Skip to main content
Skip to main content
Microsoft Security Intelligence
12 entries found.
Updated on Feb 18, 2021

This is a detection for the VBA file with XML content (commonly used in Microsoft Office files such as Excel, Word, and PowerPoint). The XML content is responsible for downloading the Cobalt Strike loader from the intended malicious URL.

Cobalt Strike is a commercially available penetration testing tool used for adversary simulation.  It’s also known for being used by threat actors in various campaigns and found in many pre-ransomware incidents.

For information about Cobalt Strike and other human-operated malware campaigns, read these blog posts: 

Alert level: severe
Updated on May 17, 2022
Alert level: severe
Updated on Mar 03, 2021

This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.

Alert level: high
Updated on Mar 23, 2021

This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.

Alert level: high
Updated on Jul 31, 2021

This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.

Alert level: severe
Updated on Aug 13, 2021

This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.

Alert level: severe
Updated on Sep 07, 2023

Behavior:Win32/CobaltStrike detects various generic behaviors exhibited by CobaltStrike Beacon.

Alert level: severe
Updated on May 16, 2019

This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.

Alert level: severe
Updated on Aug 02, 2020

This is a detection for Cobalt Strike Beacon, which is a software component that gets deployed in target devices and allows an attacker remote access to the device to perform various tasks.

Alert level: severe
Updated on Aug 21, 2023
Alert level: high
Updated on Mar 12, 2022

This threat downloads and installs other programs, including other malware, onto your PC without your consent.

TrojanDownloader:Win32/CobaltStrike is a trojan that downloads and installs the Cobalt Strike beacon.

Alert level: severe
Updated on Jul 29, 2020

This is a detection for the PowerShell script responsible for downloading the Cobalt Strike loader from an .onion website or other intended malicious URL.

Cobalt Strike is a commercially available penetration testing tool used for adversary simulation.  It’s also known for being used by threat actors in various campaigns and found in many pre-ransomware incidents.

Read the following blogs for details:

Alert level: severe