Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareCobalt Strike | Cobalt Strike can query |
| T1018 Remote System Discovery |
MalwareCobalt Strike | Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network. |
| T1027 Obfuscated Files or Information |
MalwareCobalt Strike | Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata. |
| T1046 Network Service Discovery |
MalwareCobalt Strike | Cobalt Strike can perform port scans from an infected host. |
| T1049 System Network Connections Discovery |
MalwareCobalt Strike | Cobalt Strike can produce a sessions report from compromised hosts. |
| T1055.001 Dynamic-link Library Injection |
MalwareCobalt Strike | Cobalt Strike has the ability to load DLLs via reflective injection. |
| T1057 Process Discovery |
MalwareCobalt Strike | Cobalt Strike's Beacon payload can collect information on process details. |
| T1059.001 PowerShell |
MalwareCobalt Strike | Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution. |
| T1059.003 Windows Command Shell |
MalwareCobalt Strike | Cobalt Strike uses a command-line interface to interact with systems. |
| T1059.005 Visual Basic |
MalwareCobalt Strike | Cobalt Strike can use VBA to perform execution. |
| T1059.006 Python |
MalwareCobalt Strike | Cobalt Strike can use Python to perform execution. |
| T1059.007 JavaScript |
MalwareCobalt Strike | The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions. |
| T1071.001 Web Protocols |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports. |
| T1071.002 File Transfer Protocols |
MalwareCobalt Strike | Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1071.004 DNS |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports. |
| T1095 Non-Application Layer Protocol |
MalwareCobalt Strike | Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareCobalt Strike | Cobalt Strike can deliver additional payloads to victim machines. |
| T1106 Native API |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of running shell commands without |
| T1112 Modify Registry |
MalwareCobalt Strike | Cobalt Strike can modify Registry values within |
| T1137.001 Office Template Macros |
MalwareCobalt Strike | Cobalt Strike has the ability to use an Excel Workbook to execute additional code by enabling Office to trust macros and execute code without user permission. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCobalt Strike | Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution. |
| T1197 BITS Jobs |
MalwareCobalt Strike | Cobalt Strike can download a hosted "beacon" payload using BITSAdmin. |
| T1203 Exploitation for Client Execution |
MalwareCobalt Strike | Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460. |
| T1553.002 Code Signing |
MalwareCobalt Strike | Cobalt Strike can use self signed Java applets to execute signed applet attacks. |
| T1573.001 Symmetric Cryptography |
MalwareCobalt Strike | Cobalt Strike has the ability to use AES-256 symmetric encryption in CBC mode with HMAC-SHA-256 to encrypt task commands and XOR to encrypt shell code and configuration data. |
| T1573.002 Asymmetric Cryptography |
MalwareCobalt Strike | Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server. |
| T1685 Disable or Modify Tools |
MalwareCobalt Strike | Cobalt Strike has the ability to use Smart Applet attacks to disable the Java SecurityManager sandbox. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.