Command & Control for
EDR-Monitored Environments

Evasion-first C2 framework with COFF/BOF execution, indirect syscalls, hardware breakpoint bypasses, and polymorphic builds.

krait - operator@redteam
Implant

Built to Evade

Every component designed from scratch with evasion as an architectural requirement, not a bolted-on afterthought.

COFF/BOF Execution Engine

431+ built-in commands across 23 categories including cloud and Kubernetes. Load and execute COFF object files in-process with full argument parsing and output capture.

Five Transport Protocols

HTTPS with Schannel TLS, SMB named pipes, TCP reverse connections, DNS over UDP, and DNS-over-HTTPS (DOH) for environments where raw DNS is monitored but HTTPS egress is allowed.

Seven Delivery Formats

EXE, DLL, raw shellcode, service EXE, XLL add-in, CPL applet, and staged payloads. Each format supports polymorphic builds.

Evasion Suite

Tampered syscalls, Ekko + Foliage sleep encryption, PE fluctuation, hardware breakpoint AMSI/ETW bypass, stack spoofing, module stomping/overloading, phantom DLL hollowing, process ghosting, LoadLibrary Proxy v2.

Process Injection

Windows: thread context hijack, EarlyBird APC, CreateRemoteThread, threadless injection via export hook. Linux: ptrace + memfd_create. macOS: DYLD_INSERT_LIBRARIES spawn (works with SIP) and task_for_pid inject.

Polymorphic Builds

Per-build hash seed, XOR key, AMSI variant, and AES key randomization. 13 PE cover profiles mimicking legitimate applications like OneDrive and Teams.

Traffic Mimicry

Malleable SaaS profiles for Slack, Discord, Teams, Google Drive, and OneDrive. Matching PE cover profiles make network and host artifacts look legitimate.

Linux Agent

Native Linux implant with direct syscall stubs, sleep obfuscation, ptrace process injection, fileless persistence, and polymorphic builds. Same wire protocol as Windows.

macOS Agent

Universal (arm64 + x86_64) macOS implant with SecureTransport TLS, IOKit power management, cron and shell profile persistence, DYLD_INSERT_LIBRARIES process spawning, and SOCKS5 proxy. 91 built-in BOFs.

Operator

Built to Operate

Modern operator experience with CLI, web UI, and AI interfaces. Run solo or coordinate with your team.

Client-Server Architecture

FastAPI backend with headless server mode and remote CLI connection. Run the server on infrastructure, connect from anywhere.

Multi-Operator

JWT-authenticated concurrent operators with agent soft-locking and presence tracking. See who is working on which agent in real time.

Web Dashboard

React + Tailwind dark-themed UI with sessions view, BOF browser, event timeline, and SOCKS manager. Full operational awareness at a glance.

Interactive CLI

prompt_toolkit console with tab completion, command history, styled output, and context-aware help. Feels like a native shell.

AI Operator Interface

MCP server exposing all 28 API endpoints as AI-callable tools. Automate operations with confirmation boundaries for destructive actions.

SOCKS5 Proxy

Tunnel operator tools through agents directly into target networks. Route Nmap, Impacket, or any SOCKS-aware tool through your implants.

MITRE ATT&CK Mapping

431 commands mapped to 74 techniques across the ATT&CK matrix. Export Navigator JSON layers for engagement reporting.

Agent Topology

ASCII and Graphviz DOT graph rendering of parent-child relay chains. Visualize your network of implants and their communication paths.

Redirector Support

Nginx reverse-proxy, DNS, CloudFront CDN, Azure Front Door, and GCP Cloud CDN redirector configs for production deployments. One command to build your redirector infrastructure.

