A Morning with Cobalt Strike & Symantec
ID: 4d9cad9b-c227-5c8e-84d8-6981ed6b9958
STIX ID: report--4d9cad9b-c227-5c8e-84d8-6981ed6b9958
Feed Name: Black Hills Infosec Blog
A penetration tester describes experiments using Cobalt Strike to deliver PowerShell-generated 32-bit and 64-bit payloads against Symantec endpoint protection. 32-bit payloads triggered IPS alerts and were blocked, while 64-bit shellcode established C2 in multiple configurations; however, an Amazon-like HTTP GET profile triggered Symantec HIPS to reset TCP connections, and a minor modification to the GET path bypassed that detection. The report highlights that custom, widely published C2 profiles can be signatured and that memory-delivered 64-bit shellcode may still succeed against some endpoint defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
