Ungur, P. (n.d.). HAVOC. Retrieved August 4, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareHavoc | Havoc can download files from the victim's computer. |
| T1016 System Network Configuration Discovery |
MalwareHavoc | Havoc has a module for network enumeration including determining IP addresses. |
| T1018 Remote System Discovery |
MalwareHavoc | Havoc features a module capable of host enumeration. |
| T1055.001 Dynamic-link Library Injection |
MalwareHavoc | Havoc has DLL spawn and injection modules. |
| T1055.002 Portable Executable Injection |
MalwareHavoc | Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems. |
| T1057 Process Discovery |
MalwareHavoc | Havoc can enumerate processes on targeted hosts. |
| T1059.003 Windows Command Shell |
MalwareHavoc | Havoc can execute commands via `cmd.exe`. |
| T1071.001 Web Protocols |
MalwareHavoc | Havoc can use HTTP/S listeners to establish and maintain C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareHavoc | Havoc can use an SMB listener for C2 communication. |
| T1083 File and Directory Discovery |
MalwareHavoc | The Havoc interface can display a file explorer view of the compromised host. |
| T1090 Proxy |
MalwareHavoc | Havoc has the ability to route HTTP/S communications through designated proxies. |
| T1105 Ingress Tool Transfer |
MalwareHavoc | Havoc has the ability to upload files to infected systems. |
| T1106 Native API |
MalwareHavoc | Havoc can use `NtAllocateVirtualMemory` and `NtCreateThreadEx` to aid process injection. |
| T1113 Screen Capture |
MalwareHavoc | Havoc can capture screenshots. |
| T1134.001 Token Impersonation/Theft |
MalwareHavoc | Havoc has a module capable of token impersonation. |
| T1497.003 Time Based Checks |
MalwareHavoc | The Havoc demon agent can be set to sleep for a specified time. |
| T1559 Inter-Process Communication |
MalwareHavoc | The Havoc SMB demon can use named pipes for communication through a parent demon. |
| T1570 Lateral Tool Transfer |
MalwareHavoc | Havoc has the ability to copy files from one location to another. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.