ÄÚÍøÉøÍ¸ÊÇÿһ¸ö»Æ½ð³Ç¹ÙÍø¹¤³ÌÊ¦ÈÆ²»¹ýÈ¥µÄÄÑÌ⣬Ϊʲô´ó¼Ò¶¼¾õµÃÄÚÍøÉøÍ¸Òª±ÈÆäËû·½ÃæµÄÉøÍ¸²âÊÔ¸üΪͷÌÛ£¬ÆäʵÖ÷ÒªÔÒò»¹ÊÇÔÚ´ó¼Ò¶Ô¹¥ÈëÄ¿±êÍøÂçµÄ»·¾³¸Ðµ½Ä°Éú°ÕÁË¡£µÚÒ»´Î½øÈëÄ¿±êÄÚÍø£¬¶À×ÔÒ»ÈËÃæ¶ÔÅÓ´óµÄÄ¿±êÏµÍ³ÍøÂç¡¢¸÷ÖÖ¸´ÔӵķÖÇø½á¹¹£¬ºÜÈÝÒ×·¸ÃÔºý¡£Èç¹ûÕâʱÄÜÓиöteam°ïÖúÄãÒ»Æð̽Ë÷ÄÚÍø¡¢Ò»ÆðÐ×÷£¬ÏÔÈ»»áʹµÃÄÚÍøÉøÍ¸µÄÄѶȴó´ó½µµÍ¡£
±¾ÆÚ»Æ½ð³Ç»Æ½ð³Ç¹ÙÍøÊµÑéÊÒ½«¸ø´ó¼Ò½éÉÜÒ»¿îÄܹ»ÓÃÓÚÄÚÍøÉøÍ¸Ê±ÍŶÓÐͬ×÷Õ½µÄ¹¤¾ß¡°Cobalt Strike¡±¡£
01CobaltStrike¹¤¾ß¼ò½é
Cobalt StrikeÊÇÒ»¿îÒÔmetasploitΪ»ù´¡µÄGUIµÄ¿ò¼ÜÊ½ÉøÍ¸¹¤¾ß£¬¼¯³ÉÁ˶˿Úת·¢¡¢·þÎñɨÃ裬×Ô¶¯»¯Òç³ö£¬¶àģʽ¶Ë¿Ú¼àÌý£¬winexeľÂíÉú³É£¬win dllľÂíÉú³É£¬javaľÂíÉú³É£¬officeºê²¡¶¾Éú³É£¬Ä¾ÂíÀ¦°ó£»µöÓã¹¥»÷°üÀ¨£ºÕ¾µã¿Ë¡£¬Ä¿±êÐÅÏ¢»ñÈ¡£¬javaÖ´ÐУ¬ä¯ÀÀÆ÷×Ô¶¯¹¥»÷µÈµÈ¡£
Cobalt StrikeÖ÷ÒªÓÃÓÚÍŶÓ×÷Õ½£¬¿ÉÒÔ˵ÊÇÄÚÍøÉøÍ¸ÖеÄÍŶÓÉøÍ¸ÉñÆ÷£¬CobaltStrikeÄܹ»Èöà¸ö¹¥»÷ÕßͬʱÁ¬½Óµ½ÍŶӷþÎñÆ÷ÉÏ£¬¹²Ïí¹¥»÷×ÊÔ´ÓëÄ¿±êÐÅÐĺÍSession¡£ÒªÖªµÀÖÚÈËʰ²ñ»ðÑæ¸ßµÄµÀÀí£¬µ±ÎÒÃÇ·¢ÏÖÒ»¸öÄÚÍø¿ØÖƵãºó£¬ÎªÁËʹÎÒÃǵĹ¥»÷ÊÕÒæ×î´ó»¯£¬×îºÃµÄ°ì·¨¾ÍÊǸúÍŶӹ²Ïí×ÊÔ´£¬¸øÆäËû³ÉÔ±ÌṩͬÑùµÄ½ÓÈëµã£¬Cobalt StrikeºÜºÃµÄ×öµ½ÁËÕâÒ»µã¡£Òò´ËCobalt Strike×÷Ϊһ¿îÐͬAPT¹¤¾ß£¬Õë¶ÔÄÚÍøµÄÉøÍ¸²âÊÔºÍ×÷ΪAPTµÄÖÕ¶Ë¿ØÖƹ¦ÄÜ£¬Ê¹Æä±ä³ÉÖÚ¶àAPT×éÖ¯µÄÊ×Ñ¡¹¤¾ß¡£
02Cobalt Strike¹¦ÄÜʹÓÃ
1. °²×°Cobalt Strike
a) ·þÎñ¶Ë£º
ÔÚ·þÎñ¶ËÖ´ÐÐteamserver¼´¿É£¬ÃüÁî¸ñʽΪ./teamserver <·þÎñ¶ËIP> <Á¬½ÓÃÜÂë>
Ò»°ãÀ´Ëµ£¬Èç¹ûÍŶӳÉÔ±¶¼´¦ÔÚÒ»¸ö¾ÖÓòÍøÏ£¬ÄÇôֻÐèÒªÕÒһ̨Äܹ»·ÃÎʵ½Ä¿±êÄÚÍøµÄ»úÆ÷µ±×÷·þÎñ¶Ë¼´¿É£¬ÀýÈç±¾»ú¡¢Ìø°å»úµÈµÈ£¬²»Ò»¶¨·ÇµÃʹÓÃVPS£¬»¹ÐèÒª¿¼ÂÇÄ¿±êÄÚÍøÊÇ·ñÄܳöÍø¡£
b) ¿Í»§¶Ë£º
ÔÚ¿Í»§¶Ë£¬Ö»ÐèÒªÔËÐÐcobaltstrike.jarÎļþ£¬Ä¬ÈÏÁ¬½Ó·þÎñ¶ËµÄ¶Ë¿ÚÊÇ50050£¬µ«Òª×¢ÒâµÄÊDZØÐëÒªÓë·þÎñ¶ËËùÆô¶¯µÄ°æ±¾Ïàͬ£¬ÀýÈç·þÎñ¶ËʹÓÃÁËcobaltstrike3.8°æ±¾µÄteamserver£¬ÄÇô¿Í»§¶Ë¾Í±ØÐëÆô¶¯cobaltstrike3.8µÄjarÎļþ£¬²Å²»»á³ö´í¡£

