list

List all tokens in the token vault.
Output for each token:
  • Token ID (for impersonation)
  • Username
  • Domain
  • Token type (Primary/Impersonation)
  • Session ID

token find-tokens

Scan the system for accessible tokens.
Process:
  1. Enumerate all running processes
  2. Attempt to open process token
  3. Query token information
  4. Display accessible tokens
Use case: Identify privilege escalation opportunities

token steal

Steal a token from a process and add to vault.
Examples:
Process:
  1. Open target process
  2. Open process token or duplicate specified handle
  3. Duplicate token with SecurityIdentification and SecurityImpersonation
  4. Store in token vault
  5. Return token ID

token impersonate

Apply a token from the vault to the current thread.
Example:
Effect: All subsequent operations execute under the impersonated user context
Impersonation affects the current thread. Use token revert to return to the original token.

token revert

Revert to the default process token.
Implementation: Calls RevertToSelf() to remove thread impersonation

token remove

Remove a token from the vault.

token clear

Remove all tokens from the vault.

token make

Create a token from credentials.
Example:
Methods:
  • LogonUserW with LOGON32_LOGON_NETWORK (Type 3)
  • Token added to vault automatically

token privs-get

Attempt to enable all privileges on current token.
Common privileges enabled:
  • SeDebugPrivilege
  • SeImpersonatePrivilege
  • SeLoadDriverPrivilege
  • SeTcbPrivilege
  • SeBackupPrivilege
  • SeRestorePrivilege

token privs-list

List all privileges and their states.
Output:
  • Privilege name
  • State (Enabled/Disabled)
  • Attributes

Code Execution

inline-execute

Execute a Beacon Object File (BOF) in-memory.
Example:
Features:
  • COFF parsing and linking
  • Beacon API compatibility
  • Output capture
  • Optional VEH crash protection
  • Thread-based execution (if configured)
Inline Mode (CoffeeThreaded: false)
  • Executes in current thread
  • Fastest performance
  • No job management
  • Crash will terminate agent
Threaded Mode (CoffeeThreaded: true)
  • Executes in separate thread
  • Manageable via job commands
  • Isolated from main agent
  • VEH can catch crashes

dotnet inline-execute

Execute a .NET assembly in-memory.
Example:
Process:
  1. Initialize CLR (if not already loaded)
  2. Patch AMSI in amsi.dll
  3. Create AppDomain
  4. Load assembly from memory
  5. Invoke entry point with arguments
  6. Capture console output
OPSEC: Loading the CLR is irreversible and increases process footprint. The CLR remains loaded for the lifetime of the process.

dotnet list-versions

List installed .NET Framework versions.
Output: All installed .NET versions detected in the registry

shellcode inject

Inject shellcode into a remote process.
Example:
See Injection Techniques for detailed documentation.

shellcode spawn

Spawn a sacrificial process and inject shellcode (fork & run).
Example:
Process:
  1. Spawn configured process in suspended state
  2. Allocate memory in target
  3. Write shellcode
  4. Create remote thread
  5. Resume process

Network Commands

net domain

Query domain information.
Output:
  • Domain name
  • Domain controller
  • Forest information

net dclist

Enumerate domain controllers.

net logons

Enumerate logged-on users.
API: NetWkstaUserEnum

net sessions

Enumerate active sessions on a computer.
API: NetSessionEnum

net localgroup

Enumerate local groups.
API: NetLocalGroupEnum

net group

Enumerate domain groups.

net user

Enumerate users.

net share

Enumerate shares on a computer.
API: NetShareEnum

Job Management

job list

List all running jobs.
Output:
  • Job ID
  • Job type (BOF, Download, etc.)
  • State (Running, Suspended)
  • Thread ID

job suspend

Suspend a running job.
Example:
Implementation: Calls NtSuspendThread on the job’s thread

job resume

Resume a suspended job.
Implementation: Calls NtResumeThread

job kill

Terminate and remove a job.
Process:
  1. Suspend thread
  2. Terminate thread
  3. Free allocated resources
  4. Remove from job list
Sleep obfuscation is disabled while jobs are running. Kill or suspend jobs to enable sleep obfuscation.

Transfer Management

transfer list

List active file transfers.
Output:
  • Transfer ID
  • Filename
  • Size
  • Progress
  • State

transfer stop

Pause a file transfer.

transfer resume

Resume a paused transfer.

transfer remove

Cancel and remove a transfer.

Miscellaneous Commands

screenshot

Capture a screenshot of the desktop.
Process:
  1. Get desktop device context
  2. Create compatible DC
  3. BitBlt to copy screen
  4. Convert to BMP format
  5. Send to teamserver
Requirements: GUI session (does not work in services or non-interactive sessions)

config

View or modify agent configuration.
Values:
  • injection technique: 1 (Win32), 2 (Syscall), 3 (APC)
  • memory alloc/execute: 1 (Win32), 2 (Syscall)

pivot

Manage SMB pivot connections.
Use case: Create lateral movement paths through compromised hosts

kerberos

Kerberos ticket operations.
Kerberos functionality requires appropriate privileges and network access to domain controllers.

Next Steps

Sleep Obfuscation

Configure sleep techniques for evasion

Injection Methods

Process injection techniques and OPSEC

Features Guide

Explore all Demon capabilities

Generate Payloads

Create configured Demon agents