Overview
Custom agents allow you to:Cross-Platform
Build agents for Linux, macOS, mobile, embedded systems
Any Language
Python, Go, Rust, C#, or any language with WebSocket support
Custom Protocols
Implement specialized communication methods
Unified Management
Manage alongside Demon agents in one interface
Architecture
Talon: Reference Implementation
Talon is an official example of a custom agent written in Python. It demonstrates:- Agent registration and lifecycle
- Custom command implementation
- Binary packing/unpacking
- Session management
We’ll reference Talon throughout this guide as a practical example.
Getting Started
Prerequisites
1
Enable Service API
Add to your Teamserver profile:
profiles/havoc.yaotl
2
Install havoc-py
3
Start Teamserver
Creating an Agent Type
Define Agent Class
Extend theAgentType class to define your agent:
agent.py
Register Agent Type
Connect to the Teamserver and register your agent:main.py
Implementing Commands
Command Structure
Extend theCommand class to create custom commands:
commands.py
Command Parameters
Define parameters withCommandParam:
Using Packer
ThePacker class helps build binary command payloads:
Registering Commands
Add commands to your agent class:agent.py
Session Management
Agent Check-in
When an agent checks in, register it with the Teamserver:session.py
Sending Command Output
Send agent output back to the Havoc UI:Retrieving Tasks
Poll for commands from the Teamserver:Complete Example: Talon-Inspired Agent
- agent.py
- commands.py
- main.py
Payload Generation
Implement thegenerate() method to create agent payloads:
Testing Your Agent
1
Start Service
2
Generate Payload
In Havoc UI:
- Navigate to Attack → Payload
- Select your agent type
- Configure options
- Click Generate
3
Execute Agent
4
Interact
Agent appears in the Sessions tab. Click to interact and run commands.
Best Practices
Command Design
Command Design
- Use unique command IDs (avoid conflicts)
- Implement comprehensive parameter validation
- Provide helpful error messages
- Tag with MITRE ATT&CK techniques for reporting
Error Handling
Error Handling
- Catch and report errors gracefully
- Don’t crash agent on invalid commands
- Log errors for debugging
- Send error output to UI console
Performance
Performance
- Keep check-in intervals reasonable
- Implement jitter to avoid patterns
- Use async I/O where possible
- Minimize payload size
Security
Security
- Encrypt agent communication
- Validate all input data
- Don’t hardcode credentials
- Implement anti-debugging if needed
Examples
Talon - Official Python Agent
Full-featured reference implementation with HTTP/HTTPS support, command handling, and more
Next Steps
Python API Reference
Detailed API documentation for havoc-py
External C2
Use custom transports with your agent
