1200KM / tool
Cobalt Strike — Attack Tool
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system. In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.
Tool identity and evidence
Cobalt Strike is included as an explicit framework exception. ATT&CK classifies this software object as malware; that upstream type is preserved.
Aliases: Cobalt Strike
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT29 · G0016 · Pinned relationship source (relationship--d9beae20-bd32-4141-95ff-053cf46e8210)
- Threat Group-3390 · G0027 · Pinned relationship source (relationship--4b32f8e0-ba08-45b5-bc9a-b394d99a5aba)
- Sandworm Team · G0034 · Pinned relationship source (relationship--bfa683a7-3c94-4de9-966c-2c06cfdf5a78)
- FIN6 · G0037 · Pinned relationship source (relationship--6d520715-126a-4678-ba03-cbdd70fae8d0)
- menuPass · G0045 · Pinned relationship source (relationship--b8e169f0-2d84-4785-ba46-0cd79082fcf5)
- FIN7 · G0046 · Pinned relationship source (relationship--9c61749d-ad78-476d-8cd6-ba4eafc8f74e)
- APT32 · G0050 · Pinned relationship source (relationship--4ef9490e-e347-4f4e-aa6f-c082e02349fc)
- CopyKittens · G0052 · Pinned relationship source (relationship--82c12a79-e80d-4eba-91ab-d14fd98cb539)
- Leviathan · G0065 · Pinned relationship source (relationship--d8cbc56c-4014-4e59-adfd-1899859f01d4)
- APT37 · G0067 · Pinned relationship source (relationship--e614a9ca-a922-4594-a929-30dd542d83ce)
- APT19 · G0073 · Pinned relationship source (relationship--5f830006-234e-44d1-9441-1aca7990006c)
- DarkHydrus · G0079 · Pinned relationship source (relationship--8d1da663-a3eb-4464-9be1-b43b8671e599)
- Cobalt Group · G0080 · Pinned relationship source (relationship--bab233b8-640c-4a8b-90fa-d5b959adefbb)
- TA505 · G0092 · Pinned relationship source (relationship--74dcdf15-ebdf-4faa-8316-cbf1429a8cea)
- APT41 · G0096 · Pinned relationship source (relationship--b6f1f9f1-05d9-4ac6-b191-404443430b2b)
- Wizard Spider · G0102 · Pinned relationship source (relationship--fcee0cef-7d5b-49da-928c-2a3d0cfd06b0)
- Chimera · G0114 · Pinned relationship source (relationship--f7120568-70db-4111-985c-9970775206c1)
- Indrik Spider · G0119 · Pinned relationship source (relationship--f9ca130a-1356-4a0a-9d38-ee7d2f9a51f6)
- Mustang Panda · G0129 · Pinned relationship source (relationship--43924791-6149-4869-a30c-0cad37d1e6f6)
- Aquatic Panda · G0143 · Pinned relationship source (relationship--ba215171-4b5b-407f-931e-0d97ddb64909)
- Earth Lusca · G1006 · Pinned relationship source (relationship--9889f167-2a60-4e32-8d2a-410f485551b7)
- LuminousMoth · G1014 · Pinned relationship source (relationship--f2ab4a93-9b9f-4c14-a879-200c512d406f)
- Mustard Tempest · G1020 · Pinned relationship source (relationship--9d2fbb81-fd66-4d1b-b919-58d251a06dbe)
- Cinnamon Tempest · G1021 · Pinned relationship source (relationship--dc059a21-6a00-4b04-ac54-23f9a76f4f4b)
- ToddyCat · G1022 · Pinned relationship source (relationship--56f08580-ffab-4c02-8702-adbe4de12a6a)
- Play · G1040 · Pinned relationship source (relationship--96673f49-a12b-4d0a-954f-17117b02bfa1)
- BlackByte · G1043 · Pinned relationship source (relationship--cb245afb-7787-4fc4-9ca6-0089c2d4251b)
- Storm-1811 · G1046 · Pinned relationship source (relationship--2b5ece1f-a678-40af-b4e3-1787ae3de343)
- Storm-0501 · G1053 · Pinned relationship source (relationship--2b25526e-abb9-4c6b-aa68-cc645734cdfb)
- MirrorFace · G1054 · Pinned relationship source (relationship--08fa7188-a43c-4b13-bbe7-af8f04f5b6e9)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1001.003 · Protocol or Service Impersonation · Detection rules & anomalies
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1003.002 · Security Account Manager · Detection rules & anomalies
- T1005 · Data from Local System · Detection rules & anomalies
- T1007 · System Service Discovery · Detection rules & anomalies
