ATT&CKReferencescobaltstrike manual

cobaltstrike manual

Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
MalwareCobalt Strike

Cobalt Strike can recover hashed passwords.

T1018
Remote System Discovery
MalwareCobalt Strike

Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network.

T1021.001
Remote Desktop Protocol
MalwareCobalt Strike

Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel.

T1021.006
Windows Remote Management
MalwareCobalt Strike

Cobalt Strike can use WinRM to execute a payload on a remote host.

T1027.005
Indicator Removal from Tools
MalwareCobalt Strike

Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.

T1029
Scheduled Transfer
MalwareCobalt Strike

Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval.

T1030
Data Transfer Size Limits
MalwareCobalt Strike

Cobalt Strike will break large data sets into smaller chunks for exfiltration.

T1046
Network Service Discovery
MalwareCobalt Strike

Cobalt Strike can perform port scans from an infected host.

T1047
Windows Management Instrumentation
MalwareCobalt Strike

Cobalt Strike can use WMI to deliver a payload to a remote host.

T1055
Process Injection
MalwareCobalt Strike

Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary.

T1056.001
Keylogging
MalwareCobalt Strike

Cobalt Strike can track key presses with a keylogger module.

T1057
Process Discovery
MalwareCobalt Strike

Cobalt Strike's Beacon payload can collect information on process details.

T1059.001
PowerShell
MalwareCobalt Strike

Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution.

T1070.006
Timestomp
MalwareCobalt Strike

Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in.

T1071.001
Web Protocols
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports.

T1071.002
File Transfer Protocols
MalwareCobalt Strike

Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

T1071.004
DNS
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.

T1078.002
Domain Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account.

T1078.003
Local Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a local user account.

T1090.001
Internal Proxy
MalwareCobalt Strike

Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access.

T1106
Native API
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe Cobalt Strike can also use `CreateThreadpoolWait`, `SetThreadpoolWait`, and `MessageBoxA` for sandbox evasion and execution of embedded payloads in memory.

T1113
Screen Capture
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of capturing screenshots.

T1134.001
Token Impersonation/Theft
MalwareCobalt Strike

Cobalt Strike can steal access tokens from exiting processes.

T1134.003
Make and Impersonate Token
MalwareCobalt Strike

Cobalt Strike can make tokens from known credentials.

T1185
Browser Session Hijacking
MalwareCobalt Strike

Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates.

T1548.002
Bypass User Account Control
MalwareCobalt Strike

Cobalt Strike can use a number of known techniques to bypass Windows UAC.

T1569.002
Service Execution
MalwareCobalt Strike

Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services.

T1572
Protocol Tunneling
MalwareCobalt Strike

Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.