Netskope Threat Labs

Cobalt Strike

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Cobalt Strike is a legitimate penetration testing framework that cyberattackers frequently abuse as a command and control tool. Its Beacon implant gives operators persistent access to compromised hosts, executes commands and deployed payloads, and moves laterally across a network. Malleable C2 profiles let cyberattackers disguise beacon traffic as ordinary web activity, which helps the framework evade detection, and cracked copies circulate widely in criminal toolkits.

First seen
January 2022
Last seen
October 2026
CobaltCobaltStrCobaltStrikeCobaltStrikeBeaconCobaltstrikeCobeacon

73 techniques across 11 tactics.

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

  • T1068Exploitation for Privilege Escalation
  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1029Scheduled Transfer
  • T1030Data Transfer Size Limits

TA0112 Defense Impairment

Alert Name
Application.Hacktool.CobaltStrike.A
Binary.Backdoor.CobaltStrike
Binary.Malware.CobaltStrike
Binary.Trojan.CobaltStrike
ByteCode-JAVA.Backdoor.CobaltStrikeBeacon
ByteCode-MSIL.Backdoor.CobaltStrike
ByteCode-MSIL.Backdoor.CobaltStrikeBeacon
ByteCode-MSIL.Downloader.CobaltStrike
ByteCode-MSIL.Trojan.CobaltStr
ByteCode-MSIL.Trojan.CobaltStrike
Signature Name
ET MALWARE Cobalt Strike Activity (GET)
ET MALWARE Cobalt Strike Beacon (Custom Wordpress Profile)
ET MALWARE Cobalt Strike Beacon Activity
ET MALWARE Cobalt Strike Beacon Activity (GET)
ET MALWARE Cobalt Strike CnC Activity (GET)
ET MALWARE Cobalt Strike CnC Beacon (POST)
ET MALWARE Cobalt Strike CnC Checkin (Submit Result)
ET MALWARE Cobalt Strike Get Mission Request (POST)
ET MALWARE Cobalt Strike Malleable C2 (Amazon Profile)
ET MALWARE Cobalt Strike Malleable C2 (Custom Profile)