EH-Net
May 23, 2013, 07:56:51 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-Video Review: Cobalt Strike Penetration Testing Software  (Read 25516 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4167


Editor-In-Chief


View Profile WWW
« on: June 29, 2012, 05:10:30 PM »

Ryan Linn is back with another video. This time he explores a new commercial tool that has been spawned from a free tool. But in a twist, this one comes from the same man who wrote the free version. Got to love an entrepreneurial spirit!

Let us know what you think about the tool, it's cost, plans to give it a try or anything else that hits your brain.

Permanent link: [Article]-Video Review: Cobalt Strike Penetration Testing Software

Quote


By Ryan Linn

Cobalt Strike is the latest tool that Raphael Mudge (@Armitagehacker) has released at http://www.advancedpentest.com/ to help penetration testers optimize their workflow and pen testing tasks.  Cobalt Strike is a commercially supported version of Armitage, Cyber Attack Management for Metasploit, with a whole slew of new features added to aid in social engineering attacks, phishing, and targeted exploitation.  As described on their own site:

   "Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Cobalt Strike exploits network vulnerabilities, launches spear phishing campaigns, hosts web drive-by attacks, and generates malware infected files from a powerful graphical user interface that encourages collaboration and reports all activity."

Stay with us after the break as we examine more details of this new software package, thoughts on how it might fit into your arsenal of tools and also an exclusive video by Ryan Linn offering a first look at Cobalt Strike to all EH-Netters.


Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #1 on: June 29, 2012, 05:56:14 PM »

great tool don it seems cobalt strike works with metasploit right?
Logged

ICS Academy Network Security Certified
apollo
Moderator
Full Member
*****
Offline Offline

Posts: 146


View Profile WWW
« Reply #2 on: June 29, 2012, 11:48:05 PM »

Just to be clear, Cobalt Strike leverages Metasploit for a lot of it's attacks.  It's a further development for the Armitage front end that acts as a Java based front end for Metasploit, but Cobalt Strike has addressed a lot of the workflow, reporting, and other automation that isn't easy from within Armitage, Metasploit base install or other tools that leverage Metasploit.  Cobalt Strike is a step forward from just "using Metasploit" to letting a Pen Tester take advantage of the framework core functions, but allowing a lot of the things that become tedious to be made easy through the GUI interface.  It is session aware, allows you to set easy pre-sets that are selectable, allow you to run exploits against groups of hosts, and other things that the other tools just don't let you do as easily. 


Logged

CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #3 on: June 30, 2012, 01:09:38 AM »

Thanks apollo for your efficient answer.
Logged

ICS Academy Network Security Certified
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.12 seconds with 20 queries.