logo

Modern Defenses and YOU!

ID: c0b0979c-991a-5b30-9cd8-fa4323b0b343

STIX ID: report--c0b0979c-991a-5b30-9cd8-fa4323b0b343

Feed Name: SpecterOps Blog

Date Published: 2017-10-25

Date Updated: 2026-04-30

Author: Raphael Mudge

...
...

This post outlines modern evasion and OPSEC techniques for Cobalt Strike operations: choose plausible host processes and infrastructure (e.g., aged, categorized domains, domain fronting), minimize risky child processes via session prepping (ppid spoofing, spawnto), avoid remote process injection and PowerShell in favor of API-driven actions and .NET assemblies, and improve in-memory stealth by using stageless/x64 payloads, Malleable PE options, non-RWX pages, and legitimate code-signing. It emphasizes adapting tradecraft to defender telemetry and heuristics to blend with normal activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.