Command & Control for
EDR-Monitored Environments
Evasion-first C2 framework with COFF/BOF execution, indirect syscalls, hardware breakpoint bypasses, and polymorphic builds.
Built to Evade
Every component designed from scratch with evasion as an architectural requirement, not a bolted-on afterthought.
COFF/BOF Execution Engine
235+ built-in commands across 18 categories. Load and execute COFF object files in-process with full argument parsing and output capture.
Four Transport Protocols
HTTPS with Schannel TLS, SMB named pipes for internal pivoting, TCP reverse connections, and DNS over UDP for restricted environments.
Seven Delivery Formats
EXE, DLL, raw shellcode, service EXE, XLL add-in, CPL applet, and staged payloads. Each format supports polymorphic builds.
Evasion Suite
Tampered syscalls, Ekko + Foliage sleep encryption, PE fluctuation, hardware breakpoint AMSI/ETW bypass, stack spoofing, module stomping/overloading, phantom DLL hollowing, process ghosting, LoadLibrary Proxy v2.
Process Injection
Thread context hijack, EarlyBird APC, CreateRemoteThread, and threadless injection via export hook. No new thread for threadless — payload fires on natural function call.
Polymorphic Builds
Per-build hash seed, XOR key, AMSI variant, and AES key randomization. 13 PE cover profiles mimicking legitimate applications like OneDrive and Teams.
Traffic Mimicry
Malleable SaaS profiles for Slack, Discord, Teams, Google Drive, and OneDrive. Matching PE cover profiles make network and host artifacts look legitimate.
Linux Agent
Native Linux implant with direct syscall stubs, sleep obfuscation, ptrace process injection, fileless persistence, and polymorphic builds. Same wire protocol as Windows.
Built to Operate
Modern operator experience with CLI, web UI, and AI interfaces. Run solo or coordinate with your team.
Client-Server Architecture
FastAPI backend with headless server mode and remote CLI connection. Run the server on infrastructure, connect from anywhere.
Multi-Operator
JWT-authenticated concurrent operators with agent soft-locking and presence tracking. See who is working on which agent in real time.
Web Dashboard
React + Tailwind dark-themed UI with sessions view, BOF browser, event timeline, and SOCKS manager. Full operational awareness at a glance.
Interactive CLI
prompt_toolkit console with tab completion, command history, styled output, and context-aware help. Feels like a native shell.
AI Operator Interface
MCP server exposing all 28 API endpoints as AI-callable tools. Automate operations with confirmation boundaries for destructive actions.
SOCKS5 Proxy
Tunnel operator tools through agents directly into target networks. Route Nmap, Impacket, or any SOCKS-aware tool through your implants.
MITRE ATT&CK Mapping
235 commands mapped to 74 techniques across the ATT&CK matrix. Export Navigator JSON layers for engagement reporting.
Agent Topology
ASCII and Graphviz DOT graph rendering of parent-child relay chains. Visualize your network of implants and their communication paths.
Redirector Support
Nginx reverse-proxy and DNS config generators for production deployments. One command to build your redirector infrastructure.
See It in Action
Per-Seat Annual Licensing
$1,200 per operator seat per year. Every seat gets the full platform — no feature gates, no agent limits.
Krait Standard
- Pre-compiled agent templates (EXE, DLL, shellcode, service, XLL, CPL)
- Windows + Linux agents
- All 4 transport protocols (HTTPS, SMB, TCP, DNS)
- 235+ built-in BOFs (168 Windows + 67 Linux)
- Full evasion suite (tampered syscalls, Ekko/Foliage, PE fluctuation, process ghosting)
- .NET execute-assembly (fork & run + in-process)
- Threadless injection + 3 other injection methods
- 8 traffic profiles + 13 cover profiles
- Polymorphic builds
- SOCKS5 proxy
- MITRE ATT&CK reporting
- Web dashboard + CLI + MCP AI interface
- Multi-operator support with per-seat licensing
- Unlimited agents
- Template patcher — configure agents without compiling
- All updates for the license year
235+ Built-in Commands
Organized across 18 categories covering the full attack lifecycle, from reconnaissance to post-exploitation.
Reconnaissance
11Host, network, and environment enumeration
Execution
3Command, PowerShell, .NET assembly execution
File Operations
5Upload, download, delete, copy, move
Lateral Movement
4WMI, PsExec, WinRM, SMB
Privilege Escalation
3UAC bypasses, token theft
Persistence
2COM hijack, scheduled tasks
Credential Access
8Nanodump, hashdump, WiFi passwords, DPAPI, credential files
Injection
3CreateRemoteThread, spawn-as, inject test
Process Management
3Dump, destroy, suspend/resume
User Administration
5Add, remove, enable, disable, password set
Service Control
4Create, start, stop, delete
Registry
4Set, delete, save, query
Host Enumeration
15Environment, drivers, DPAPI, installed software
Network
17ARP, netstat, DNS, shares, sessions, domain trust
Active Directory
15LDAP, ADCS, Kerberoast, user/group enum
Privesc Enumeration
6Services, tasks, autoruns, patches, registry checks
Credential Hunting
7Credential manager, autologon, PSH history, credential files
Environment Recon
8Firewall, Defender, Sysmon, pipes, PATH hijack, WSUS
What's Coming in v3.0
macOS Agent
Native macOS implant with platform-specific evasion techniques and persistence mechanisms.
Cloud Redirector Toolkit
One-command cloud deployment with domain fronting support for AWS, Azure, and GCP.
Collaborative Operations
Shared notes, tagging, campaign timelines, and after-action reports for team engagements.
Cloud BOF Library
AWS, Azure, and GCP reconnaissance and post-exploitation commands as BOFs.
Get in Touch
Join the Community
Connect with other operators, share techniques, get support, and stay updated on new releases.
Join Discord