Cobalt Strike
Cobalt Strike is an adversary simulation and red team operations platform built around its Beacon payload and Malleable C2 framework. Operated by Fortra, LLC, it serves government agencies, financial institutions, healthcare providers, and security consultancies.
- Company typePrivate
- Founded2012
- HeadquartersWashington, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Cobalt Strike does
Cobalt Strike is a commercial adversary simulation and red team operations platform founded in 2012 by Raphael Mudge and operated today as a product brand within Fortra, LLC following Fortra's 2020 acquisition. The platform enables security teams to emulate advanced persistent threats (APTs) by replicating adversary tactics, techniques, and procedures against customer environments, testing not just vulnerabilities but also detection, response, and blue team readiness. Customers include U.S. government agencies, financial institutions, healthcare organizations, large enterprises, and security consulting firms.
Cobalt Strike firmographics
Firmographics- Name
- Cobalt Strike
- Legal name
- Fortra, LLC
- Website
- https://www.cobaltstrike.com/
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Cobalt Strike is an adversary simulation and red team operations platform built around its Beacon payload and Malleable C2 framework. Operated by Fortra, LLC, it serves government agencies, financial institutions, healthcare providers, and security consultancies.
- Ownership category
- akta.pro rank
Cobalt Strike industry classification
Industry- Product category
- Adversary Simulation and Red Team Operations Software
- NAICS
- Other Scientific and Technical Consulting Services (54169), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industries
- IT Risk Management (ITRM) (HDADAIAD), Security Architecture & Engineering Advisory (Zero Trust, IAM, Network) (BPAKADAF)
Keywords
Where Cobalt Strike is headquartered
LocationHeadquarters
- HQ city
- Washington
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Cobalt Strike business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations
Revenue model
- Software Licensing: Enterprise software licensing model with quote-based pricing. Cobalt Strike is sold as an annual license with tiered pricing based on organizational needs. Bundles with Core Impact and OST available at discounted rates. Professional support and training are offered as add-ons.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise annual license with quote-based pricing |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels7 records
Cobalt Strike product offering
Product offeringCore offering
Cobalt Strike is a software platform for adversary simulations and red team operations, providing a post-exploitation agent (Beacon) and covert command-and-control channels for emulating advanced persistent threat behavior during security assessments. It enables operators to customize network indicators through Malleable C2 profiles, extend tradecraft via the Arsenal Kit (UDRL, Sleepmask Kit, Mutator Kit, BeaconGate), automate workflows through a REST API, and collaborate on team-based operations. The platform is sold as enterprise software with annual licensing and is interoperable with Fortra's Core Impact and Outflank Security Tooling products.
Product overview
Cobalt Strike is a unified adversary simulation and red team operations platform built around its signature Beacon payload and malleable C2 framework. The core platform (Cobalt Strike) is complemented by extensibility tools including the Arsenal Kit (customizable toolkits for threat emulation), REST API (for scripting and automation), User-Defined Reflective Loaders (UDRL), and User Defined Command and Control (UDC2) for custom C2 channels. The Community Kit provides over 100 user-contributed extensions. As part of Fortra's cybersecurity portfolio, Cobalt Strike interoperates with Core Impact (automated pen testing) and Outflank Security Tooling/OST (evasive attack simulation), available individually or bundled together in the Advanced Bundle, Red Team Suite, Offensive Security Suite, and Elite Bundle. Training offerings include Cobalt Strike Certified Operator (CSCO) and partnership courses with Zero-Point Security for Red Team Operations, BOF Development, and UDRL/Sleepmask Development. Cobalt Strike Research Labs provides exclusive tools and techniques for bundle customers.
Differentiator
Problem solved
Functional benefit
Products and services
- Cobalt Strike Adversary simulation and red team operations platform built around its signature Beacon payload and Malleable C2 framework, providing post-exploitation capabilities for emulating advanced persistent threat behavior. Sold as an annual enterprise license with quote-based pricing through Fortra's direct sales organization.
- Core Impact Automated penetration testing software from Core Security that efficiently exploits vulnerabilities, providing certified exploits, Rapid Penetration Tests (RPTs), and multi-vector testing capabilities. Interoperable with Cobalt Strike through session passing, tunneling, and shared BOF APIs.
