Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Jan 21, 2021 | Updated Dec 19, 2022

Behavior:Win32/CobaltStrike.A!nri

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

This is a behavioral monitoring signature for network activities related to Cobalt Strike, a commercial adversary simulation software often used by ransomware operators and other threat actors to deploy other threats.

If you have cloud-delivered protection, your device gets the latest defenses against new and unknown threats. If you don't have this feature enabled, update your antimalware definitions and run a full scan to remove this threat.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us