Immersive Content Team. (2024, April 9). Havoc C2 Framework – A Defensive Operator’s Guide. Retrieved August 13, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareHavoc | Havoc can download files from the victim's computer. |
| T1059.001 PowerShell |
MalwareHavoc | Havoc can facilitate the execution of PowerShell commands. |
| T1059.003 Windows Command Shell |
MalwareHavoc | Havoc can execute commands via `cmd.exe`. |
| T1071.001 Web Protocols |
MalwareHavoc | Havoc can use HTTP/S listeners to establish and maintain C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareHavoc | Havoc can use an SMB listener for C2 communication. |
| T1105 Ingress Tool Transfer |
MalwareHavoc | Havoc has the ability to upload files to infected systems. |
| T1113 Screen Capture |
MalwareHavoc | Havoc can capture screenshots. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.