S0154: Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]
Security context for executives and security teams
S0154: Cobalt Strike describes [Cobalt Strike](https://attack.mitre.org/software/S0154) is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.(Citation: cobaltstrike manual) In addition to its own capabilities, [Cobalt Strike](https://attack.mitre.org/s...
Executive priority
S0154: Cobalt Strike is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S0154: Cobalt Strike by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Linux, macOS, Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S0154: Cobalt Strike appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1090.004 | Domain FrontingSub-technique | Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting.CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1548.003 | Sudo and Sudo CachingSub-technique | Cobalt Strike can use |
| Enterprise | T1553.002 | Code SigningSub-technique | Cobalt Strike can use self signed Java applets to execute signed applet attacks.CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1059.007 | JavaScriptSub-technique | The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions.CitationTalos Cobalt Strike September 2020 |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel.[1]CitationCybereason Bumblebee August 2022 |
| Enterprise | T1106 | Native API | Cobalt Strike's Beacon payload is capable of running shell commands without |
| Enterprise | T1550.002 | Pass the HashSub-technique | Cobalt Strike can perform pass the hash.CitationCobalt Strike TTPs Dec 2017 |
| Enterprise | T1078.002 | Domain AccountsSub-technique | Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account.[1]CitationCobaltStrike Daddy May 2017CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1027.005 | Indicator Removal from ToolsSub-technique | Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.[1]CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1548.002 | Bypass User Account ControlSub-technique | Cobalt Strike can use a number of known techniques to bypass Windows UAC.[1]CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1016 | System Network Configuration Discovery | Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers.CitationCyberreason Anchor December 2019CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1569.002 | Service ExecutionSub-technique | Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services.[1]CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1005 | Data from Local System | Cobalt Strike can collect data from a local system.CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1055.001 | Dynamic-link Library InjectionSub-technique | Cobalt Strike has the ability to load DLLs via reflective injection.CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1056.001 | KeyloggingSub-technique | Cobalt Strike can track key presses with a keylogger module.[1]CitationAmnesty Intl. Ocean Lotus February 2021CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1197 | BITS Jobs | Cobalt Strike can download a hosted "beacon" payload using BITSAdmin.CitationCobaltStrike Scripted Web DeliveryCitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1055.012 | Process HollowingSub-technique | Cobalt Strike can use process hollowing for execution.CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1518 | Software Discovery | The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has.CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1078.003 | Local AccountsSub-technique | Cobalt Strike can use known credentials to run commands and spawn processes as a local user account.[1]CitationCobaltStrike Daddy May 2017 |
| Enterprise | T1090.001 | Internal ProxySub-technique | Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access.[1]CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1068 | Exploitation for Privilege Escalation | Cobalt Strike can exploit vulnerabilities such as MS14-058.CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1113 | Screen Capture | Cobalt Strike's Beacon payload is capable of capturing screenshots.[1]CitationAmnesty Intl. Ocean Lotus February 2021CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1564.010 | Process Argument SpoofingSub-technique | Cobalt Strike can use spoof arguments in spawned processes that execute beacon commands.CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1112 | Modify Registry | Cobalt Strike can modify Registry values within |
| Enterprise | T1069.002 | Domain GroupsSub-technique | Cobalt Strike can identify targets by querying account groups on a domain contoller.CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1049 | System Network Connections Discovery | Cobalt Strike can produce a sessions report from compromised hosts.CitationTalos Cobalt Strike September 2020 |
| Enterprise | T1001.003 | Protocol or Service ImpersonationSub-technique | Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI.CitationCobalt Strike Manual 4.3 November 2020 Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.CitationCisco Talos Qilin Ransomware OCT 2025 |
| Enterprise | T1134.004 | Parent PID SpoofingSub-technique | Cobalt Strike can spawn processes with alternate PPIDs.CitationCobaltStrike Daddy May 2017CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1134.001 | Token Impersonation/TheftSub-technique | Cobalt Strike can steal access tokens from exiting processes.[1]CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1543.003 | Windows ServiceSub-technique | Cobalt Strike can install a new service.CitationCobalt Strike TTPs Dec 2017 |