Interface

See It in Action

Web Dashboard
3
Active
1
Dead
2
Operators
agent-01 WS-PC0142 HTTPS
agent-02 DC-PROD01 SMB
agent-03 FS-BACKUP TCP
CLI Interface
krait> help lateral wmi-exec Execute command via WMI psexec PsExec-style lateral move winrm-exec Execute via WinRM smb-exec Execute via SMB service krait> wmi-exec DC-PROD01 whoami [+] CORP\admin
Network Topology
Krait Server WS-PC0142 DC-PROD01 FS-BACKUP SQL-INT01 SMB HTTPS HTTPS DOH
BOF Browser
Search 431 commands...
Active Directory 15 commands
Network 17 commands
Credential Access 8 commands
Host Enumeration 15 commands
Pricing

Per-Seat Annual Licensing

$1,200 per operator seat per year. Every seat gets the full platform — no feature gates, no agent limits.

Krait Standard

$1,200 /seat/year
  • Pre-compiled agent templates (EXE, DLL, shellcode, service, XLL, CPL)
  • Windows + Linux + macOS agents
  • All 5 transport protocols (HTTPS, SMB, TCP, DNS, DOH)
  • 431+ built-in BOFs (217 Windows + 115 Linux + 99 macOS)
  • Full evasion suite (tampered syscalls, Ekko/Foliage, PE fluctuation, process ghosting)
  • .NET execute-assembly (fork & run + in-process)
  • Threadless injection + 3 other injection methods
  • 8 traffic profiles + 13 cover profiles
  • Polymorphic builds
  • SOCKS5 proxy
  • MITRE ATT&CK reporting
  • Web dashboard + CLI + MCP AI interface
  • Multi-operator support with per-seat licensing
  • Unlimited agents
  • Template patcher — configure agents without compiling
  • All updates for the license year
Request Access
Arsenal

431+ Built-in Commands

Organized across 23 categories covering the full attack lifecycle, from reconnaissance to cloud post-exploitation.

Reconnaissance

11

Host, network, and environment enumeration

Execution

3

Command, PowerShell, .NET assembly execution

File Operations

5

Upload, resumable download, delete, copy, move

Lateral Movement

4

WMI, PsExec, WinRM, SMB

Privilege Escalation

3

UAC bypasses, token theft

Persistence

2

COM hijack, scheduled tasks

Credential Access

8

Nanodump, hashdump, WiFi passwords, DPAPI, credential files

Injection

2

CreateRemoteThread, spawn-as

Process Management

3

Dump, destroy, suspend/resume

User Administration

5

Add, remove, enable, disable, password set

Service Control

4

Create, start, stop, delete

Registry

4

Set, delete, save, query

Host Enumeration

15

Environment, drivers, DPAPI, installed software

Network

17

ARP, netstat, DNS, shares, sessions, domain trust

Active Directory

15

LDAP, ADCS, Kerberoast, user/group enum

Privesc Enumeration

6

Services, tasks, autoruns, patches, registry checks

Credential Hunting

7

Credential manager, autologon, PSH history, credential files

Environment Recon

8

Firewall, Defender, Sysmon, pipes, PATH hijack, WSUS

Cloud — AWS

15

Credential discovery, resource access, lateral movement

Cloud — Azure

8

Resource enumeration, Key Vault, storage, VM run commands

Cloud — Entra ID

14

Identity enumeration, app secrets, role assignments, PIM

Cloud — GCP

8

Credential discovery, resource enumeration, secret access

Kubernetes

3

Pod/service enum, secret dumping, RBAC analysis

Roadmap

What's Coming in v4.0

1

Initial Access Toolkit

HTML smuggling with polymorphic JS, LNK/ISO/CHM payload generators, and MSI installer packaging. Wraps any Krait payload format for phishing delivery.

2

Phishing Infrastructure

Campaign manager with email templates and tracking, landing page cloner with credential capture, WebDAV delivery with NTLM capture.

3

macOS-Native BOFs

macOS-specific BOFs for keychain access, TCC bypass, and Gatekeeper enumeration. 91 shared BOFs already shipped with macOS agent.

Community

Get in Touch

Join the Community

Connect with other operators, share techniques, get support, and stay updated on new releases.

Join Discord

Email

info@krait.red