Netskope Threat Labs

Havoc

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Havoc is an open source post exploitation framework that gives operators encrypted command and control, module loading, and extensive evasion options on compromised Windows hosts. Red teams use it in authorized testing, and cyberattackers have adopted it as a flexible alternative to older frameworks, so its detections warrant verification against authorized use.

First seen
December 2022
Last seen
September 2026

29 techniques across 7 tactics.

TA0001 Initial Access

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1016System Network Configuration Discovery
  • T1018Remote System Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1087Account Discovery

TA0008 Lateral Movement

  • T1570Lateral Tool Transfer

TA0009 Collection

TA0011 Command and Control

Alert Name
Binary.Backdoor.Havoc
Boot.Virus.Havoc
Document-Word.Trojan.Havoc
Gen:Variant.Backdoor.Havoc.1
Trojan.Dropper.Boot.Havoc.X
Trojan.Ransom.Havoc.B
Trojan.Ransom.Havoc.C
Win32.Ransomware.Havoc
Win64.Backdoor.Havoc
Win64.Trojan.Havoc