ÕýÈ·Ìîд·þÎñ¶ËIPÒÔ¼°¶Ë¿ÚºÍÃÜÂë¼´¿É£¬³É¹¦Á¬½Ó·þÎñ¶Ë¡£

2. Cobalt Strike¹¦ÄܽéÉÜ
|Cobalt Strike
|<-------New Connection #½¨Á¢ÐµÄÁ¬½Ó£¬ÔÊÐíÁ¬½Ó¶à¸ö·þÎñÆ÷¶Ë
|<-------Preferences #Æ«ºÃÉèÖ㨽çÃæ¡¢¿ØÖÆÌ¨ÑùʽÉèÖõȣ©
|<-------Visualization #´°¿ÚÊÓͼģʽ£¨½á¹ûÊä³öģʽ£©
|<-------Pivot Graph #͸ÊÓͼģʽ
|<-------Session Table #Session±íģʽ
|<-------Target Table #Ä¿±ê±íģʽ
|<-------VPN Interfaces #VPN½ÓÈë
|<-------Listeners #¼àÌýÆ÷£¨´´½¨Listener£©
|<-------Script Manager #½Å±¾¹ÜÀí¹¦ÄÜ
|View
|<-------Applications #ÏÔʾĿ±ê»úµÄÓ¦ÓÃÐÅÏ¢
|<-------Credentials #ƾ֤£¨ËùÓÐͨ¹ýMimikatzץȡµÄÃÜÂë¶¼´æ´¢ÔÚÕâÀ
|<-------Downloads #ÏÂÔØÎļþ
|<-------Event Log #ʼþÈÕÖ¾£¬Ö÷»úÉÏÏ߼Ǽ¼°ÍŶӽ»Á÷¼Ç¼
|<-------Keystrokes #¼üÅ̼Ǽ
|<-------Proxy Pivots #´úÀíÄ£¿é
|<-------Screenshots #²é¿´Ä¿±ê»ú½ØÍ¼
|<-------Script Console #½Å±¾¿ØÖÆÌ¨
|<-------Targets #ÏÔʾĿ±êÖ÷»ú
|<-------Web Log #WebÈÕÖ¾
|Attacks
|<-------Packages
|<-------HTML Application #Éú³É¶ñÒâµÄHTAľÂí
|<-------MS Office Macro #Éú³ÉOfficeºê²¡¶¾Îļþ
|<-------Payload Generator #Éú³É¸÷ÖÖÓïÑÔ°æ±¾µÄpayload
|<-------USB/CD AutoPlay #Éú³É×Ô¶¯²¥·ÅÖ´ÐеÄľÂíÎļþ
|<-------Windows Dropper #À¦°óÆ÷¡¢ÊµÏÖ¶ÔÎĵµÀà½øÐÐÀ¦°ó
|<-------Windows Executable #Éú³ÉEXEµÄpayload
|<-------Windows Executable(S) #°Ñ°üº¬payload£¬StagelessÉú³ÉEXE
|<-------Web Drive-by #µöÓã¹¥»÷
|<-------Manage #¶Ô¿ªÆôµÄWeb·þÎñ½øÐйÜÀí
|<-------Clone Site #¿ËÂ¡ÍøÕ¾
|<-------Host File #ÌṩWebÒÔ¹©ÏÂÔØÄ³Îļþ
|<-------Scripted Web Delivery #ÌṩWebÒÔ¹©ÏÂÔØpowershell
|<-------Signed Applet Attack #ʹÓÃjava×ÔÇ©ÃûµÄ³ÌÐò½øÐеöÓã
|<-------Smart Applet Attack #×Ô¶¯¼ì²âjava°æ±¾½øÐй¥»÷
|<-------System Profiler #ÓÃÀ´»ñȡϵͳÐÅÏ¢
|<-------Spear Phish #ÓʼþµöÓã
|Reporting #±¨¸æÕ¹Ê¾Ä£¿é
3. Cobalt StrikeʹÓ÷½·¨
ÔÚÊìϤÁËCobalt Strike½çÃæÉÏËùÌṩµÄ¹¦Äܺó£¬ÎÒÃǽÓÏÂÀ´×ÅÖØ½²½âÒ»ÏÂCobalt StrikeµÄʹÓ÷½·¨¡£Ê¹ÓÃCobalt Strike×îÖ÷ÒªµÄÄ¿µÄÊÇΪÁËÈÃÍŶӵįäËû³ÉÔ±Ò²Äܹ»¶ÔÎÒÃÇ¿ØÖƵÄÄÚÍøÈ⼦½øÐвÙ×÷£¬ËùÒÔÎÒÃǵÚÒ»²½¿Ï¶¨ÊÇÈÃÎÒÃǵÄÄÚÍøÊܿػú³É¹¦ÉÏÏß¡£
Ê×ÏÈʹÓÃCobalt Strike×Ô´øµÄAttacksÄ£¿éÉú³ÉÎÒÃÇËùÐèÒªµÄľÂíÎļþ£¬ËùÒÔÎÒÃǵã»÷Attacks->Packages£¬¸ù¾ÝÊܿػúµÄ¾ßÌå²Ù×÷ϵͳ¼°°æ±¾Ñ¡Ôñ¶ÔÓ¦ÀàÐ͵ÄľÂíÎļþ£¬¼ÙÉèÎÒÃÇ¿ØÖÆÁËһ̨WIN2012µÄÄÚÍøÖ÷»ú£¬ÄÇôÎÒÃÇÑ¡ÔñpackagesÖеÄWindows Executable¹¦ÄÜ£¬ÏëÒªÉú³ÉÒ»¸öEXEÀàÐ͵ÄľÂíÎļþ¡£

ÕâÀïÎÒÃÇÐèÒªÅäÖÃÒ»ÏÂListener¼àÌýÆ÷£¬¼àÌýÆ÷µÄ¸ÅÄîÔںܶ๤¾ßÖж¼³öÏÖ¹ý£¬ÏñʲôMetasploit¡¢EmpireµÈµÈ£¬ÕâÀï¾Í²»ÔÙ׸Êö¡£×ܶøÑÔÖ®£¬ÔÚÅäÖüàÌýÆ÷ʱCobalt StrikeÖ»ÌṩÁË9ÖÖpayload£¬ÈçÏÂͼ£º

