Cobalt Strike Certified Operator Training II (CSCO II) is designed to build upon practical skills learned in CSCO I.

By the end of this self-paced course, you will be equipped to extend and tailor Cobalt Strike for advanced payload delivery and static, load-time, runtime, and post-exploitation evasion using hands-on tradecraft such as Aggressor Script, UDRLs, Sleep Mask, Beacon Gate, and more. 

Training Content

1. Getting Started

  • Welcome

2. Aggressor Script

  • Introduction
  • Sleep 101
  • Script Console
  • Script Manager
  • Aggressor Script Demo
  • Aggressor Script Lab

3. Stage 0 Payloads

  • Introduction
  • AppDomainManager Hijack
  • Shellcode Injection
  • Payload Delivery
  • Stage 0 Demo
  • Stage 0 Lab

4. UDRLs

  • Introduction
  • PE Review
  • PIC Primer
  • PIC Primer Demo
  • PIC Primer Lab
  • Loader Fundamentals
  • Beacon Calling Convention
  • Integration with Aggressor
  • Simple Loader Demo
  • Simple Loader Lab
  • PIC Projects
  • Stardust Demo
  • Stardust Lab

5. Static Evasion

  • Obfuscating Beacon at rest
  • Bypassing memory scanners

6. Load-Time Evasion

  • Introduction
  • Export Address Filtering
  • Export Address Filtering Demo
  • Export Address Filtering Lab
  • Module Stomping
  • Call Stack Spoofing
  • Call Stack Spoofing Demo
  • Call Stack Spoofing Lab

7. Built-in Runtime Evasion

  • Sleepmask
  • Beacon User Data
  • Sleepmask Demo
  • Sleepmask Lab
  • BeaconGate
  • BeaconGate Demo
  • BeaconGate Lab

8. Custom Runtime Evasion

  • Beyond BeaconGate
  • IAT Hooking Demo
  • IAT Hooking Lab
  • Freeing Beacon

9. Postex Evasion

  • Introduction
  • Reflective DLLs
  • Beacon Object Files
  • BOF Cocktails Demo
  • BOF Cocktails Lab
  • Native Commands & Beacon Interpreter

10. Custom Process Injection

  • Introduction
  • Process Injection Spawn
  • Process Injection Explicit
  • Process Injection Dialogue

11. UDC2

  • Introduction
  • UDC2 BOF
  • UDC2 Server
  • UDC2 Evasion
  • UDC2 Demo
  • UDC2 Lab

12. Capstone

  • Introduction
  • Capstone Lab

13. Development Environment

  • Introduction
  • Environment Setup
  • Environment Setup Walkthrough

14. Next Steps

  • Course Evaluation — 3 questions
  • Certificate of Completion

PRODUCT SUMMARY

Key Features

  • 70 lessons
  • Hands-on Labs: The curriculum is reinforced with a series of interactive labs designed to solidify core concepts at your own pace, providing a realistic learning experience.
  • Format: Self-paced, online

FAQ

Is Lab access included with the course?

  • Yes, lab access is included with the course to hone your skills at your own pace.

Do the labs support multiple geographical regions?

  • Yes, your IP address is used to determine the best delivery region for the lab instance.  The available regions are: London, Ashburn, Seattle, Veritas, and Singapore. If a VPN is used while launching a lab, the instance will be geolocated to the country the VPN is configured for.  You should also expect this to negatively impact the lab’s performance.

Who should take CSCO II Training?

  • CSCO II is designed for Cobalt Strike operators who have completed CSCO I or have equivalent practical experience. Learners should be familiar with Beacon, payload delivery, and core Cobalt Strike workflows.

What will I learn in CSCO II Training?

  • You’ll learn advanced Cobalt Strike tradecraft, including Aggressor Script, Stage 0 payloads, User-Defined Reflective Loaders, static and runtime evasion, Sleep Mask, BeaconGate, post-exploitation evasion, custom process injection, UDC2, and related techniques.

Ready to Sign Up?

For more information on training and to get started, contact our experts.