logo

CobaltStrike: The Penetration Testing Framework & Our Adversaries

ID: ae6e7a49-23bc-5f6a-a338-ab0a995f1dd8

STIX ID: report--ae6e7a49-23bc-5f6a-a338-ab0a995f1dd8

Feed Name: BushidoToken Blog

Threat Score
75/100

Date Published: 2020-06-27

Date Updated: 2026-07-22

...
...

This report catalogs numerous sightings and analyses of CobaltStrike being used by red teams, cybercriminal groups (including ransomware affiliates such as those deploying WastedLocker, Maze, Sodinokibi/REvil), and state-sponsored APTs for access, lateral movement, and persistence. It highlights maldocs, PowerShell and shellcode delivery, living-off-the-land techniques, and CobaltStrike beaconing masquerading as benign traffic, and recommends monitoring beacon indicators and endpoint infection vectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.