½«ÒÔÉÏÐÅÏ¢ÅäÖúú󣬵ã»÷Generate£¨Éú³É£©ÎÒÃǾ͵õ½ÁËÒ»¸öEXEÀàÐ͵ÄľÂíÎļþ¡£

½«Ä¾ÂíÎļþͨ¹ýÉÏ´«µã´«ÈëÄ¿±êÖ÷»ú²¢Ö´ÐУ¬¾Í¿ÉÒÔ¾ªÏ²µÄ·¢ÏÖÔÚCobalt Strike³öÏÖÁËÄ¿±ê»úµÄÐÅÏ¢¡£¶øÍŶӵįäËû³ÉÔ±Ò²¶¼¿ÉÒÔ¶ÔÕą̂»úÆ÷½øÐвÙ×÷ÁË¡£

³É¹¦½«Ëù¿ØÖƵÄÄ¿±ê»ú×ÊÔ´ÉÏÏßÖ®ºó£¬ÍŶÓÄ򵀮äËû³ÉÔ±¼´¿É¶Ô¸Ą̃»úÆ÷½øÐнøÒ»²½ÉøÍ¸¡£ÍŶӳÉԱͨ¹ýµã»÷Ä¿±ê»úÓÒ¼ü£¬Ñ¡ÔñInteract¹¦ÄÜ£¬¾Í¿ÉÒÔ¿ªÊ¼¶ÔÄ¿±ê¼°½øÐвÙ×÷£¬µ«ÊÇÍŶӳÉÔ±ËùÄܲÙ×÷µÄ¾ÍÊÇbeaconËùÌṩµÄ¸÷ÖÖÃüÁ½ÓÏÂÀ´ÎÒÃÇÀ´¿´Ò»¿´Beacon¶¼ÌṩÁËʲôָÁî¸øÉøÍ¸ÈËÔ±¡£
4. BeaconµÄÖ¸Áî½éÉÜ
browserpivot ×¢ÈëÊܺ¦Õßä¯ÀÀÆ÷½ø³Ì
bypassuac ÈÆ¹ýUACÌáÉýȨÏÞ
cancel È¡ÏûÕýÔÚ½øÐеÄÏÂÔØ
cd Çл»Ä¿Â¼
checkin Ç¿ÖÆÈñ»¿Ø¶Ë»ØÁ¬Ò»´Î
clear Çå³ýBeaconÄÚ²¿µÄÈÎÎñ¶ÓÁÐ
covertvpn ²¿ÊðCovert VPN¿Í»§¶Ë
cp ¸´ÖÆÎļþ
dcsync ´ÓDCÖÐÌáÈ¡ÃÜÂëHash
desktop Ô¶³Ì×ÀÃæ·þÎñ
dllinject ·´ÉäDLL×¢Èë½ø³Ì
download ÏÂÔØÎļþ
downloads ÁгöÕýÔÚ½øÐеÄÎļþÏÂÔØ
drives ÁгöÄ¿±êÅÌ·û
elevate ʹÓÃexp
execute ÔÚÄ¿±ê»úÉÏÖ´ÐгÌÐò
exit ½áÊøbeacon»á»°
getsystem ³¢ÊÔ»ñÈ¡SYSTEMȨÏÞ
getuid »ñÈ¡Óû§ID
hashdump ת´¢ÃÜÂëHashÖµ
inject ÔÚ×¢Èë½ø³ÌÉú³É»á»°
jobkill ½áÊøÒ»¸öºǫ́ÈÎÎñ
jobs Áгöºǫ́ÈÎÎñ
kerberos_ccache_use ´ÓcacheÎļþÖе¼ÈëÆ±¾ÝÓ¦ÓÃÓڴ˻Ự
kerberos_ticket_purge Çå³ýµ±Ç°»á»°µÄƱ¾Ý
kerberos_ticket_use ´ÓticketÎļþÖе¼ÈëµÄƱ¾ÝÓ¦ÓÃÓڴ˻Ự
keylogger ¼üÅ̼Ǽ
kill ½áÊø½ø³Ì
link ͨ¹ýÃüÃû¹ÜµÀÁ¬½Óµ½Beacon¶ÔµÈµã
logonpasswords ʹÓÃMimikatzת´¢ÃÜÂëhashºÍƾ֤
ls ÁгöÎļþ
make_token ´´½¨ÁîÅÆÒÔ´«µÝƾ¾Ý
mimikatz ÔËÐÐMimikatzÃüÁî
mkdir ´´½¨Ä¿Â¼
mode dns ʹÓÃDNS A×÷ΪͨÐÅͨµÀ
mode dns-txt ʹÓÃDNS TXT×÷ΪͨÐÅͨµÀ
