Threat intelligence report
Cobalt Strike
AcceptableA curated, source-backed profile showing how the production renderer presents narrative, code, metadata, and citation evidence for review.
This sample is intentionally shorter than a generated report and omits the full research methodology, raw extraction record, and evaluator appendix. It is a retained schema-4 fixture, so current snapshot-verified admissibility is intentionally unassessed.
- Content quality
- 3.50 / 5.00
- Acceptable · readiness tracked separately
- Category
- Malware
- Canonical report category
- Threat family
- Post Exploitation Framework
- Canonical report classification
- Sources
- 3 cited
- Open and inspect each source
Intelligence narrative
Cobalt Strike
Executive Summary
Cobalt Strike is a commercial adversary-simulation platform whose Beacon payload supports post-exploitation activity. The official product documentation describes its command-and-control and extensibility features; MITRE ATT&CK catalogs the software as S0154 and maps observed techniques.
Defenders should treat the presence of an unauthorized Beacon as high-priority evidence while preserving the distinction between legitimate assessment use and malicious deployment.
Profile Metadata
| Field | Value |
|---|---|
| Category | Post-exploitation framework |
| Classification | Dual-use software |
| ATT&CK software ID | S0154 |
| Review posture | Acceptable |
Capabilities and Observed Use
- Beacon supports command execution, file transfer, and configurable command-and-control behavior.
- Operators can adapt traffic profiles and extend workflows for an engagement.
- CISA reporting documents threat actors using Cobalt Strike Beacons for persistence, credential access, lateral movement, and data exfiltration in a wider intrusion chain. S3
Forensic Artifacts
A memory-resident Beacon payload inside an injected process is a forensic artifact analysts can preserve and investigate. S2
Detection Guidance
Correlate endpoint and network evidence rather than relying on a single signature:
- Investigate process injection and memory-resident payload behavior.
- Hunt for periodic callbacks to low-reputation infrastructure, accounting for sleep and jitter. S1 S2
- Review credential-access and lateral-movement activity that follows an initial Beacon alert.
title: Suspicious Beacon Follow-on Activity
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: "\\rundll32.exe"
Image|endswith: "\\powershell.exe"
condition: selection
Mitigation Priorities
- Restrict unnecessary outbound traffic and monitor long-lived HTTP, HTTPS, and DNS sessions.
- Enforce least privilege and application control to limit payload execution and lateral movement. S2 S3
- Preserve endpoint telemetry needed to connect injection, credential access, and command-and-control activity.
This sample demonstrates the report format. Analysts should validate each finding against current evidence before operational use.
Analyst workspace
Start with evidence attached
Generate a report, inspect each source, and keep the evidence beside the analyst decision.