Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF execution, and HTTP/DNS transports.
Lockjaw is an advanced, modular command-and-control (C2) framework engineered for red team engagements, adversarial simulations, and stealth operations. It utilizes a modern split-language architecture: a high-concurrency Rust Teamserver coupled with an evasive, dependency-free Zig implant and pure-assembly position-independent code (PIC) stagers.
THIS IS ALPHA SOFTWARE Use at your own risk. Not all features have been tested, the code has not been reviewed. There are bugs and certain commands may not work.
The following have been tested:
BOF support has not been tested.
+------------------------------------+
| Operator CLI (Python) |
| Async TUI / Prompt-Toolkit |
+-----------------+------------------+
| HTTPS / REST API (Port 50051)
v
+------------------------------------+
| Lockjaw Teamserver |
| (Rust / Tokio) |
| - SQLite Storage (SQLx) |
| - Dynamic Zig Cross-Compiler |
| - Multi-Transport Listener Manager|
+--------+------------------+--------+
| |
HTTPS / HTTP DNS (UDP 53)
(WinHTTP) (Hickory DNS / Base32)
| |
v v
+------------------------------------+
| Lockjaw Implant (Zig) |
| - Indirect Syscalls (Halo's Gate) |
| - Reflective & PoolParty Injection|
| - In-Memory BOF Execution Engine |
| - Ghost AMSI Bypass (HWBP + VEH) |
| - IAT-Clean Dynamic API Resolv. |
| - RC4-Encrypted Communications |
+------------------------------------+
x86_64-windows. Standalone, zero external C-runtime dependencies, running in the .Windows subsystem (headless, no console window).pic_stager.s) with safe-stack architecture, shadow space preservation, and dynamic PEB traversal, alongside lightweight PowerShell download cradles.prompt_toolkit featuring real-time checkin alerts, numeric indexing, prefix matching, context management, and automatic file upload/download synchronization.ntdll.dll using DJB2 hashing.syscall; ret gadgets residing within the .text section of ntdll.dll, evading user-mode API hooks, call stack inspection, and return-address origin checks.AddVectoredExceptionHandler).0xDEADBEEF) to configure debug registers on AmsiScanBuffer.EXCEPTION_SINGLE_STEP, zeroes RAX (AMSI_RESULT_CLEAN = 0), and cleanly returns execution to caller..text memory bytes and avoids SetThreadContext detection vectors.InLoadOrderModuleList) and resolves function addresses dynamically via compile-time case-sensitive (djb2) and case-insensitive (djb2_i) hashing..Windows subsystem GUI application.ShowWindow(hWnd, SW_HIDE).SECURITY_IGNORE_ALL_CERT_ERRORS) enabling operational use with self-signed TLS certificates and domain fronting.ping 127.0.0.1 -n 3 > nul & del /f /q ...) to securely wipe the binary from disk.migrate <pid> reflective):
NtCreateSection + NtMapViewOfSection mapped RW locally and RWX remotely).NtAllocateVirtualMemory / NtWriteVirtualMemory).NtCreateThreadEx indirect syscalls.migrate <pid> reflective_poolstomp):
NtQuerySystemInformation to discover existing thread pool worker factories (TpWorkerFactory).WorkerFactoryBasicInformation, overwrites the factory's StartRoutine with an execution trampoline, and triggers agent execution by incrementing WorkerFactoryThreadMinimum via NtSetInformationWorkerFactory.CreateRemoteThread / NtCreateThreadEx (e.g., Sysmon Event ID 8, ETW threat intelligence providers).AMD64 object files.IMAGE_REL_AMD64_ADDR64, IMAGE_REL_AMD64_ADDR32, IMAGE_REL_AMD64_ADDR32NB, IMAGE_REL_AMD64_REL32).__imp__<DLL>$<Function> convention.BeaconDataParse, BeaconDataInt, BeaconDataShort, BeaconDataLength, BeaconDataExtract.BeaconFormatAlloc, BeaconFormatReset, BeaconFormatFree, BeaconFormatAppend, BeaconFormatPrintf, BeaconFormatToString, BeaconFormatInt.BeaconOutput, BeaconPrintf, BeaconIsAdmin.