Skip to main content
External C2 allows you to route Demon agent traffic through custom transport channels while the Teamserver handles agent parsing and command dispatching.

Overview

Havoc’s External C2 implementation separates transport from command logic:
  • Your Responsibility: Implement custom transport (DNS, ICMP, cloud APIs, etc.)
  • Teamserver’s Role: Parse agent packets, dispatch commands, manage sessions
This architecture enables:

Custom Protocols

DNS, ICMP, custom binary protocols

Cloud Services

AWS SQS, Azure Service Bus, GCP Pub/Sub

Domain Fronting

CDN-based traffic redirection

Covert Channels

Social media, file sharing, IoT protocols

Architecture

  1. Demon agent sends encrypted packet
  2. Your transport receives and forwards to Teamserver external endpoint
  3. Teamserver parses packet, processes command
  4. Response flows back through your transport
  5. Agent receives and decrypts response

Configuration

Teamserver Profile

Enable the Service API in your profile:
profiles/havoc.yaotl
The Service directive creates a WebSocket endpoint at ws://<host>:<port>/<endpoint> for External C2 communication.

Starting the Teamserver

You’ll see output confirming the Service endpoint is available:

Implementation

Service API Connection

Connect to the Teamserver using the Service API:
externalc2.py

Registering External C2 Listener

Send a ListenerAddExC2 message to register your external listener:
The Teamserver creates an endpoint at:

Forwarding Agent Traffic

When you receive agent data through your transport:
1

Receive from Transport

2

Forward to Teamserver

3

Return Response via Transport

Teamserver Endpoint Handling

The External C2 endpoint handles agent packets identically to HTTP listeners:
teamserver/pkg/handlers/external.go
The parseAgentRequest function:
  1. Decrypts the agent packet
  2. Parses the Demon protocol
  3. Processes commands
  4. Generates encrypted response
  5. Returns response bytes
This is the same logic used by HTTP/HTTPS listeners.

Complete Example: DNS ExternalC2

Protocol Flow

Best Practices

  • Always validate data before forwarding to Teamserver
  • Handle Teamserver connection failures gracefully
  • Implement retry logic for transient failures
  • Log errors for debugging without exposing sensitive data
  • Use connection pooling for HTTP requests
  • Implement caching for repeated requests
  • Consider async/await for I/O operations
  • Monitor latency between transport and Teamserver
  • Validate and sanitize all input data
  • Use TLS for Teamserver connections in production
  • Implement rate limiting to prevent abuse
  • Don’t log decrypted agent data
  • Test with Demon agent in controlled environment
  • Verify packet forwarding with Wireshark/tcpdump
  • Monitor Teamserver logs for parsing errors
  • Use --debug flag during development

Debugging

1

Enable Debug Output

2

Monitor Service Connection

3

Check External Endpoint

Limitations

  • One agent packet per request (Demon protocol limitation)
  • Must preserve packet integrity (no fragmentation)
  • Teamserver expects standard Demon packet format
  • External endpoint is HTTP only (TLS termination at your layer)

Example Use Cases

DNS Tunneling

Route traffic through DNS queries (A, TXT, CNAME records)

Cloud Queues

Use AWS SQS, Azure Storage Queues for async C2

Webhooks

Integrate with Slack, Discord, Microsoft Teams

IoT Protocols

MQTT, CoAP for IoT-based infrastructure

Next Steps

Service API Reference

Complete Python API documentation

Custom Agents

Build agents that work with External C2