| Enterprise | T1059.005 | Visual BasicSub-technique | Cobalt Strike can use VBA to perform execution.CitationCobalt Strike TTPs Dec 2017CitationCobaltStrike Daddy May 2017CitationTalos Cobalt Strike September 2020 |
| Enterprise | T1055 | Process Injection | Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary.[1]CitationCobalt Strike Manual 4.3 November 2020CitationDFIR Conti Bazar Nov 2021 |
| Enterprise | T1007 | System Service Discovery | Cobalt Strike can enumerate services on compromised hosts.CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1070.006 | TimestompSub-technique | Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in.[1]CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1083 | File and Directory Discovery | Cobalt Strike can explore files on a compromised system.CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1071.004 | DNSSub-technique | Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.[1]CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1029 | Scheduled Transfer | Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval.[1] |
| Enterprise | T1069.001 | Local GroupsSub-technique | Cobalt Strike can use |
| Enterprise | T1059.001 | PowerShellSub-technique | Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk.[1]CitationCyberreason Anchor December 2019 Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution.CitationCobalt Strike TTPs Dec 2017CitationCobaltStrike Daddy May 2017CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1021.004 | SSHSub-technique | Cobalt Strike can SSH to a remote service.CitationCobalt Strike TTPs Dec 2017CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1620 | Reflective Code Loading | Cobalt Strike's |
| Enterprise | T1018 | Remote System Discovery | Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network.[1]CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1003.001 | LSASS MemorySub-technique | Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes.CitationCobalt Strike Manual 4.3 November 2020 |
| Enterprise | T1685 | Disable or Modify Tools | Cobalt Strike has the ability to use Smart Applet attacks to disable the Java SecurityManager sandbox.CitationTalos Cobalt Strike September 2020CitationCobalt Strike Manual 4.3 November 2020 |
Groups, software, and campaigns
G0119: Indrik Spider
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.[1][2][3]
G1043: BlackByte
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]
G1020: Mustard Tempest
Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.[1][2][3][4]
G0096: APT41
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]
G0045: menuPass
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.[1][2]
menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.[3][4][5][6][7][1][2]
G0050: APT32
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]
G0037: FIN6
G1046: Storm-1811
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]
G0046: FIN7
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]
G0034: Sandworm Team
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]
In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]
G0129: Mustang Panda
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. [1][2][3][4][5][6][7][8][9][10][11][12][13]
G0067: APT37
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.[1][2][3]
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
C0018: C0018
C0018 was a month-long ransomware intrusion that successfully deployed AvosLocker onto a compromised network. The unidentified actors gained initial access to the victim network through an exposed server and used a variety of open-source tools prior to executing AvosLocker.[1][2]
C0021: C0021
C0021 was a spearphishing campaign conducted in November 2018 that targeted public sector institutions, non-governmental organizations (NGOs), educational institutions, and private-sector corporations in the oil and gas, chemical, and hospitality industries. The majority of targets were located in the US, particularly in and around Washington D.C., with other targets located in Europe, Hong Kong, India, and Canada. C0021's technical artifacts, tactics, techniques, and procedures (TTPs), and targeting overlap with previous suspected APT29 activity.[1][2]
C0015: C0015
C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.[1]
C0024: SolarWinds Compromise
The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.[1] Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.[2][3][4][5][1][6][7][8]
In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes.[9][10][11] The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.[12]
C0040: APT41 DUST
APT41 DUST was conducted by APT41 from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. APT41 DUST targeted sectors such as shipping, logistics, and media for information gathering purposes. APT41 used previously-observed malware such as DUSTPAN as well as newly observed tools such as DUSTTRAP in APT41 DUST.[1]
C0017: C0017
C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.14 | Current bundle | 10002cfaa9d1… | ||
| 19.1 | 1.14 | Older bundle | 10002cfaa9d1… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]cobaltstrike manual
Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.
Open source URL - [2]mitre-attackS0154Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
