ATT&CKReferencesImmersive Labs Havoc C2 APR 2024

Immersive Labs Havoc C2 APR 2024

Immersive Content Team. (2024, April 9). Havoc C2 Framework – A Defensive Operator’s Guide. Retrieved August 13, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareHavoc

Havoc can download files from the victim's computer.

T1059.001
PowerShell
MalwareHavoc

Havoc can facilitate the execution of PowerShell commands.

T1059.003
Windows Command Shell
MalwareHavoc

Havoc can execute commands via `cmd.exe`.

T1071.001
Web Protocols
MalwareHavoc

Havoc can use HTTP/S listeners to establish and maintain C2 communications.

T1071.002
File Transfer Protocols
MalwareHavoc

Havoc can use an SMB listener for C2 communication.

T1105
Ingress Tool Transfer
MalwareHavoc

Havoc has the ability to upload files to infected systems.

T1113
Screen Capture
MalwareHavoc

Havoc can capture screenshots.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.