Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
MalwareCobalt Strike | Cobalt Strike can recover hashed passwords. |
| T1018 Remote System Discovery |
MalwareCobalt Strike | Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network. |
| T1021.001 Remote Desktop Protocol |
MalwareCobalt Strike | Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel. |
| T1021.006 Windows Remote Management |
MalwareCobalt Strike | Cobalt Strike can use |
| T1027.005 Indicator Removal from Tools |
MalwareCobalt Strike | Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods. |
| T1029 Scheduled Transfer |
MalwareCobalt Strike | Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval. |
| T1030 Data Transfer Size Limits |
MalwareCobalt Strike | Cobalt Strike will break large data sets into smaller chunks for exfiltration. |
| T1046 Network Service Discovery |
MalwareCobalt Strike | Cobalt Strike can perform port scans from an infected host. |
| T1047 Windows Management Instrumentation |
MalwareCobalt Strike | Cobalt Strike can use WMI to deliver a payload to a remote host. |
| T1055 Process Injection |
MalwareCobalt Strike | Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary. |
| T1056.001 Keylogging |
MalwareCobalt Strike | Cobalt Strike can track key presses with a keylogger module. |
| T1057 Process Discovery |
MalwareCobalt Strike | Cobalt Strike's Beacon payload can collect information on process details. |
| T1059.001 PowerShell |
MalwareCobalt Strike | Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution. |
| T1070.006 Timestomp |
MalwareCobalt Strike | Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in. |
| T1071.001 Web Protocols |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports. |
| T1071.002 File Transfer Protocols |
MalwareCobalt Strike | Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1071.004 DNS |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports. |
| T1078.002 Domain Accounts |
MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account. |
| T1078.003 Local Accounts |
MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a local user account. |
| T1090.001 Internal Proxy |
MalwareCobalt Strike | Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access. |
| T1106 Native API |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of running shell commands without |
| T1113 Screen Capture |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of capturing screenshots. |
| T1134.001 Token Impersonation/Theft |
MalwareCobalt Strike | Cobalt Strike can steal access tokens from exiting processes. |
| T1134.003 Make and Impersonate Token |
MalwareCobalt Strike | Cobalt Strike can make tokens from known credentials. |
| T1185 Browser Session Hijacking |
MalwareCobalt Strike | Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates. |
| T1548.002 Bypass User Account Control |
MalwareCobalt Strike | Cobalt Strike can use a number of known techniques to bypass Windows UAC. |
| T1569.002 Service Execution |
MalwareCobalt Strike | Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services. |
| T1572 Protocol Tunneling |
MalwareCobalt Strike | Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.