LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

EnterpriseS0154MalwareObject v1.14Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S0154: Cobalt Strike describes [Cobalt Strike](https://attack.mitre.org/software/S0154) is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.(Citation: cobaltstrike manual) In addition to its own capabilities, [Cobalt Strike](https://attack.mitre.org/s...

Executive priority

S0154: Cobalt Strike is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S0154: Cobalt Strike by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Linux, macOS, Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S0154: Cobalt Strike appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

44 rows
DomainIDNameRelationship / procedure
EnterpriseT1090.004Domain FrontingSub-technique

Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1548.003Sudo and Sudo CachingSub-technique

Cobalt Strike can use sudo to run a command.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1553.002Code SigningSub-technique

Cobalt Strike can use self signed Java applets to execute signed applet attacks.CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1059.007JavaScriptSub-technique

The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions.CitationTalos Cobalt Strike September 2020

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel.[1]CitationCybereason Bumblebee August 2022

EnterpriseT1106Native API

Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe[1]CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020 Cobalt Strike can also use `CreateThreadpoolWait`, `SetThreadpoolWait`, and `MessageBoxA` for sandbox evasion and execution of embedded payloads in memory.CitationCisco Talos Qilin Ransomware OCT 2025

EnterpriseT1550.002Pass the HashSub-technique

Cobalt Strike can perform pass the hash.CitationCobalt Strike TTPs Dec 2017

EnterpriseT1078.002Domain AccountsSub-technique

Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account.[1]CitationCobaltStrike Daddy May 2017CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1027.005Indicator Removal from ToolsSub-technique

Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.[1]CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1548.002Bypass User Account ControlSub-technique

Cobalt Strike can use a number of known techniques to bypass Windows UAC.[1]CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1016System Network Configuration Discovery

Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers.CitationCyberreason Anchor December 2019CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1569.002Service ExecutionSub-technique

Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services.[1]CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1005Data from Local System

Cobalt Strike can collect data from a local system.CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

Cobalt Strike has the ability to load DLLs via reflective injection.CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1056.001KeyloggingSub-technique

Cobalt Strike can track key presses with a keylogger module.[1]CitationAmnesty Intl. Ocean Lotus February 2021CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1197BITS Jobs

Cobalt Strike can download a hosted "beacon" payload using BITSAdmin.CitationCobaltStrike Scripted Web DeliveryCitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1055.012Process HollowingSub-technique

Cobalt Strike can use process hollowing for execution.CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1518Software Discovery

The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1078.003Local AccountsSub-technique

Cobalt Strike can use known credentials to run commands and spawn processes as a local user account.[1]CitationCobaltStrike Daddy May 2017

EnterpriseT1090.001Internal ProxySub-technique

Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access.[1]CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1068Exploitation for Privilege Escalation

Cobalt Strike can exploit vulnerabilities such as MS14-058.CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1113Screen Capture

Cobalt Strike's Beacon payload is capable of capturing screenshots.[1]CitationAmnesty Intl. Ocean Lotus February 2021CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1564.010Process Argument SpoofingSub-technique

Cobalt Strike can use spoof arguments in spawned processes that execute beacon commands.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1112Modify Registry

Cobalt Strike can modify Registry values within HKEY_CURRENT_USER\Software\Microsoft\Office\\Excel\Security\AccessVBOM\ to enable the execution of additional code.CitationTalos Cobalt Strike September 2020

EnterpriseT1069.002Domain GroupsSub-technique

Cobalt Strike can identify targets by querying account groups on a domain contoller.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1049System Network Connections Discovery

Cobalt Strike can produce a sessions report from compromised hosts.CitationTalos Cobalt Strike September 2020

EnterpriseT1001.003Protocol or Service ImpersonationSub-technique

Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI.CitationCobalt Strike Manual 4.3 November 2020 Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.CitationCisco Talos Qilin Ransomware OCT 2025

EnterpriseT1134.004Parent PID SpoofingSub-technique

Cobalt Strike can spawn processes with alternate PPIDs.CitationCobaltStrike Daddy May 2017CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1134.001Token Impersonation/TheftSub-technique

Cobalt Strike can steal access tokens from exiting processes.[1]CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1543.003Windows ServiceSub-technique

Cobalt Strike can install a new service.CitationCobalt Strike TTPs Dec 2017

EnterpriseT1059.005Visual BasicSub-technique

Cobalt Strike can use VBA to perform execution.CitationCobalt Strike TTPs Dec 2017CitationCobaltStrike Daddy May 2017CitationTalos Cobalt Strike September 2020

EnterpriseT1055Process Injection

Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary.[1]CitationCobalt Strike Manual 4.3 November 2020CitationDFIR Conti Bazar Nov 2021

EnterpriseT1007System Service Discovery

Cobalt Strike can enumerate services on compromised hosts.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1070.006TimestompSub-technique

Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in.[1]CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1083File and Directory Discovery

Cobalt Strike can explore files on a compromised system.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1071.004DNSSub-technique

Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.[1]CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1029Scheduled Transfer

Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval.[1]

EnterpriseT1069.001Local GroupsSub-technique

Cobalt Strike can use net localgroup to list local groups on a system.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1059.001PowerShellSub-technique

Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk.[1]CitationCyberreason Anchor December 2019 Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution.CitationCobalt Strike TTPs Dec 2017CitationCobaltStrike Daddy May 2017CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1021.004SSHSub-technique

Cobalt Strike can SSH to a remote service.CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1620Reflective Code Loading

Cobalt Strike's execute-assembly command can run a .NET executable within the memory of a sacrificial process by loading the CLR.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1018Remote System Discovery

Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network.[1]CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1003.001LSASS MemorySub-technique

Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes.CitationCobalt Strike Manual 4.3 November 2020

EnterpriseT1685Disable or Modify Tools

Cobalt Strike has the ability to use Smart Applet attacks to disable the Java SecurityManager sandbox.CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1043: BlackByte

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0045: menuPass

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.[1][2]

menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.[3][4][5][6][7][1][2]

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

GroupEnterprise

G0037: FIN6

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.[1][2]

GroupEnterprise

G1046: Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

GroupEnterprise

G0129: Mustang Panda

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. [1][2][3][4][5][6][7][8][9][10][11][12][13]

GroupEnterprise

G0067: APT37

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.[1][2][3]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

CampaignEnterprise

C0018: C0018

C0018 was a month-long ransomware intrusion that successfully deployed AvosLocker onto a compromised network. The unidentified actors gained initial access to the victim network through an exposed server and used a variety of open-source tools prior to executing AvosLocker.[1][2]

CampaignEnterprise

C0021: C0021

C0021 was a spearphishing campaign conducted in November 2018 that targeted public sector institutions, non-governmental organizations (NGOs), educational institutions, and private-sector corporations in the oil and gas, chemical, and hospitality industries. The majority of targets were located in the US, particularly in and around Washington D.C., with other targets located in Europe, Hong Kong, India, and Canada. C0021's technical artifacts, tactics, techniques, and procedures (TTPs), and targeting overlap with previous suspected APT29 activity.[1][2]

CampaignEnterprise

C0015: C0015

C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.[1]

CampaignEnterprise

C0024: SolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.[1] Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.[2][3][4][5][1][6][7][8]

In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes.[9][10][11] The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.[12]

CampaignEnterprise

C0017: C0017

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.14
Created
Modified
Raw hash
10002cfaa9d10df6...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.14Current bundle10002cfaa9d1…
19.11.14Older bundle10002cfaa9d1…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    cobaltstrike manual

    Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.

    Open source URL
  2. [2]
    mitre-attackS0154
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.