Cobalt Strike Certified Operator Training II (CSCO II) is designed to build upon practical skills learned in CSCO I.
By the end of this self-paced course, you will be equipped to extend and tailor Cobalt Strike for advanced payload delivery and static, load-time, runtime, and post-exploitation evasion using hands-on tradecraft such as Aggressor Script, UDRLs, Sleep Mask, Beacon Gate, and more.
Training Content
1. Getting Started
- Welcome
2. Aggressor Script
- Introduction
- Sleep 101
- Script Console
- Script Manager
- Aggressor Script Demo
- Aggressor Script Lab
3. Stage 0 Payloads
- Introduction
- AppDomainManager Hijack
- Shellcode Injection
- Payload Delivery
- Stage 0 Demo
- Stage 0 Lab
4. UDRLs
- Introduction
- PE Review
- PIC Primer
- PIC Primer Demo
- PIC Primer Lab
- Loader Fundamentals
- Beacon Calling Convention
- Integration with Aggressor
- Simple Loader Demo
- Simple Loader Lab
- PIC Projects
- Stardust Demo
- Stardust Lab
5. Static Evasion
- Obfuscating Beacon at rest
- Bypassing memory scanners
6. Load-Time Evasion
- Introduction
- Export Address Filtering
- Export Address Filtering Demo
- Export Address Filtering Lab
- Module Stomping
- Call Stack Spoofing
- Call Stack Spoofing Demo
- Call Stack Spoofing Lab
7. Built-in Runtime Evasion
- Sleepmask
- Beacon User Data
- Sleepmask Demo
- Sleepmask Lab
- BeaconGate
- BeaconGate Demo
- BeaconGate Lab
8. Custom Runtime Evasion
- Beyond BeaconGate
- IAT Hooking Demo
- IAT Hooking Lab
- Freeing Beacon
9. Postex Evasion
- Introduction
- Reflective DLLs
- Beacon Object Files
- BOF Cocktails Demo
- BOF Cocktails Lab
- Native Commands & Beacon Interpreter
10. Custom Process Injection
- Introduction
- Process Injection Spawn
- Process Injection Explicit
- Process Injection Dialogue
11. UDC2
- Introduction
- UDC2 BOF
- UDC2 Server
- UDC2 Evasion
- UDC2 Demo
- UDC2 Lab
12. Capstone
- Introduction
- Capstone Lab
13. Development Environment
- Introduction
- Environment Setup
- Environment Setup Walkthrough
14. Next Steps
- Course Evaluation — 3 questions
- Certificate of Completion
PRODUCT SUMMARY
Key Features
- 70 lessons
- Hands-on Labs: The curriculum is reinforced with a series of interactive labs designed to solidify core concepts at your own pace, providing a realistic learning experience.
- Format: Self-paced, online
FAQ
Is Lab access included with the course?
- Yes, lab access is included with the course to hone your skills at your own pace.
Do the labs support multiple geographical regions?
- Yes, your IP address is used to determine the best delivery region for the lab instance. The available regions are: London, Ashburn, Seattle, Veritas, and Singapore. If a VPN is used while launching a lab, the instance will be geolocated to the country the VPN is configured for. You should also expect this to negatively impact the lab’s performance.
Who should take CSCO II Training?
- CSCO II is designed for Cobalt Strike operators who have completed CSCO I or have equivalent practical experience. Learners should be familiar with Beacon, payload delivery, and core Cobalt Strike workflows.
What will I learn in CSCO II Training?
- You’ll learn advanced Cobalt Strike tradecraft, including Aggressor Script, Stage 0 payloads, User-Defined Reflective Loaders, static and runtime evasion, Sleep Mask, BeaconGate, post-exploitation evasion, custom process injection, UDC2, and related techniques.
Ready to Sign Up?
For more information on training and to get started, contact our experts.