Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0154
MITRE ATT&CK Malware

Cobalt Strike (S0154)

ShareXLinkedInRedditHN

[Cobalt Strike](https://attack.mitre.org/software/S0154) is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.(Citation: cobaltstrike manual) In addition to its own capabilities, [Cobalt Strike](https://attack.mitre.org/software/S0154) leverages the capabilities of other well-known tools such as Metasploit and [Mimikatz](https://attack.mitre.org/software/S0002).(Citation: cobaltstrike manual)

Platforms: Linux, macOS, Windows

▪Techniques implemented (73)

T1090.004Domain FrontingT1548.003Sudo and Sudo CachingT1553.002Code SigningT1059.007JavaScriptT1021.001Remote Desktop ProtocolT1106Native APIT1550.002Pass the HashT1078.002Domain AccountsT1027.005Indicator Removal from ToolsT1548.002Bypass User Account ControlT1016System Network Configuration DiscoveryT1569.002Service ExecutionT1005Data from Local SystemT1055.001Dynamic-link Library InjectionT1056.001KeyloggingT1197BITS JobsT1055.012Process HollowingT1518Software DiscoveryT1078.003Local AccountsT1090.001Internal ProxyT1068Exploitation for Privilege EscalationT1113Screen CaptureT1564.010Process Argument SpoofingT1112Modify RegistryT1069.002Domain GroupsT1049System Network Connections DiscoveryT1001.003Protocol or Service ImpersonationT1134.004Parent PID SpoofingT1134.001Token Impersonation/TheftT1543.003Windows ServiceT1059.005Visual BasicT1055Process InjectionT1007System Service DiscoveryT1070.006TimestompT1083File and Directory DiscoveryT1071.004DNST1029Scheduled TransferT1069.001Local GroupsT1059.001PowerShellT1021.004SSHT1620Reflective Code LoadingT1018Remote System DiscoveryT1003.001LSASS MemoryT1685Disable or Modify ToolsT1012Query RegistryT1087.002Domain AccountT1497.002User Activity Based ChecksT1030Data Transfer Size LimitsT1046Network Service DiscoveryT1135Network Share DiscoveryT1071.001Web ProtocolsT1573.002Asymmetric CryptographyT1185Browser Session HijackingT1140Deobfuscate/Decode Files or InformationT1572Protocol TunnelingT1021.006Windows Remote ManagementT1573.001Symmetric CryptographyT1095Non-Application Layer ProtocolT1132.001Standard EncodingT1105Ingress Tool TransferT1021.002SMB/Windows Admin SharesT1218.011Rundll32T1071.002File Transfer ProtocolsT1059.006PythonT1047Windows Management InstrumentationT1003.002Security Account ManagerT1134.003Make and Impersonate TokenT1203Exploitation for Client ExecutionT1021.003Distributed Component Object ModelT1057Process DiscoveryT1137.001Office Template MacrosT1059.003Windows Command ShellT1027Obfuscated Files or Information

▪Used by groups (30)

G1054MirrorFaceG1053Storm-0501G1046Storm-1811G0129Mustang PandaG0027Threat Group-3390G0050APT32G1022ToddyCatG0073APT19G0037FIN6G0092TA505G0052CopyKittensG0079DarkHydrusG1040PlayG1006Earth LuscaG0046FIN7G1020Mustard TempestG0096APT41G0045menuPassG0143Aquatic PandaG0080Cobalt GroupG0034Sandworm TeamG1043BlackByteG0065LeviathanG0016APT29G1021Cinnamon TempestG0067APT37G1014LuminousMothG0114ChimeraG0119Indrik SpiderG0102Wizard Spider
S0154on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.