havoc-py library provides a Python interface to Havoc’s Service API, enabling custom agent development, automation, and extensibility.
Installation
The havoc-py library requires Python 3.8 or higher.
Core Classes
HavocService
Manages the WebSocket connection to the Teamserver Service API.Constructor
string
required
WebSocket URL to the Teamserver Service endpoint
string
required
Service password (defined in Teamserver profile)
Methods
method
Register a custom agent type with the Teamserver.Parameters:
agent(AgentType): Agent instance to register
method
Register an External C2 listener.Parameters:
name(str): Display name for the External C2endpoint(str): HTTP endpoint path for agent traffic
AgentType
Base class for defining custom agent types.Class Attributes
string
required
Agent name displayed in the Havoc UI
string
required
Author attribution (e.g., “@username”)
string
required
Version string (e.g., “1.0.0”)
string
required
Brief description of the agent’s purpose
integer
required
Unique identifier for the agent type (hexadecimal)
list
required
List of supported payload formats
list
required
List of supported operating systems:
"Windows", "Linux", "MacOS"dict
required
Configuration options displayed in the payload generation UI
list
required
List of Command instances defining available commands
Methods
method
Generate the agent payload.Example:
Command
Defines a custom command for your agent.Class Attributes
integer
required
Unique identifier for the command (e.g.,
0x100)string
required
Command name as typed in the console
string
required
Brief description shown in help text
string
required
Detailed usage information
boolean
required
Whether command requires administrator/root privileges
list
required
List of MITRE ATT&CK technique IDs (e.g.,
["T1059"])list
required
List of CommandParam instances defining parameters
Methods
method
Generate the binary command payload.Example:
CommandParam
Defines a command parameter.Constructor
string
required
Parameter name (referenced in
arguments dict)boolean
required
If
True, UI shows file picker. If False, shows text input.boolean
required
Whether parameter is optional
Packer
Utility class for building binary command payloads.Methods
method
Add a 32-bit integer (little-endian).Example:
method
Add a null-terminated string.Example:
method
Add raw bytes.Example:
property
Get the packed binary data.Returns:
bytes object with packed dataComplete Examples
Basic Shell Command
shell_command.py
File Upload Command
upload_command.py
Complete Agent Example
Service API Protocol
Authentication
Message Types
- RegisterAgent
- AgentRegister
- AgentTask
- AgentOutput
Best Practices
Command IDs
Command IDs
- Use unique command IDs starting from
0x100 - Reserve
0x00-0xFFfor system commands - Document your ID allocation scheme
- Avoid ID conflicts between commands
Parameter Validation
Parameter Validation
Error Handling
Error Handling
Logging
Logging
Resources
havoc-py Repository
Official Python API source code
Talon Example
Reference implementation using havoc-py
Custom Agents Guide
Step-by-step agent development
External C2 Guide
Using havoc-py for External C2
