Malware.View on attack.mitre.org
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic. |
| T1003.001 LSASS Memory |
Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes. |
| T1003.002 Security Account Manager |
Cobalt Strike can recover hashed passwords. |
| T1005 Data from Local System |
Cobalt Strike can collect data from a local system. |
| T1007 System Service Discovery |
Cobalt Strike can enumerate services on compromised hosts. |
| T1012 Query Registry |
Cobalt Strike can query |
| T1016 System Network Configuration Discovery |
Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers. |
| T1018 Remote System Discovery |
Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network. |
| T1021.001 Remote Desktop Protocol |
Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel. |
| T1021.002 SMB/Windows Admin Shares |
Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement. |
| T1021.003 Distributed Component Object Model |
Cobalt Strike can deliver Beacon payloads for lateral movement by leveraging remote COM execution. |
| T1021.004 SSH |
Cobalt Strike can SSH to a remote service. |
| T1021.006 Windows Remote Management |
Cobalt Strike can use |
| T1027 Obfuscated Files or Information |
Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata. |
| T1027.005 Indicator Removal from Tools |
Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.