> For the complete documentation index, see [llms.txt](https://f1rstbyt3.gitbook.io/hacking-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://f1rstbyt3.gitbook.io/hacking-notes/command-and-control/cobaltstrike/listeners.md).

# Listeners

#### Try deploy two types i.e. HTTPs and DNS incase one gets caught other beacon looks more discreet

jump via smb

make a redundant egress beacon - when using smb if you create a beacon half way&#x20;

Make new outbound once further machiens are compromised using different domain&#x20;

### DNS:&#x20;

always ensure you have a high TTL (1hour +) on your domain - normal IOC if domain has low TTL

#### dns\_idle:

changes nslookup response from 0.0.0.0 to custom value

#### dns\_stager\_subhost

&#x20;removes .stage.12345 from the dns response and replaces it with the custom value

### HTTP:

### HTTPs:

Try not to use a letsencrypt cert

### SMB:

enumerate named pipes:

```powershell
[System.IO.Directory]::GetFiles("\\.\\pipe\\")
```