mode dns6 ʹÓÃDNS AAAA×÷ΪͨÐÅͨµÀ
mode http ʹÓÃHTTP×÷ΪͨÐÅͨµÀ
mv ÒÆ¶¯Îļþ
net ÔËÐÐnetÃüÁî
note ±¸×¢
portscan ¶Ë¿ÚɨÃè
powerpick ͨ¹ýunmanaged powershellÖ´ÐÐÃüÁî
powershell ͨ¹ýpowershell.exeÖ´ÐÐÃüÁî
powershell-import µ¼Èëpowershell½Å±¾
ppid ΪÅÉÉúµÄpost-ex½ø³ÌÉèÖø¸PID
ps չʾ½ø³ÌÁбí
psexec ʹÓ÷þÎñÔÚÖ÷»úÉÏÉú³É»á»°
psexec_psh ʹÓÃPowerShellÔÚÖ÷»úÉÏÉú³É»á»°
psinject ÔÚÌØ¶¨½ø³ÌÖÐÖ´ÐÐPowerShellÃüÁî
pth ʹÓÃMimikatz½øÐйþÏ£´«µÝ
pwd ÏÔʾ³öµ±Ç°Ä¿Â¼
rev2self »Ö¸´ÔʼÁîÅÆ
rm ɾ³ýÎļþ»òÎļþ¼Ð
rportfwd ¶Ë¿Úת·¢
runas ÒÔÆäËûÓû§È¨ÏÞÖ´ÐгÌÐò
runu ÒÔÆäËû½ø³ÌIDÖ´ÐгÌÐò1
screenshot ÆÁÄ»½ØÍ¼
shell Ö´ÐÐcmdÃüÁî
shinject ½«shellcode×¢Èë½ø³Ì
shspawn Æô¶¯Ò»¸ö½ø³Ì²¢½«shellcode×¢Èë
sleep ÉèÖÃÐÝÃßʱ¼ä
socks Æô¶¯SOCKS4´úÀí
socks stop ֹͣSOCKS4
spawn Éú³É»á»°
spawnas ÒÔÁíÒ»Óû§Éí·ÝÉú³É»á»°
spawnu ÒÔÁíÒ»½ø³ÌIDÉú³É»á»°
ssh ʹÓÃsshÁ¬½ÓÔ¶³ÌÖ÷»ú
ssh-key ʹÓÃÃÜÔ¿Á¬½ÓÔ¶³ÌÖ÷»ú
steal_token ´Ó½ø³ÌÖÐÇÔÈ¡ÁîÅÆ
timestomp ½«Ò»¸öÎļþµÄʱ¼ä´ÁÓ¦Óõ½ÁíÒ»¸öÎļþ
unlink ¶Ï¿ªÁ¬½Ó
upload ÉÏ´«Îļþ
wdigest ʹÓÃMimikatzת´¢Ã÷ÎÄÆ¾¾Ý
winrm ʹÓÃWinRMºáÏòÉøÍ¸
wmi ʹÓÃWMIºáÏòÉøÍ¸
03Cobalt StrikeÄÚÍøÊµÕ½
ÍøÂç»·¾³£º
¹¥»÷»úIP£º192.168.20.35
Ä¿±êÄÚÍøÌø°å»ú£º192.168.210.102£¨WIN10£©
Ä¿±êÄÚÍøÓò¿Ø»ú£º192.168.210.108£¨WinServer 2012£©
¼ÙÉè³ÉÔ±AÒѾ³É¹¦ÈÃÄÚÍøÄ³Ì¨»úÆ÷£¨192.168.210.102£©ÉÏÏßCobalt Strike£¬³ÉÔ±B¿ªÊ¼³¢ÊÔ½øÒ»²½ÄÚÍøÉøÍ¸£¬Ê×ÏȲ鿴¸Ą̃»úÆ÷µÄÐÅÏ¢¡£¿ÉÒÔ¿´µ½£¬Õą̂»úÆ÷´¦ÔÚÒ»¸öHZMCµÄÓòÖУ¬ËùÒÔÎÒÃǵÄÏÂÒ»²½¼Æ»®¾ÍÊÇÏë°ì·¨ÄÃÏÂÓò¿ØÖ÷»úDC¡£