- T1012 · Query Registry · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1018 · Remote System Discovery · Detection rules & anomalies
- T1021.001 · Remote Desktop Protocol · Detection rules & anomalies
- T1021.002 · SMB/Windows Admin Shares · Detection rules & anomalies
- T1021.003 · Distributed Component Object Model · Detection rules & anomalies
- T1021.004 · SSH · Detection rules & anomalies
- T1021.006 · Windows Remote Management · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.005 · Indicator Removal from Tools · Detection rules & anomalies
- T1029 · Scheduled Transfer · Detection rules & anomalies
- T1030 · Data Transfer Size Limits · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1055.001 · Dynamic-link Library Injection · Detection rules & anomalies
- T1055.012 · Process Hollowing · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1059.005 · Visual Basic · Detection rules & anomalies
- T1059.006 · Python · Detection rules & anomalies
- T1059.007 · JavaScript · Detection rules & anomalies
- T1068 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1069.001 · Local Groups · Detection rules & anomalies
- T1069.002 · Domain Groups · Detection rules & anomalies
- T1070.006 · Timestomp · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1071.002 · File Transfer Protocols · Detection rules & anomalies
- T1071.004 · DNS · Detection rules & anomalies
- T1078.002 · Domain Accounts · Detection rules & anomalies
- T1078.003 · Local Accounts · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1090.001 · Internal Proxy · Detection rules & anomalies
- T1090.004 · Domain Fronting · Detection rules & anomalies
- T1095 · Non-Application Layer Protocol · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1132.001 · Standard Encoding · Detection rules & anomalies
- T1134.001 · Token Impersonation/Theft · Detection rules & anomalies
- T1134.003 · Make and Impersonate Token · Detection rules & anomalies
- T1134.004 · Parent PID Spoofing · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1137.001 · Office Template Macros · Detection rules & anomalies
- T1140 · Deobfuscate/Decode Files or Information · Detection rules & anomalies
- T1185 · Browser Session Hijacking · Detection rules & anomalies
- T1197 · BITS Jobs · Detection rules & anomalies
- T1203 · Exploitation for Client Execution · Detection rules & anomalies
- T1218.011 · Rundll32 · Detection rules & anomalies
- T1497.002 · User Activity Based Checks · Detection rules & anomalies
- T1518 · Software Discovery · Detection rules & anomalies
- T1543.003 · Windows Service · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1548.003 · Sudo and Sudo Caching · Detection rules & anomalies
- T1550.002 · Pass the Hash · Detection rules & anomalies
- T1553.002 · Code Signing · Detection rules & anomalies
- T1564.010 · Process Argument Spoofing · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
- T1572 · Protocol Tunneling · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1620 · Reflective Code Loading · Detection rules & anomalies
- T1685 · Disable or Modify Tools · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Application Log Content · DC0038
- Cloud Service Enumeration · DC0083
- Cloud Service Modification · DC0069
- Command Execution · DC0064
- Container Enumeration · DC0091
- Driver Load · DC0079
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Firewall Rule Modification · DC0051
- Firmware Modification · DC0004
- Host Status · DC0018
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Named Pipe Metadata · DC0048
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Process Termination · DC0033
- Scheduled Job Metadata · DC0005
- Script Execution · DC0029
- Service Creation · DC0060
- Service Metadata · DC0041
- Service Modification · DC0065
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- WMI Creation · DC0008
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.