Skip to main content
Havoc’s Service API enables you to create custom agents in any language that can communicate over WebSocket. These agents appear in the Havoc UI alongside Demon agents with full command and control capabilities.

Overview

Custom agents allow you to:

Cross-Platform

Build agents for Linux, macOS, mobile, embedded systems

Any Language

Python, Go, Rust, C#, or any language with WebSocket support

Custom Protocols

Implement specialized communication methods

Unified Management

Manage alongside Demon agents in one interface

Architecture

Talon: Reference Implementation

Talon is an official example of a custom agent written in Python. It demonstrates:
  • Agent registration and lifecycle
  • Custom command implementation
  • Binary packing/unpacking
  • Session management
We’ll reference Talon throughout this guide as a practical example.

Getting Started

Prerequisites

1

Enable Service API

Add to your Teamserver profile:
profiles/havoc.yaotl
2

Install havoc-py

3

Start Teamserver

Creating an Agent Type

Define Agent Class

Extend the AgentType class to define your agent:
agent.py

Register Agent Type

Connect to the Teamserver and register your agent:
main.py
Your agent type now appears in the Havoc UI under Attack → Payload.

Implementing Commands

Command Structure

Extend the Command class to create custom commands:
commands.py

Command Parameters

Define parameters with CommandParam:

Using Packer

The Packer class helps build binary command payloads:

Registering Commands

Add commands to your agent class:
agent.py

Session Management

Agent Check-in

When an agent checks in, register it with the Teamserver:
session.py

Sending Command Output

Send agent output back to the Havoc UI:

Retrieving Tasks

Poll for commands from the Teamserver:

Complete Example: Talon-Inspired Agent

Payload Generation

Implement the generate() method to create agent payloads:

Testing Your Agent

1

Start Service

Expected output:
2

Generate Payload

In Havoc UI:
  1. Navigate to Attack → Payload
  2. Select your agent type
  3. Configure options
  4. Click Generate
3

Execute Agent

4

Interact

Agent appears in the Sessions tab. Click to interact and run commands.

Best Practices

  • Use unique command IDs (avoid conflicts)
  • Implement comprehensive parameter validation
  • Provide helpful error messages
  • Tag with MITRE ATT&CK techniques for reporting
  • Catch and report errors gracefully
  • Don’t crash agent on invalid commands
  • Log errors for debugging
  • Send error output to UI console
  • Keep check-in intervals reasonable
  • Implement jitter to avoid patterns
  • Use async I/O where possible
  • Minimize payload size
  • Encrypt agent communication
  • Validate all input data
  • Don’t hardcode credentials
  • Implement anti-debugging if needed

Examples

Talon - Official Python Agent

Full-featured reference implementation with HTTP/HTTPS support, command handling, and more

Next Steps

Python API Reference

Detailed API documentation for havoc-py

External C2

Use custom transports with your agent