Black Hat Session: Next-Generation Post-Exploitation in Cobalt Strike

Event: Black Hat USA

Location: Las Vegas, Nevada

Format: Arsenal

Track: Malware

Recent advances in Windows AI/ML APIs now enable the direct integration of AI/ML models into post-exploitation DLLs, allowing them to run within active Cobalt Strike sessions for enhanced on-target classification. This work presents two examples of such integration. The first leverages a custom-trained model to detect passwords in text extracted from documents. The second adapts an open-source embedding model into a compatible format, enabling semantic search capabilities within the target environment.

Aug
06
Wednesday
Aug 06, 2025
12:00 pm
Meet Your Presenter

Steve Salinas

Sr. Cybersecurity Researcher, Development - Fortra Cobalt Strike

Steve is a Marine Corps veteran who has leveraged his expertise throughout his career to develop and contribute to offensive security tools, often collaborating with diverse technical teams.