¸ù¾ÝÎÒÃÇÉÏһƪÎÄÕ£¬Ïêϸ½éÉÜÁËѰÕÒÓò¿ØÖ÷»úµÄ¼¸ÖÖ·½·¨£¬ÀýÈçping ÓòÃû»òÕßnet view /domainµÈµÈ£¬ÎÒÃdzɹ¦·¢ÏÖÁËÓò¿ØÖ÷»úµÄIP£¬Îª192.168.210.108

½ÓÏÂÀ´ÎÒÃdz¢ÊÔ¿´¿´ÔÚ102µÄ»úÆ÷ÉÏÊÇ·ñ±£ÁôÓÐÓò¿ØÃÜÂ룬ËùÒÔÎÒÃÇʹÓÃMimikatz¶Áȡһϱ¾µØµÄÃÜÂëת´¢£¬¹ûÈ»·¢ÏÖÁËÓòÕË»§ÃÜÂëµÄNTLM£¬ËäȻû·¢ÏÖÃ÷ÎÄÓеã¿Éϧ£¬±Ï¾¹W10ÒÔÉϵÄϵͳÒѾĬÈϲ»´æ´¢Ã÷ÎÄÃÜÂëÁË£¬µ«ÊÇÎÒÃÇ¿ÉÒÔÀûÓÃNTLMʵÐйþÏ£´«µÝ¡£


¸ú¾ÝÎÒÃÇǰ¼¸ÆªÎÄÕÂËù·ÖÎö¹ýµÄ¹þÏ£´«µÝ¹¥»÷Ò»Ñù£¬ÎÒÃÇÔÚ102Õą̂»úÆ÷ÉÏ£¬ÀûÓÃÓòÕË»§µÄNTLM½øÐÐPTH£¬Ö´ÐÐÒÔÏÂÃüÁ
mimikatz sekurlsa::pth /user:administrator
/domain:HZMC /ntlm:<ÓòÕË»§hash> /run:"cmd -whidden"
³É¹¦´«µÝ£¬²¢Ö´ÐÐÁËÒ»¸öCMD³ÌÐò£¬Í¨¹ý»ñÈ¡CMDµÄ½ø³ÌID¿ÉÒÔµÃÖª£¬ËûµÄPIDÊÇ5040.

½ÓÏÂÀ´£¬ÎÒÃÇÀûÓÃCobalt StrikeÌṩµÄÇÔÈ¡ÁîÅÆ¹¦ÄÜ£¬»ñµÃ¸Õ¸Õ´´½¨CMDµÄ½ø³ÌµÄÁîÅÆ£¬Ö´ÐÐÒÔÏÂÃüÁ
Stael_token 5040
ÕâʱÎÒÃÇÒѾ»ñµÃÁËÓëÓò¿ØCMD½»»¥µÄȨÏÞ¡£

µ«Õ⻹²»¹»£¬ÎÒÃÇÐèÒªÒ»¸ö¸üΪÎȶ¨µÄȨÏÞ£¬×îºÃÄܽ«Óò¿ØDCÉÏÏßµ½Cobalt StrikeÖУ¬ËùÒÔÎÒÃÇÔ¶³Ì´´½¨Ò»¸ö¼Æ»®ÈÎÎñ£¬²¢½«Ò»¸öÔ¶³ÌľÂíÎļþÀûÓÃcopyÃüÁî´«È뵽Ŀ±ê»úÖУ¬Í¨¹ý¼Æ»®ÈÎÎñÀ´´¥·¢¸ÃľÂíÎļþµÄÖ´ÐУ¬Ê¹Æä³É¹¦ÉÏÏß¡£


×îÖÕÓò¿Ø»ú³É¹¦ÉÏÏߣ¬ÖÁ´ËÎÒÃdzɹ¦»ñµÃÁ˸ÃÓòÄÚËùÓлúÆ÷µÄ·ÃÎÊȨÏÞ
