Cobalt Strike Hunting — DLL Hijacking/Attack Analysis

Michael Koczwara
6 min readAug 17, 2021

DLL Hijacking via Cobalt Strike & Attack Analysis.

Agenda

  • Hijack Execution Flow: DLL Search Order Hijacking.
  • Payload extraction from the PCAP (VT, Triage, and CyberChef Analysis).
  • Attack Analysis.
  • DLL Hijacking via Cobalt Strike/Sysrep.

--

--