Overview
Modules enable:Custom Commands
Add new commands to the Demon agent
No Recompilation
Load modules at runtime without rebuilding
Isolation
Execute in fork & run processes for safety
Integration
Seamlessly integrate with existing workflows
Official Modules
Havoc provides official modules at github.com/HavocFramework/Modules:Powerpick
Executes unmanaged PowerShell commands by loading the CLR runtime into a fork & run process.- Loads CLR 4.0.30319 into sacrificial process
- Executes PowerShell without
powershell.exe - Bypasses application whitelisting
- Captures output and returns to operator
InvokeAssembly
Executes .NET assemblies in a separate process by bootstrapping the CLR.- Custom CLR version selection (default:
v4.0.30319) - Custom AppDomain name (default:
DefaultAppDomain) - Argument passing to assembly
- Output redirection and capture
Module Structure
A Havoc module consists of:Creating a Module
Module Template
Start with the official template:Module.py
Define your module in Python:Module.py
C Implementation
Implement the module logic in C:Source/Main.c
Beacon API
Havoc modules use the Beacon Object File (BOF) API for compatibility:Building Modules
Compiling to COFF/BOF
Modules are compiled as COFF (Common Object File Format) objects:COFF files are position-independent code loaded via the Demon COFF loader.
Makefile Example
Loading Modules
From Havoc Client
1
Open Scripts Manager
Navigate to Scripts → Scripts Manager in the Havoc client
2
Load Module
Click Load and select your
Module.py file3
Verify Registration
Check the console for confirmation:
4
Use Command
Interact with a Demon session and use your new command:
Auto-load on Startup
Place modules in thescripts/ directory to load automatically:
Example: Powerpick Module
View Powerpick Implementation
View Powerpick Implementation
The Powerpick module demonstrates advanced techniques:The C implementation:
Powerpick/Module.py
- Creates sacrificial process (defined in config)
- Injects CLR loader shellcode
- Loads
mscorlib.dlland PowerShell assemblies - Executes command and captures output
- Returns output to teamserver
Example: InvokeAssembly Module
View InvokeAssembly Implementation
View InvokeAssembly Implementation
InvokeAssembly/Module.py
Best Practices
Error Handling
Error Handling
Memory Management
Memory Management
OPSEC Considerations
OPSEC Considerations
- Use indirect syscalls where possible
- Avoid suspicious API calls (e.g.,
CreateRemoteThread) - Clean up artifacts (files, registry keys)
- Implement anti-debugging checks
- Use fork & run for risky operations
Testing
Testing
Advanced Techniques
Custom Packer Class
Multi-Command Modules
Module.py
Dynamic Library Loading
Source/Main.c
Debugging Modules
1
Enable Debug Output
Use
BeaconPrintf for debug messages:2
Test COFF Loader
Use standalone COFF loader for testing:
3
Check Teamserver Logs
Monitor Teamserver output:
Resources
Official Modules
Powerpick, InvokeAssembly, and module template
Beacon API Reference
BOF API documentation (Cobalt Strike compatible)
Python API
havoc-py reference for Module.py
Custom Agents
Build agents instead of modules
Troubleshooting
Module Not Loading
Module Not Loading
- Check
Module.pysyntax - Verify COFF files exist and are referenced correctly
- Check Havoc console for error messages
- Ensure module name is unique
Command Not Working
Command Not Working
- Verify command ID matches between Python and C
- Check argument packing/unpacking
- Enable debug output in C code
- Test with simple arguments first
Compilation Errors
Compilation Errors
- Ensure correct mingw-w64 toolchain installed
- Check include paths for Beacon.h
- Verify target architecture (x64 vs x86)
- Use
-masm=intelfor inline assembly
