logo

A Morning with Cobalt Strike & Symantec

ID: 4d9cad9b-c227-5c8e-84d8-6981ed6b9958

STIX ID: report--4d9cad9b-c227-5c8e-84d8-6981ed6b9958

Feed Name: Black Hills Infosec Blog

Threat Score
60/100

Date Published: 2017-12-04

Date Updated: 2026-04-27

Author: BHIS

...
...

A penetration tester describes experiments using Cobalt Strike to deliver PowerShell-generated 32-bit and 64-bit payloads against Symantec endpoint protection. 32-bit payloads triggered IPS alerts and were blocked, while 64-bit shellcode established C2 in multiple configurations; however, an Amazon-like HTTP GET profile triggered Symantec HIPS to reset TCP connections, and a minor modification to the GET path bypassed that detection. The report highlights that custom, widely published C2 profiles can be signatured and that memory-delivered 64-bit shellcode may still succeed against some endpoint defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.