ATT&CKReferencesHavoc Framework Documentation

Havoc Framework Documentation

Ungur, P. (n.d.). HAVOC. Retrieved August 4, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareHavoc

Havoc can download files from the victim's computer.

T1016
System Network Configuration Discovery
MalwareHavoc

Havoc has a module for network enumeration including determining IP addresses.

T1018
Remote System Discovery
MalwareHavoc

Havoc features a module capable of host enumeration.

T1055.001
Dynamic-link Library Injection
MalwareHavoc

Havoc has DLL spawn and injection modules.

T1055.002
Portable Executable Injection
MalwareHavoc

Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems.

T1057
Process Discovery
MalwareHavoc

Havoc can enumerate processes on targeted hosts.

T1059.003
Windows Command Shell
MalwareHavoc

Havoc can execute commands via `cmd.exe`.

T1071.001
Web Protocols
MalwareHavoc

Havoc can use HTTP/S listeners to establish and maintain C2 communications.

T1071.002
File Transfer Protocols
MalwareHavoc

Havoc can use an SMB listener for C2 communication.

T1083
File and Directory Discovery
MalwareHavoc

The Havoc interface can display a file explorer view of the compromised host.

T1090
Proxy
MalwareHavoc

Havoc has the ability to route HTTP/S communications through designated proxies.

T1105
Ingress Tool Transfer
MalwareHavoc

Havoc has the ability to upload files to infected systems.

T1106
Native API
MalwareHavoc

Havoc can use `NtAllocateVirtualMemory` and `NtCreateThreadEx` to aid process injection.

T1113
Screen Capture
MalwareHavoc

Havoc can capture screenshots.

T1134.001
Token Impersonation/Theft
MalwareHavoc

Havoc has a module capable of token impersonation.

T1497.003
Time Based Checks
MalwareHavoc

The Havoc demon agent can be set to sleep for a specified time.

T1559
Inter-Process Communication
MalwareHavoc

The Havoc SMB demon can use named pipes for communication through a parent demon.

T1570
Lateral Tool Transfer
MalwareHavoc

Havoc has the ability to copy files from one location to another.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.