Cobalt Strike by Core Security is a threat emulation tool that provides a post-exploitation agent and covert channels for adversary simulations and red team exercises. It allows companies to emulate the tactics of a long-term embedded threat actor in an IT network. Cobalt Strike's Malleable C2 enables changing network indicators to resemble different malware. Beacon, Cobalt Strike's post-exploitation payload, simulates advanced attacker behavior during adversary simulations and red team engagements. It can gain an initial foothold by being embedded into an executable, added to a document, or delivered as a client-side exploit. Beacon can perform reconnaissance, execute commands, and deploy additional payloads. Cobalt Strike’s Command and Control (C2) framework is easily modifiable to meet operator needs. Users can incorporate personalized tools or browse tools published by others in the Cobalt Strike user community. Beacon offers communication channels to reduce identification risk. Malleable can change network indicators to mask Beacon activity or simulate real-world ATPs. Egress can occur using HTTP, HTTPS, and peer-to-peer connections via TCP or named pipes using SMB. The Cobalt Strike Arsenal Kit includes customizable tools for simulating real-world adversary tactics. Operators can use tools like the Sleep Mask Kit and User Defined Reflective Loaders to tailor software operations for each engagement. Cobalt Strike has multiple reporting options for data synthesis and analysis. Report types include interoperable products.