Skip to content
Fortra fortra mobile logo Cobalt Strike
  • Fortra.com
  • Blog
  • Download
  • Contact Us

Main Navigation

  • Product
    • Features
      • Arsenal Kit
      • Beacon
      • Malleable C2
      • Interoperability
      • Community
      • Flexibility
      • UDRL
      • View More Features >
    • Interoperability
      • Core Impact
      • Outflank Security Tooling
    • Bundles and Suites
      • Cobalt Strike + Core Impact
      • Cobalt Strike + Outflank Security Tooling
      • Cobalt Strike, Core Impact, Outflank Security Tooling
      • View All Product Bundles and Suites >
  • Industry
    • Finance
    • Healthcare
    • Government & Public Sector 
  • Support
    • Training
    • User Manuals
    • Community Kit
  • Resources
    • Releases
    • Blog
    • Events / Webinars
    • Datasheets
    • Videos
    • Screenshots
  • About Us
  • REQUEST PRICING
  • Search

CTA Type: Blog

Rethinking Reporting for Red Team Operations

Posted on September 9, 2015 (March 18, 2025)

Cobalt Strike 3.0 is coming in a few weeks. This upcoming release is the result of a large engineering effort that paralleled my existing efforts to maintain Cobalt Strike 2.x. One of the big motivators for this parallel effort was to take a fresh look at logging and reporting. Today’s Cobalt Strike produces reports that […]

Read More… from Rethinking Reporting for Red Team Operations

The Aggressor Project (Preview)

Posted on September 2, 2015 (March 19, 2025)

If you’ve run into me at a conference during the 2015 calendar year, there’s a strong chance you’ve heard about or saw the Aggressor project. Aggressor is a ground-up rewrite of Cobalt Strike’s team server and client to better serve its Red Team Operations and Adversary Simulation use cases. I expect to ship this work […]

Read More… from The Aggressor Project (Preview)

Raphael’s Magic Quadrant

Posted on August 3, 2015 (March 18, 2025)

BlackHat is about to start in a few days. I think this is an appropriate time to share a non-technical, business only post. There is a new market for offensive tools and services. Our trade press doesn’t write about it yet. I don’t believe industry analysts have caught onto these ideas yet. The leaders behind mature […]

Read More… from Raphael’s Magic Quadrant

Cobalt Strike 2.5 – Advanced Pivoting

Posted on July 29, 2015 (July 18, 2023)

I spend a lot of my red time in the Access Manager role. This is the person on a red team who manages callbacks for the red cell. Sometimes, I like to grab a Beacon and drive around a network. It’s important to get out once in a while and enjoy what’s there. Cobalt Strike […]

Read More… from Cobalt Strike 2.5 – Advanced Pivoting

WinRM is my Remote Access Tool

Posted on July 22, 2015 (March 19, 2025)

One of my favorite blog posts last year was Adversary Tricks and Treats from CrowdStrike. In this post, CrowdStrike details the tradecraft of an actor they dub Deep Panda. In an attempt to skirt advanced malware hunting capability, Deep Panda leverages native tools to control target systems and spread laterally in a network. With the […]

Read More… from WinRM is my Remote Access Tool

Models for Red Team Operations

Posted on July 9, 2015 (March 18, 2025)

Recently, I had an email from someone asking for a call to discuss different models of red team operations. This gentlemen sees his team as a service provider to his parent organization. He wants to make sure his organization sees his team as more than just dangerous folks with the latest tools doing stuff no […]

Read More… from Models for Red Team Operations

How to Pass-the-Hash with Mimikatz

Posted on May 21, 2015 (July 18, 2023)

I’m spending a lot of time with mimikatz lately. I’m fascinated by how much capability it has and I’m constantly asking myself, what’s the best way to use this during a red team engagement? A hidden gem in mimikatz is its ability to create a trust relationship from a username and password hash. Here’s the […]

Read More… from How to Pass-the-Hash with Mimikatz

An unnecessary addiction to DNS communication

Posted on May 14, 2015 (July 17, 2023)

I regularly hear stories from my users about how they got past a tough situation and had success that they claim was not possible without Cobalt Strike. As a developer, these emails are fun to read, and they give me a lot of job satisfaction. One of the features these users love is DNS Beacon. […]

Read More… from An unnecessary addiction to DNS communication

2015’s Red Team Tradecraft

Posted on April 29, 2015 (September 19, 2023)

“There is a theory which states that if ever anyone discovers exactly what the Universe is for and why it is here, it will instantly disappear and be replaced by something even more bizarre and inexplicable. There is another theory which states that this has already happened.” ― Douglas Adams, The Restaurant at the End […]

Read More… from 2015’s Red Team Tradecraft

User-defined Storage-based Covert Communication

Posted on April 23, 2015 (March 19, 2025)

One of my favorite Cobalt Strike technologies is Malleable C2. This is a domain specific language for user-defined storage-based covert communication. That’s just a fancy way of saying that you, the operator, have control over what Cobalt Strike’s Beacon looks like when it communicates with you. When I do red team work, I see the […]

Read More… from User-defined Storage-based Covert Communication

  • «
  • 1
  • …
  • 14
  • 15
  • 16
  • 17
  • 18
  • …
  • 28
  • »
Fortra
  • tel:+1-800-328-1000
  • Email Us
  • Request Support
  • Subscribe
  • X
  • LinkedIn
  • Youtube
  • Reddit
  • Bluesky

Footer Menu 1

  • Features
    • Beacon
    • Interoperablity
    • Community
      • All Features >

Footer Menu 2

  • Interoperability
    • Core Impact
    • Outflank Security Tooling

Footer Menu 3

  • Support
    • Training
    • Community Kit

Footer Menu 4

  • Resources
    • Blog
    • Screenshots
    • Datasheets
      • All Resources >

Footer Menu 5

  • About
    • Corporate Compliance & Ethics
    • Newsroom

Contact Information

Privacy Policy

Cookie Policy

Terms of Service

Impressum

Copyright © Fortra, LLC and its group of companies. Fortra®, the Fortra® logos, and other identified marks are proprietary trademarks of Fortra, LLC.