Overview
Havoc’s External C2 implementation separates transport from command logic:- Your Responsibility: Implement custom transport (DNS, ICMP, cloud APIs, etc.)
- Teamserver’s Role: Parse agent packets, dispatch commands, manage sessions
Custom Protocols
DNS, ICMP, custom binary protocols
Cloud Services
AWS SQS, Azure Service Bus, GCP Pub/Sub
Domain Fronting
CDN-based traffic redirection
Covert Channels
Social media, file sharing, IoT protocols
Architecture
- Demon agent sends encrypted packet
- Your transport receives and forwards to Teamserver external endpoint
- Teamserver parses packet, processes command
- Response flows back through your transport
- Agent receives and decrypts response
Configuration
Teamserver Profile
Enable the Service API in your profile:profiles/havoc.yaotl
The
Service directive creates a WebSocket endpoint at ws://<host>:<port>/<endpoint> for External C2 communication.Starting the Teamserver
Implementation
Service API Connection
Connect to the Teamserver using the Service API:- Python
- Go
externalc2.py
Registering External C2 Listener
Send aListenerAddExC2 message to register your external listener:
Forwarding Agent Traffic
When you receive agent data through your transport:1
Receive from Transport
2
Forward to Teamserver
3
Return Response via Transport
Teamserver Endpoint Handling
The External C2 endpoint handles agent packets identically to HTTP listeners:teamserver/pkg/handlers/external.go
View parseAgentRequest Logic
View parseAgentRequest Logic
The
parseAgentRequest function:- Decrypts the agent packet
- Parses the Demon protocol
- Processes commands
- Generates encrypted response
- Returns response bytes
Complete Example: DNS ExternalC2
Protocol Flow
Initial Agent Registration
Initial Agent Registration
Command Execution
Command Execution
Best Practices
Error Handling
Error Handling
- Always validate data before forwarding to Teamserver
- Handle Teamserver connection failures gracefully
- Implement retry logic for transient failures
- Log errors for debugging without exposing sensitive data
Performance
Performance
- Use connection pooling for HTTP requests
- Implement caching for repeated requests
- Consider async/await for I/O operations
- Monitor latency between transport and Teamserver
Security
Security
- Validate and sanitize all input data
- Use TLS for Teamserver connections in production
- Implement rate limiting to prevent abuse
- Don’t log decrypted agent data
Testing
Testing
- Test with Demon agent in controlled environment
- Verify packet forwarding with Wireshark/tcpdump
- Monitor Teamserver logs for parsing errors
- Use
--debugflag during development
Debugging
1
Enable Debug Output
2
Monitor Service Connection
3
Check External Endpoint
Limitations
Example Use Cases
DNS Tunneling
Route traffic through DNS queries (A, TXT, CNAME records)
Cloud Queues
Use AWS SQS, Azure Storage Queues for async C2
Webhooks
Integrate with Slack, Discord, Microsoft Teams
IoT Protocols
MQTT, CoAP for IoT-based infrastructure
Next Steps
Service API Reference
Complete Python API documentation
Custom Agents
Build agents that work with External C2
