daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cobalt-strike-kits.md (5394B)


      1 ---
      2 title: "Cobalt Strike - Kits"
      3 section: "Command & Control"
      4 sectionSlug: "command-control"
      5 sourcePath: "docs/command-control/cobalt-strike-kits.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/command-control/cobalt-strike-kits.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Cobalt Strike - Kits
     12 
     13 * [Cobalt Strike Community Kit](https://cobalt-strike.github.io/community_kit/) - Community Kit is a central repository of extensions written by the user community to extend the capabilities of Cobalt Strike
     14 
     15 ## Elevate Kit
     16 
     17 UAC Token Duplication : Fixed in Windows 10 Red Stone 5 (October 2018)
     18 
     19 ```powershell
     20 beacon> runasadmin
     21 
     22 Beacon Command Elevators
     23 ========================
     24 
     25     Exploit                         Description
     26     -------                         -----------
     27     ms14-058                        TrackPopupMenu Win32k NULL Pointer Dereference (CVE-2014-4113)
     28     ms15-051                        Windows ClientCopyImage Win32k Exploit (CVE 2015-1701)
     29     ms16-016                        mrxdav.sys WebDav Local Privilege Escalation (CVE 2016-0051)
     30     svc-exe                         Get SYSTEM via an executable run as a service
     31     uac-schtasks                    Bypass UAC with schtasks.exe (via SilentCleanup)
     32     uac-token-duplication           Bypass UAC with Token Duplication
     33 ```
     34 
     35 ## Persistence Kit
     36 
     37 * [0xthirteen/MoveKit](https://github.com/0xthirteen/MoveKit)
     38 * [fireeye/SharPersist](https://github.com/fireeye/SharPersist)
     39 
     40     ```powershell
     41     # List persistences
     42     SharPersist -t schtaskbackdoor -m list
     43     SharPersist -t startupfolder -m list
     44     SharPersist -t schtask -m list
     45 
     46     # Add a persistence
     47     SharPersist -t schtaskbackdoor -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Something Cool" -m add
     48     SharPersist -t schtaskbackdoor -n "Something Cool" -m remove
     49 
     50     SharPersist -t service -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Some Service" -m add
     51     SharPersist -t service -n "Some Service" -m remove
     52 
     53     SharPersist -t schtask -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Some Task" -m add
     54     SharPersist -t schtask -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Some Task" -m add -o hourly
     55     SharPersist -t schtask -n "Some Task" -m remove
     56     ```
     57 
     58 ## Resource Kit
     59 
     60 > The Resource Kit is Cobalt Strike's means to change the HTA, PowerShell, Python, VBA, and VBS script templates Cobalt Strike uses in its workflows
     61 
     62 ## Artifact Kit
     63 
     64 > Cobalt Strike uses the Artifact Kit to generate its executables and DLLs. The Artifact Kit is a source code framework to build executables and DLLs that evade some anti-virus products. The Artifact Kit build script creates a folder with template artifacts for each Artifact Kit technique. To use a technique with Cobalt Strike, go to Cobalt Strike -> Script Manager, and load the artifact.cna script from that technique's folder.
     65 
     66 [Artifact Kit (Cobalt Strike 4.0)](https://www.youtube.com/watch?v=6mC21kviwG4)
     67 
     68 * Download the artifact kit : `Go to Help -> Arsenal to download Artifact Kit (requires a licensed version of Cobalt Strike)`
     69 * Install the dependencies : `sudo apt-get install mingw-w64`
     70 * Edit the Artifact code
     71     * Change pipename strings
     72     * Change `VirtualAlloc` in `patch.c`/`patch.exe`, e.g: HeapAlloc
     73     * Change Import
     74 * Build the Artifact
     75 * Cobalt Strike -> Script Manager > Load .cna
     76 
     77 ## Mimikatz Kit
     78 
     79 * Download and extract the .tgz from the Arsenal
     80 * Load the mimikatz.cna aggressor script
     81 * Use mimikatz functions as normal
     82 
     83 ## Sleep Mask Kit
     84 
     85 > The Sleep Mask Kit is the source code for the sleep mask function that is executed to obfuscate Beacon, in memory, prior to sleeping.
     86 
     87 Use the included `build.sh` or `build.bat` script to build the Sleep Mask Kit on Kali Linux or Microsoft Windows. The script builds the sleep mask object file for the three types of Beacons (default, SMB, and TCP) on both x86 and x64 architectures in the sleepmask directory. The default type supports HTTP, HTTPS, and DNS Beacons.
     88 
     89 ## Mutator Kit
     90 
     91 > The Mutator Kit, introduced by Cobalt Strike, is a tool designed to create uniquely mutated versions of a "sleep mask" used in payloads to evade detection by static signatures. It utilizes LLVM obfuscation techniques to alter the sleep mask, making it difficult for memory scanning tools to identify the mask based on predefined patterns, thereby enhancing operational security for red team activities.
     92 
     93 The OBFUSCATIONS variable can be `flattening`,`substitution`,`split-basic-blocks`,`bogus`.
     94 
     95 ```ps1
     96 OBFUSCATIONS=substitution mutator.sh x64 -emit-llvm -S example.c -o example_with_substitutions.ll
     97 mutator.sh x64 -c -DIMPL_CHKSTK_MS=1 -DMASK_TEXT_SECTION=1 -o sleepmask.x64.o src49/sleepmask.c
     98 ```
     99 
    100 ## Thread Stack Spoofer
    101 
    102 > An advanced in-memory evasion technique that spoofs Thread Call Stack. This technique allows to bypass thread-based memory examination rules and better hide shellcodes while in-process memory.
    103 
    104 Thread Stack Spoofer is now enabled by default in the Artifact Kit, it is possible to disable it via the option `artifactkit_stack_spoof` in the config file `arsenal_kit.config`.
    105 
    106 ## References
    107 
    108 * [Introducing the Mutator Kit: Creating Object File Monstrosities with Sleep Mask and LLVM - @joehowwolf @HenriNurmi](https://www.cobaltstrike.com/blog/introducing-the-mutator-kit-creating-object-file-monstrosities-with-sleep-mask-and-llvm)