Red Team Posted on December 15, 2020 (May 3, 2022) Agent Deployed: Core Impact and Cobalt Strike Interoperability Core Impact 20.3 has shipped this week. With this release, we’re revealing patterns for interoperability between Core Impact and Cobalt Strike. In this post, I’ll Read More
Red Team Posted on December 8, 2020 (May 3, 2022) A Red Teamer Plays with JARM I spent a little time looking into Saleforce’s JARM tool released in November. JARM is an active tool to probe the TLS/SSL stack of a Read More
BOF, Red Team Posted on September 17, 2020 (May 3, 2022) Beacon Object File ADVENTURES: Some Zerologon, SMBGhost, and Situational Awareness Cobalt Strike can use PowerShell, .NET, and Reflective DLLs for its post-exploitation features. This is the weaponization problem set. How to take things, developed outside Read More
Red Team Posted on February 19, 2019 (May 3, 2022) Cobalt Strike Team Server Population Study From February 4, 2019 to February 15, 2019 Strategic Cyber LLC connected to several live Cobalt Strike team servers to download Beacon payloads, analyze them, Read More
Red Team Posted on June 4, 2018 (May 3, 2022) Broken Promises and Malleable C2 Profiles Red Team infrastructure is a detail-heavy subject. Take the case of domain fronting through a CDN like CloudFront. You have to setup the CloudFront distribution, Read More
Red Team Posted on April 23, 2018 (May 3, 2022) Fighting the Toolset What happens when your advantages become a disadvantage? That’s the theme of Fighting the Toolset. This lecture discusses Offensive PowerShell, staging, memory-injected DLLs, and remote Read More
Red Team Posted on February 8, 2018 (June 6, 2022) In-Memory Evasion Many analysts and automated solutions take advantage of various memory detections to find injected DLLs in memory. Memory detections look at the properties (and content) Read More
Red Team Posted on October 25, 2017 (May 3, 2022) Modern Defenses and YOU! Part 9 of Advanced Threat Tactics covers a lot of my thoughts on evasion. The ideas in that lecture are still relevant, the defenses discussed Read More
BOF, Red Team Posted on June 23, 2017 (May 3, 2022) OPSEC Considerations for Beacon Commands Update January 9, 2020 – This topic is now part of the Cobalt Strike documentation. Head over to the Beacon Command Behavior page for the Read More
Red Team Posted on February 6, 2017 (November 29, 2022) High-reputation Redirectors and Domain Fronting Working on Cobalt Strike, I get some insight into what folks are trying to do with it. Recently, the use of domain fronting for redirectors Read More