- Outflank Security Tooling (OST) Advanced offensive security toolset created for experienced red teamers, explicitly developed to bypass defensive measures. Includes tools for payload generation, Office intrusion, steganography, lateral movement, and covert C2 operations, integrating directly with Cobalt Strike via BOFs and reflective DLL loading.
- Advanced Bundle Product bundle combining Core Impact and Cobalt Strike, providing unified pen testing and red teaming capabilities with interoperability features including session passing and SOCKS tunneling, available at discounted bundle pricing through Fortra sales.
- Red Team Suite Product bundle combining Cobalt Strike and Outflank Security Tooling (OST) for sophisticated attack simulations. Includes access to Cobalt Strike Research Labs tools and Cobalt Strike Certified Operator (CSCO) training.
- Offensive Security Suite Comprehensive suite combining Core Impact, Cobalt Strike, and OST for holistic security testing methodology. Provides exclusive Cobalt Strike Research Labs access plus both CSCO and CICO operator training.
- Elite Bundle Advanced bundle combining Fortra VM (vulnerability management), Core Impact (penetration testing), and Cobalt Strike with OST (threat emulation) for comprehensive security assessment.
- Cobalt Strike Certified Operator Training I (CSCO I) Introductory training course created in collaboration between Cobalt Strike and Zero-Point Security, teaching fundamental features of Cobalt Strike for security professionals new to red teaming.
- Red Team Operations I Training Zero-Point Security course providing knowledge and skills necessary to excel in adversary simulation exercises with Cobalt Strike. Includes certification: Red Team Operator.
- Red Team Operations II Training Zero-Point Security advanced course providing skills necessary to operate against modern defenses with Cobalt Strike. Includes certification: Red Team Lead.
- BOF Development & Tradecraft Training Zero-Point Security course teaching how to write and unit test Beacon Object Files (BOFs) for use in Cobalt Strike and other C2 frameworks.
- UDRL & Sleepmask Development Training Zero-Point Security course teaching students how to apply low-level Windows knowledge and offensive tradecraft in writing User-Defined Reflective Loaders and Sleepmask components for Cobalt Strike.
Quantifiable outcome
- Over 700 healthcare security incidents reported in 2024 with ~186 million people affected; red teaming can help identify vulnerabilities before exploitation
- +3 more outcomes
Companies that use Cobalt Strike
Customer profileNamed customers4 records
Segments5 records
Ideal customer profiles4 records
Cobalt Strike technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
Feature10 records
Cobalt Strike partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and minor.
- FortracoreFortra (formerly HelpSystems) acquired Cobalt Strike in 2020 to add to its Core Security portfolio. Cobalt Strike is now part of Fortra's comprehensive cybersecurity portfolio alongside Core Impact and Outflank Security Tooling. Fortra provides enterprise sales, support, and ongoing development resources.
- Outflank Security Tooling (OST)coreOST is a curated set of offensive tools developed with Cobalt Strike in mind. Many OST tools integrate directly using BOFs including Kerberos interaction, novel coercion techniques, and O365 token extraction. OST's Payload Generator enhances Beacon's evasiveness. Outflank was acquired by Fortra in 2022 and its team collaborates closely with Cobalt Strike R&D.
- Core ImpactcoreCore Impact is an automated pen testing tool with interoperability with Cobalt Strike via session passing and tunneling. Beacon can function in both tools, and Core Impact's certified exploits can be launched directly through Beacon. Both products are part of Fortra's Core Security portfolio and research teams collaborate on interoperability enhancements.
- Zero-Point SecuritycoreZero-Point Security, a CREST-approved training operator, created Red Team Ops 1, Red Team Ops 2, BOF Development, and UDRL/Sleepmask Development courses in collaboration with Cobalt Strike. The Cobalt Strike Certified Operator (CSCO) training is jointly developed. Daniel Duggan (RastaMouse), founder of Zero-Point Security, joined Fortra in 2026.
