1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / tool

Cobalt Strike — Attack Tool

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system. In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.

Tool identity and evidence

Cobalt Strike is included as an explicit framework exception. ATT&CK classifies this software object as malware; that upstream type is preserved.

Aliases: Cobalt Strike

Primary tool reference

Existing author guides

No reviewed association in this snapshot.

Primary documentation

No reviewed association in this snapshot.

Connected ecosystem references

Linked tags

Documented actor use

Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.

Technique-specific simulations and detections

Detection links describe the associated behavior, not independently verified tool-specific signatures.

Telemetry context

Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.