ATT&CKReferencesCobaltStrike Daddy May 2017

CobaltStrike Daddy May 2017

Mudge, R. (2017, May 23). Cobalt Strike 3.8 – Who’s Your Daddy?. Retrieved June 4, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareCobalt Strike

Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution.

T1059.005
Visual Basic
MalwareCobalt Strike

Cobalt Strike can use VBA to perform execution.

T1059.006
Python
MalwareCobalt Strike

Cobalt Strike can use Python to perform execution.

T1078.002
Domain Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account.

T1078.003
Local Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a local user account.

T1134.004
Parent PID Spoofing
MalwareCobalt Strike

Cobalt Strike can spawn processes with alternate PPIDs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.