LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.Citationcobaltstrike manual

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.Citationcobaltstrike manual

EnterpriseS0154MalwareObject v1.14Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Cobalt Strike matters because it is a legitimate adversary-simulation and remote access tool whose post-exploitation capabilities span the ATT&CK lifecycle. In practice, this makes it a high-value validation target: if an organization cannot distinguish authorized security testing from unauthorized remote access and post-compromise activity, executives may lack reliable evidence during ransomware, espionage, or supply-chain incident decisions.

Executive priority

Prioritize Cobalt Strike coverage as a resilience and incident-readiness question, not just a malware signature question. ATT&CK relationships show use across ransomware intrusions, public-sector and critical-industry targeting, financially motivated groups, and state-linked groups. Leaders should ask whether security testing tools are governed, whether SOC and IR teams can rapidly validate unauthorized use across Windows, Linux, and macOS, and whether telemetry is sufficient to support audit, legal, and business-continuity decisions during a suspected compromise.

Technical view

ATT&CK provides no official detection guidance for S0154, so defenders should validate coverage against the behaviors implied by a full-featured remote access and post-exploitation platform rather than rely on a single indicator. SOC and IR teams should confirm visibility across supported platforms: process execution, parent-child process relationships, command execution, credential-access tool interaction where applicable because Cobalt Strike can leverage tools such as Mimikatz, network connections associated with remote access, and evidence of lateral or post-exploit activity. Relationship context makes this especially relevant in investigations involving ransomware campaigns, exposed or vulnerable Internet-facing applications, supply-chain compromise, phishing-led intrusions, and activity associated with the listed groups and campaigns.

Likely telemetry

  • Endpoint process creation and command-line telemetry on Windows, Linux, and macOS
  • Network connection and egress telemetry for remote access sessions
  • Authentication and credential-use logs, especially where post-exploitation activity is suspected
  • EDR or host audit data showing execution of security tools, dual-use tools, or chained tooling such as Mimikatz
  • Server and application logs for incidents that begin from exposed or vulnerable Internet-facing systems

Detection direction

  • Inventory and govern legitimate Cobalt Strike use so the SOC can separate approved adversary simulation from suspicious execution.
  • Build detections around post-exploitation behavior patterns and telemetry correlation, because ATT&CK does not provide an official detection section for this object.
  • Tune alerts with context from relationships: ransomware intrusions, APT campaigns, financially motivated groups, public-sector targeting, supply-chain compromise, exposed servers, and vulnerable Internet-facing applications are all represented in related ATT&CK objects.
  • Validate coverage across Windows, Linux, and macOS rather than assuming endpoint controls are Windows-only.
  • Treat tool-name or hash-only detection as insufficient; prioritize behavior, execution context, network activity, and credential-use evidence.

Mitigation priorities

  • Establish approval, logging, and change-control requirements for any authorized adversary-simulation tooling.
  • Ensure endpoint and network telemetry collection is enabled and retained across Windows, Linux, and macOS systems that matter to business operations.
  • Harden and monitor Internet-facing applications and exposed servers, since related campaign context includes initial compromise through vulnerable or exposed services.
  • Strengthen credential protection and monitoring because Cobalt Strike can leverage other tools such as Mimikatz.
  • Prepare IR playbooks that distinguish legitimate testing from unauthorized remote access and post-exploitation activity.
Additional notes and limits

The supplied ATT&CK object identifies Cobalt Strike as commercial adversary-simulation software with broad post-exploitation capability and relationships to numerous campaigns and groups, including ransomware and state-linked activity. This take emphasizes defensive validation and governance because the tool can be legitimate in one context and suspicious in another.

No official ATT&CK detection text, aliases, labels, or object-specific tactics were provided. Local telemetry, approved-tool inventories, red-team schedules, and incident evidence are required before determining whether observed activity is authorized, malicious, or relevant to a specific threat actor.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.Citationcobaltstrike manual

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.Citationcobaltstrike manual

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.14
Created
Modified
Raw hash
10002cfaa9d10df6...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.