ATT&CKReferencesTalos Cobalt Strike September 2020

Talos Cobalt Strike September 2020

Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareCobalt Strike

Cobalt Strike can query HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to determine if the security setting for restricting default programmatic access is enabled.

T1018
Remote System Discovery
MalwareCobalt Strike

Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network.

T1027
Obfuscated Files or Information
MalwareCobalt Strike

Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata.

T1046
Network Service Discovery
MalwareCobalt Strike

Cobalt Strike can perform port scans from an infected host.

T1049
System Network Connections Discovery
MalwareCobalt Strike

Cobalt Strike can produce a sessions report from compromised hosts.

T1055.001
Dynamic-link Library Injection
MalwareCobalt Strike

Cobalt Strike has the ability to load DLLs via reflective injection.

T1057
Process Discovery
MalwareCobalt Strike

Cobalt Strike's Beacon payload can collect information on process details.

T1059.001
PowerShell
MalwareCobalt Strike

Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution.

T1059.003
Windows Command Shell
MalwareCobalt Strike

Cobalt Strike uses a command-line interface to interact with systems.

T1059.005
Visual Basic
MalwareCobalt Strike

Cobalt Strike can use VBA to perform execution.

T1059.006
Python
MalwareCobalt Strike

Cobalt Strike can use Python to perform execution.

T1059.007
JavaScript
MalwareCobalt Strike

The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions.

T1071.001
Web Protocols
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports.

T1071.002
File Transfer Protocols
MalwareCobalt Strike

Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

T1071.004
DNS
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.

T1095
Non-Application Layer Protocol
MalwareCobalt Strike

Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications.

T1105
Ingress Tool Transfer
MalwareCobalt Strike

Cobalt Strike can deliver additional payloads to victim machines.

T1106
Native API
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe Cobalt Strike can also use `CreateThreadpoolWait`, `SetThreadpoolWait`, and `MessageBoxA` for sandbox evasion and execution of embedded payloads in memory.

T1112
Modify Registry
MalwareCobalt Strike

Cobalt Strike can modify Registry values within HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to enable the execution of additional code.

T1137.001
Office Template Macros
MalwareCobalt Strike

Cobalt Strike has the ability to use an Excel Workbook to execute additional code by enabling Office to trust macros and execute code without user permission.

T1140
Deobfuscate/Decode Files or Information
MalwareCobalt Strike

Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution.

T1197
BITS Jobs
MalwareCobalt Strike

Cobalt Strike can download a hosted "beacon" payload using BITSAdmin.

T1203
Exploitation for Client Execution
MalwareCobalt Strike

Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460.

T1553.002
Code Signing
MalwareCobalt Strike

Cobalt Strike can use self signed Java applets to execute signed applet attacks.

T1573.001
Symmetric Cryptography
MalwareCobalt Strike

Cobalt Strike has the ability to use AES-256 symmetric encryption in CBC mode with HMAC-SHA-256 to encrypt task commands and XOR to encrypt shell code and configuration data.

T1573.002
Asymmetric Cryptography
MalwareCobalt Strike

Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server.

T1685
Disable or Modify Tools
MalwareCobalt Strike

Cobalt Strike has the ability to use Smart Applet attacks to disable the Java SecurityManager sandbox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.