National Cyber Warfare Foundation (NCWF)

Inside CnaEmulator: standing up a teamserver-free harness for Aggressor Script development


0 user ratings
2026-09-30 11:30:59
milo
Red Team (CNA)
"Inside

CnaEmulator is a standalone Java harness that validates .cna Aggressor Script syntax, mocks Beacon APIs, and executes BOFs via COFFLoader64.exe for authorized tool developers and researchers.








Tooliterat0r/CnaEmulator — standalone emulation and testing harness for Cobalt Strike Aggressor Scripts
CategoryJava development/testing harness for offensive tooling
Primary UseValidating .cna syntax, mocking Beacon APIs, and regression-testing BOF aliases without a teamserver or GUI client
Safe UseIntended for security researchers, tool developers, and BOF authors working in authorized lab environments and controlled development workflows
Telemetry NotePurely a local development tool; it launches no network infrastructure, and defenders should note that BOF execution occurs in-process via COFFLoader64.exe on the analyst's own machine, leaving only local process and stdout traces

Anyone who has written a Cobalt Strike Aggressor Script knows the friction: the natural edit-test loop for a .cna file traditionally demands a licensed teamserver, a connected GUI client, and at least one live Beacon session before an alias can be exercised end to end. iterat0r/CnaEmulator attacks exactly that bottleneck. It is a standalone, general-purpose development, emulation, and testing harness, written in Java, that compiles and validates .cna scripts against the real Sleep 2.1 engine, mocks the Aggressor API surface, and even executes Beacon Object Files in memory through COFFLoader64.exe — all without a single piece of Cobalt Strike infrastructure running.


The architecture is best understood as three layers stitched together by a thin CLI. The first layer is the parsing core: the CnaEmulator.java class bridges the Sleep engine, so the check action performs genuine compilation rather than regex-based linting. The README claims it accurately catches runaway strings, unescaped characters, parser syntax errors, and missing delimiters, reporting exact file line numbers. That detail matters, because .cna scripts are Sleep source at heart, and shallow syntax checkers routinely miss the failure modes that actually break script loading on a real teamserver.


The second layer is API emulation. CnaEmulator reimplements the documented Aggressor function catalog — process injection, token manipulation, filesystem, network, and GUI callback APIs — returning realistic mock values or positive non-error results. The idea is that a script's control flow can be exercised fully offline: aliases resolve, guard clauses fire, argument counts validate, and blog/berror/btask messages format correctly to stdout. Functions like beacon_command_register, beacon_commands, and beacon_command_detail maintain a live command catalog, which is what powers the tool's interactive help system.


The third layer is where the harness gets genuinely interesting for BOF authors. bof_pack implements native Little-Endian serialization matching Cobalt Strike's datap binary format — 'i' for 4-byte integers, 's' for shorts, 'z' for length-prefixed null-terminated strings, 'Z' for wide UTF-16LE strings, and 'b' for length-prefixed binary buffers, each with a 4-byte length prefix. The harness intercepts beacon_inline_execute($bid, $bof_data, "go", $packed_args), converts the packed arguments to hex, and spawns COFFLoader64.exe go as a child subprocess, streaming its console output live to stdout. In practical terms, you get the argument-marshalling contract of the real Beacon execution path exercised against the same public COFF loader from trustedsec/COFFLoader.


Operationally, the project is Windows-centric and self-contained. The repository ships cna_emulator.bat as the recommended launcher, which handles JDK discovery, classpath assembly, and path resolution. Prerequisites are a Java JDK 17+ with JAVA_HOME set, Sleep 2.1 as sleep.jar (locatable via a SLEEP_JAR environment variable or placement in the root/CnaEmulator directory), and COFFLoader64.exe in the root or pointed to via COFFLOADER_PATH. Four actions drive everything: check for syntax validation, run for single alias execution with live BOF dispatch, test for automated batteries, and console for an interactive beacon> prompt with command history and per-alias help.


The test action deserves attention because it encodes a whole methodology for regression-testing offensive tooling. CnaEmulator auto-discovers companion suites named

 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.