Command & Control for
EDR-Monitored Environments
Evasion-first C2 framework with COFF/BOF execution, indirect syscalls, hardware breakpoint bypasses, and polymorphic builds.
Built to Evade
Every component designed from scratch with evasion as an architectural requirement, not a bolted-on afterthought.
COFF/BOF Execution Engine
431+ built-in commands across 23 categories including cloud and Kubernetes. Load and execute COFF object files in-process with full argument parsing and output capture.
Five Transport Protocols
HTTPS with Schannel TLS, SMB named pipes, TCP reverse connections, DNS over UDP, and DNS-over-HTTPS (DOH) for environments where raw DNS is monitored but HTTPS egress is allowed.
Seven Delivery Formats
EXE, DLL, raw shellcode, service EXE, XLL add-in, CPL applet, and staged payloads. Each format supports polymorphic builds.
Evasion Suite
Tampered syscalls, Ekko + Foliage sleep encryption, PE fluctuation, hardware breakpoint AMSI/ETW bypass, stack spoofing, module stomping/overloading, phantom DLL hollowing, process ghosting, LoadLibrary Proxy v2.
Process Injection
Windows: thread context hijack, EarlyBird APC, CreateRemoteThread, threadless injection via export hook. Linux: ptrace + memfd_create. macOS: DYLD_INSERT_LIBRARIES spawn (works with SIP) and task_for_pid inject.
Polymorphic Builds
Per-build hash seed, XOR key, AMSI variant, and AES key randomization. 13 PE cover profiles mimicking legitimate applications like OneDrive and Teams.
Traffic Mimicry
Malleable SaaS profiles for Slack, Discord, Teams, Google Drive, and OneDrive. Matching PE cover profiles make network and host artifacts look legitimate.
Linux Agent
Native Linux implant with direct syscall stubs, sleep obfuscation, ptrace process injection, fileless persistence, and polymorphic builds. Same wire protocol as Windows.
macOS Agent
Universal (arm64 + x86_64) macOS implant with SecureTransport TLS, IOKit power management, cron and shell profile persistence, DYLD_INSERT_LIBRARIES process spawning, and SOCKS5 proxy. 91 built-in BOFs.
Built to Operate
Modern operator experience with CLI, web UI, and AI interfaces. Run solo or coordinate with your team.
Client-Server Architecture
FastAPI backend with headless server mode and remote CLI connection. Run the server on infrastructure, connect from anywhere.
Multi-Operator
JWT-authenticated concurrent operators with agent soft-locking and presence tracking. See who is working on which agent in real time.
Web Dashboard
React + Tailwind dark-themed UI with sessions view, BOF browser, event timeline, and SOCKS manager. Full operational awareness at a glance.
Interactive CLI
prompt_toolkit console with tab completion, command history, styled output, and context-aware help. Feels like a native shell.
AI Operator Interface
MCP server exposing all 28 API endpoints as AI-callable tools. Automate operations with confirmation boundaries for destructive actions.
SOCKS5 Proxy
Tunnel operator tools through agents directly into target networks. Route Nmap, Impacket, or any SOCKS-aware tool through your implants.
MITRE ATT&CK Mapping
431 commands mapped to 74 techniques across the ATT&CK matrix. Export Navigator JSON layers for engagement reporting.
Agent Topology
ASCII and Graphviz DOT graph rendering of parent-child relay chains. Visualize your network of implants and their communication paths.
Redirector Support
Nginx reverse-proxy, DNS, CloudFront CDN, Azure Front Door, and GCP Cloud CDN redirector configs for production deployments. One command to build your redirector infrastructure.
See It in Action
Per-Seat Annual Licensing
$1,200 per operator seat per year. Every seat gets the full platform — no feature gates, no agent limits.
Krait Standard
- Pre-compiled agent templates (EXE, DLL, shellcode, service, XLL, CPL)
- Windows + Linux + macOS agents
- All 5 transport protocols (HTTPS, SMB, TCP, DNS, DOH)
- 431+ built-in BOFs (217 Windows + 115 Linux + 99 macOS)
- Full evasion suite (tampered syscalls, Ekko/Foliage, PE fluctuation, process ghosting)
- .NET execute-assembly (fork & run + in-process)
- Threadless injection + 3 other injection methods
- 8 traffic profiles + 13 cover profiles
- Polymorphic builds
- SOCKS5 proxy
- MITRE ATT&CK reporting
- Web dashboard + CLI + MCP AI interface
- Multi-operator support with per-seat licensing
- Unlimited agents
- Template patcher — configure agents without compiling
- All updates for the license year
431+ Built-in Commands
Organized across 23 categories covering the full attack lifecycle, from reconnaissance to cloud post-exploitation.
Reconnaissance
11Host, network, and environment enumeration
Execution
3Command, PowerShell, .NET assembly execution
File Operations
5Upload, resumable download, delete, copy, move
Lateral Movement
4WMI, PsExec, WinRM, SMB
Privilege Escalation
3UAC bypasses, token theft
Persistence
2COM hijack, scheduled tasks
Credential Access
8Nanodump, hashdump, WiFi passwords, DPAPI, credential files
Injection
2CreateRemoteThread, spawn-as
Process Management
3Dump, destroy, suspend/resume
User Administration
5Add, remove, enable, disable, password set
Service Control
4Create, start, stop, delete
Registry
4Set, delete, save, query
Host Enumeration
15Environment, drivers, DPAPI, installed software
Network
17ARP, netstat, DNS, shares, sessions, domain trust
Active Directory
15LDAP, ADCS, Kerberoast, user/group enum
Privesc Enumeration
6Services, tasks, autoruns, patches, registry checks
Credential Hunting
7Credential manager, autologon, PSH history, credential files
Environment Recon
8Firewall, Defender, Sysmon, pipes, PATH hijack, WSUS
Cloud — AWS
15Credential discovery, resource access, lateral movement
Cloud — Azure
8Resource enumeration, Key Vault, storage, VM run commands
Cloud — Entra ID
14Identity enumeration, app secrets, role assignments, PIM
Cloud — GCP
8Credential discovery, resource enumeration, secret access
Kubernetes
3Pod/service enum, secret dumping, RBAC analysis
What's Coming in v4.0
Initial Access Toolkit
HTML smuggling with polymorphic JS, LNK/ISO/CHM payload generators, and MSI installer packaging. Wraps any Krait payload format for phishing delivery.
Phishing Infrastructure
Campaign manager with email templates and tracking, landing page cloner with credential capture, WebDAV delivery with NTLM capture.
macOS-Native BOFs
macOS-specific BOFs for keychain access, TCC bypass, and Gatekeeper enumeration. 91 shared BOFs already shipped with macOS agent.
Get in Touch
Join the Community
Connect with other operators, share techniques, get support, and stay updated on new releases.
Join Discord