Cobalt Strike. (2017, December 8). Tactics, Techniques, and Procedures. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCobalt Strike | Cobalt Strike can collect data from a local system. |
| T1021.002 SMB/Windows Admin Shares |
MalwareCobalt Strike | Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement. |
| T1021.004 SSH |
MalwareCobalt Strike | Cobalt Strike can SSH to a remote service. |
| T1055.012 Process Hollowing |
MalwareCobalt Strike | Cobalt Strike can use process hollowing for execution. |
| T1059.001 PowerShell |
MalwareCobalt Strike | Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution. |
| T1059.003 Windows Command Shell |
MalwareCobalt Strike | Cobalt Strike uses a command-line interface to interact with systems. |
| T1059.005 Visual Basic |
MalwareCobalt Strike | Cobalt Strike can use VBA to perform execution. |
| T1059.006 Python |
MalwareCobalt Strike | Cobalt Strike can use Python to perform execution. |
| T1068 Exploitation for Privilege Escalation |
MalwareCobalt Strike | Cobalt Strike can exploit vulnerabilities such as MS14-058. |
| T1135 Network Share Discovery |
MalwareCobalt Strike | Cobalt Strike can query shared drives on the local system. |
| T1543.003 Windows Service |
MalwareCobalt Strike | Cobalt Strike can install a new service. |
| T1550.002 Pass the Hash |
MalwareCobalt Strike | Cobalt Strike can perform pass the hash. |
| T1569.002 Service Execution |
MalwareCobalt Strike | Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.