Skip to main content
Havoc’s module system allows you to extend the Demon agent’s functionality without modifying the core codebase. Modules are loaded dynamically from the Havoc client and can add new commands, techniques, and capabilities.

Overview

Modules enable:

Custom Commands

Add new commands to the Demon agent

No Recompilation

Load modules at runtime without rebuilding

Isolation

Execute in fork & run processes for safety

Integration

Seamlessly integrate with existing workflows

Official Modules

Havoc provides official modules at github.com/HavocFramework/Modules:

Powerpick

Executes unmanaged PowerShell commands by loading the CLR runtime into a fork & run process.
Features:
  • Loads CLR 4.0.30319 into sacrificial process
  • Executes PowerShell without powershell.exe
  • Bypasses application whitelisting
  • Captures output and returns to operator

InvokeAssembly

Executes .NET assemblies in a separate process by bootstrapping the CLR.
Features:
  • Custom CLR version selection (default: v4.0.30319)
  • Custom AppDomain name (default: DefaultAppDomain)
  • Argument passing to assembly
  • Output redirection and capture

Module Structure

A Havoc module consists of:

Creating a Module

Module Template

Start with the official template:

Module.py

Define your module in Python:
Module.py

C Implementation

Implement the module logic in C:
Source/Main.c

Beacon API

Havoc modules use the Beacon Object File (BOF) API for compatibility:

Building Modules

Compiling to COFF/BOF

Modules are compiled as COFF (Common Object File Format) objects:
COFF files are position-independent code loaded via the Demon COFF loader.

Makefile Example

Loading Modules

From Havoc Client

1

Open Scripts Manager

Navigate to Scripts → Scripts Manager in the Havoc client
2

Load Module

Click Load and select your Module.py file
3

Verify Registration

Check the console for confirmation:
4

Use Command

Interact with a Demon session and use your new command:

Auto-load on Startup

Place modules in the scripts/ directory to load automatically:

Example: Powerpick Module

The Powerpick module demonstrates advanced techniques:
Powerpick/Module.py
The C implementation:
  • Creates sacrificial process (defined in config)
  • Injects CLR loader shellcode
  • Loads mscorlib.dll and PowerShell assemblies
  • Executes command and captures output
  • Returns output to teamserver

Example: InvokeAssembly Module

InvokeAssembly/Module.py

Best Practices

  • Use indirect syscalls where possible
  • Avoid suspicious API calls (e.g., CreateRemoteThread)
  • Clean up artifacts (files, registry keys)
  • Implement anti-debugging checks
  • Use fork & run for risky operations

Advanced Techniques

Custom Packer Class

Multi-Command Modules

Module.py

Dynamic Library Loading

Source/Main.c

Debugging Modules

1

Enable Debug Output

Use BeaconPrintf for debug messages:
2

Test COFF Loader

Use standalone COFF loader for testing:
3

Check Teamserver Logs

Monitor Teamserver output:

Resources

Official Modules

Powerpick, InvokeAssembly, and module template

Beacon API Reference

BOF API documentation (Cobalt Strike compatible)

Python API

havoc-py reference for Module.py

Custom Agents

Build agents instead of modules

Troubleshooting

  • Check Module.py syntax
  • Verify COFF files exist and are referenced correctly
  • Check Havoc console for error messages
  • Ensure module name is unique
  • Verify command ID matches between Python and C
  • Check argument packing/unpacking
  • Enable debug output in C code
  • Test with simple arguments first
  • Ensure correct mingw-w64 toolchain installed
  • Check include paths for Beacon.h
  • Verify target architecture (x64 vs x86)
  • Use -masm=intel for inline assembly