Abridged sample record. It uses the same report renderer as the analyst workspace, with no account needed.

Generate a report
Back to home

Threat intelligence report

Cobalt Strike

Acceptable

A curated, source-backed profile showing how the production renderer presents narrative, code, metadata, and citation evidence for review.

This sample is intentionally shorter than a generated report and omits the full research methodology, raw extraction record, and evaluator appendix. It is a retained schema-4 fixture, so current snapshot-verified admissibility is intentionally unassessed.

Content quality
3.50 / 5.00
Acceptable · readiness tracked separately
Category
Malware
Canonical report category
Threat family
Post Exploitation Framework
Canonical report classification
Sources
3 cited
Open and inspect each source

Intelligence narrative

Cobalt Strike

Executive Summary

Cobalt Strike is a commercial adversary-simulation platform whose Beacon payload supports post-exploitation activity. The official product documentation describes its command-and-control and extensibility features; MITRE ATT&CK catalogs the software as S0154 and maps observed techniques.

Defenders should treat the presence of an unauthorized Beacon as high-priority evidence while preserving the distinction between legitimate assessment use and malicious deployment.

Profile Metadata

FieldValue
CategoryPost-exploitation framework
ClassificationDual-use software
ATT&CK software IDS0154
Review postureAcceptable

Capabilities and Observed Use

  • Beacon supports command execution, file transfer, and configurable command-and-control behavior.
  • Operators can adapt traffic profiles and extend workflows for an engagement.
  • CISA reporting documents threat actors using Cobalt Strike Beacons for persistence, credential access, lateral movement, and data exfiltration in a wider intrusion chain. S3

Forensic Artifacts

A memory-resident Beacon payload inside an injected process is a forensic artifact analysts can preserve and investigate. S2

Detection Guidance

Correlate endpoint and network evidence rather than relying on a single signature:

  1. Investigate process injection and memory-resident payload behavior.
  2. Hunt for periodic callbacks to low-reputation infrastructure, accounting for sleep and jitter. S1 S2
  3. Review credential-access and lateral-movement activity that follows an initial Beacon alert.
title: Suspicious Beacon Follow-on Activity
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith: "\\rundll32.exe"
    Image|endswith: "\\powershell.exe"
  condition: selection

Mitigation Priorities

  • Restrict unnecessary outbound traffic and monitor long-lived HTTP, HTTPS, and DNS sessions.
  • Enforce least privilege and application control to limit payload execution and lateral movement. S2 S3
  • Preserve endpoint telemetry needed to connect injection, credential access, and command-and-control activity.

This sample demonstrates the report format. Analysts should validate each finding against current evidence before operational use.

Analyst workspace

Start with evidence attached

Generate a report, inspect each source, and keep the evidence beside the analyst decision.

Open workspace