Attackers continue to use legitimate tools and “living off the land” tactics to exploit victims. Cobalt Strike is marketed by its makers as “software for adversary simulations and red team operations” The trouble with detecting and blocking such attacks is that they’re designed to look legitimate. Organizations must monitor for both, to better identify potential intrusions, says cybersecurity firm Sekoia. In March, Microsoft warned that attackers were wielding Azure “LoLBins,” aka “Living off the Land” with an extra helping of hacker lulz.”]
Source: https://www.databreachtoday.com/blogs/block-this-now-cobalt-strike-other-red-team-tools-p-3167

