Cobalt Strike
Think like the attacker — because red teams have to be the attacker
What it is
About Cobalt Strike
Cobalt Strike provides a post-exploitation Beacon agent, covert command-and-control channels and team-collaboration features that let penetration testers simulate a stealthy, persistent adversary inside a target network. It is the long-standing gold standard for professional red-team engagements, though its capabilities have also made it a favourite of real-world ransomware operators, making licensed, controlled use and detection-engineering awareness both critical skills.
What you can do with it
Capabilities
Deploy a Beacon payload to simulate post-exploitation persistence and lateral movement
Run collaborative, multi-operator red team engagements with shared C2 infrastructure
Emulate specific known threat-actor TTPs to test blue-team detection
Pivot through compromised hosts to reach deeper network segments
Generate reports mapping simulated attack paths to MITRE ATT&CK techniques
How to learn it
Learning Resources
Official Cobalt Strike documentation and the vendor's training/certification offerings
SANS SEC565 (Red Team Operations and Adversary Emulation) course
TrustedSec and Red Siege blog write-ups on Cobalt Strike tradecraft
Practise legally in a home lab or via platforms like HackTheBox/TryHackMe red-team modules (note: full Cobalt Strike itself requires a paid, vetted licence)
Pro Tip
Never run Cobalt Strike (or any C2 framework) against a network without explicit written authorisation — its capabilities are functionally identical to real malware, and unlicensed/cracked copies are a leading tool in actual ransomware attacks
Skills that use this tool
Roles that use this tool