ATT&CKReferencesCobalt Strike Manual 4.3 November 2020

Cobalt Strike Manual 4.3 November 2020

Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples56

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareCobalt Strike

Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.

T1003.001
LSASS Memory
MalwareCobalt Strike

Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes.

T1003.006
DCSync
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync.

T1005
Data from Local System
MalwareCobalt Strike

Cobalt Strike can collect data from a local system.

T1007
System Service Discovery
MalwareCobalt Strike

Cobalt Strike can enumerate services on compromised hosts.

T1012
Query Registry
MalwareCobalt Strike

Cobalt Strike can query HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to determine if the security setting for restricting default programmatic access is enabled.

T1016
System Network Configuration Discovery
MalwareCobalt Strike

Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers.

T1018
Remote System Discovery
MalwareCobalt Strike

Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network.

T1021.004
SSH
MalwareCobalt Strike

Cobalt Strike can SSH to a remote service.

T1021.006
Windows Remote Management
MalwareCobalt Strike

Cobalt Strike can use WinRM to execute a payload on a remote host.

T1027
Obfuscated Files or Information
MalwareCobalt Strike

Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata.

T1027.005
Indicator Removal from Tools
MalwareCobalt Strike

Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.

T1046
Network Service Discovery
MalwareCobalt Strike

Cobalt Strike can perform port scans from an infected host.

T1047
Windows Management Instrumentation
MalwareCobalt Strike

Cobalt Strike can use WMI to deliver a payload to a remote host.

T1055
Process Injection
MalwareCobalt Strike

Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary.

T1055.001
Dynamic-link Library Injection
MalwareCobalt Strike

Cobalt Strike has the ability to load DLLs via reflective injection.

T1055.012
Process Hollowing
MalwareCobalt Strike

Cobalt Strike can use process hollowing for execution.

T1056.001
Keylogging
MalwareCobalt Strike

Cobalt Strike can track key presses with a keylogger module.

T1057
Process Discovery
MalwareCobalt Strike

Cobalt Strike's Beacon payload can collect information on process details.

T1059.001
PowerShell
MalwareCobalt Strike

Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution.

T1059.003
Windows Command Shell
MalwareCobalt Strike

Cobalt Strike uses a command-line interface to interact with systems.

T1059.006
Python
MalwareCobalt Strike

Cobalt Strike can use Python to perform execution.

T1068
Exploitation for Privilege Escalation
MalwareCobalt Strike

Cobalt Strike can exploit vulnerabilities such as MS14-058.

T1069.001
Local Groups
MalwareCobalt Strike

Cobalt Strike can use net localgroup to list local groups on a system.

T1069.002
Domain Groups
MalwareCobalt Strike

Cobalt Strike can identify targets by querying account groups on a domain contoller.

T1070.006
Timestomp
MalwareCobalt Strike

Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in.

T1071.001
Web Protocols
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports.

T1071.004
DNS
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.

T1078.002
Domain Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account.

T1083
File and Directory Discovery
MalwareCobalt Strike

Cobalt Strike can explore files on a compromised system.

T1090.001
Internal Proxy
MalwareCobalt Strike

Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access.

T1090.004
Domain Fronting
MalwareCobalt Strike

Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting.

T1095
Non-Application Layer Protocol
MalwareCobalt Strike

Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications.

T1105
Ingress Tool Transfer
MalwareCobalt Strike

Cobalt Strike can deliver additional payloads to victim machines.

T1106
Native API
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe Cobalt Strike can also use `CreateThreadpoolWait`, `SetThreadpoolWait`, and `MessageBoxA` for sandbox evasion and execution of embedded payloads in memory.

T1113
Screen Capture
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of capturing screenshots.

T1132.001
Standard Encoding
MalwareCobalt Strike

Cobalt Strike can use Base64, URL-safe Base64, or NetBIOS encoding in its C2 traffic.

T1134.001
Token Impersonation/Theft
MalwareCobalt Strike

Cobalt Strike can steal access tokens from exiting processes.

T1134.004
Parent PID Spoofing
MalwareCobalt Strike

Cobalt Strike can spawn processes with alternate PPIDs.

T1140
Deobfuscate/Decode Files or Information
MalwareCobalt Strike

Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution.

T1185
Browser Session Hijacking
MalwareCobalt Strike

Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates.

T1197
BITS Jobs
MalwareCobalt Strike

Cobalt Strike can download a hosted "beacon" payload using BITSAdmin.

T1203
Exploitation for Client Execution
MalwareCobalt Strike

Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460.

T1218.011
Rundll32
MalwareCobalt Strike

Cobalt Strike can use `rundll32.exe` to load DLL from the command line.

T1518
Software Discovery
MalwareCobalt Strike

The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has.

T1548.002
Bypass User Account Control
MalwareCobalt Strike

Cobalt Strike can use a number of known techniques to bypass Windows UAC.

T1548.003
Sudo and Sudo Caching
MalwareCobalt Strike

Cobalt Strike can use sudo to run a command.

T1550.002
Pass the Hash
ToolMimikatz

Mimikatz's SEKURLSA::Pth module can impersonate a user, with only a password hash, to execute arbitrary commands.

T1553.002
Code Signing
MalwareCobalt Strike

Cobalt Strike can use self signed Java applets to execute signed applet attacks.

T1555
Credentials from Password Stores
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.