🎯 Goal

Today I explored several well-known offensive security frameworks and techniques used by attackers after initial access.

Topics included:

  • Metasploit
  • Cobalt Strike
  • PowerShell Empire
  • LOLBins (Living Off The Land Binaries)

The objective was to understand how attackers use legitimate system tools to execute malicious actions.


🛠 What I Did

I researched several well-known frameworks used in offensive security and real-world attacks.

Metasploit

Metasploit is an exploitation framework used for:

  • vulnerability exploitation
  • payload delivery
  • penetration testing

It allows attackers and researchers to test systems by launching exploits against vulnerable services.


Cobalt Strike

Cobalt Strike is a commercial adversary simulation tool often used by red teams.

However, it has also been widely abused by attackers.

Capabilities include:

  • command-and-control communication
  • post-exploitation operations
  • lateral movement
  • persistence mechanisms

PowerShell Empire

PowerShell Empire is another post-exploitation framework built around PowerShell.

It enables attackers to:

  • execute commands remotely
  • maintain persistence
  • escalate privileges
  • move laterally within networks.

🔗 Key Cybersecurity Connections

These frameworks often appear in real attack chains.

Example:

Initial access
↓
Payload execution
↓
Cobalt Strike beacon deployed
↓
Attacker performs lateral movement

Understanding these tools helps defenders recognize suspicious behavior.


🔍 Investigation Questions

If activity related to these frameworks appeared in endpoint telemetry, an analyst might investigate questions such as:

  • Which process initiated the suspicious activity?
  • Was PowerShell executed with unusual command-line arguments?
  • Did the system spawn unexpected child processes following execution?
  • Was there network communication with command-and-control infrastructure?
  • Are multiple hosts showing similar process execution patterns?
  • Did the activity occur shortly after initial access or credential compromise?

These types of questions help analysts determine whether post-exploitation frameworks are being used inside the environment.


🚨 Detection Opportunities

Possible detection strategies include:

  • detecting suspicious PowerShell execution patterns
  • monitoring abnormal parent → child process relationships
  • identifying beacon-like network traffic patterns associated with command-and-control activity
  • alerting on unusual execution of LOLBins such as rundll32, powershell, or certutil
  • correlating process execution with lateral movement behavior

Endpoint telemetry such as EDR data, PowerShell logs, and Sysmon process events can provide strong visibility into these behaviors.


🧭 MITRE ATT&CK Techniques

The behaviors associated with these frameworks relate to several MITRE ATT&CK techniques:

  • T1059 – Command and Scripting Interpreter
  • T1218 – Signed Binary Proxy Execution
  • T1105 – Ingress Tool Transfer
  • T1021 – Remote Services (Lateral Movement)
  • T1071 – Application Layer Protocol (Command-and-Control)

Mapping these techniques helps defenders understand how attackers move through different phases of an intrusion.


⚠ Challenges

One challenge is that many attacker techniques rely on legitimate system tools.

This makes detection harder.


📚 LOLBins (Living Off The Land Binaries)

LOLBins are legitimate system binaries abused by attackers.

Examples include:

  • powershell.exe
  • rundll32.exe
  • certutil.exe

Attackers use these tools to:

  • download payloads
  • execute malicious scripts
  • evade security controls.

📚 What I Learned

A famous LOLBin technique involves abusing:

rundll32 + mshtml

Example attack chain:

rundll32.exe
↓
loads mshtml engine
↓
downloads remote script
↓
executes payload

This technique is sometimes referred to as Squiblydoo.

Because it uses built-in Windows components, it can bypass some security restrictions.


➡ Next Steps

Next I want to explore:

  • how these techniques appear in logs
  • detection strategies used by SOC teams
  • command line indicators of compromise.

🧠 Reflection

Understanding attacker tools is essential for defenders.

Security analysts must recognize when legitimate utilities are being used in suspicious ways.


🧩 Lessons Learned

What worked

Studying real attack tools helped connect theoretical concepts to practical threats.

What broke

Many attacker techniques rely on legitimate binaries.

Why it broke

Traditional security models often assume malicious tools are obvious.

Fix / takeaway

Detection must focus on behavior, not only on binaries.


📈 Skill Progression Context

Learning about offensive frameworks strengthens understanding of:

  • adversary behavior
  • post-exploitation techniques
  • detection engineering

This knowledge will later support:

  • threat hunting
  • detection rule creation
  • SOC investigations.