Contents

HavocC2 Donut Plugin


Havoc C2 plugin for Donut

I just made a Havoc C2 plugin to help spawn donut-generated shellcode into a new process. Will add some more features as time permits - really wanted this to help out with a ‘bypassing EDR’ talk I’m planning for next month. There’s a python plugin for the main and dev branches in the Havoc-Donut plugin repository.

Make sure to use a Havoc C2 dev branch that contains this pull request. Can also use the branch here.

Installing and using the Havoc-Donut plugin

Make sure to install and compile Donut on the host you are running your Havoc C2 client. Also ensure the donut python module is installed. Full directions for this is in the Donut repository. Also check out more details on Donut here. Then just load the appropriate plugin in the C2 client. havoc-donut-main.py is for the main branch and havoc-donut.py is for the dev branch of Havoc.

Comments

You can use your Fediverse (i.e. Mastodon, among many others) account to reply to this post.