- Community Kit ContributorsminorCobalt Strike's Community Kit is a curated repository of over 100 tools written by users and shared with the community. Contributors submit tools for review and inclusion. The community also contributes to roadmap through feedback on Slack, Discord, and social media.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
Cobalt Strike competitors and assessment
Company assessmentDirect peers
- Core Impact: Automated penetration testing platform and Fortra sister product, with session-passing interoperability with Cobalt Strike; competes for the same offensive-security budget in the same Fortra portfolio.
- Outflank Security Tooling: Evasive offensive toolset now part of the Fortra family alongside Cobalt Strike; many OST tools integrate directly with Beacon via BOFs, making it both a peer and a tightly integrated complement.
- Brute Ratel: Commercial C2/adversary-simulation framework positioned as a direct alternative to Cobalt Strike, marketed explicitly to red team operators with comparable evasion and post-exploitation capabilities.
- Scythe: Adversary emulation platform built around a custom C2 (SCYTHE) with purple-team and threat-representative testing workflows that closely overlap Cobalt Strike's core use cases for enterprise red teams.
Broad incumbents
- SafeBreach: Continuous security validation platform that simulates attacker techniques to measure controls; addresses a closely adjacent buyer (security operations leaders) with an automated, less-operator-heavy model.
- AttackIQ: Breach and attack simulation platform offering continuous adversary-emulation testing; competes for the same security-validation budget but with broader enterprise GTM and managed-service options.
- Pentera: Automated security-validation vendor focused on continuous penetration testing; competes for offensive-security budget with a hands-off, operator-light model versus Cobalt Strike's expert-driven workflow.
Emerging players
- Plextrac: Purple-team and reporting platform that ingests red team / pen test findings; while not a C2 competitor, it is increasingly purchased alongside Cobalt Strike to operationalize adversary-emulation programs.
- Mythic: Open-source, cross-platform C2 framework widely adopted by red teams and researchers; provides comparable post-exploitation capabilities to Cobalt Strike at no licensing cost.
- MITRE Caldera: Open-source adversary emulation platform from MITRE that replicates adversary TTPs at the operation level; competes for the same threat-emulation budget with a much lower price point and extensibility story.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Cobalt Strike social profiles
Digital presenceCobalt Strike financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cobalt Strike leadership team
Management profileNumber of profiles
Profiles1 record
Cobalt Strike funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cobalt Strike M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cobalt Strike
What does Cobalt Strike do?
Cobalt Strike is a software platform for adversary simulations and red team operations, providing a post-exploitation agent (Beacon) and covert command-and-control channels for emulating advanced persistent threat behavior during security assessments. It enables operators to customize network indicators through Malleable C2 profiles, extend tradecraft via the Arsenal Kit (UDRL, Sleepmask Kit, Mutator Kit, BeaconGate), automate workflows through a REST API, and collaborate on team-based operations. The platform is sold as enterprise software with annual licensing and is interoperable with Fortra's Core Impact and Outflank Security Tooling products.
Is Cobalt Strike a public or private company?
Cobalt Strike is a private company. It is classified as corporate owned and is currently operating.
When was Cobalt Strike founded?
Cobalt Strike was founded in 2012. It employs 1 to 10 people.
Where is Cobalt Strike based?
Cobalt Strike is headquartered in Washington, United States, in the North America region.
How does Cobalt Strike make money?
One revenue line is on record: software Licensing.
Who are Cobalt Strike's main competitors?
Direct peers on record are Core Impact, Outflank Security Tooling, Brute Ratel and Scythe. Broad incumbents are SafeBreach, AttackIQ and Pentera. Emerging players are Plextrac, Mythic and MITRE Caldera.
Does Cobalt Strike have an API?
Yes. The Cobalt Strike REST API expands functionality through a language-agnostic interface, letting operators script and automate workflows in whatever programming language suits their needs. It provides structured command routes, task tracking that ties commands to their output, and server-side artifact storage that allows the whole team to use the same artifacts, like BOFS, assemblies, and payloads. The result is a foundation for custom clients, AI-assisted workflows via MCP, and tailored automation. Developer documentation is at hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/api/index.html.
What industry is Cobalt Strike in?
Cobalt Strike's product category is Adversary Simulation and Red Team Operations Software. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of HDADAIAD, IT Risk Management (ITRM). Its NAICS code is 54169 and its SIC code is 7373.