Why is it that so much cybercrime gets committed using Cobalt Strike? A tool originally developed to help red teams mimic the behavior of attackers, it became a tool of the attackers. How did that happen? Why does it still happen? What does it mean for detection and attribution in the future? And perhaps most importantly, can we stop them from using our tools against us?