Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareCobalt Strike | Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic. |
| T1003.001 LSASS Memory |
MalwareCobalt Strike | Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes. |
| T1003.006 DCSync |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync. |
| T1005 Data from Local System |
MalwareCobalt Strike | Cobalt Strike can collect data from a local system. |
| T1007 System Service Discovery |
MalwareCobalt Strike | Cobalt Strike can enumerate services on compromised hosts. |
| T1012 Query Registry |
MalwareCobalt Strike | Cobalt Strike can query |
| T1016 System Network Configuration Discovery |
MalwareCobalt Strike | Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers. |
| T1018 Remote System Discovery |
MalwareCobalt Strike | Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network. |
| T1021.004 SSH |
MalwareCobalt Strike | Cobalt Strike can SSH to a remote service. |
| T1021.006 Windows Remote Management |
MalwareCobalt Strike | Cobalt Strike can use |
| T1027 Obfuscated Files or Information |
MalwareCobalt Strike | Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata. |
| T1027.005 Indicator Removal from Tools |
MalwareCobalt Strike | Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods. |
| T1046 Network Service Discovery |
MalwareCobalt Strike | Cobalt Strike can perform port scans from an infected host. |
| T1047 Windows Management Instrumentation |
MalwareCobalt Strike | Cobalt Strike can use WMI to deliver a payload to a remote host. |
| T1055 Process Injection |
MalwareCobalt Strike | Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary. |
| T1055.001 Dynamic-link Library Injection |
MalwareCobalt Strike | Cobalt Strike has the ability to load DLLs via reflective injection. |
| T1055.012 Process Hollowing |
MalwareCobalt Strike | Cobalt Strike can use process hollowing for execution. |
| T1056.001 Keylogging |
MalwareCobalt Strike | Cobalt Strike can track key presses with a keylogger module. |
| T1057 Process Discovery |
MalwareCobalt Strike | Cobalt Strike's Beacon payload can collect information on process details. |
| T1059.001 PowerShell |
MalwareCobalt Strike | Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution. |
| T1059.003 Windows Command Shell |
MalwareCobalt Strike | Cobalt Strike uses a command-line interface to interact with systems. |
| T1059.006 Python |
MalwareCobalt Strike | Cobalt Strike can use Python to perform execution. |
| T1068 Exploitation for Privilege Escalation |
MalwareCobalt Strike | Cobalt Strike can exploit vulnerabilities such as MS14-058. |
| T1069.001 Local Groups |
MalwareCobalt Strike | Cobalt Strike can use |
| T1069.002 Domain Groups |
MalwareCobalt Strike | Cobalt Strike can identify targets by querying account groups on a domain contoller. |
| T1070.006 Timestomp |
MalwareCobalt Strike | Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in. |
| T1071.001 Web Protocols |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports. |
| T1071.004 DNS |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports. |
| T1078.002 Domain Accounts |
MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account. |
| T1083 File and Directory Discovery |
MalwareCobalt Strike | Cobalt Strike can explore files on a compromised system. |
| T1090.001 Internal Proxy |
MalwareCobalt Strike | Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access. |
| T1090.004 Domain Fronting |
MalwareCobalt Strike | Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting. |
| T1095 Non-Application Layer Protocol |
MalwareCobalt Strike | Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareCobalt Strike | Cobalt Strike can deliver additional payloads to victim machines. |
| T1106 Native API |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of running shell commands without |
| T1113 Screen Capture |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of capturing screenshots. |
| T1132.001 Standard Encoding |
MalwareCobalt Strike | Cobalt Strike can use Base64, URL-safe Base64, or NetBIOS encoding in its C2 traffic. |
| T1134.001 Token Impersonation/Theft |
MalwareCobalt Strike | Cobalt Strike can steal access tokens from exiting processes. |
| T1134.004 Parent PID Spoofing |
MalwareCobalt Strike | Cobalt Strike can spawn processes with alternate PPIDs. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCobalt Strike | Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution. |
| T1185 Browser Session Hijacking |
MalwareCobalt Strike | Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates. |
| T1197 BITS Jobs |
MalwareCobalt Strike | Cobalt Strike can download a hosted "beacon" payload using BITSAdmin. |
| T1203 Exploitation for Client Execution |
MalwareCobalt Strike | Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460. |
| T1218.011 Rundll32 |
MalwareCobalt Strike | Cobalt Strike can use `rundll32.exe` to load DLL from the command line. |
| T1518 Software Discovery |
MalwareCobalt Strike | The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has. |
| T1548.002 Bypass User Account Control |
MalwareCobalt Strike | Cobalt Strike can use a number of known techniques to bypass Windows UAC. |
| T1548.003 Sudo and Sudo Caching |
MalwareCobalt Strike | Cobalt Strike can use |
| T1550.002 Pass the Hash |
ToolMimikatz | Mimikatz's |
| T1553.002 Code Signing |
MalwareCobalt Strike | Cobalt Strike can use self signed Java applets to execute signed applet attacks. |
| T1555 Credentials from Password Stores |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.