Command & Control for
EDR-Monitored Environments

Evasion-first C2 framework with COFF/BOF execution, indirect syscalls, hardware breakpoint bypasses, and polymorphic builds.

krait - operator@redteam
Implant

Built to Evade

Every component designed from scratch with evasion as an architectural requirement, not a bolted-on afterthought.

COFF/BOF Execution Engine

235+ built-in commands across 18 categories. Load and execute COFF object files in-process with full argument parsing and output capture.

Four Transport Protocols

HTTPS with Schannel TLS, SMB named pipes for internal pivoting, TCP reverse connections, and DNS over UDP for restricted environments.

Seven Delivery Formats

EXE, DLL, raw shellcode, service EXE, XLL add-in, CPL applet, and staged payloads. Each format supports polymorphic builds.

Evasion Suite

Tampered syscalls, Ekko + Foliage sleep encryption, PE fluctuation, hardware breakpoint AMSI/ETW bypass, stack spoofing, module stomping/overloading, phantom DLL hollowing, process ghosting, LoadLibrary Proxy v2.

Process Injection

Thread context hijack, EarlyBird APC, CreateRemoteThread, and threadless injection via export hook. No new thread for threadless — payload fires on natural function call.

Polymorphic Builds

Per-build hash seed, XOR key, AMSI variant, and AES key randomization. 13 PE cover profiles mimicking legitimate applications like OneDrive and Teams.

Traffic Mimicry

Malleable SaaS profiles for Slack, Discord, Teams, Google Drive, and OneDrive. Matching PE cover profiles make network and host artifacts look legitimate.

Linux Agent

Native Linux implant with direct syscall stubs, sleep obfuscation, ptrace process injection, fileless persistence, and polymorphic builds. Same wire protocol as Windows.

Operator

Built to Operate

Modern operator experience with CLI, web UI, and AI interfaces. Run solo or coordinate with your team.

Client-Server Architecture

FastAPI backend with headless server mode and remote CLI connection. Run the server on infrastructure, connect from anywhere.

Multi-Operator

JWT-authenticated concurrent operators with agent soft-locking and presence tracking. See who is working on which agent in real time.

Web Dashboard

React + Tailwind dark-themed UI with sessions view, BOF browser, event timeline, and SOCKS manager. Full operational awareness at a glance.

Interactive CLI

prompt_toolkit console with tab completion, command history, styled output, and context-aware help. Feels like a native shell.

AI Operator Interface

MCP server exposing all 28 API endpoints as AI-callable tools. Automate operations with confirmation boundaries for destructive actions.

SOCKS5 Proxy

Tunnel operator tools through agents directly into target networks. Route Nmap, Impacket, or any SOCKS-aware tool through your implants.

MITRE ATT&CK Mapping

235 commands mapped to 74 techniques across the ATT&CK matrix. Export Navigator JSON layers for engagement reporting.

Agent Topology

ASCII and Graphviz DOT graph rendering of parent-child relay chains. Visualize your network of implants and their communication paths.

Redirector Support

Nginx reverse-proxy and DNS config generators for production deployments. One command to build your redirector infrastructure.

Interface

See It in Action

Web Dashboard
3
Active
1
Dead
2
Operators
agent-01 WS-PC0142 HTTPS
agent-02 DC-PROD01 SMB
agent-03 FS-BACKUP TCP
CLI Interface
krait> help lateral wmi-exec Execute command via WMI psexec PsExec-style lateral move winrm-exec Execute via WinRM smb-exec Execute via SMB service krait> wmi-exec DC-PROD01 whoami [+] CORP\admin
Network Topology
Krait Server WS-PC0142 DC-PROD01 FS-BACKUP SQL-INT01 SMB HTTPS HTTPS DNS
BOF Browser
Search 235 commands...
Active Directory 15 commands
Network 17 commands
Credential Access 8 commands
Host Enumeration 15 commands
Pricing

Per-Seat Annual Licensing

$1,200 per operator seat per year. Every seat gets the full platform — no feature gates, no agent limits.

Krait Standard

$1,200 /seat/year
  • Pre-compiled agent templates (EXE, DLL, shellcode, service, XLL, CPL)
  • Windows + Linux agents
  • All 4 transport protocols (HTTPS, SMB, TCP, DNS)
  • 235+ built-in BOFs (168 Windows + 67 Linux)
  • Full evasion suite (tampered syscalls, Ekko/Foliage, PE fluctuation, process ghosting)
  • .NET execute-assembly (fork & run + in-process)
  • Threadless injection + 3 other injection methods
  • 8 traffic profiles + 13 cover profiles
  • Polymorphic builds
  • SOCKS5 proxy
  • MITRE ATT&CK reporting
  • Web dashboard + CLI + MCP AI interface
  • Multi-operator support with per-seat licensing
  • Unlimited agents
  • Template patcher — configure agents without compiling
  • All updates for the license year
Request Access
Arsenal

235+ Built-in Commands

Organized across 18 categories covering the full attack lifecycle, from reconnaissance to post-exploitation.

Reconnaissance

11

Host, network, and environment enumeration

Execution

3

Command, PowerShell, .NET assembly execution

File Operations

5

Upload, download, delete, copy, move

Lateral Movement

4

WMI, PsExec, WinRM, SMB

Privilege Escalation

3

UAC bypasses, token theft

Persistence

2

COM hijack, scheduled tasks

Credential Access

8

Nanodump, hashdump, WiFi passwords, DPAPI, credential files

Injection

3

CreateRemoteThread, spawn-as, inject test

Process Management

3

Dump, destroy, suspend/resume

User Administration

5

Add, remove, enable, disable, password set

Service Control

4

Create, start, stop, delete

Registry

4

Set, delete, save, query

Host Enumeration

15

Environment, drivers, DPAPI, installed software

Network

17

ARP, netstat, DNS, shares, sessions, domain trust

Active Directory

15

LDAP, ADCS, Kerberoast, user/group enum

Privesc Enumeration

6

Services, tasks, autoruns, patches, registry checks

Credential Hunting

7

Credential manager, autologon, PSH history, credential files

Environment Recon

8

Firewall, Defender, Sysmon, pipes, PATH hijack, WSUS

Roadmap

What's Coming in v3.0

1

macOS Agent

Native macOS implant with platform-specific evasion techniques and persistence mechanisms.

2

Cloud Redirector Toolkit

One-command cloud deployment with domain fronting support for AWS, Azure, and GCP.

3

Collaborative Operations

Shared notes, tagging, campaign timelines, and after-action reports for team engagements.

4

Cloud BOF Library

AWS, Azure, and GCP reconnaissance and post-exploitation commands as BOFs.

Community

Get in Touch

Join the Community

Connect with other operators, share techniques, get support, and stay updated on new releases.

Join Discord

Email

info@krait.red